Legal

Privacy Policy

Last updated 4 October 2026 · Version 6

Last updated: 2026-10-04

1. Who we are

Fin-Central is a trading name of Nikah AI Limited, a company registered in England and Wales (company number 17199968), registered office Office 1216 Fitzrovia, 60 Tottenham Court Road, London, W1T 2EW. Registered with the UK Information Commissioner's Office (ICO), registration number ZC176381.

Contact: privacy@fin-central.com (data protection) · legal@fin-central.com (legal) · support@fin-central.com (support).

We provide finance-control software for UK businesses that works from ledger data you import as CSV/XLSX files; direct connections to Xero, QuickBooks and Sage are not yet available. We have not appointed a Data Protection Officer because the law does not require one for our processing; privacy@fin-central.com reaches the person responsible for data protection.

2. Controller vs processor — an important distinction

Our role under UK GDPR depends on the data:

  • We are the controller for the personal data of the people who register and use the service — account holders and their team (name, work email, hashed password, login/audit records, billing contact). This policy governs that data.
  • We are a processor for the data you import or sync from your accounting system to run the service. That data can contain personal data belonging to your customers, suppliers and staff (e.g. names on invoices, payees, contact details). For that data your organisation is the controller and we process it only on your instructions, under the Data Processing Addendum (/legal/dpa).

3. Personal data we collect (as controller)

  • Account data: name, work email, company name, hashed password, role. If a colleague invites you, we receive your name and email from them.
  • Sign-up record: the date you accepted the Terms of Service, the version accepted, and your confirmation that you signed up for a business.
  • Usage & security data: log-in history, IP/device/browser metadata, audit records of actions in the app, support correspondence.
  • Email delivery log: for each email the service sends you, the address, subject line, date and whether delivery succeeded.
  • Error log: technical error messages from the server, which occasionally quote a value (such as an email address) that was being processed.
  • Billing data: plan, billing contact and subscription status. Payments are taken by Stripe, our payment processor (see §6); we never see or store full card numbers.
  • Walkthrough enquiries: name, work email, company, role and your message, if you ask for a walkthrough.

4. How we use it

To create and secure your account, deliver and support the service, process billing, meet legal/accounting obligations, respond to enquiries, and improve reliability and safety. We do not sell your personal data or use it for third-party advertising. We take no significant decision about you based solely on automated processing — §7 sets out what that means under UK GDPR Articles 22A to 22D and what the safeguards are.

5. Legal bases (UK GDPR Article 6)

  • Contract — to provide the service your organisation signs up for, and to keep the record of what was agreed.
  • Legitimate interests — security, fraud prevention, answering walkthrough enquiries, keeping delivery and error logs, and product improvement (balanced against your rights).
  • Legal obligation — accounting, tax and statutory record-keeping.
  • Consent — only where separately requested, which you can withdraw at any time. We do not currently send marketing email.

6. Sharing & subprocessors

We share personal data only with the providers that run the service and with parties you choose to connect. Today that means:

  • Hosting — the application, database, email server and backups run on the hosting provider named on /legal/subprocessors, in the United Kingdom. Email is sent from our own mail server on that hosting, not through a third-party email service.
  • Cloudflare — provides DNS for our domain and forwards email you send to our contact addresses (support, privacy, legal) to our business mailbox.
  • Stripe — takes subscription payments for Fin-Central. It collects your payment details and billing address, and if you save a card for reuse it holds it against your email address (you may see that saved-card wallet called Onelink, which is Stripe's UK brand name for it). Your contract for the software is with Nikah AI Limited; Stripe calculates and accounts for any tax on your payment, and the price you see is the total you pay. Stripe handles payment data partly on our behalf and partly as a controller in its own right (for example for fraud prevention, tax and its own legal obligations), under its own privacy policy at stripe.com/privacy.
  • An AI model provider — OpenCode Zen, and the model it routes to. When an AI feature runs (the Copilot's conversational answers, board-pack commentary, audit-pack analysis, Reconcile Mode suggestions) the words that describe the transaction or question are sent there and an answer comes back. Every figure is still computed here, from your ledger, before any of it is sent, and account numbers, sort codes, passwords and connector tokens are never part of what goes. With a feature switched off for your workspace nothing is sent to it at all.
  • Accounting connections (Xero, QuickBooks, Sage) — only when direct connections are available on this service and you authorise one with OAuth consent. They are not yet available.

