Your data, plainly
Privacy Policy
What we collect, why, and what we'll never do with it — in plain English, because a privacy policy you can't read protects nobody.
Who we are. SilentShift is a trading name of Thomas Jutla, Reading, England. For data protection law, we’re the controller of the personal data described below. Contact: tom@silentshift.co.uk.
Last updated: 29 July 2026.
This website
This site keeps things minimal by design:
- No accounts, no forms, no tracking cookies. The site is static pages.
- If you email us (every contact route on this site is an email link), we receive what you send — your address, your name if it’s in the message, and the contents. We use it to reply and to run any engagement that follows. Email is held in our Google Workspace account.
- Hosting. The site is served by Cloudflare, which processes visitor IP addresses as part of delivering and securing any website it serves — that’s standard server operation, under Cloudflare’s own privacy policy.
- If we add analytics in future, this policy will be updated first and the tool will be a privacy-respecting one.
During an engagement
- Access to your systems. To do the work we need access — preferably an account you create for us in each platform (it can be switched off in one click and leaves a clear record of what we did), or where a platform doesn’t support that, credentials you share with us. Any shared credentials are kept in an encrypted password manager, never in plain text, and never used for anything but the agreed work.
- When the work ends, revoke our access. Remove our accounts and change any passwords we were privileged to. We’ll remind you at handover — it’s on the checklist, and we’d rather you were safe than polite.
- Everything we see is under NDA. We sign a mutual non-disclosure agreement before work starts, so the data we’re privy to in your systems is protected contractually as well as by this policy. The NDA template is published here — not shared, not removed, not repeated.
- Your business data stays yours. Systems we build run in accounts held in your name; we access them only to do the agreed work. We don’t copy your customer data into our own systems beyond what’s needed to do the job, and we delete working copies when the job is done.
- Contact details of the people we work with (names, work emails, phone numbers) are kept for running the engagement, invoicing, and our legal obligations — kept for the engagement plus 6 years (the limitation period for contracts), then deleted.
- Third-party platforms we set up for you (hosting, AI providers, analytics and so on) process data under their privacy policies, under your contract with them. We’ll point you at the relevant policies when we recommend a platform.
- Our lawful bases are: performing a contract with you, our legitimate interest in running and promoting our business, and legal obligation (tax and accounting records).
What we never do
- We never sell personal data.
- We never use your business data to train AI models.
- We never move data out of your accounts into ours beyond what the agreed work needs.
Your rights
Under UK GDPR you can ask us for a copy of your personal data, ask us to correct it, delete it, restrict how we use it, or object to our use of it. Email tom@silentshift.co.uk and we’ll respond within a month.
If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk — though we’d appreciate the chance to fix it first.
A half-hour call costs nothing
I'll ask about six questions and tell you honestly whether this is worth doing.
Book a free half-hour callOr just email me: tom@silentshift.co.uk