ServicesContactClient Login

Privacy Policy

Last updated: 18 August 2026 — v01

This is the privacy policy of Selfless Services Ltd, company number 17062047, trading as Build Before We Pitch ("BBWP", "we", "us" or "our"). Our registered office is at Piccadilly Business Centre, Blackett Street, Manchester, United Kingdom, M12 6AE.

This policy explains how we collect, use, store, disclose and protect personal data when people visit our website, request or view a demonstration, communicate with us, become customers, use a service we operate, or otherwise interact with Build Before We Pitch.

You can contact us about privacy using the contact form or contact details published on our website, or by writing to our registered office above. Our dedicated privacy contact is contact@buildbeforewepitch.com.

We are registered with the Information Commissioner's Office (ICO) under registration reference ZC211708 (registered 2 August 2026, expiring 1 August 2027).

This policy applies where we decide why and how personal data is processed and therefore act as controller. Where we process a client’s end-user or customer data solely on that client’s instructions, we generally act as processor and the client remains controller. That processor activity is governed by our customer contract and data-processing terms.

1. The law and our approach

1.1We process personal data in accordance with applicable UK data protection law, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), in each case as amended from time to time, including by the Data (Use and Access) Act 2025.

1.2We apply the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability.

1.3We do not appoint a Data Protection Officer merely by publishing this policy. If the law later requires us to appoint one, we will update our contact information accordingly.

2. Who this policy covers

2.1This policy may apply to website visitors, prospects, business contacts, sole traders, customers, prospective customers, client personnel, suppliers, contractors and other people who communicate with us.

2.2Our services are aimed at businesses and adults. They are not designed for children and we do not knowingly invite children to submit personal data to us.

2.3A customer website or application that we build may have its own privacy notice issued by that customer. If you are an end user of a customer’s service, you should read that customer’s privacy notice because the customer normally decides the purposes for which your information is collected.

3. How we obtain personal data

3.1We may obtain personal data directly from you when you submit a build request, complete an intake form, ask for a quotation, communicate with us, enter an Order, make a payment, provide project materials, request support or otherwise interact with us.

3.2Our website (buildbeforewepitch.com) includes an AI-driven chat assistant. Messages you send through it are processed to generate a response and may be reviewed by us to follow up on your enquiry. The chat interface discloses that you are interacting with an AI assistant, not a human, before you send a message.

3.3We may generate information from your use of our website, portals, demonstration environments or managed services, including technical logs and security events.

3.4We may receive limited information from service providers, payment providers, referral or trade partners, publicly available business sources, or another person at your organisation where this is relevant to a genuine business relationship.

3.5Where we build a private speculative demonstration using material already published by a business on its public website, we may temporarily use publicly available business content and associated contact information to create and present that demonstration. We do not treat public availability as permission to use personal data for unrelated purposes.

4. Categories of personal data we may process

4.1Identity and contact data, such as name, job title, business name, business address, email address, telephone number and other contact details.

4.2Enquiry and project data, such as your brief, build request, desired functionality, technical requirements, business information, instructions, approvals and project communications.

4.3Customer Materials that may contain personal data, such as photographs, text, contact lists, form content, sample data or other materials you ask us to use in a demonstration or project.

4.4Account and access data, such as usernames, account identifiers, permission levels and records relating to access. We do not need to know or retain a plaintext password where a platform can manage credentials securely.

4.5Transaction and billing data, such as quotations, invoices, payment status, transaction references and subscription or hosting status. Full card details are normally processed by the relevant payment provider rather than stored by us.

4.6Technical and usage data, such as IP address, device and browser information, timestamps, page or feature use, diagnostics, logs and security events.

4.7Support and communications data, including emails, messages, call notes, tickets, feedback, complaints and records of actions taken.

4.8Marketing and preference data, including subscription, opt-out and communication preferences.

4.9AI workflow data, where an agreed project uses AI-assisted tools and project content is submitted to or generated through those tools.

5. Special category and highly sensitive information

5.1We do not ordinarily need special category personal data, criminal-offence data or highly sensitive personal information to market or provide standard website and web-application services.

5.2Please do not send such information unless it is genuinely necessary for an agreed project and we have first agreed the purpose, roles and safeguards.

5.3If we are instructed as processor to handle special category or other high-risk Customer Data in a client system, the client is responsible for identifying the lawful basis and any additional condition required by law, and we will apply the agreed processor safeguards.

6. Purposes and lawful bases

The lawful basis depends on the purpose and the person whose information we process. A contract lawful basis can apply where an individual asks us to take a necessary step before entering a contract or where processing is necessary to perform a contract with that individual. Where our contract is with a company or other organisation and we process an employee or representative’s business contact details, legitimate interests will often be the more appropriate basis.

7. Legitimate interests

7.1Where we rely on legitimate interests, we identify the specific interest, consider whether the processing is necessary for that purpose, and balance it against the rights and interests of the individual.