The current list, with purposes and locations, is at /legal/subprocessors. We may also disclose data where the law requires it.

7. AI features

What reaches an AI provider is the minimum the feature needs to answer: the description, date, amount and nominal code of the bank lines being reconciled, or your question together with the figures our own tools returned for it. No account number, sort code, password or connector credential is ever included. AI output is decision support, is labelled as such, and is not professional advice. Every AI feature can be switched off per organisation, and the deterministic answer — the one this product gave before any model was configured — still runs underneath it.

Automated decisions and AI

What our AI does. Fin-Central includes an AI copilot. It reads the financial information in your account and produces commentary, analysis and suggestions — for example explaining a variance, drafting a note for a board pack, or flagging a figure worth checking. It produces material for you to read and act on. It does not make decisions about you, and it does not decide anything by itself. Every figure you rely on, and every decision you take from it, is yours.

We do not make solely automated significant decisions about you. From 5 February 2026 UK GDPR Articles 22A to 22D govern a decision that produces a legal effect for you, or has a similarly significant effect for you, where there is no meaningful human involvement in taking it. We do not make any such decision about you. Where a decision about you matters — suspending or restricting your access, refusing or closing an account, or a billing decision you dispute — a person takes it or reviews it.

If we ever restrict, suspend or close your access, you always get all four of these:

  • We tell you — what we have done, when, and the reason, at the time we do it.
  • You can make representations to us about it, and we will consider them.
  • You can obtain human intervention — ask for a person to look at it, and a person will.
  • You can contest the decision — ask for it to be reconsidered, and we will tell you the outcome.

Email support@fin-central.com or use /contact for any of those. The same route is written into section 12 of our Terms, so it is a contractual right and not only a statement here.

We do not use your content to train AI models. Your financial data and your documents are processed to produce the output you asked for, and for nothing else. We name the AI provider we send it to, and where it is, on our sub-processor list. We tell you what we do and do not know about what that provider does with it — we have no zero-retention arrangement with any AI provider, we do not promise on their behalf, and their own terms are what govern their use of it.

If this ever changes, this notice changes first. If we build anything that makes a significant decision about a person automatically — in particular anything touching health, disability, political opinions, religion, trade-union membership, genetic or biometric data, sex life or sexual orientation, or criminal offences — we will update this notice before switching it on, because Article 22B treats those decisions differently and more strictly.

No profiling for advertising or scoring. We do not profile you or build a score about you, and we do not sell or share personal data for anyone else to do so.

8. Security

Data is encrypted in transit (TLS). Connector credentials and 2FA secrets are encrypted at rest (AES-256-GCM); passwords and 2FA recovery codes are stored only as one-way hashes. To be precise rather than reassuring: other data, including your accounting records and the audit log, is not encrypted by the application itself — it is held in access-controlled database storage on our UK hosting provider's infrastructure, and we do not claim disk-level encryption for it or its backups. Access is role-based across five roles, tenant-isolated and audit-logged. Two-factor authentication is available to every user and required for our own platform administrators, and we enforce a password policy. We hold no security certification. See our Security overview.

9. Retention

We state exact periods rather than "as long as necessary", and every period below is the period the deletion job actually applies: each one is set in src/lib/retention.ts, and the test suite fails the build if this table and those constants disagree — so this table cannot go on describing a period the product has stopped applying.

Data we process on your behalf, as processor. This is your ledger, and for it you are the controller. You hold your own statutory six-year records in your accounting system, which we do not replace, so we keep a shorter working copy rather than a second six-year archive of records you already have:

WhatKept forWhy this period
Audit evidence files and the text extracted from them90 days after the engagement closesThe largest and most sensitive holding. Your audit pack is a complete, self-describing ZIP you keep, and your auditor keeps their own copy. Evidence on an open engagement is never deleted, however old
Audit log13 monthsA full audit cycle plus a month of overlap for year-on-year comparison. Entries evidencing an erasure, a data export, an account deletion or a refused export are exempt and never deleted — they are the record that your rights were honoured. The sign-up entry recording acceptance of the Terms is also exempt — it is the record of the contract
Bank transactions24 monthsRecurring-payment detection needs twelve; twenty-four gives a year-on-year comparison
Supplier bills and their line itemsat least 36 monthsNot deleted on a shorter schedule: the three-year supplier-spend comparison depends on them
General ledger and trial balanceat least 27 monthsNot deleted on a shorter schedule: statutory accounts need prior-year comparatives and the audit pack needs opening balances
Vendor lookup cache12 monthsA cache; a twelve-month-cold entry has no value left

Data we hold as controller. Your account and billing records: for the life of your subscription and for up to 6 years afterwards, which is the period UK tax and company law requires of us as a business. Marketing enquiries: 24 months from last contact. Password-reset requests, which record the requesting IP address: deleted as soon as the link expires.

