Privacy Notice
How we process personal data under UK GDPR.
Last updated: 4 October 2026
This Privacy Notice explains how Nikah AI Limited ("GigBlend", "we", "us") uses personal data when you use the Platform, under the UK GDPR and the Data Protection Act 2018.
Controller: Nikah AI Limited, Office 1216 Fitzrovia, 60 Tottenham Court Road, London, W1T 2EW, company number 17199968.
Contact: privacy@gig-blend.com
Data protection contact: privacy@gig-blend.com
ICO registration: ZC176381
1. Data we collect
- Identity and contact: name, email address, display name, country and time zone
- Account and security: a password hash (never the password), your sign-in sessions with the IP address and browser details recorded when you sign in, and a record that you accepted the terms and confirmed you are 18 or over
- Seller profile: display name, headline, bio, skills and languages, your Stripe Connect account identifier and whether payouts are enabled (no identity documents)
- Orders and money: orders, packages, prices, fees, refunds, payouts and ledger entries, and the statements you make at checkout
- Content: order briefs and files, messages, deliverables, disputes, reviews (published with your name) and reports sent through the report form
- AI processing records: job status, model used, cost and quality-check results for each order
- Technical and audit logs: errors, administrative actions and security events
- Marketing preference: whether you opted in to product updates
We do not hold payment card numbers, bank details, dates of birth or identity documents. Where seller verification needs them, Stripe collects and holds them under its own terms.
2. Where it comes from
From you; from Stripe (payment and Connect account status); from buyers or sellers you deal with on an order; and from people who report content that involves you.
3. Why we use it and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Accounts, orders, messaging and delivery | Contract |
| Taking payment, refunds, payouts and keeping accounts | Contract; legal obligation |
| Producing AI deliverables you buy | Contract |
| Screening briefs and listings for academic cheating and other prohibited work | Legal obligation; legitimate interests (keeping the Platform lawful) |
| Handling reports, moderation and online safety duties | Legal obligation (Online Safety Act 2023); legitimate interests |
| Fraud prevention, security and account protection | Legitimate interests |
| Service emails about your orders and account | Contract |
| Product update emails | Consent (you can opt out at any time) |
| Reporting seller information to HMRC where required | Legal obligation (SI 2023/817) |
| Tax, accounting and legal compliance | Legal obligation |
| Establishing or defending legal claims | Legitimate interests |
We do not use analytics or advertising tools, and we do not use your data to train AI models.
4. AI processing
When you buy an AI or AI-with-review Gig, your brief and files are sent to AI model providers to produce the deliverable, and a separate AI model checks the result. We reach these models through two AI gateway services, OpenCode Zen (opencode.ai) and OpenRouter (openrouter.ai), which pass the request to the model's provider. The models we currently use are developed by Alibaba (the Qwen models), Anthropic (Claude), OpenAI (GPT), DeepSeek and Google (Gemini). An Alibaba model is the one most likely to handle your order, because it sits in every one of our service routes and is also our default; we name it first for that reason rather than alphabetically. We keep this list current, and if you want to know which model produced a specific order, ask us and we will tell you — it is recorded against the order. Whether a gateway or model provider keeps the content of a request, and for how long, is governed by that provider's own terms. Do not include special category data (such as health information) or information about children in a brief unless the Gig needs it.
5. Who we share it with
| Recipient | What for | Where |
|---|---|---|
| OVHcloud | Hosting of the Platform, its database, files and our outgoing email server | United Kingdom |
| Stripe (including Stripe Connect) | Payments, refunds, seller onboarding, identity checks and payouts | UK, EEA and United States |
| OpenCode Zen and OpenRouter, and the model providers they route to | Producing and checking AI deliverables | United States and other countries where those providers operate |
| Cloudflare | DNS for our domain, and routing of email sent to our addresses | Global network |
| Google (Gmail) | The mailbox that receives email sent to our @ addresses | United States and elsewhere |
| The other party to your order | Buyer, seller or staff reviewer, to perform the order | As applicable |
| HMRC and other authorities | Where the law requires | UK |
| Professional advisers | Legal, accounting and tax advice | UK |
We do not sell personal data.
6. International transfers
Some of the recipients above process data outside the UK, in particular in the United States. Where that happens, the transfer relies on the safeguards in that provider's own data protection terms, which for the providers we use are the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or UK adequacy regulations where those regulations cover the provider. We are completing our own written record of which mechanism applies to each provider, and of our risk assessment for each transfer. Until that record is complete we will not claim more certainty than we have: if you want to know the position for a specific provider before you buy, ask us at privacy@gig-blend.com and we will tell you what we have. The AI gateway that receives your order content is OpenCode Zen (opencode.ai); if it is unavailable we fall back to OpenRouter (openrouter.ai). Both are in the United States, and both pass your content on to the model providers listed above.
