Article 28 processor DPA
A UK GDPR Schedule 1 Data Processing Agreement signed on every engagement where the studio processes client data. Roles, sub-processors, and breach duties in writing before any data moves.
Every small venture now handles data a regulator, an insurer, or an enterprise buyer will one day ask about. Most get a website with the data as an afterthought, then discover the gap when a deal, a claim, or a complaint forces the question.
bygild's focus is the layer that answers it: the lawful basis on the form, the retention that actually runs, the consent that was actually recorded, and the assessment written before the code. Governance designed in is cheap and it sells. Bolted on, it is expensive and it embarrasses.
These are not templates bought off a shelf. Each was written for the studio's own regulated work and carries into every engagement that touches personal data.
A UK GDPR Schedule 1 Data Processing Agreement signed on every engagement where the studio processes client data. Roles, sub-processors, and breach duties in writing before any data moves.
Regulation 22(2) record-of-consent on any marketing contact: who consented, to what, when, and from where. The record is the point, not the checkbox.
Every form states what is collected, the lawful basis, how long it is kept, and the person's rights, at the point of submission, not buried in a policy nobody opens.
A 90-day PII anonymisation routine enforces the retention policy automatically. A policy that depends on someone remembering is not a policy.
On data-sensitive builds, a Data Protection Impact Assessment comes first: what data, why, for how long, and what could go wrong. The assessment shapes the architecture, not the other way round.
Data minimisation as a design rule. The highest-risk data goes to specialist third parties, so the platform itself holds less, secures less, and has less to explain.
Small firms are adopting AI faster than they are governing it. The pressure arrives commercially before it arrives legally: an enterprise client's procurement questionnaire asking what AI you use, on what data, with what oversight, and a deal that waits on the answer.
bygild maintains an AI Governance and Acceptable Use Policy mapped to the EU AI Act risk tiers, the NIST AI Risk Management Framework, and ISO/IEC 42001, and is building out this practice for UK SMEs that use AI but have no compliance function: the registers, policies, and evidence that let a small firm answer those questions honestly.
The scope line is deliberate and firm. The studio builds evidence systems and infrastructure: what you run, what it touches, and the record that proves it. It does not give legal advice, and says so on every engagement.
KeyProof is the method applied end to end: verification infrastructure handling photo ID, DVLA licence checks, and e-signed agreements, scoped with a DPIA before the first line of code, a clear lawful basis, and a specialist third party holding the raw ID so the platform never does.
A free 30-minute call. Tell us what you run and what it touches, and you leave with a clear sense of where you stand, whether or not we work together.