Skip to content
Legal

Privacy Policy

One policy covering northbytes.org, the Northbytes client portal, and everything we send.

Effective Date: 25 July 2026

1. Introduction

1.1 Northbytes is a small UK software studio. We build and look after websites, apps and internal systems for other businesses, charities and schools.

1.2 This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what rights you have over it.

1.3 We handle personal data in accordance with the UK GDPR and the Data Protection Act 2018.

1.4 It applies whether you are a visitor to our website, someone who has enquired, a client, a person who works for a client, or a business we have contacted for the first time.

1.5 We have written this in plain English on purpose. If anything here is unclear, ask us and we will explain it properly.

2. Who We Are

2.1 Northbytes is a trading name of Northstarsolutionz Ltd, a company registered in England and Wales under company number 17223975.

2.2 Our registered office is 5 Sandstone Rise, Chatham, England, ME5 9DH.

2.3 Northstarsolutionz Ltd, trading as Northbytes, is the data controller for the personal data described in this Policy. Where we say “we”, “us” or “Northbytes”, that is who we mean.

2.4 For privacy questions and for any request about your data, contact piers@northbytes.org. For anything else, hello@northbytes.org reaches us just as well.

2.5 We are two founders. There is no call centre between you and the people who actually handle your data.

3. What This Policy Covers

3.1 Covered by this Policy

3.1.1 This website, northbytes.org, including the analytics and cookie consent described in Section 5.

3.1.2 The Northbytes portal at portal.northbytes.org — both the client area our clients sign in to, and the internal system our team uses to run the business.

3.1.3 The public links we share with clients: status pages, printable invoices and bug-report forms (Section 9).

3.1.4 The email, printed letters, phone calls and WhatsApp messages we send and receive (Sections 6, 11 and 12).

3.2 Not covered by this Policy

3.2.1 The websites and apps we build and host for clients. On those, the client is the data controller and their own privacy policy applies. Our role there is explained in Section 15.

3.2.2 Apps we publish in our own right that have their own privacy policy — for example our fitness app, The Forge, whose policy is linked from its App Store listing.

3.2.3 Third party websites we link to. Once you leave our site, that site's policy applies.

3.3 Superseded material

3.3.1 This Policy replaces every earlier Northbytes privacy notice, including the one written for our previous AI project-specification system, which is no longer in service.

4. The Northbytes Website

4.1 No accounts, no tracking by default

4.1.1 northbytes.org is a static website. There is nothing to sign up for and no account to create.

4.1.2 We do not use advertising pixels, cross-site tracking, fingerprinting or behavioural profiling anywhere on the site.

4.1.3 Nothing is sent to Google Analytics unless you have explicitly accepted analytics cookies. See Section 5.

4.2 Hosting and server logs

4.2.1 The site is hosted on Fly.io in the London region.

4.2.2 As with any website, serving a page involves your IP address, browser user-agent and the page requested being processed by our hosting infrastructure. This is used to deliver the site and to protect it from abuse, not to build a profile of you.

4.2.3 We do not combine hosting request data with any other data about you.

4.3 The enquiry form

4.3.1 The enquiry form on our contact page currently composes a pre-filled email in your own email application. When you press send, the message travels from your email provider to our Google Workspace inbox. We do not run a server that captures the form as you type it.

4.3.2 The details you choose to include — typically your name, email address, an optional budget range and a description of what you want built — are then held as an enquiry, as described in Section 6.

4.3.3 If we later switch the form to submit directly to a form provider, we will name that provider in Section 14 before doing so.

4.4 Data stored in your browser

4.4.1 We store your cookie consent choice in your browser's local storage under the key “northbytes-cookie-consent”, so that we do not ask you again on every visit.

4.4.2 Where a page is passphrase-protected, such as our private demos, your browser remembers that you unlocked it. This is a simple flag; it is not linked to you.

4.4.3 Neither value is sent to us or to anyone else. Clearing your browser data removes both.

5. Cookies and Analytics

5.1 Consent first

5.1.1 We use Google Analytics 4 (property G-CFLHGTHBEX), provided by Google, to understand how many people visit the site and which pages are useful.

5.1.2 Google Analytics is not loaded at all until you accept it in the cookie banner. Until then, no analytics cookies are set and no data reaches Google.

