Last updated: 2026-08-21
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the operator named below, trading as Fin-Central ("Processor", "we"), and the customer organisation ("Controller", "you").
Fin-Central is a trading name of Nikah AI Ltd, a company registered in England and Wales (company number 17199968), registered office Office 1216 Fitzrovia, 60 Tottenham Court Road, London, W1T 2EW. Registered with the UK Information Commissioner's Office (ICO), registration number ZC176381.
Contact: privacy@fin-central.com (data protection) · legal@fin-central.com (legal) · support@fin-central.com (support).
It governs our processing of personal data on your behalf under UK GDPR Article 28 and the Data Protection Act 2018. Where it conflicts with the Terms on data protection, this DPA prevails.
1. Roles
You are the controller and we are the processor of the personal data contained in the accounting, ledger, banking, invoice and contact data you import or sync ("Customer Personal Data"). You are responsible for the lawfulness of that data and for having a lawful basis to provide it to us.
2. Subject matter, duration, nature & purpose
- Subject matter / purpose: processing necessary to provide the finance-control, reconciliation, forecasting, reporting and AI features of the service.
- Duration: for the term of your subscription and any post-termination export window.
- Nature: collection, storage, organisation, structuring, analysis, retrieval and deletion by automated means.
3. Types of personal data & categories of data subjects
- Types: names, business contact details, transaction/invoice references, payment amounts and dates, and any personal data present in fields you import.
- Data subjects: your customers, suppliers, employees and other contacts represented in your accounting data.
4. Our obligations
We will: 1. Process Customer Personal Data only on your documented instructions (including via the app's configuration), unless required by law (and will then tell you unless prohibited). 2. Ensure personnel authorised to process are under a duty of confidentiality. 3. Implement appropriate technical and organisational security measures (UK GDPR Art 32) — encryption in transit, encryption of credentials/2FA secrets at rest (AES-256-GCM), role-based access, tenant isolation, audit logging. 4. Engage subprocessors only under written terms with equivalent obligations, maintain the list at /legal/subprocessors, and give at least 30 days' notice of changes so you may object. 5. Assist you, taking into account the nature of processing, to respond to data-subject rights requests and to meet your Art 32–36 obligations (security, breach notification, DPIAs, prior consultation). 6. Notify you without undue delay (and in any event within 72 hours of our becoming aware) of a personal data breach affecting Customer Personal Data, with the information you need to meet your own obligations. 7. On termination, delete or return Customer Personal Data at your choice, except where retention is required by law. 8. Make available information necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and security controls.
5. International transfers
Where we or a subprocessor process Customer Personal Data outside the UK/EEA, we will ensure a valid transfer mechanism (UK adequacy regulations or the UK IDTA / Addendum to the EU SCCs) with appropriate safeguards.
6. Liability
Liability under this DPA is subject to the limitations of liability in the Terms.
7. How to execute
This DPA is incorporated by reference when you accept the Terms. If your organisation requires a countersigned copy, email legal@fin-central.com.