Legal

Privacy Policy

Effective date: 25 June 2026 · Last updated: 2 July 2026 · Version 1.1

This Privacy Policy explains how GLYD Limited collects, uses, stores, and protects personal data, and the rights you have over that data. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2026.

Two different relationships

GLYD provides software to law firms and conveyancing practices. The way data protection law applies to us depends on whose data we are handling:

  • As a controller — for personal data about the people who use our service directly: account holders, their staff, website visitors, and people who join our waiting list. This policy is our notice to you about that data.
  • As a processor— for personal data contained in the legal matters a law firm uploads to GLYD (for example, the buyers, sellers, and borrowers in a conveyancing transaction). For that data, the law firm is the controller and decides how it is used. We process it only on the firm's documented instructions.

If you are a client of a law firm that uses GLYD and you want to know how your data is handled, please contact that firm in the first instance; their own privacy notice governs that relationship. Section 9 explains the processor relationship in more detail.

Section 1

Who we are

GLYD Limited (“GLYD”, “we”, “us”, “our”) is a company registered in England and Wales under company number 17238069. We provide software that helps law firms and licensed conveyancers manage the post-completion stage of property transactions.

For the personal data described in this policy, GLYD Limited is the data controller.

You can reach us about anything in this policy at privacy@glydapp.co.uk.

Section 2

The personal data we collect

We collect the following categories of personal data when you use GLYD or interact with us.

Account and identity data

When you register for an account or are invited to one by your firm: your name, work email address, the firm you belong to, your role, and an encrypted record of your password. If you sign in using a Microsoft or Google account, we receive your name and email address from that provider to authenticate you.

Usage and technical data

When you use the service we record activity needed to operate it securely and maintain an audit trail: log-in and log-out events, actions taken within a matter, IP address, timestamps, browser and device information, and session details. Some of this is required for security and to meet the record-keeping expectations placed on legal service providers.

Waiting list and enquiry data

If you ask for early access or contact us, we collect the details you give us — typically your name, email address, firm name, and the content of your message.

Communications data

Records of correspondence between you and us, including support requests and the emails we send you about your account.

Legal matter data

The substantive personal data inside a conveyancing matter — the names, addresses, and financial details of buyers, sellers, borrowers, and other parties contained in uploaded deeds and documents — is uploaded and controlled by the law firm, not by GLYD. We process it on the firm's behalf as described in Section 9. We do not decide what that data is used for, and we do not use it for our own purposes.

Section 3

Why we use your data and our lawful basis

Under UK GDPR we must have a lawful basis for each way we use personal data. The table below sets out what we do and why.

What we do

Lawful basis

Create and manage your account, authenticate you, and provide the GLYD service to you and your firm.

Performance of a contract (with you or your firm), or our legitimate interest in providing the service where no contract is directly with you.

Keep the service secure: rate-limiting, access logging, fraud and abuse prevention, and maintaining an audit trail.

Legitimate interests (keeping the service and its data secure), and compliance with our legal and regulatory obligations.

Respond to your support requests and communicate with you about your account or the service.

Performance of a contract, and our legitimate interest in supporting our users.

Manage our waiting list and respond to early-access enquiries.

Consent, or our legitimate interest in responding to people who contact us.

Meet our own legal, accounting, and regulatory obligations.

Compliance with a legal obligation.

Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests or rights. You can ask us about that assessment using the contact details in Section 14.

Section 4

Who we share data with

We do not sell your personal data. We share it only with the service providers that help us run GLYD, and only to the extent each one needs it. These providers act as our processors, under written terms that require them to protect the data and use it only on our instructions.

Provider

What they do for us

What they handle

Google Cloud (Vertex AI)

AI processing used to read and extract information from uploaded legal documents.

Document contents submitted for extraction. Google does not use this data to train its models, under the Google Cloud Data Processing Addendum.

Fly.io

Application and database hosting (London region).

Account, usage, and matter data held in our database.

Tigris

Object storage for the legal documents uploaded to GLYD (London region).

The uploaded legal documents and the personal data they contain. Governed by Tigris's Data Processing Agreement.

Vercel

Hosting and delivery of our web front-end.

Technical and usage data needed to serve the application.

Resend

Sending transactional emails (for example, account and notification emails).

Recipient email address and email content. Resend retains email content for 30 days, then deletes it.

We keep a current list of our sub-processors and will update this policy when it changes. We may also disclose personal data where we are required to do so by law, by a regulator, or by a court, or to establish, exercise, or defend legal claims.

Section 5

International data transfers

We aim to keep personal data within the United Kingdom. Our application and database hosting is located in the UK (London region), and the legal documents uploaded to GLYD are stored using Tigris object storage in its London (United Kingdom) region.