5.1.3 If you reject, Google Analytics is never loaded and your choice is remembered.

5.2 What the cookies are

5.2.1 If you accept, Google Analytics sets first party cookies named _ga and cookies beginning _ga_. They distinguish one visitor and one session from another.

5.2.2 These cookies last up to two years.

5.2.3 We set advertising signals — ad storage, ad personalisation and ad user data — to denied. Google Analytics 4 does not log or store IP addresses.

5.2.4 We use no other cookies. In particular, the client portal does not use cookies for tracking; its sign-in cookie is described in Section 8.

5.3 What we measure

5.3.1 Pages viewed, approximate location derived at the point of collection, device and browser type, and how visitors move through the site.

5.3.2 Two specific events: when someone completes an enquiry, and when someone clicks one of our contact details. We record that it happened, not what you wrote.

5.3.3 We use this to decide what to write and fix next. We do not use it for advertising, retargeting or profiling, and we never sell it.

5.4 Changing your mind

5.4.1 You can withdraw or change consent at any time using the “Cookie Settings” link in the site footer.

5.4.2 Withdrawing stops collection immediately, switches on Google's opt-out flag for our property, and expires the analytics cookies already in your browser.

5.4.3 Our legal basis for analytics is your consent, and only your consent.

6. When You Contact Us

6.1 Email, phone and WhatsApp

6.1.1 You can reach us by email, by phone, or by WhatsApp on the number published on our contact page. All three are your choice; none is required.

6.1.2 Email to us is received and stored in Google Workspace. WhatsApp messages are handled by WhatsApp Ireland, part of Meta: the message content is end-to-end encrypted in transit, but the fact that you messaged us, and your phone number, are visible to WhatsApp under its own terms. If you would rather not use Meta's service, email or phone us instead.

6.1.3 We may keep a short written note of a phone call — what was discussed and what was agreed. We do not record calls.

6.2 What we do with an enquiry

6.2.1 We use your details to reply, to scope what you are asking for and to quote honestly for it.

6.2.2 An enquiry that turns into a conversation is recorded in our portal as a client or lead record — see Section 7.

6.2.3 An enquiry that goes nowhere is kept as mail in our inbox and deleted in the ordinary course of clearing it out.

6.2.4 We do not add enquirers to a marketing list, and we do not send newsletters.

7. Client Records We Hold

7.1 General

7.1.1 We run our business from our own portal at portal.northbytes.org. Almost everything we hold about a client lives there, in a Postgres database hosted in London.

7.1.2 The categories below are the complete list. Where a field is free text — a note, a description, a comment — it holds whatever we wrote, so we keep those professional and relevant.

7.2 Client and contact details

7.2.1 For the client organisation: name, company name, status (lead, active or past), email address, phone number, and internal notes.

7.2.2 For each named contact at that organisation: name, email address, phone number and job role.

7.2.3 A “next action” and which of us owns it, so nothing is dropped.

7.3 Notes, meetings and decisions

7.3.1 A dated timeline per client: general notes, meeting records (including the meeting date) and decisions taken, each recorded against whichever of us wrote it.

7.3.2 These are working notes about the engagement. They are internal and are not shown in the client area of the portal.

7.4 Project and delivery data

7.4.1 Projects: name, description, type, status, production and staging URLs, linked code repositories, hosting plan, monthly fee, renewal date and any linked error-monitoring project.

7.4.2 Issues and tasks: titles, descriptions, comments, priorities, due dates, who they are assigned to and when they were completed.

7.4.3 Maintenance records: the checklist run for each week, month, quarter and year, each item's result, any note against it, and which of us checked it and when.

7.4.4 Uptime and error monitoring for the sites we host, described in Section 15.

7.5 Contracts, invoices and money

7.5.1 Contracts: title, type, effective and expiry dates, whether it auto-renews, its monthly value, and the signed PDF itself.

7.5.2 Invoices: invoice number, line items, VAT rate, totals, issue and due dates, and when it was sent and paid.

7.5.3 Income and expense records, including receipts, where an expense is billable to a client.

7.5.4 Payments made by card are handled by Stripe, as described in Section 14. We never see or store full card numbers.

7.6 Files and mail

7.6.1 Files uploaded against a client, project, task, contract or expense: the file itself, its original filename, type, size, who uploaded it and when. Files are stored in S3-compatible object storage or on the application's own disk.