7. How long we keep it
Most of the periods below are enforced automatically by a scheduled job, not by anyone remembering: deliverable files, security and sign-in logs, closed reports, notifications, email logs, payment-provider event records, action links, sessions and dormant accounts are all swept on a schedule, and for those the period is exact rather than a maximum.
Two are not, and we would rather tell you than imply otherwise. The six-year record of orders, invoices, ledger entries and payouts and the five-year seller-reporting record have no automatic deletion at all. Those are the records tax and reporting law requires us to be able to produce, so the six and five years are minimum periods we must keep them for, not deadlines on which they vanish, and we have deliberately not pointed an unattended job at them. In practice that means we currently keep them indefinitely. If the period that applies to your records has passed and you want them erased, ask us at privacy@gig-blend.com and we will do it and confirm. Everything else in this table is a stopwatch.
| Data | We keep it for | Why that period |
|---|---|---|
| Deliverable files, and the free-text content of your brief | 90 days after the order is settled: accepted or auto-accepted, revisions used up and any dispute window closed | Long enough to re-download work and raise a late complaint. The questions your brief answered are kept; the answers are deleted. |
| Orders, invoices, ledger entries, payouts | 6 years from the end of the accounting period | Finance Act 1998 Sch 18 para 21, and the limitation period for contract claims (Limitation Act 1980 s.5) |
| Seller identity and earnings records for platform reporting | 5 years after the end of the reportable period | The Platform Operators (Due Diligence and Reporting Requirements) Regulations 2023 (SI 2023/817) |
| Messages you send | Deleted when you close your account; attachments expire with the order's files at 90 days | Not needed once the order and any dispute are closed |
| Sign-in and sign-out history | 90 days | Enough to investigate a recent account compromise |
| Other security and admin audit records (moderation, refund, payout and account decisions) | 6 years | They evidence decisions about money and accounts, which can be challenged for 6 years |
| Reports sent through the report form | 12 months after the report is closed | Enough to deal with repeat abuse and challenges to a decision |
| Record that you registered | Kept for the life of the account | It is the evidence that you accepted the terms at sign-up |
| An account that confirmed its email but never bought or sold | Deleted after 365 days with no sign-in | It serves no purpose once dormant |
| An account that never confirmed its email address | Deleted after 90 days with no sign-in, if it has no orders and no seller profile | An unconfirmed sign-up otherwise holds an email address for ever, and the person who owns that address can never register it |
| Notifications | 30 days once read, 180 days otherwise | They restate what is already on your order |
| Record that we emailed you | Address and subject line deleted at 90 days; the template name, outcome and date are kept | Proof of delivery does not require your address |
| Sessions | Expire 30 days after your last visit, and 90 days after sign-in regardless of activity | A sliding session should be convenient, not permanent |
| Password-reset and email-confirmation links | The reset link 1 hour, the confirmation link 24 hours, and both are deleted the moment they are used or replaced by a newer one | A link that opens your account should outlive the walk to your inbox and nothing more |
| Payment provider event records | 90 days | Only the event id, amount and status; never the provider's object |
| Marketing consent | Until you withdraw it | PECR reg 22 |
Closing your account deletes everything above that is not in a statutory row. Where a statutory row applies we keep the record and replace your name and email address with a permanent tombstone, so the books still balance but the record no longer identifies you.
8. Your rights
You have the right to access, correct, erase, restrict or object to the use of your data, to data portability, and to withdraw consent. Some rights are limited where we must keep data by law or for legal claims. You can complain to the Information Commissioner's Office (ico.org.uk), though we would like the chance to help first.
How to use them: sign in and use Account → Your data to download your data as JSON or close your account immediately, or email privacy@gig-blend.com.
9. Children
The Platform is for people aged 18 or over, and everyone confirms their age when creating an account. If we learn that an account belongs to someone under 18, we close it.
10. Security
See the Security page. Report a vulnerability to support@gig-blend.com.
11. Automated decisions
Some decisions are automated: an AI model checks each AI deliverable before release, and briefs and listings are screened for academic cheating and refused if they match. We treat one of them as capable of having a significant effect on you: if an automated screen refuses a listing you wanted to sell, that stops you earning here, so you can require a person to review it. The others — the quality check on a deliverable, and the screen on a brief you submit as a buyer — do not stop you obtaining anything you have paid for: a refused brief takes no money and a rejected draft is regenerated or refunded.
In every case you can require a human review, get an explanation of the decision and contest it. The quickest route is the dispute or message button on the item itself, which reaches us on the platform and does not depend on email; you can also email privacy@gig-blend.com. We do not use automated decisions about you that are based on special category data, and none of them profiles you — they look at the text of the thing being screened, not at the person.
12. Changes
We will update this Notice and the date above when our practices change, and tell you about significant changes.
Questions?
Privacy: privacy@gig-blend.com · Legal: legal@gig-blend.com · See also Contact & company information.