Engineering that respects GDPR by design
UK and EU teams operate under GDPR, the UK Data Protection Act, PECR, and often FCA, MHRA, or sector-specific regimes. Our engineers ship with those constraints in mind from day one β EU-region hosting, data-processing agreements, DPIA-ready architectures, encryption in transit and at rest, and clear controls over which subprocessors touch personal data.
On-prem and open-source LLMs for regulated industries
For UK legal, financial, and healthcare buyers, sending customer data to a third-party model is often unacceptable. We build RAG pipelines that run entirely inside your perimeter, with open-source models (Llama 3, Mistral, Qwen) hosted on your own infrastructure or a UK-region AWS / Azure tenancy. PII redaction, query logging, and access controls are built in.
IR35-friendly, GBP invoicing, London-hour delivery
Our standard engagement is a B2B service contract β outside IR35 for typical project work β with clear scope, deliverables, and control resting with our supplier entity. We invoice in GBP, EUR, or USD, keep London business hours, and can meet in London for workshops and reviews where useful.
What our London clients typically need
π‘οΈGDPR-safe delivery, day one
DPIA-ready architectures, DPAs, and lawful-basis mapping baked into every engagement.
π¦FCA-aware fintech builds
Consumer-duty flows, KYC/AML integrations, and regulated-message controls for UK fintechs.
π©ΊNHS & MHRA-aware healthcare
DTAC / DSPT-friendly architectures, encrypted patient portals, and audit trails.
π€On-prem RAG & LLM deployment
Open-source model deployment inside your UK/EU perimeter β no data leaves the tenancy.
πISO 27001 / SOC 2 readiness
Access reviews, change management, DR, and incident response ready for audit.
βοΈAWS eu-west / Azure UK South
EU-region deployment with UK-aware DPAs and Standard Contractual Clauses handled.
Services we deliver in London
Industries we serve locally
Fintech & FCAHealthcare & NHSLegal & LegalTechInsurancePropTechE-Commerce & RetailMedia & PublishingPublic Sector
Also serving
Frequently asked questions
Are your engagements GDPR-compliant?
Yes. We deliver with EU-region hosting, data-processing agreements, DPIA-ready architectures, and clear controls over which subprocessors touch personal data. Our engineers routinely ship for regulated UK and EU clients.
Is the engagement outside IR35?
Our standard model is a B2B service contract β outside IR35 for typical project work β with clear scope, deliverables, and control resting with our supplier entity, not with the client. We can provide the CEST and SDS supporting documentation your finance team asks for.
Can we host on UK / EU infrastructure only?
Yes. AWS eu-west-1 (Ireland), eu-west-2 (London), Azure UK South and UK West, or GCP europe-west2 (London) β with SCCs and UK IDTA where applicable. On-prem or private-cloud deployment is available for AI workloads that must stay off public cloud.
Can you run RAG entirely inside our UK tenancy?
Yes. For regulated industries we deploy RAG pipelines and open-source LLMs (Llama, Mistral, Qwen) inside your UK-region AWS or Azure tenancy or your on-prem infrastructure. No customer data touches a third-party model API.
Do you invoice in GBP?
Yes. GBP, EUR, and USD invoicing all supported.
Are your developers UK-time-zone aligned?
Our UK-serving team overlaps the full London business day. For lighter engagements, at least 5β7 hours of overlap is standard.