Legal

Privacy notice

Last updated: 19 July 2026

bygild ("we", "us", "bygild") is a software studio operated by Khalid Mohamed, sole trader, based in London, United Kingdom. We build websites, portals, and digital products for small UK ventures. This notice explains what personal information we handle when you visit bygild.com, contact us, or use a client portal we host, and what your rights are under the UK GDPR and the Data Protection Act 2018.

Two roles, two privacy positions

bygild handles personal data in two distinct ways, each with a different legal basis. This notice covers both.

  • As data controller, for: direct enquiries by email, phone, or the contact form, any correspondence that follows, and any business-to-business outreach to prospective clients (currently paused, see below).
  • As data processor, for: the personal data that our clients hold in the sites and portals we build and host for them (for example, Noor Hair & Beauty and OneGoal FC). In that arrangement the client is the controller and we process the data only on their written instructions under a separate Article 28 arrangement.

What we collect when you visit bygild.com

The public site is a brochure. It does not set advertising or analytics cookies, and it does not run third-party trackers. The third parties invoked when a page loads are:

  • Cloudflare, sitting in front of bygild.com to provide the content delivery network, basic DDoS protection, and cookieless Web Analytics. Cloudflare may record your IP address, request headers, and similar technical signals in short-lived security logs. Personal data may transit international Cloudflare edge nodes under the safeguards described below.
  • Google Fonts, currently used to serve the typeface stylesheet. We are migrating to self-hosted fonts on the bygild.com public surface. This change will remove the only outbound third-party font request from the public site.

There is no comment box, no newsletter signup, and no account creation on the public site. The only way to actively submit personal data through bygild.com is the contact form or a direct email.

What we collect when you contact us directly

If you email hello@bygild.com, call us, or submit the contact form, we receive the contact details and the contents of your message. Where the form is used, we also record your IP address and browser/OS string for rate-limiting and abuse prevention (stripped after 90 days), the submission timestamp, and the page you came from if your browser sends a referrer. We hold this in our mailbox and, where relevant, in a simple record so we can carry on the conversation.

Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)) in responding to your enquiry and, where you are asking us to quote for or begin work, steps taken at your request prior to entering a contract (Article 6(1)(b)).

Outreach to prospective clients

From time to time we contact organisations we think would benefit from our work. This outreach is currently paused. When it runs, and where the recipient is a corporate subscriber (a registered company, charity, or similar), we rely on legitimate interests (UK GDPR Article 6(1)(f)) and the PECR business-to-business exemption to the direct-marketing rules. Every outreach message includes a clear identifier, a real reply address, and a one-tap unsubscribe instruction. We default to not contacting individual subscribers (sole traders, residential addresses, named-person email patterns) until we can confirm they are a corporate subscriber. Anyone who opts out is added to a permanent suppression list so we do not contact them again. To opt out, reply with the word "unsubscribe" or email hello@bygild.com.

Lawful basis for processing

We rely on the following UK GDPR Article 6(1) bases, depending on the activity:

  • Contract (Art 6(1)(b)): portal access for clients, work delivered under a signed agreement, and pre-contract steps taken at your request.
  • Legal obligation (Art 6(1)(c)): accounting, tax, and statutory record keeping.
  • Legitimate interests (Art 6(1)(f)): responding to enquiries, security logs, business-to-business outreach as described above, and the general running of the studio.
  • Consent (Art 6(1)(a)): where we ever ask for it explicitly. You can withdraw consent at any time at hello@bygild.com.

Client portals (where bygild is processor)

Some clients use a portal we host at bygild.com/clients/portal/. It uses session cookies (strictly necessary, no consent required under PECR Reg 6(4)). When a client uploads data through the portal (opening hours, services, gallery photos, testimonials, contact-form submissions from their public site), bygild acts as a data processor on their behalf. The Article 28 arrangement between bygild and each client sets out the technical and organisational measures we apply, the sub-processors we use, and the data return and deletion process at the end of the engagement.

If you are a member of the public who has used a client's public site (for example, booking at noorhairdressers.com), the controller is that client, not bygild. Contact them directly to exercise your rights, and consult their own privacy notice for full detail.

Software we build for clients

bygild builds and maintains software for its clients as the contractor and developer, including KeyProof (keyproof.co.uk). Where a client operates its own live product, that client is the controller of its own users' data and runs its own privacy notice. bygild does not control that production data through this site.

