wirely.

Privacy Policy

Last updated: August 2026

This policy covers wirely.co.uk and the Wirely client portal. Wirely is a trading name of Byter Ltd (registered in England and Wales, company number 11372197), whose registered office is 33 Cavendish Square, London W1G 0PW.

When we are the controller, and when we are not

There are two different kinds of personal data here and they are not governed the same way.

Byter Ltd is the controller of the data described in this policy — enquiries, assistant applications and records, client account and billing details, and the contents of the portal insofar as it is our record of the service. That is the data your rights below apply to.

We are a processor of the personal data inside a client's own systems that an assistant works with on their instructions — their customers, their suppliers, their staff. The client is the controller of that data and decides what happens to it; we only act on their instructions, as set out in the Data protection clause of our terms. If you are a customer of one of our clients and want to exercise a right over your data, ask them — we will help them answer you, but we cannot act on it ourselves.

What we collect

If you enquire about hiring an assistant — your name, email address, and optionally your company, phone number, the role you need, an estimate of hours, and whatever you write in the message field.

If you apply to work as an assistant — the form asks only for your name, email address, country and the discipline you are applying in. Applying does not create an account: it creates a record that a person at Wirely reads and decides on. Only if we accept you do we create a login, and only then are you asked for anything else.

If you go on to complete your assistant setup — the six steps ask for a good deal more, because we are taking someone on rather than answering an enquiry: your phone number, date of birth, home address, an emergency contact, your skills, tools and languages, the days and hours you work, and your tax status. Your hourly rate is agreed with us and set by us — you do not enter it. You upload photo ID, proof of address, your signed agreements and your CV. You also give us the account details you want to be paid into.

Special care with two of those. Your uploaded documents are held in private storage that is not readable from the public internet and is only reachable through short-lived links we issue to you and to our staff. Your payment details are encrypted before they are stored, with a key that is never given to the database, and every single time a member of staff reveals them we record who did it, when, and why — that record is written before the details are shown, so an unlogged look is not possible.

With either form — the page you submitted from, the referring page, any campaign tags in the URL, and your browser's user-agent string. We also store a salted, one-way hash of your IP address so we can rate-limit submissions. We do not store the address itself and the hash cannot be reversed to recover it.

If you use the client portal — your account details, the tasks you raise, the messages and files exchanged on them, and the time your assistant logs against them.

If you work as an assistant — a record of the time you spend on each client: how many minutes, against which task, what you wrote about it, and, when you use the timer, the moment you started and the moment you stopped. We also record what you asked us to approve, what we decided, and any reason we gave. This exists so you are paid correctly and so a client can be shown what was done for them; it is not attendance monitoring, we do not track what is on your screen, and a timer left running for more than ten hours is discarded rather than recorded.

Also if you work as an assistant — the invoices you raise with us, including the period, hours, rate and amount, and what we decided about each one. And any end-of-day reports you write: what you got done, anything in your way, and what you plan to pick up next. Reports are read by Wirely staff and are never shown to a client, which is enforced by the database rather than by our remembering — the table has no policy that would let a client account read a single row of it.

How we use it

Enquiries and applications are used to respond to you and to decide whether we can work together. Portal data is used to deliver the service you are paying for and to show you what was done. We do not sell your data, and we do not use it for advertising.

Lawful basis

For enquiries and the first step of an assistant application we rely on legitimate interests — you contacted us and expect a reply. For the rest of an assistant's setup, and for portal data, we rely on performance of our contract with you, or steps taken at your request before entering one. Identity documents are collected to satisfy our obligation to check who we are engaging. For analytics we rely on your consent, which you give or withhold through the banner and can change at any time.

AI processing

Where an assistant asks for a first draft on a task, the task's content and any written procedures on your account are sent to Anthropic's Claude API to produce that draft. A human assistant reviews and edits every draft before it reaches you, and you can see both the draft and the final version. Anthropic processes this data as our sub-processor and does not use it to train its models. If you would rather no task content was processed this way, tell us and we will turn it off for your account.