7.2Our legitimate interests may include responding to business enquiries, developing prospective commercial relationships, operating and improving our services, maintaining security, preventing fraud, administering corporate customer relationships, recovering debts, and establishing or defending legal claims.

7.3You may object to processing based on legitimate interests. We will consider the objection in accordance with applicable law.

8. Demonstration builds and prospective customers

8.1A Demo Build may be created before a paid customer relationship begins. We use information supplied with a build request, or limited publicly available business material where appropriate, to evaluate fit and create a demonstration.

8.2We do not use a private Demo Build as a reason to make unrelated use of a prospect’s personal data.

8.3If a prospect does not proceed, we apply the retention approach in clause 18 and delete or anonymise demonstration data when it is no longer needed.

9. When we act as processor for a client

9.1A client may ask us to host or maintain a website, form, database or application through which the client collects personal data from its own users or customers.

9.2Where the client determines the purpose and essential means of that processing and we handle the information only on the client’s documented instructions, the client is controller and we are processor.

9.3In that role we do not use Customer Data for our own unrelated marketing or profiling. We process it to provide the contracted service, maintain security, comply with lawful instructions and meet our processor obligations.

9.4Our Website and Service Terms include data-processing terms covering instructions, confidentiality, security, sub-processors, assistance, breaches, audits, deletion and international transfers.

9.5If we and a client decide jointly why and how particular personal data is processed, the parties will document any required joint-controller arrangement rather than treating the role as processor by default.

10. Sharing personal data

10.1We do not sell personal data.

10.2We may disclose personal data where reasonably necessary to providers and professional advisers that support our business or Services, including:

10.2.1cloud hosting, deployment, content-delivery, domain and infrastructure providers;

10.2.2development, repository, monitoring, testing, security and support platforms;

10.2.3AI or automation providers used for an agreed workflow;

10.2.4email, CRM, communications and project-management providers;

10.2.5payment processors and financial service providers;

10.2.6analytics providers, subject to the cookie and storage/access rules described below;

10.2.7accountants, insurers, legal advisers and other professional advisers;

10.2.8regulators, courts, law-enforcement bodies or public authorities where disclosure is required or permitted by law.

10.3Where a provider acts as our processor, we require appropriate contractual and security protections. Some providers act as independent controllers for their own regulated or operational purposes, for example certain payment providers.

10.4If our business or relevant assets are sold, reorganised or transferred, personal data may be disclosed to appropriate prospective or actual transaction parties subject to confidentiality and data-protection requirements.

11. AI providers and project content

11.1Where an agreed project uses AI-assisted tools, the information submitted to an AI provider depends on the task. It may include code, prompts, excerpts of Customer Materials or technical context.

11.2We seek to minimise personal data submitted to AI tools and choose providers and settings that we reasonably consider appropriate for the project and risk.

11.3We do not intentionally submit special category data or highly sensitive personal data to an AI provider unless that processing is expressly agreed and an appropriate legal and contractual basis is in place.

11.4Third-party AI providers may operate outside the UK. Any restricted transfer of personal data is handled in accordance with clause 15.

12. Payment information

12.1Where a third-party payment provider handles a payment, full payment-card information is normally entered into and processed through that provider’s systems rather than stored by us.

12.2We may receive transaction references, payment status, limited payment-method information and billing details needed to administer the account, issue refunds, keep financial records and deal with disputes.

13. Direct marketing

13.1We may send marketing about our own services where permitted by law. The rules depend on the recipient and communication channel.

13.2Where consent is required, we will seek it through an appropriate affirmative action. Where we lawfully rely on legitimate interests for business-to-business marketing, we will consider reasonable expectations and privacy impact.

13.3Every marketing email we send should provide a clear way to unsubscribe or object. You can also object by contacting us.

13.4We may keep a minimal suppression record after an opt-out so that we can respect the preference and avoid sending further marketing.

14. Cookies and other storage or access technologies

14.1Our website and online services may use cookies, local storage, pixels, scripts or similar technologies to store information on, or access information from, a user’s device.

14.2Some technologies do not require consent where a PECR exception applies. This may include technologies used solely for transmitting a communication, those strictly necessary to provide a service requested by the user, and qualifying technologies used solely for statistical purposes or to adapt appearance or functionality.

14.3Where we rely on the statistical-purpose or appearance/functionality exception, we will provide clear information and a simple, free means to object, and we will keep the use within the conditions of that exception.

14.4Where no exception applies, we will obtain prior consent before using the relevant non-essential technology. Advertising, cross-site tracking and profiling technologies will not be treated as exempt merely because they also produce analytics.

14.5Our consent or preference mechanism should allow users to make appropriate choices and later withdraw consent or object as easily as reasonably practicable.

14.6The technologies actually used may change as our website develops. We will keep our user-facing cookie information and controls aligned with the technologies and purposes we deploy.

