Work Focus About Blog Client portal Get in touch
Current focus

Cyber and AI governance,
engineered into every build.

Practice Data-protection engineering, AI governance
Standards UK GDPR · PECR · EU AI Act · NIST AI RMF · ISO/IEC 42001
Scope line Evidence systems and infrastructure, never legal advice
Proof KeyProof, scoped DPIA-first before any code
Why this

Every small venture now handles data a regulator, an insurer, or an enterprise buyer will one day ask about. Most get a website with the data as an afterthought, then discover the gap when a deal, a claim, or a complaint forces the question.

bygild's focus is the layer that answers it: the lawful basis on the form, the retention that actually runs, the consent that was actually recorded, and the assessment written before the code. Governance designed in is cheap and it sells. Bolted on, it is expensive and it embarrasses.

Data protection, engineered

Groundwork authored in-house, applied to every build.

These are not templates bought off a shelf. Each was written for the studio's own regulated work and carries into every engagement that touches personal data.

Article 28 processor DPA

A UK GDPR Schedule 1 Data Processing Agreement signed on every engagement where the studio processes client data. Roles, sub-processors, and breach duties in writing before any data moves.

PECR consent records

Regulation 22(2) record-of-consent on any marketing contact: who consented, to what, when, and from where. The record is the point, not the checkbox.

Article 13 transparency

Every form states what is collected, the lawful basis, how long it is kept, and the person's rights, at the point of submission, not buried in a policy nobody opens.

Retention that runs itself

A 90-day PII anonymisation routine enforces the retention policy automatically. A policy that depends on someone remembering is not a policy.

DPIA before code

On data-sensitive builds, a Data Protection Impact Assessment comes first: what data, why, for how long, and what could go wrong. The assessment shapes the architecture, not the other way round.

Hold less, risk less

Data minimisation as a design rule. The highest-risk data goes to specialist third parties, so the platform itself holds less, secures less, and has less to explain.

AI governance

Small firms are adopting AI faster than they are governing it. The pressure arrives commercially before it arrives legally: an enterprise client's procurement questionnaire asking what AI you use, on what data, with what oversight, and a deal that waits on the answer.

bygild maintains an AI Governance and Acceptable Use Policy mapped to the EU AI Act risk tiers, the NIST AI Risk Management Framework, and ISO/IEC 42001, and is building out this practice for UK SMEs that use AI but have no compliance function: the registers, policies, and evidence that let a small firm answer those questions honestly.

The scope line is deliberate and firm. The studio builds evidence systems and infrastructure: what you run, what it touches, and the record that proves it. It does not give legal advice, and says so on every engagement.

In the work

Not a services page. A working method.

KeyProof is the method applied end to end: verification infrastructure handling photo ID, DVLA licence checks, and e-signed agreements, scoped with a DPIA before the first line of code, a clear lawful basis, and a specialist third party holding the raw ID so the platform never does.

Read the KeyProof case study → About the studio →
Next step

Handling data you are
not sure about?

A free 30-minute call. Tell us what you run and what it touches, and you leave with a clear sense of where you stand, whether or not we work together.

Studiobygild.
BasedLondon, remote-first UK-wide
HoursMon to Fri, 09:00 to 18:00 UK
ResponseWithin one business day
Emailhello@bygild.com