One of our providers, Resend, processes email data in the United States. Where personal data is transferred to Resend in the US, that transfer is protected by the UK Addendum to the EU Standard Contractual Clauses, incorporated into Resend's Data Processing Agreement. This is a transfer mechanism recognised under UK GDPR.

Some providers may, in the course of delivering their service, route or cache technical data outside the UK. Where that happens, we rely on an appropriate safeguard recognised under UK GDPR (such as the UK Addendum to the Standard Contractual Clauses or an adequacy decision). You can ask us for more detail about the safeguards that apply to any specific transfer.

Section 6

How long we keep data

We keep personal data only for as long as we need it for the purposes set out in this policy, or for as long as we are required to keep it by law.

Data

Retention

Legal documents and matter data (processed on a firm's behalf)

Retained in line with the firm's instructions and the file-retention obligations that apply to conveyancing work — a minimum of seven years from completion. In Tigris object storage this is enforced by an automatic deletion rule.

AI processing logs (records of document extraction)

Automatically deleted after seven years.

Access and security logs

Retained for a minimum of 12 months to support security and audit requirements.

Account data

Retained for the life of the account and deleted, or returned, after the account is closed, subject to any legal retention obligations.

Waiting list and enquiry data

Retained while we operate the waiting list or until you ask us to remove you.

Section 7

How we protect your data

We take technical and organisational measures to keep personal data secure, including:

  • Encryption of data in transit using TLS.
  • Encryption of our database storage volumes at rest.
  • Access controls and role-based permissions, so people can only see the data their role requires.
  • Logging of access and significant actions, to support monitoring and audit.
  • Rate-limiting and account-lockout protections against unauthorised access.
  • Written data protection terms with each of our service providers.

No system can be guaranteed completely secure, but we work to protect your data and to identify and respond to risks.

Section 8

Your rights

Under UK data protection law you have the following rights over your personal data:

Access

To be told whether we hold your data and to receive a copy of it.

Rectification

To have inaccurate or incomplete data corrected.

Erasure

To ask us to delete your data in certain circumstances.

Restriction

To ask us to limit how we use your data in certain circumstances.

Portability

To receive certain data in a structured, commonly used, machine-readable format.

Objection

To object to processing we carry out on the basis of legitimate interests.

Withdraw consent

Where we rely on consent, to withdraw it at any time, without affecting processing already carried out.

Automated decision-making

Rights in relation to automated decision-making, as described in Section 11.

To exercise any of these rights, contact us at privacy@glydapp.co.uk. We will respond within one month. There is normally no charge.

If your request relates to personal data inside a legal matter that we process on behalf of a law firm, we will direct your request to that firm, as they are the controller for that data.

Section 9

When GLYD acts as a processor

When a law firm uploads a legal matter to GLYD, the firm is the controller of the personal data in that matter and GLYD is the processor. This means:

  • We process that data only on the firm's documented instructions.
  • We do not use it for our own purposes, and we never use it to train AI models.
  • We make the same security measures and sub-processor protections described in this policy available to that data.
  • Our handling of that data is governed by a separate Data Processing Agreement between GLYD and the firm.

If you are an individual whose data appears in a conveyancing matter (for example, a buyer or seller), the law firm acting in your transaction is responsible for telling you how your data is used. Please contact that firm to exercise your rights over that data.

Section 10

Cookies and analytics

We use cookies and similar technologies that are strictly necessary to operate the service — for example, to keep you signed in and to keep your session secure. These are required for the application to function. Where we use any cookies that are not strictly necessary, we will ask for your consent and give you a way to opt out.

Section 11

Automated processing and AI

GLYD uses artificial intelligence to read uploaded legal documents and extract structured information from them (for example, names, title numbers, and dates). This is a support tool: the extracted information is presented to a qualified fee earner for review, and the system does not make legal decisions or final submissions on its own. A person remains responsible for reviewing and approving every form and submission.

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement.

The AI processing is carried out using Google Cloud's Vertex AI. The data sent for processing is not used to train Google's models, under the Google Cloud Data Processing Addendum.

Section 12

Children

GLYD is a professional tool intended for use by law firms and conveyancers. It is not directed at children, and we do not knowingly collect personal data from children through the service.

Section 13

Changes to this policy

We may update this policy from time to time — for example, when we add a new service provider or change how the service works. When we do, we will update the “last updated” date above, and where the change is significant we will take reasonable steps to bring it to your attention. We encourage you to review this page periodically.

Section 14

How to contact us or complain

If you have any questions about this policy, or you want to exercise your rights, contact us at:

GLYD Limited

Email: privacy@glydapp.co.uk

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, if you are unhappy with how we have handled your data. We would, however, appreciate the chance to address your concerns first.

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk

GLYD Limited is a company registered in England and Wales (company number 17238069). © 2026 GLYD Limited. All rights reserved.