Skip to content

Privacy Notice

How we process personal data under UK GDPR.

Last updated: 4 October 2026

This Privacy Notice explains how Nikah AI Limited ("GigBlend", "we", "us") uses personal data when you use the Platform, under the UK GDPR and the Data Protection Act 2018.

Controller: Nikah AI Limited, Office 1216 Fitzrovia, 60 Tottenham Court Road, London, W1T 2EW, company number 17199968.
Contact: privacy@gig-blend.com
Data protection contact: privacy@gig-blend.com
ICO registration: ZC176381

1. Data we collect

  • Identity and contact: name, email address, display name, country and time zone
  • Account and security: a password hash (never the password), your sign-in sessions with the IP address and browser details recorded when you sign in, and a record that you accepted the terms and confirmed you are 18 or over
  • Seller profile: display name, headline, bio, skills and languages, your Stripe Connect account identifier and whether payouts are enabled (no identity documents)
  • Orders and money: orders, packages, prices, fees, refunds, payouts and ledger entries, and the statements you make at checkout
  • Content: order briefs and files, messages, deliverables, disputes, reviews (published with your name) and reports sent through the report form
  • AI processing records: job status, model used, cost and quality-check results for each order
  • Technical and audit logs: errors, administrative actions and security events
  • Marketing preference: whether you opted in to product updates

We do not hold payment card numbers, bank details, dates of birth or identity documents. Where seller verification needs them, Stripe collects and holds them under its own terms.

2. Where it comes from

From you; from Stripe (payment and Connect account status); from buyers or sellers you deal with on an order; and from people who report content that involves you.

3. Why we use it and our lawful basis

PurposeLawful basis
Accounts, orders, messaging and deliveryContract
Taking payment, refunds, payouts and keeping accountsContract; legal obligation
Producing AI deliverables you buyContract
Screening briefs and listings for academic cheating and other prohibited workLegal obligation; legitimate interests (keeping the Platform lawful)
Handling reports, moderation and online safety dutiesLegal obligation (Online Safety Act 2023); legitimate interests
Fraud prevention, security and account protectionLegitimate interests
Service emails about your orders and accountContract
Product update emailsConsent (you can opt out at any time)
Reporting seller information to HMRC where requiredLegal obligation (SI 2023/817)
Tax, accounting and legal complianceLegal obligation
Establishing or defending legal claimsLegitimate interests

We do not use analytics or advertising tools, and we do not use your data to train AI models.

4. AI processing

When you buy an AI or AI-with-review Gig, your brief and files are sent to AI model providers to produce the deliverable, and a separate AI model checks the result. We reach these models through two AI gateway services, OpenCode Zen (opencode.ai) and OpenRouter (openrouter.ai), which pass the request to the model's provider. The models we currently use are developed by Alibaba (the Qwen models), Anthropic (Claude), OpenAI (GPT), DeepSeek and Google (Gemini). An Alibaba model is the one most likely to handle your order, because it sits in every one of our service routes and is also our default; we name it first for that reason rather than alphabetically. We keep this list current, and if you want to know which model produced a specific order, ask us and we will tell you — it is recorded against the order. Whether a gateway or model provider keeps the content of a request, and for how long, is governed by that provider's own terms. Do not include special category data (such as health information) or information about children in a brief unless the Gig needs it.

5. Who we share it with

RecipientWhat forWhere
OVHcloudHosting of the Platform, its database, files and our outgoing email serverUnited Kingdom
Stripe (including Stripe Connect)Payments, refunds, seller onboarding, identity checks and payoutsUK, EEA and United States
OpenCode Zen and OpenRouter, and the model providers they route toProducing and checking AI deliverablesUnited States and other countries where those providers operate
CloudflareDNS for our domain, and routing of email sent to our addressesGlobal network
Google (Gmail)The mailbox that receives email sent to our @ addressesUnited States and elsewhere
The other party to your orderBuyer, seller or staff reviewer, to perform the orderAs applicable
HMRC and other authoritiesWhere the law requiresUK
Professional advisersLegal, accounting and tax adviceUK

We do not sell personal data.

6. International transfers

Some of the recipients above process data outside the UK, in particular in the United States. Where that happens, the transfer relies on the safeguards in that provider's own data protection terms, which for the providers we use are the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or UK adequacy regulations where those regulations cover the provider. We are completing our own written record of which mechanism applies to each provider, and of our risk assessment for each transfer. Until that record is complete we will not claim more certainty than we have: if you want to know the position for a specific provider before you buy, ask us at privacy@gig-blend.com and we will tell you what we have. The AI gateway that receives your order content is OpenCode Zen (opencode.ai); if it is unavailable we fall back to OpenRouter (openrouter.ai). Both are in the United States, and both pass your content on to the model providers listed above.