Publishing assistant profiles

Once an assistant is verified, we may publish a profile of them on our public roster so businesses can see the kind of people we work with. These profiles do not name anyone. They carry a reference such as WL-7K2M, the disciplines the assistant covers, a short description we write ourselves, the skills we select, their timezone, working days and hours, an experience band and a rough availability band. They do not carry a name, a photograph, contact details, an address, a country or town, or what the assistant is paid. A client learns who an assistant is only after we have matched them.

A business that has sent us a brief can see a fuller version of the same profiles: a written account of how the assistant works, the tools they work with and the sectors they know. That link is emailed to them and works for thirty days. The fuller version withholds exactly what the public one withholds — the extra text is written by us, and no additional detail from an assistant's own record is released at either tier.

This reduces what a reader can work out, but it does not make the data anonymous: we still hold it next to the assistant's identifying record, so it remains personal data and every right below still applies to it. We list an assistant only after they are verified, we write the public description ourselves rather than republishing what they wrote for us, and an assistant can see exactly what is published about them on their own profile page. Any assistant can ask to be taken off the roster at any time, for any reason or none, and we will remove them.

Where a business asks about a particular profile, we record which reference they asked about alongside their enquiry, so we can answer it.

Who else processes your data

  • Supabase — database and portal authentication
  • Vercel — website and application hosting
  • Resend — transactional and notification email
  • Anthropic — AI drafting, as described above

Where your data goes

Our assistants work from a number of countries, and some of them are outside the UK. We recruit worldwide and match people on the hours a client needs covered rather than on where they live, so an assistant working on a UK client's account may be accessing that account from outside the UK.

Where personal data is transferred outside the UK, we rely on the UK Government's adequacy regulations where the country is covered by one, and otherwise on the International Data Transfer Addendum to the European Commission's standard contractual clauses, or an equivalent safeguard. Every assistant is separately bound by the non-disclosure agreement and data protection policy they sign with us before they are assigned to anybody, which carry the same obligations in either direction.

Assistants work inside a client's own systems on permissions that client grants — not on a copy of their data — so the client keeps the ability to see and remove that access at any time. Our own service providers listed above are established in the UK, the EEA or the United States, and each is engaged under terms including the transfer safeguards above.

If you are a client and you need to know which countries apply to your account specifically, email us and we will tell you. If a proposed assistant's location would not work for you, say so before we match you and we will match you with somebody else.

How long we keep it

Client enquiries that do not become accounts are kept for up to 24 months, so we recognise you if you come back to us.

Assistant applications, including anything you upload during setup, are kept on file after a decision — including if we turn you down — in case a suitable client comes along later and we want to approach you again. We do not delete them on a timer. If you would rather we removed yours, email us and we will, and the email we send when we turn someone down says so explicitly.

Client account and task data is retained for the life of the account and for six years afterwards, which is the period we may need it for tax and contractual records.

You can ask us to delete anything we hold about you at any point, whatever the periods above — see Your rights below.

Cookies and local storage

Wirely sets very little, and nothing at all for advertising. There are no third-party tracking cookies on this site.

These are the only two things we store in your browser. Set out as a list rather than a table so it reads on a phone without scrolling sideways.

  • sb-<project>-auth-token — an essential cookie that keeps you signed in to the portal. Set only when you sign in, and cleared when you sign out or it expires. Without it the portal cannot know who you are, so it cannot be switched off.
  • lpn_consent_v1 — not a cookie but a local storage entry, which means it stays in your browser and is never sent to us. It records whether you accepted or declined analytics so the banner stops asking. It lasts until you clear this site's storage.

Analytics. If you accept in the banner, we load Vercel Analytics to count page views. It is cookie-free and does not build a profile of you or follow you to other sites. It is not loaded at all unless you accept, and declining costs you nothing on this site.

To change your mind, use the control at the bottom of this page. It takes effect immediately, and turning analytics off is exactly as easy as turning it on.

Your rights

Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to processing, or ask us to restrict it. Email hello@wirely.co.uk and we will respond within one month. If you are not satisfied you can complain to the Information Commissioner's Office at ico.org.uk.

Contact

For anything on this page, email hello@wirely.co.uk. Written enquiries can be sent to Byter Ltd at 33 Cavendish Square, London W1G 0PW.

You have not been asked yet — the banner will appear on your next page. Changing it takes effect immediately — you do not need to reload.