7.6.2 A log of every email the portal sends you: the recipient address, subject and the full message body, together with when it was sent and whether it was delivered. This exists so that we can always tell you exactly what we sent you.

7.6.3 Bug reports submitted through a project's public form, including the reporter's name and email address where they chose to give one.

7.7 Our own team

7.7.1 For the people who work at Northbytes we hold name, work email address, a securely hashed password, role, and a record of sign-in sessions and of any access to the credential vault.

7.7.2 Passwords are hashed with bcrypt and are never stored in a readable form.

8. The Client Portal

8.1 What it is

8.1.1 Active clients can sign in at portal.northbytes.org/client to see the work we are doing for them.

8.1.2 The client area shows: your projects and the work currently open on each; your hosting and maintenance checklists, including every past checklist and exactly what was checked; a summary of errors your site's monitoring has caught; the status of the servers your site runs on; and your contracts, which you can download.

8.1.3 It shows only your organisation's data. Access is scoped to your client record at the database query level, not by hiding things in the interface.

8.2 What the client area deliberately does not show

8.2.1 Our internal notes on your account, including meeting and decision notes and the notes we write against maintenance checklist items.

8.2.2 Commercial fields such as your hosting plan, monthly fee and renewal date, which are queried out rather than merely hidden.

8.2.3 Anything at all belonging to another client.

8.3 Signing in

8.3.1 There is no password. You enter your email address and we email a six-digit code to the address we hold for you.

8.3.2 The code is valid for ten minutes, can be used once, and is deleted when used or replaced.

8.3.3 We limit attempts to five in fifteen minutes per email address, and we give the same response whether or not the address belongs to a client, so the portal cannot be used to find out who our clients are.

8.3.4 Signing in creates a session cookie named nb_client. It is signed, marked httpOnly and, in production, secure — it cannot be read by scripts in your browser. It lasts thirty days if you tick “trust this device”, and otherwise disappears when you close your browser.

8.3.5 Signing out deletes the session on our server as well as the cookie. If your account stops being active, existing sessions stop working immediately.

8.3.6 The portal sets no analytics or tracking cookies of any kind.

10. Credentials and Access to Your Systems

10.1 Delivering and maintaining a system usually means holding credentials for it — hosting, domain registrars, content systems, third party services.

10.2 Credentials are stored in the portal's vault. The username, label and URL are stored as written; the secret itself and any notes are encrypted with AES-256-GCM using a key held only in the application's environment, never in the database or the code.

10.3 Only administrators can open the vault, and every single reveal of a secret is logged with who did it and when.

10.4 Where we mirror code to a client-owned repository, the access token for that repository is encrypted the same way.

10.5 We ask for the narrowest access that does the job, and we will hand credentials back and remove our own access when an engagement ends. If you would rather rotate a credential than trust us to delete it, tell us and we will help you rotate it.

11. Prospects and Cold Outreach

11.1 Why this section exists

11.1.1 We contact businesses who have not heard of us, by email and occasionally by post. Where we did not get your details from you, the law requires us to tell you where we did get them. This section does that.

11.1.2 We contact organisations, at business addresses, about business services. We do not cold-contact private individuals at home.

11.2 Where the details come from

11.2.1 Email prospects: publicly listed business information, sourced through a prospecting tool that compiles business listings from Google Maps. That gives us the business name, trade, phone number, published email address, website, address and town, its public review count, its public social links, and an automated assessment of its website's speed, security and quality.

11.2.2 Letter prospects: the Companies House public register. We look at UK companies incorporated in the last few days whose declared trade is on a shortlist we keep, and take the company number, name, type, incorporation date, SIC codes and registered office address.

11.2.3 All of it is public information. We do not buy marketing lists and we do not scrape private data.

11.3 What we then do

11.3.1 We record the business against a pipeline in our portal, along with notes of any calls or emails, so we know what has been said and by whom.

11.3.2 Email: one first email, then a single follow-up on the same thread about three days later if there is no reply. After that the automatic sequence stops. We send at a deliberately low daily cap and only during UK working hours, Monday to Friday.

11.3.3 Post: a letter drafted for that company and read in full by one of us before it is approved. Nothing is posted without a person approving it. Letters are printed and posted by Stannp and addressed to the registered office.

