Legal

Subprocessors

Last updated 4 October 2026 · Version 6

Last updated: 2026-10-04

We use the third-party providers below to deliver the service. We engage each under written terms with data-protection obligations equivalent to our own, and we remain responsible for their processing. We give at least 30 days' notice of additions or changes (see the DPA); to be notified, email privacy@fin-central.com.

Several rows are conditional: we integrate with them only when the corresponding feature is enabled, and while it is off no data reaches that provider at all. Rows marked "not in use" or "not yet available" receive no data.

SubprocessorPurposeLocationWhen used
OVHcloud (OVH SAS)Application & server hostingUnited Kingdom (London)Always
PostgreSQL, run inside this deploymentPrimary data storageSame as hosting, aboveAlways
Resend (Resend, Inc.)Transactional email — verification, password reset, billing notices, digestUS, under the UK IDTA / SCCsOnly if we configure a Resend API key or relay our mail server through Resend; neither is in use. Email is sent from our own mail server on the hosting above, which is not a separate subprocessor, and any third-party relay is listed here before it is used
Cloudflare, Inc.DNS for our domain, and forwarding of email sent to our contact addresses (support, privacy, legal) to our business mailboxGlobal network, under the UK IDTA / SCCsAlways for DNS; for email only when you write to us
Stripe (Stripe Payments UK Ltd)Subscription payments. Your contract for the software is with Nikah AI Limited; Stripe takes the payment, calculates and accounts for any UK VAT due on the sale, and issues your receipt and invoice. Stripe collects your payment details and billing address, and if you save a card for reuse it holds it against your email address (you may see that wallet called Onelink, Stripe's UK brand name for it). Stripe handles that data partly on our behalf and partly as a controller in its own right — including for fraud prevention, tax and its own legal obligations — under its own privacy policy (stripe.com/privacy)UK / EU / USWhenever you choose a plan or pay for a subscription
Xero, Intuit (QuickBooks), SageAccounting data sync via your OAuth consentUK / EU / USOnly if you connect that system. Direct connections are not yet available on this service
TrueLayerOpen-banking data (bank feeds)UK / EUOnly if you connect Open Banking. Not yet available on this service
OpenCode Zen (opencode.ai), and the model it routes toThe language-model layer of the Copilot, board-pack commentary, audit-pack analysis, vendor-name suggestions and Reconcile Mode correctionsThe model operator's infrastructure, outside the UK; transferred under the UK IDTA / Addendum to the EU SCCsOnly for the AI features enabled for your workspace. What is sent is the description, date, amount and nominal code of the records in front of the feature, or your question plus the ledger figures our tools returned. Account numbers, sort codes, passwords and connector tokens are never sent. With a feature's flag off for a workspace, nothing is sent and the rules engine answers alone. The model in use is named at /trust and in the operator's diagnostics
Amazon Web Services (S3) or Cloudflare (R2)Uploaded evidence & attachment storageRegion stated here when enabledOnly if external file storage is enabled; not in use — files stay with our hosting provider above
Amazon Web Services (KMS) or Google Cloud KMSEnvelope encryption of connector credentialsRegion stated here when enabledOnly if managed KMS is enabled; not in use — a local key is used
SerpAPI (SerpApi, LLC)Identifying the vendor behind an unrecognised bank-transaction description, for the recurring-payments and supplier featuresUS, under the UK IDTA / SCCsOnly if SERPAPI_API_KEY is set. With no key set, no search request is made and the feature falls back to a local dictionary
Microsoft (Bing Search API)Same purpose as the row above; the alternative search engineUS, under the UK IDTA / SCCsOnly if BING_SEARCH_API_KEY is set and no SerpAPI key is. With no key set, nothing is sent
NoneError/uptime monitoring and website analyticsSame as hosting, above unless stated otherwise"None" means no third-party monitoring or analytics service is used

Accounting connectors and AI providers only receive the data necessary for the feature you enable. AI features can be turned off per organisation, in which case no data is sent to an AI provider.

On the search engines, precisely. When vendor enrichment is enabled, what leaves our service is the normalised description text of a bank transaction — for example ADOBE * 800 LICENSE 4071 — sent as a search query so the vendor behind it can be named. That text can contain a counterparty's name. It is sent with no account number, no amount, no date, no other transaction field and nothing identifying you or your organisation. If a key is set for one of these engines and AI features are also enabled, the top few search results are then passed to the AI provider named above to extract the vendor name. Enrichment is off unless we set a search key; those two environment variables are the only switch, and with neither set the feature uses a built-in dictionary and makes no outbound request.

The database is not a separate third-party subprocessor: PostgreSQL runs as part of this deployment, on the hosting provider named in the first row.

On monitoring and analytics, precisely. The application bundles no error-reporting or product-analytics library. It includes one optional website-analytics loader — Plausible (cookieless), Google Analytics 4, or a Google Ads conversion tag — and it is switched off, so no third-party script is requested and your browser contacts no one but us. If we ever switch one on, that provider will be named in the monitoring row above with 30 days' notice; Plausible sets no cookie, and the two Google tags set cookies and will not load at all until you have consented. See the Cookie Policy.