RSA.Irish · Legal v2026-08-14.3

Privacy Policy

How RSA.Irish processes learner account data, local learning progress, support correspondence and security records.

Effective: 14 August 2026Contact: Freersa.Irish@gmail.com
Brand clarification: RSA.Irish uses “RSA” as an acronym for Rural Speed Ambition. It does not stand for the Road Safety Authority. RSA.Irish is an independent educational project and is not an official Road Safety Authority, TheoryTest.ie or government service. Nothing on this page removes rights that cannot lawfully be waived.

1. Who controls the data

Data Controller: Stanyslav Metlushko, operator of the RSA.Irish independent educational project. Data-protection and legal contact: Freersa.Irish@gmail.com. RSA.Irish is a project name and does not replace the Controller’s legal identity. If the service is later transferred to a company or other legal entity, this Privacy Policy will be updated before that entity becomes the controller.

2. What the current trainer stores

The learner application stores practice progress, mistakes, settings and local legal-gate state in browser localStorage on the user’s device. When a learner creates or uses an account, the service also processes the registered-account data described below through Supabase authentication and the project database. Learning statistics may be synchronised to the registered account when the user is authenticated.

If you email the project, the project processes the information in your message and associated email metadata in order to respond and keep necessary correspondence records. If you use the Monobank support link, the payment is handled on Monobank’s external service under its own privacy terms.

3. Data processed for registered accounts

Registered account data includes or may include first name, email address, mobile phone number, preferred language, verification/account status, login and activity timestamps, planned test date, learning progress, mock-exam history, bookmarks/mistakes, consent timestamps and legal-policy version, and security/audit information.

4. Purposes and legal bases

Account administration and requested educational service: processing necessary to provide requested account functionality and service.

Security, abuse prevention, audit and service integrity: legitimate interests in protecting users and the service, balanced against user rights.

Legal compliance and handling rights requests: compliance with applicable legal obligations.

Optional communications or analytics, if introduced: a separate lawful basis and consent mechanism will be used where required. The current build does not include advertising cookies or third-party analytics.

5. Recipients and processors

Hosting, database and authentication providers such as Vercel and Supabase process data on behalf of the project subject to their contracts and applicable data-protection requirements. Gmail/Google processes project email. Monobank processes payment-support transactions when the user leaves the site for the external payment page.

The project does not sell personal data. Data may be disclosed where required by law or reasonably necessary to establish, exercise or defend legal claims.

6. International transfers

Some processors may handle data outside Ireland or the EEA. Where GDPR requires safeguards, appropriate transfer mechanisms must be used by the relevant controller/processor.

7. Retention

Local learning progress stays on the device until the user resets progress, clears browser storage, or removes site data.

Registered profile and learning records are kept while the account is active. After a verified deletion request, deletion or anonymisation is scheduled within 30 days, except for narrowly necessary legal, fraud-prevention, security, or dispute records.

Administrative/security audit records are normally retained for 12 months. Support and legal correspondence may be retained for up to 24 months after the matter is closed. Payment-card credentials are not received by RSA.Irish; the external payment provider applies its own retention rules.

These periods are reviewed at least annually and whenever the service’s purposes or processors materially change.

8. Security

RSA.Irish uses reasonable technical and organisational measures for account and admin data, including managed authentication, email verification, restricted database access and multi-factor authentication for administrative access. No internet system is absolutely secure. Do not send passwords or sensitive payment credentials by email.

9. Changes

Material changes to this Privacy Policy will be dated and, where required, brought to registered users’ attention. New processing incompatible with the existing legal basis will not be silently introduced.