11.3.4 Every cold email carries our registered company identity and a one-line way to stop: reply “unsubscribe”.

11.3.5 We watch our own outreach mailbox for replies and bounces so that a reply stops the sequence immediately, and an address that bounces is never emailed again.

11.4 Your control over it

11.4.1 Our lawful basis is legitimate interests: promoting a business service to another business, using published business contact details, with a clear opt-out on every message.

11.4.2 You can object at any time, for any reason or none, by replying to any message or emailing piers@northbytes.org. We will stop.

11.4.3 When you opt out, we keep a minimal record of the business and the fact that you opted out. That record exists precisely so that you are never contacted again — deleting it entirely would risk us writing to you a second time.

12. Automated Emails, Letters and Messages

12.1 Automatic messages to you

12.1.1 Sign-in codes for the client portal, sent to the email address we hold for you.

12.1.2 Invoice notices when an invoice is sent, and a reminder if it becomes overdue.

12.1.3 Bug-report updates telling the reporter that a report was accepted, declined or fixed — only where they gave an email address.

12.1.4 Cold outreach emails and letters, as set out in Section 11.

12.1.5 These are service and business messages, not marketing. We do not run a mailing list.

12.2 Automatic messages to us

12.2.1 A weekly Monday summary to each founder covering work due, open maintenance, invoices and renewals.

12.2.2 Reminders about contracts approaching expiry, sites reporting problems and follow-ups falling due.

12.2.3 Some of these reminders are also pushed to a private Telegram chat between the two of us. Those messages can contain a client's or a prospect's business name and a link back to the portal, so Telegram sees that much; the underlying records stay in the portal.

12.3 How our mail is sent

12.3.1 Outbound mail is sent through our own Google Workspace mailboxes. A separate transactional provider, Resend, is configured as a fallback if Workspace is unavailable.

12.3.2 Every message the portal sends is recorded in full in the email log described at 7.6.2.

12.3.3 Physical letters are produced and posted by Stannp, a UK print-and-post service. They receive the recipient company's name and address and the letter text.

13. How We Use AI

13.1 What we use it for

13.1.1 We use AI as a drafting and research tool: writing first drafts of social posts, cold outreach emails and letters, summarising checklists, and helping us query our own records.

13.1.2 Our main AI provider is Anthropic (Claude). Our portal also exposes a connector that lets us ask Claude questions about our own portal records, signed in as one of us. Client and prospect details can therefore be sent to Anthropic's API in the course of that work.

13.1.3 Anthropic processes that data on our instructions as our processor, and does not use data submitted through its API to train its models.

13.1.4 We use Google's Gemini API for web-search research when planning content. It receives search topics, not client data.

13.1.5 We use Fal.ai to generate illustrative images for social posts. It receives an image description, not personal data.

13.2 Where the line is

13.2.1 We do not put credentials, card details or the contents of the vault into any AI system.

13.2.2 We do not use AI to make decisions about people. It drafts; we decide.

13.2.3 Letters are read in full and approved by a person before they are posted. Social content is approved before it is published.

13.2.4 Cold outreach emails are the one exception worth naming plainly: once one of us has chosen a business and queued it, the first email and its single follow-up are drafted by AI and sent automatically within the limits in Section 11. A person chooses every recipient; a person does not read every draft.

14. Our Sub-processors

14.1 General

14.1.1 We keep the list of companies that process data on our behalf deliberately short, and we name all of them here.

14.1.2 Each one is used for a specific purpose, receives only what that purpose needs, and is bound by its own data processing terms.

14.1.3 We do not sell, rent or share personal data with anyone for their own marketing.

14.2 Infrastructure

14.2.1 Fly.io — hosting for this website, the portal and the client sites we host. Our applications and databases run in Fly's London region.

14.2.2 Tigris, the S3-compatible object storage attached to our Fly infrastructure — uploaded files, receipts and contract PDFs.

14.2.3 Sentry — error monitoring for the sites we host, on Sentry's European data region. Explained further in Section 15.

14.2.4 GitHub — source code, issue tracking and, where a client wants their own copy of the code, a mirrored repository they own.

