Capabilities Services Tech FAQ Get in touch

Discover. Deliver. Protect.

Two short engagements to find what's worth building. Four ways to build it. And two productised packs to keep you on the right side of GDPR. Pick what your problem needs.

Two ways to find out what's worth doing.

Before we build anything, we need to know what's worth building. Two short paid engagements. Credited in full against any project that follows.

00 · Workshop
£500

AI Discovery Session

A half-day working session with whoever runs the operation. We map your processes, spot the obvious automation candidates, and rank them by ROI.

  • Half-day on-site or video call
  • Three ranked automation candidates
  • One-page summary you can act on
~4 hours · delivered the same day Book a session →
00 · Audit
£1,500

AI Readiness Audit

A full written report. Workflow analysis, tool recommendations, and a 90-day implementation roadmap you can take to any developer — or to us.

  • Process & data audit across the business
  • Vendor / tooling recommendations
  • 90-day implementation roadmap
  • Credited in full against a follow-on build
~2 weeks · written report Commission an audit →
AI & Dev Lead AI / Dev Sprint Legacy Revision Product Development

Four ways to make it happen.

01

Your AI & Development Lead

Monthly retainer. We own the technical roadmap — AI, dev, integrations — then build it.

From £1,500per month

You don't need a full-time engineering hire. You need someone senior who shows up, owns the technical side of your business — AI, integrations, custom software — and actually builds the things they recommend. That's this.

Engagement
Monthly retainer
Investment
From £1,500/mo
Time to start
Subject to availability
Deliverables/q
Entirely up to you

A real technical roadmap

Mapped to your operation, ranked by ROI, refreshed each quarter. Covers AI, integrations and the custom dev that holds it all together.

Builds, not slide decks

We deliver working software, automations and integrations — not recommendations someone else has to implement.

On call between sessions

Monthly working sessions with leadership. Quick technical questions answered in between, by message.

Tooling and vendor calls

We sit in on demos, evaluate AI and software vendors, and stop you buying things you don't need.

Best fit if: you're an SME owner or operations leader who needs a senior technical contact owning the AI and software side, has a budget under what an agency would charge, and wants one person to land the work — not a timesheet.
02

AI / Development Sprint

One job, fixed price, 2–4 weeks. AI build or straight dev — you know what you're buying.

£2.5k – £10kfixed price

One workflow. Fixed scope. Fixed price. Two to four weeks. You know exactly what you're paying for and exactly what you're getting before we start.

Engagement
Fixed-price project
Investment
£2,500 – £10,000
Build duration
2 – 4 weeks
Outcome
One job, done

Discovery & scoping

We map the workflow as it actually runs today, not how the procedure document says it does.

Build & integrate

Built against your real systems — accounting, CRM, email, file shares — not a demo sandbox. AI, custom code, or both, depending on what the job needs.

Test & hand over

Run in parallel with whatever you do today until you trust the new way. Documentation in plain English, not jargon.

30-day aftercare

Tweaks, adjustments, edge cases caught in the first month — included, no extra invoices.

Best fit if: you have one specific job that needs doing — an automation eating hours every week, an integration nobody's built yet, a small internal tool the team keeps asking for — and you want it solved without signing up to a retainer.
03

Legacy / Unsupported System Revision

Old VB.NET, WinForms, or Access apps brought back to life — modern, supported, AI where it helps.

From £3,000project

The business runs on a piece of software nobody else will touch. VB.NET. WinForms. Access. A C# desktop app the original developer left a decade ago. You can't replace it — too much sits on top — but you want it modern, supportable, and AI-aware. We do that work.

Engagement
Project-based
Investment
From £3,000
Timeline
6 – 14 weeks
Outcome
Modern, supported, AI where it helps

System audit

What the code does, where it's brittle, what depends on it, what it'd cost to keep running for another five years.

Modernise where it counts

Pull the parts that need pulling. Leave the rest. Add APIs so newer tools can talk to it.

AI where it earns its place

Where the work calls for it: AI that reads your documents, answers questions in plain English, and runs the steps that used to need a person. Bolted onto the system you already trust.

Documentation & support

Written so the next person can pick it up. Optional ongoing support if you want continuity.

Best fit if: your business depends on a piece of software a senior engineer once built, the engineer has moved on, and modern dev shops have either quoted you a full rebuild or politely declined. Manufacturing, distribution, trade, and stock-management businesses — this is most often you.
04

Product Development

An idea you want built. We design it, ship it, keep it running.

£8k – £20ktypical MVP

You have an idea. Something only your team understands well enough to build. We act as your engineering team. Design it, ship it, keep it running.

Engagement
Project + ongoing
Investment
£8,000 – £20,000
MVP timeline
8 – 16 weeks
What you get
A real product

Product shaping

We turn an idea into a buildable spec — what's in the MVP, what's deferred, who the first ten customers are.

The whole build

Backend, frontend, integrations, hosting — and an AI layer where the product needs one. One team, one accountable contact.

Operate & iterate

Once it's live we keep it running, watch the numbers, and ship the changes that matter.

Built on what we use ourselves

Same stack we ship StockTracker and EdiMerge on. We've already tripped over the bugs so you don't have to.

