UK GDPR · Data Protection Act 2018
Privacy Policy
Last updated: 7 September 2026
1. Who we are
Beyondizmai is the trading name of Carl Willett, a sole trader based in the United Kingdom. For UK data-protection law, Carl Willett is the data controller for personal data processed through this website and the Beyondizmai service.
Contact: hello@beyondizmai.co.uk
Business address: 102 Phillpott Avenue, Southend-on-Sea, Essex SS2 4RL
This notice explains how we collect, use, store, and protect personal data when you visit our website or use our Technical Site Guard / Core Technical Repair software (continuous technical SEO hygiene and Vision AI ALT-tagging — software, not an agency), in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It is plain-English information, not legal advice.
2. The data we collect
We only collect what we need for the request, payment, and repair flow described on the site. Depending on how you contact us, that may include:
Identity and contact data
Name (or trading name), email address, and any notes you choose to include in a plan request.
Site and onboarding data
Website URL and platform type (WordPress — native now; Shopify, Wix, and Squarespace — coming soon; custom HTML/React — fix file for developer; or “not sure”). Site access credentials (for example Application Passwords or API tokens) are collected only after payment, through encrypted onboarding — never via the public request form or ordinary email.
Payment data
Payments are handled by Stripe. Stripe is the system of record for payment and customer billing data when live; we do not mirror full customer databases. Card details are collected and processed by Stripe; we do not store raw card numbers on our systems. We may receive limited billing metadata from Stripe (for example payment status, amount, and the email tied to the payment).
Technical and preference data
Basic technical data that your browser may send (such as IP address, browser type, and operating system) when you load the site. On this static site, browser storage is limited to non-PII preferences only (bz-theme and bz-consent in local storage). We do not put names, emails, or site credentials in localStorage or sessionStorage. See the Cookie Policy.
3. How we use your data (legal bases)
Performance of a contract
To reply to your plan request, send a Stripe payment link where payment is due, complete encrypted onboarding after payment, run the local automated Core Technical Repair or Technical Site Guard sweeps you bought, and email you the PDF optimisation report.
Legitimate interests
To keep the website secure, prevent abuse, and improve clarity of the service — balanced against your rights and expectations.
Consent
Where you accept optional analytics (if and when any analytics are enabled) via the cookie banner, or where you ask us to contact you about something that is not strictly required to deliver a purchased service. You can withdraw consent at any time.
Legal obligation
Where we must keep limited records for tax, accounting, or other UK legal requirements.
4. Local processing and minimisation
We minimise what we hold. Payments are handled by Stripe. Site access credentials are collected only after payment, stored encrypted for the job, then deleted. We don’t keep your site content as a long-term archive.
As described on the landing page, AI analysis and code synthesis for your site work are performed locally on private, sandboxed NVIDIA hardware. Website data used for those repairs is not uploaded to public third-party AI clouds. Credentials supplied on the encrypted onboarding form are used by automated scripts to apply fixes and are not meant for human browsing of your files.
5. Sharing your data
We do not sell your personal data. We share it only where needed to provide the service:
- Stripe — payment processing (system of record for payments when live). We may send a Stripe payment link where payment is due; this static site does not embed live Stripe Checkout or card fields.
- Email — plan requests currently use a temporary mailto flow to hello@beyondizmai.co.uk (or you send the same details yourself). Treat the inbox as a PII store: the message is kept minimal (contact, site URL, plan, optional platform/note). Do not put passwords or keys in that email. Your email provider and ours will process that message.
We do not invent or list analytics, CRM, or other processors that are not part of the live site today. If that changes, this policy will be updated.
When this site is served on public hosting, transport security (HTTPS) and related browser protections such as HSTS and Content-Security-Policy are expected at the host/CDN layer. Opening these HTML files locally does not itself send those headers.
6. International transfers
Stripe and some email infrastructure may process data outside the UK. Where that happens, we rely on appropriate safeguards required by UK data-protection law (for example the mechanisms Stripe describes in its own documentation). Ask us if you need more detail for your situation.
7. Retention
We minimise retention. Plan-request emails are kept only as long as needed to reply and arrange payment. Site access credentials are never kept as a standing store: they exist only for an ephemeral job (encrypted at rest for that job), with a time-to-live of at most 7 days, and are deleted when the job completes (or sooner if cancelled). We do not keep your site content as a long-term archive. Stripe holds payment data as the system of record; we do not mirror full customer databases. Limited billing or invoice metadata we receive may be kept longer where UK law requires (for example tax and accounting).
8. Your rights
Under the UK GDPR you can ask us to:
- access the personal data we hold about you;
- correct inaccurate data;
- erase data in certain circumstances (“right to be forgotten”);
- restrict or object to certain processing;
- receive a portable copy of data you provided, where applicable; and
- withdraw consent where processing is based on consent.
Email hello@beyondizmai.co.uk to exercise these rights. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Do not treat this page as formal legal advice.