14.3 Communication

14.3.1 Google Workspace — our email, calendar and documents, and the mailboxes our portal sends from.

14.3.2 Resend — fallback transactional email.

14.3.3 Stannp — printing and posting physical letters.

14.3.4 WhatsApp, part of Meta — only where you choose to message us there.

14.3.5 Telegram — internal reminders between the two founders.

14.4 Payments and analytics

14.4.1 Stripe — card payments, and the payment and customer insight Stripe provides on top of them: which invoices were paid, when, and how our customer base is trending. Stripe collects card and billing details directly from you and holds them on its own systems; we receive confirmation and transaction records, never full card numbers. Stripe is certified to PCI DSS Level 1.

14.4.2 Google Analytics 4 — website analytics on northbytes.org only, and only with your consent, as set out in Section 5.

14.5 AI

14.5.1 Anthropic — AI drafting and the portal connector described in Section 13.

14.5.2 Google (Gemini API) — web-search research for content planning.

14.5.3 Fal.ai — image generation for social content.

14.6 Public sources we read from

14.6.1 Companies House — the public register of UK companies, which we read for the letters described in Section 11. It is a source of public data, not a processor acting for us.

14.6.2 A business-listing prospecting tool that compiles public Google Maps listings, used the same way and for the same purpose.

14.7 Changes to this list

14.7.1 If we add a sub-processor that handles client personal data, we will update this list. Clients under an ongoing agreement can ask to be told in advance.

15. Sites We Build and Host for Clients

15.1 Our role

15.1.1 When we build or host a website or app for a client, the personal data of that site's own users belongs to the client. The client is the controller; we are their processor.

15.1.2 We act on the client's instructions, under the terms of our contract with them, and we do not use their users' data for our own purposes.

15.1.3 If you are a user of a site we built for someone else, that organisation's privacy policy applies, and requests about your data should go to them. We will support them in answering you.

15.2 What that involves in practice

15.2.1 Hosting and backups, which means we necessarily have access to the site's database.

15.2.2 Error monitoring through Sentry, which captures technical detail about a failure. That detail can include a user's IP address, browser and the page they were on, and occasionally data submitted to the page. Sentry data is held in the European region and retained for a limited period, typically ninety days.

15.2.3 Uptime and infrastructure status pulled from Fly.io, which contains no personal data.

15.2.4 Maintenance work — dependency updates, security patches, backup restore tests and form testing — carried out to a fixed checklist, the results of which our clients can see in the client portal.

17. How Long We Keep Data

17.1 General

17.1.1 We keep personal data only as long as we need it, and then delete or anonymise it.

17.1.2 The periods below are what we work to.

17.2 Website and analytics

17.2.1 Google Analytics event data: no more than fourteen months.

17.2.2 Analytics cookies: up to two years, or until you withdraw consent, whichever comes first.

17.3 Client data

17.3.1 Client records, project data, notes, files and the email log: for the life of the engagement and for six years afterwards, which matches the period in which a contractual claim can be brought.

17.3.2 Financial records, including invoices, expenses and payment records: six years, as required by HMRC.

17.3.3 Contracts: for six years after they end, or longer where the contract itself requires it.

17.3.4 Credentials: deleted when the engagement ends or sooner on request. The log of who revealed a credential is kept as an audit record.

17.4 Short-lived data

17.4.1 Portal sign-in codes: ten minutes, and deleted as soon as they are used.

17.4.2 Client portal sessions: thirty days at most, and shorter if you did not choose to trust the device.

17.4.3 Error monitoring data: held by Sentry for its retention period, typically ninety days.

17.5 Prospects

17.5.1 Business prospects we are actively working: while there is a realistic prospect of doing business, and no more than twenty-four months from the last contact.

17.5.2 Opt-outs and businesses we decided not to contact: kept as a suppression record for as long as we do outreach, so that we do not contact them again.

18. Security

18.1 Access

18.1.1 Everything in the portal is behind a sign-in. Staff accounts use passwords hashed with bcrypt; client accounts use single-use emailed codes and have no password to steal.

18.1.2 Session cookies are cryptographically signed, httpOnly and, in production, secure. Sessions are recorded server-side so they can be revoked.

18.1.3 Both sign-in routes are rate limited to five failed attempts in fifteen minutes.

18.1.4 Staff access is role-based, and the credential vault is restricted to administrators with every access logged.

18.2 Data protection measures

18.2.1 Credentials and their notes are encrypted at rest with AES-256-GCM, using a key that lives only in the application environment.

18.2.2 Client-facing queries name the exact columns they return, so internal and commercial fields cannot leak into the client portal even by accident.