15. International transfers

15.1Some service providers may process personal data outside the United Kingdom.

15.2Where a transfer is a restricted transfer under UK data protection law, we will use a lawful transfer route. Depending on the recipient and destination, this may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework for an eligible certified recipient, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another permitted safeguard or exception.

15.3Where appropriate safeguards require a transfer risk assessment, now referred to in legislation as the data protection test, we will assess whether the standard of protection will be materially lower after transfer and apply supplementary measures where required.

15.4You may contact us for more information about the safeguard used for a particular transfer where that information is relevant to you.

15.5If we target or monitor people in the EEA in a way that brings processing within the EU GDPR, we will assess and comply with any additional EU GDPR obligations, including any representative requirement that applies. We do not appoint an EU representative merely because a website is technically accessible from the EEA.

16. Security

16.1We use technical and organisational measures that we consider appropriate to the nature of the personal data and the risk, which may include access controls, authentication, encryption in transit, secure configuration, logging, backup controls, supplier due diligence, vulnerability management and incident response.

16.2No online system is completely secure. You should use strong credentials and notify us promptly if you suspect unauthorised access to an account or system we manage for you.

16.3Where we act as processor, security obligations are also governed by the applicable data-processing terms.

17. Automated decision-making

17.1We may use automation to assist development, administration, security or workflow tasks.

17.2We do not currently use solely automated processing to make a decision about a prospect or customer that produces legal effects or similarly significant effects on that individual.

17.3If that changes, we will assess the applicable legal requirements and update the relevant privacy information before introducing the processing where required.

18. How long we keep personal data

18.1We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Our normal starting points are:

18.1.1Prospect and non-converting demo records: normally up to 6 months after the last substantive contact or demonstration activity, unless a shorter period is requested or a longer period is reasonably needed for an active dispute, legal claim, fraud/security issue or documented business reason.

18.1.2Customer project and contract records: normally for the duration of the relationship and up to 6 years after completion or termination where needed for contractual, tax, accounting or legal-claim purposes.

18.1.3Invoices and accounting records: for the period required by applicable tax and accounting law, commonly at least 6 years where relevant.

18.1.4Technical and security logs: normally up to 12 months, unless a shorter operational period is sufficient or a longer period is reasonably required to investigate a security incident or legal issue.

18.1.5Support and complaint records: for as long as reasonably needed to resolve the matter and retain an appropriate record, taking account of limitation, regulatory and accountability needs.

18.1.6Marketing records: until you unsubscribe or we determine that continued marketing is no longer appropriate; a minimal suppression record may be retained to honour an opt-out.

18.1.7Customer Data processed as processor: as instructed by the Customer and the applicable contract. After termination, deletion from backups may occur through the normal secure backup cycle, normally within 90 days unless a different technical period is documented.

18.2We may anonymise information so that it no longer identifies an individual and retain the anonymised information for statistics, security or service improvement.

19. Your data-protection rights

19.1Subject to the conditions and exemptions in applicable law, you may have rights to:

19.1.1be informed about how your personal data is used;

19.1.2request access to personal data we hold about you;

19.1.3ask us to correct inaccurate or incomplete personal data;

19.1.4ask us to erase personal data in appropriate circumstances;

19.1.5ask us to restrict processing in appropriate circumstances;

19.1.6object to processing based on legitimate interests and object to direct marketing;

19.1.7receive certain personal data in a portable format where the right applies;

19.1.8withdraw consent at any time where processing is based on consent, without affecting processing already carried out lawfully;

19.1.9obtain safeguards and other information relating to certain international transfers; and

19.1.10challenge qualifying solely automated decisions where the law provides that right.

19.2We may need to verify identity before acting on a rights request. We will respond within the statutory period and may extend, refuse or charge a reasonable fee only where applicable law permits.

20. Data protection complaints

20.1If you are concerned about how we use personal data, please raise a data protection complaint using the contact form or privacy contact details published on our website, or write to our registered office. You can also email us directly at contact@buildbeforewepitch.com.

20.2We will acknowledge receipt of a data protection complaint within 30 days, take appropriate steps to investigate it without undue delay, keep you informed where appropriate and communicate the outcome.

20.3You also have the right to complain to the Information Commissioner’s Office (ICO). We would appreciate the opportunity to address the concern first, but you are not required to do so before contacting the ICO. Our ICO registration reference is ZC211708.

21. Accuracy and changes to your information

21.1Please tell us if personal data relevant to an active relationship changes so that we can keep appropriate records accurate.

21.2If you have an account with a third-party platform used for the Service, you may also be able to update information through that platform.

22. Changes to this Privacy Policy

22.1We may update this policy to reflect changes in our business, technology, providers or law.

22.2The current version will be published through our website and the ‘Last updated’ date will be changed. Where a change materially affects an ongoing processing activity and law requires direct notice, we will provide appropriate notice.