7. How long we keep it

Most of the periods below are enforced automatically by a scheduled job, not by anyone remembering: deliverable files, security and sign-in logs, closed reports, notifications, email logs, payment-provider event records, action links, sessions and dormant accounts are all swept on a schedule, and for those the period is exact rather than a maximum.

Two are not, and we would rather tell you than imply otherwise. The six-year record of orders, invoices, ledger entries and payouts and the five-year seller-reporting record have no automatic deletion at all. Those are the records tax and reporting law requires us to be able to produce, so the six and five years are minimum periods we must keep them for, not deadlines on which they vanish, and we have deliberately not pointed an unattended job at them. In practice that means we currently keep them indefinitely. If the period that applies to your records has passed and you want them erased, ask us at privacy@gig-blend.com and we will do it and confirm. Everything else in this table is a stopwatch.

DataWe keep it forWhy that period
Deliverable files, and the free-text content of your brief90 days after the order is settled: accepted or auto-accepted, revisions used up and any dispute window closedLong enough to re-download work and raise a late complaint. The questions your brief answered are kept; the answers are deleted.
Orders, invoices, ledger entries, payouts6 years from the end of the accounting periodFinance Act 1998 Sch 18 para 21, and the limitation period for contract claims (Limitation Act 1980 s.5)
Seller identity and earnings records for platform reporting5 years after the end of the reportable periodThe Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023 (SI 2023/817)
Messages you sendDeleted when you close your account; attachments expire with the order's files at 90 daysNot needed once the order and any dispute are closed
Sign-in and sign-out history90 daysEnough to investigate a recent account compromise
Other security and admin audit records (moderation, refund, payout and account decisions)6 yearsThey evidence decisions about money and accounts, which can be challenged for 6 years
Reports sent through the report form12 months after the report is closedEnough to deal with repeat abuse and challenges to a decision
Record that you registeredKept for the life of the accountIt is the evidence that you accepted the terms at sign-up
An account that confirmed its email but never bought or soldDeleted after 365 days with no sign-inIt serves no purpose once dormant
An account that never confirmed its email addressDeleted after 90 days with no sign-in, if it has no orders and no seller profileAn unconfirmed sign-up otherwise holds an email address for ever, and the person who owns that address can never register it
Notifications30 days once read, 180 days otherwiseThey restate what is already on your order
Record that we emailed youAddress and subject line deleted at 90 days; the template name, outcome and date are keptProof of delivery does not require your address
SessionsExpire 30 days after your last visit, and 90 days after sign-in regardless of activityA sliding session should be convenient, not permanent
Password-reset and email-confirmation linksThe reset link 1 hour, the confirmation link 24 hours, and both are deleted the moment they are used or replaced by a newer oneA link that opens your account should outlive the walk to your inbox and nothing more
Payment provider event records90 daysOnly the event id, amount and status; never the provider's object
Marketing consentUntil you withdraw itPECR reg 22

Closing your account deletes everything above that is not in a statutory row. Where a statutory row applies we keep the record and replace your name and email address with a permanent tombstone, so the books still balance but the record no longer identifies you.

8. Your rights

You have the right to access, correct, erase, restrict or object to the use of your data, to data portability, and to withdraw consent. Some rights are limited where we must keep data by law or for legal claims. You can complain to the Information Commissioner's Office (ico.org.uk), though we would like the chance to help first.

How to use them: sign in and use Account → Your data to download your data as JSON or close your account immediately, or email privacy@gig-blend.com.

9. Children

The Platform is for people aged 18 or over, and everyone confirms their age when creating an account. If we learn that an account belongs to someone under 18, we close it.

10. Security

See the Security page. Report a vulnerability to support@gig-blend.com.

11. Automated decisions

Some decisions are automated: an AI model checks each AI deliverable before release, and briefs and listings are screened for academic cheating and refused if they match. We treat one of them as capable of having a significant effect on you: if an automated screen refuses a listing you wanted to sell, that stops you earning here, so you can require a person to review it. The others — the quality check on a deliverable, and the screen on a brief you submit as a buyer — do not stop you obtaining anything you have paid for: a refused brief takes no money and a rejected draft is regenerated or refunded.

In every case you can require a human review, get an explanation of the decision and contest it. The quickest route is the dispute or message button on the item itself, which reaches us on the platform and does not depend on email; you can also email privacy@gig-blend.com. We do not use automated decisions about you that are based on special category data, and none of them profiles you — they look at the text of the thing being screened, not at the person.

12. Changes

We will update this Notice and the date above when our practices change, and tell you about significant changes.

Questions?

Privacy: privacy@gig-blend.com · Legal: legal@gig-blend.com · See also Contact & company information.

Privacy notice: how we use data · GigBlend