18.2.3 Uploaded files are stored under generated keys rather than guessable paths, and are served only to an authenticated session.

18.2.4 All traffic to our sites and the portal is encrypted in transit over TLS.

18.2.5 Public links to status pages, invoices and bug-report forms use long random tokens, and can be disabled.

18.3 If something goes wrong

18.3.1 We monitor our systems and those we host for errors and outages.

18.3.2 In the event of a personal data breach we will contain and investigate it, notify the Information Commissioner's Office within seventy-two hours where the law requires it, and tell affected people directly where there is a high risk to them.

18.3.3 No system is perfectly secure. We would rather tell you quickly and plainly than manage the news.

19. International Transfers

19.1 Our applications, databases and file storage are hosted in the United Kingdom, in Fly.io's London region. Error monitoring is held in the European Union.

19.2 Some of our suppliers are based in, or process data in, the United States — including Anthropic, Google, Stripe, Fly.io, GitHub and Fal.ai. Using them means personal data can be transferred outside the UK.

19.3 Where that happens we rely on the appropriate safeguards permitted by UK law: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, and where relevant the supplier's certification under the UK extension to the EU–US Data Privacy Framework.

19.4 You can ask us which safeguard applies to a particular supplier and we will tell you.

20. Your Rights

20.1 What you can ask for

20.1.1 Access — a copy of the personal data we hold about you, and an explanation of what we do with it.

20.1.2 Rectification — correction of anything inaccurate or incomplete.

20.1.3 Erasure — deletion, where we have no continuing lawful reason to hold it.

20.1.4 Restriction — that we pause processing while a dispute about accuracy or lawfulness is resolved.

20.1.5 Objection — to processing we base on legitimate interests. For direct marketing, including our outreach, this right is absolute and we will always stop.

20.1.6 Portability — a copy in a common, machine-readable format, and transmission to another provider where that is technically feasible.

20.1.7 Withdrawal of consent — for analytics, at any time, without affecting what was lawfully done beforehand.

20.2 How to exercise them

20.2.1 Email piers@northbytes.org. A plain request in your own words is enough; you do not need to cite legislation or use a particular form.

20.2.2 We may ask you to confirm your identity before we act, so that we do not hand your data to someone else.

20.2.3 We will respond within one month. If a request is genuinely complex we may extend that by up to two further months and will tell you why.

20.2.4 We do not charge for this.

20.3 Limits

20.3.1 We may have to keep some data despite a deletion request — most often accounting records we are legally required to hold for six years, and outreach suppression records that exist to keep you off our list.

20.3.2 Where you are a user of a site we run for a client, the client is the controller and your request should go to them; see Section 15.

20.4 Complaints

20.4.1 If you are unhappy with how we have handled your data, tell us first and we will try to put it right.

20.4.2 You also have the right to complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk or on 0303 123 1113.

21. Automated Decision-Making

21.1 We do not make decisions about people by automated means alone that produce legal effects or similarly significant effects on them.

21.2 Our automation schedules work, sends service messages, drafts content and paces cold outreach. It does not decide who we work with, what we charge, or whether to accept a project. Those are human decisions.

21.3 Automated scoring is applied to business websites during prospecting — speed, security and quality — not to people.

21.4 See Section 13 for exactly where AI drafts are reviewed by a person and where they are not.

22. Children

22.1 Our website and portal are aimed at businesses and are not directed at children.

22.2 We do not knowingly collect data about children through them. If you believe we have, tell us and we will delete it.

22.3 Where we build a system for a client that is used by children, for example a school project, the client is the controller and additional protections are agreed with them in the contract.

23. Changes to This Policy

23.1 We update this Policy when what we actually do changes — a new sub-processor, a new part of the portal, a new way of working.

23.2 The current version is always published on this page with the effective date at the top.

23.3 Where a change materially affects clients, we will tell them by email as well.

23.4 This Policy is governed by the laws of England and Wales, and disputes arising from it are subject to the exclusive jurisdiction of the courts of England and Wales.

24. Contact

24.1 Privacy questions and data rights requests: piers@northbytes.org.

24.2 Anything else: hello@northbytes.org.

24.3 Postal address: Northstarsolutionz Ltd, 5 Sandstone Rise, Chatham, England, ME5 9DH.

24.4 Northbytes is a trading name of Northstarsolutionz Ltd, registered in England and Wales, company number 17223975.