Being exact about the 6 years. Marketing enquiries and password-reset requests are removed by the automatic sweep described above. Account and billing records are not: there is no age-based job that deletes them at the end of the six years, and removing them is an action a person performs. We would rather say that than write "then deleted" and let it imply a timer we have not built. What you do not have to wait for is your own request — you can erase your account yourself from Settings → Security, and if you are the only owner the same control closes the organisation's account in full, files included, after a second confirmation. You can also ask us at privacy@fin-central.com instead.

Logs. The email delivery log and the error log have no automatic deletion either. They are kept while the service runs because they are how we answer "you never sent me that email" or trace a fault; if you erase your account, your address is redacted from both.

On termination, you may export your data for 30 days. After that we delete the organisation's records — a step we carry out, not an automatic timer, and one you can ask us to take sooner — and deletion means the rows and the underlying files, followed by a storage-reclaim step so the deleted content is no longer readable in the database file.

Backups. The database is backed up nightly. Routine backups are kept for 14 days on the hosting server and copied to storage we control in the United Kingdom, where they are kept for 30 days. A small number of one-off backups taken before maintenance are kept longer and deleted by hand. Backups taken before a deletion still contain the deleted data until they are removed. No provider can make an already-written backup forget a row, and we would rather say so than imply deletion is instantaneous everywhere.

The deletion job runs automatically every night as a scheduled task on our server; it is not a background timer inside the application, because in a multi-instance deployment that would mean several copies of a delete job racing one another.

10. Your rights

You have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent.

How to ask, and how long we take. Ask at privacy@fin-central.com or use /contact, which works on screen and gives you a reference whether or not email reaches you. You can also export your own data yourself from your account settings at any time, which is usually faster than asking us.

We answer a request within one month of receiving it.

  • If your request is complex, or you have made several, we may take up to two further months. If that happens we will tell you within the first month, and tell you why.
  • If we reasonably need you to tell us more precisely what you want, or to confirm who you are, we will ask you — and the clock pauses from the day we ask until the day you answer. We will make the question as specific as we can, so you are not guessing.
  • We will not use a request for clarification to delay you. If we can answer part of your request without clarification, we will.

We do not charge for any of this, unless a request is manifestly unfounded or excessive — and then we will explain before doing anything.

If we refuse a request, in whole or in part, we will tell you why, and we will tell you that you can complain to us, complain to the Information Commissioner's Office, and bring a claim in court.

If your request concerns data we process on a client's behalf, we will refer you to that client (the controller).

You can complain to us about how we handle your personal data. If you think we have handled your personal data in a way that breaches data protection law, you have the right to complain directly to us, under section 164A of the Data Protection Act 2018. Write to privacy@fin-central.com, or use /contact and mark your message as a data-protection complaint. We will acknowledge your complaint within 30 days, take appropriate steps to look into it, and tell you the outcome without undue delay. We will also tell you then what out-of-court redress is available — there is none we are a member of or able to refer you to, and we say so on /refunds rather than leaving you to look for one.

You can also complain to the regulator. The Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk/make-a-complaint, 0303 123 1113. You do not have to complain to us first, and complaining to us does not stop you going to the ICO or bringing a claim in court.

11. International transfers

The service, its database and its backups are hosted in the United Kingdom. Stripe and Cloudflare may process payment and email-routing data outside the UK under their own transfer safeguards. Where we engage a subprocessor that processes personal data outside the UK/EEA, we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, and we name it on the subprocessor list first.

12. Changes

We will post updates here, increment the version, and adjust the "last updated" date. For a material change we will tell you by a notice in the product and on your billing page, and by email where we can reach you — in that order, and not by email alone. We say it that way because email to some providers is outside our control and a notice you never receive is not a notice.