Internal admin surface

bygild.com/app is a private surface used only by Khalid Mohamed for running the studio. It is locked behind passkey login, served over HTTPS only, and never indexed.

Sub-processors and infrastructure providers

The third parties that may handle personal data on our behalf or on our infrastructure:

  • Cloudflare, Inc. (United States) - content delivery network, security, cookieless analytics in front of bygild.com and most client sites. Self-certified under the UK Extension to the EU-US Data Privacy Framework; an International Data Transfer Addendum (IDTA) is in place as a fallback safeguard.
  • Namecheap UK Ltd (Stellar shared hosting, United Kingdom) - PHP web hosting and IMAP mail for bygild.com and client subdomains. UK-based.
  • Resend, Inc. (United States) - transactional email delivery for portal notifications and outreach. UK-to-US transfer covered by the UK Extension to the EU-US Data Privacy Framework, IDTA fallback.
  • Backblaze, Inc. (United States) - encrypted offsite backups of portal data. UK-to-US transfer covered by the UK Extension to the EU-US Data Privacy Framework, IDTA fallback.

We do not sell, rent, or share personal data with any third party for their own marketing purposes.

Cookies

bygild.com sets two first-party cookies, and asks for your consent before the non-essential one:

  • gild_consent - records whether you accepted or declined the visitor-count cookie, so the banner does not reappear. Set once you make a choice; expires after 180 days. Strictly necessary to honour your preference (PECR Reg 6(4)).
  • gild_vid - a random identifier used only to count unique visitors. It holds no personal data and does not track you across other sites. Set only if you click "Accept" on the cookie banner, and removed if you decline; expires after 180 days.

Cloudflare may also set short-lived strictly necessary cookies to protect the site against attacks (PECR Reg 6(4) exemption, no consent required). The client portal uses a session cookie for login, also strictly necessary. We do not run advertising, marketing, profiling, social-media, or third-party analytics cookies anywhere.

How long we keep your data

  • Email, phone, and contact-form correspondence: up to 24 months from your last contact, then deleted, unless we are required to retain it for accounting reasons. The contact form itself stores only the details you enter (name, email, phone, message); it does not log your IP address or browser.
  • Outreach records: 12 months from last contact for active prospects, then archived; anyone who unsubscribes is added to a permanent suppression list (the minimum personal data needed to honour the opt-out).
  • Portal data (where bygild is processor): for the duration of the engagement plus 30 days, then deleted unless the client asks us to extend.
  • Accounting and tax records: six years, as required by HMRC.
  • Cloudflare security logs: up to 30 days, retained by Cloudflare and accessible to us only for incident review.

International data transfers

Some of our sub-processors (Cloudflare, Resend, Backblaze) operate from the United States. Each transfer relies on the UK Extension to the EU-US Data Privacy Framework where the recipient is self-certified, with the ICO's International Data Transfer Addendum (IDTA) as a fallback. Web hosting and mailbox storage are UK-based.

Your rights

Under the UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access: ask for a copy of the personal data we hold about you
  • Rectification: ask us to correct anything inaccurate or incomplete
  • Erasure: ask us to delete your data ("right to be forgotten")
  • Restriction: ask us to limit how we use your data
  • Portability: ask for your data in a structured, machine-readable format
  • Objection: object to processing based on legitimate interests, including direct marketing
  • Withdraw consent: where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out

To exercise any of these, email hello@bygild.com. We respond within one calendar month. There is no charge. Where bygild holds your data as a processor on a client's behalf, we will pass your request to that client (the controller) and support them in answering it.

Complaints

If you are unhappy with how we handle your personal data, you have the right to complain to the Information Commissioner's Office (ICO):

  • Online: ico.org.uk/concerns
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

ICO registration

bygild is registered with the Information Commissioner's Office as a data controller. Our registration reference is [ICO reference, to be confirmed].

Changes to this notice

We may update this notice from time to time. The "last updated" date above shows when. Material changes that affect how we process your data will be communicated directly to anyone whose data is affected.

Contact

Data controller: Khalid Mohamed, trading as bygild, sole trader, London, United Kingdom.

Privacy questions: hello@bygild.com

← Back to bygild.com