Last updated: 2026-10-04
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the operator named below, trading as Fin-Central ("Processor", "we"), and the customer organisation ("Controller", "you").
Fin-Central is a trading name of Nikah AI Limited, a company registered in England and Wales (company number 17199968), registered office Office 1216 Fitzrovia, 60 Tottenham Court Road, London, W1T 2EW. Registered with the UK Information Commissioner's Office (ICO), registration number ZC176381.
Contact: privacy@fin-central.com (data protection) · legal@fin-central.com (legal) · support@fin-central.com (support).
It governs our processing of personal data on your behalf under UK GDPR Article 28 and the Data Protection Act 2018. Where it conflicts with the Terms on data protection, this DPA prevails.
1. Roles
You are the controller and we are the processor of the personal data contained in the accounting, ledger, banking, invoice and contact data you import or sync ("Customer Personal Data"). You are responsible for the lawfulness of that data and for having a lawful basis to provide it to us. You must not upload special category data or criminal offence data except where it is incidentally present in ordinary accounting records.
2. Subject matter, duration, nature & purpose
- Subject matter / purpose: processing necessary to provide the finance-control, reconciliation, forecasting, reporting and AI features of the service.
- Duration: for the term of your subscription and any post-termination export window.
- Nature: collection, storage, organisation, structuring, analysis, retrieval and deletion by automated means.
3. Types of personal data & categories of data subjects
- Types: names, business contact details, transaction/invoice references, payment amounts and dates, and any personal data present in fields you import.
- Data subjects: your customers, suppliers, employees and other contacts represented in your accounting data.
4. Our obligations
We will: 1. Process Customer Personal Data only on your documented instructions (these Terms, this DPA and your use and configuration of the app), unless required by law (and will then tell you unless prohibited). We will tell you promptly if, in our opinion, an instruction infringes UK data protection law. 2. Ensure personnel authorised to process are under a duty of confidentiality. 3. Implement appropriate technical and organisational security measures (UK GDPR Art 32) — encryption in transit, encryption of connector credentials and 2FA secrets at rest (AES-256-GCM), hashed passwords, role-based access, tenant isolation and audit logging. Other ledger data is not encrypted by the application and we do not claim disk-level encryption for it, as described on /trust. 4. Use subprocessors only under written terms imposing equivalent data-protection obligations. You give general authorisation for the subprocessors listed at /legal/subprocessors; we give at least 30 days' notice of any addition or replacement so you may object, and if you do and we cannot reasonably accommodate the objection you may terminate the affected service and we will refund any prepaid fees for the period after termination. We remain liable for our subprocessors' performance. 5. Assist you, taking into account the nature of processing, to respond to data-subject rights requests and to meet your Art 32–36 obligations (security, breach notification, DPIAs, prior consultation). Where a request reaches us directly we answer within one month, extendable by up to two further months for a complex request or several requests (we tell you inside the first month, with the reason), and the period pauses from the day we ask for clarification until the day we receive it — the "stop the clock" provision the Data (Use and Access) Act 2025 added with effect from 5 February 2026. These are the same periods published in our Privacy Policy, deliberately, so that the deadline you are working to and the deadline we are working to are the same one. 6. Notify you without undue delay (and in any event within 72 hours of our becoming aware) of a personal data breach affecting Customer Personal Data, with the information you need to meet your own obligations. 7. On termination, return Customer Personal Data by making the app's export tools available for 30 days, and then delete it on your instruction or when we close the account, except where retention is required by law. Copies in backups are removed as those backups expire (see the Privacy Policy for the periods). 8. Make available information necessary to demonstrate compliance and allow for and contribute to audits. We will first answer reasonable written security questionnaires; where that is not enough, or a regulator requires it, you (or an independent auditor bound by confidentiality) may audit no more than once in any 12 months, on at least 30 days' notice, during business hours, at your cost, and without compromising the security of the service or other customers' data.
5. International transfers
Customer Personal Data is hosted, and backed up, in the United Kingdom. We will not transfer it outside the UK except to a subprocessor named on the subprocessor list, and then only under a valid transfer mechanism (UK adequacy regulations or the UK IDTA / Addendum to the EU SCCs).
6. Liability
Liability under this DPA is subject to the limitations of liability in the Terms.
7. How to execute
This DPA is incorporated by reference when you accept the Terms. If your organisation requires a countersigned copy, email legal@fin-central.com.
8. Complaints about our data handling
To us. Anyone whose personal data we handle — you, your staff, or a data subject represented in the data you import — has the right to complain directly to us under section 164A of the Data Protection Act 2018. Write to privacy@fin-central.com, or use /contact and mark the message as a data-protection complaint. We will acknowledge it within 30 days, take appropriate steps to look into it, and tell you the outcome without undue delay. Where the complaint concerns data we process on your behalf as processor, we will tell you about it so you can discharge your own obligations as controller.
To the regulator. A complaint can also go to the Information Commissioner's Office — ico.org.uk/make-a-complaint, 0303 123 1113. Neither route is a precondition for the other, and complaining to us does not delay or replace a complaint to the ICO or a claim in court.