Best fit if: you've spotted a gap in your industry, you understand the customer better than anyone, and you need an engineering partner who can ship — not a freelancer who'll ghost you at month three.

Software that touches personal data? Get the privacy pack done first.

GDPR expects more than a privacy policy.

Any system that collects, stores, moves, or makes decisions on personal data carries legal obligations that go well beyond a privacy policy on your website. Two ways to get this done — a focused DPIA for a specific AI tool you're rolling out, or a full GDPR pack covering the system around it.

You probably need a DPIA (Data Protection Impact Assessment) if…
  • Your software (or any AI in it) makes — or supports — decisions about people. Staff, customers, applicants, suppliers.
  • You're processing special-category data — health, race, religion, beliefs, biometrics, sexuality, criminal history.
  • You're monitoring people systematically — productivity tools, email or communication analysis, customer-interaction tracking.
  • You're combining personal data from multiple sources, or sending it to a new processor (cloud provider, LLM API, analytics vendor).
  • You're rolling out AI chatbots, copilots, or LLM tools where staff or customer data goes into the prompts — Claude, ChatGPT, Microsoft Copilot, Gemini, or any custom AI integration.
01

Privacy & GDPR Pack

10-document pack covering DPIA, DPA, risk register, runbooks & more — drafted ready for your DPO or solicitor to review.

From £1,200per system

DPIA-led documentation pack for any system that touches personal data. We assess what you have, send due-diligence questionnaires to your processors, and build the documentation pack around the agreed changes — fixed-price, per system or process flow.

How it works
  1. 01
    Assessment We work through the system and flag the privacy weaknesses worth fixing.
  2. 02
    Processor questionnaires Due-diligence questionnaires go out to any third-party processors — cloud, AI, analytics. Their answers feed the pack.
  3. 03
    Changes You decide which to act on. We incorporate the agreed changes into the pack.
  4. 04
    Draft delivered The full pack — ready for your DPO or solicitor to review.
  5. 05
    One revision One round of revisions after their feedback. Included.
Engagement
Fixed-price per system
Investment
From £1,200
Time to start
~2 weeks
Format
Word + PDF
What's in the pack
  • Data flow diagram + controller/processor map
  • Full DPIA (ICO template — risks identified, mitigated, residual rated)
  • Privacy notice section + Legitimate Interests Assessment
  • Sub-processor register
  • Article 28 Data Processing Agreement (DPA) template
  • Customer trust FAQ
  • Incident response runbook (system-specific scenarios)
  • Vendor due diligence checklist
  • Staff transparency note
  • One-page sales summary you can hand to your customers
Included: one round of revisions after your DPO or solicitor reviews the draft.
We're not your DPO or your solicitor. The pack is drafted for review and sign-off by your own legal/data-protection advisor — not relied on as legal advice.
02

AI Tool DPIA

Focused DPIA for an AI rollout — Claude, ChatGPT, Copilot, Gemini, or any custom AI integration.

From £750per AI tool

Rolling out an AI chatbot, copilot, or LLM tool where staff or customer data goes into the prompts? You almost certainly need a DPIA before go-live. This is the focused engagement to do it.

How it works
  1. 01
    Pre-screen A short questionnaire tells us whether a DPIA is the right tool for this rollout.
  2. 02
    Intake Structured form covering the AI tool, use cases, data going in and out, and your existing controls.
  3. 03
    Clarify Email or short call to fill any gaps — whatever the scope needs.
  4. 04
    Draft & deliver DPIA + risk register, Word + PDF, with one revision after your DPO/solicitor reviews.
Engagement
Fixed-price per tool
Investment
£750 single · £1,200 for 2–3 tools
Time to start
~1 week
Format
Word + PDF
What you get
  • Pre-screen questionnaire — confirms a DPIA is the right tool for this rollout
  • Full DPIA (ICO template, populated from your intake)
  • Provider data block — training-data position, retention, sub-processors, transfer mechanism, DPA reference
  • Risk register with mitigations
  • Lawful basis & necessity / proportionality assessment
  • Staff transparency note (where applicable)
Covers: Claude (Team / Enterprise), ChatGPT (Team / Enterprise), Microsoft 365 Copilot, Google Gemini for Workspace, Azure OpenAI, and custom AI API integrations.
Included: one round of revisions after your DPO or solicitor reviews the draft.
Already a Defy build client? This is bundled with any project that puts an AI tool on personal data.
We're not your DPO or your solicitor. The DPIA is drafted for review and sign-off by your own legal/data-protection advisor — not relied on as legal advice.
Built for SMEs Scope, price and pace sized for the businesses we actually serve — not Fortune 500 budgets.
One person, start to finish The senior who scopes the work also builds it. No account managers, no handoffs, no junior swap-out after sign-off.
Years of shipping working software Not new to this. AI sits on top of a long career of building systems that don't fall over.
Still here after launch Every project includes a defined support period — and an ongoing arrangement if you want continuity.

Not sure which one fits?

Tell us the problem and we'll tell you straight which engagement makes sense — or refer you elsewhere if it isn't us.