Effective date: 27 July 2026
Kikin Financial Limited ("Kikin", "we", "our", or "us") protects and respects your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data, and sets out your rights under UK data protection law.
Kikin Financial Limited (company no. 14569152) is the data controller of the personal information we hold about you. Our registered address is 4th Floor, 14 Museum Place, Cardiff, CF10 3BH.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
You have the right to make a complaint to the Information Commissioner's Office (ICO) at any time — ico.org.uk / 0303 123 1113.
This policy applies when you use https://www.kikin.io/ (the "Website") or our services, and to individuals who are associated with a company that uses our services — including shareholders, directors, persons with significant control (PSC), beneficial owners, attorneys under a power of attorney, employees, workers, and contractors of any such company (each an "Engaging Entity").
We use the information we collect to correspond with you, perform our agreements with you, comply with our regulatory responsibilities (including Know Your Client and anti-money laundering requirements), carry out marketing activities, and operate our business day to day.
We collect and process the following categories of personal data about you. Where processing is based on legitimate interests, we have carried out a balancing test and concluded that our interests are not overridden by your rights and interests. You may request details of this assessment by contacting us.
Where the provision of certain personal data is required for us to provide a service, we will indicate this. If you choose not to provide it, we may be unable to provide the service requested.
We collect personal data from the following sources:
Directly from you, when you:
Automatically, when you use the Website:
From third-party data sources — we receive personal data about directors, persons of significant control, and your Engaging Entity from the following sources. This is disclosed under Article 14 UK GDPR:
Note on publicly available data: Director names, partial dates of birth, and registered addresses obtained from Companies House are personal data even though they appear on a public register. We use them solely for credit assessment and compliance with our anti-money laundering obligations.
We will store your personal data for no longer than necessary for the purposes set out in this policy.
Personal data processed for anti-money laundering and customer due diligence purposes is retained for five years from the end of the business relationship (or from completion of an occasional transaction), as required by Regulation 40 of the Money Laundering Regulations 2017. MLR 2017 also imposes a deletion duty at the end of that period unless we have a separate legal ground to continue processing. Where additional retention is necessary — for example, to pursue or defend contractual claims under the Limitation Act 1980, or to comply with FCA record-keeping rules — data is retained for a maximum of six years from the end of the business relationship, limited to what is necessary for that purpose.
For other personal data, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised disclosure, the purposes for which we process it, whether we can achieve those purposes through other means, and applicable legal, regulatory, tax, accounting, or other requirements.
We share your personal data with the categories of recipients set out below. Where a recipient acts as a processor on our instructions, we have a written data processing agreement in place. Where a recipient is an independent controller, they process your data under their own legal obligations and privacy notice.
These organisations process your personal data only on our documented instructions:
Note on AI service providers: The AI vendors listed above are contracted as processors and are prohibited under their data processing agreements from using your personal data to train their models or for any purpose other than providing the inference service to us. Where a vendor's standard consumer terms allow training use, we are on enterprise or API terms that exclude this. Contact us if you have questions about a specific provider's terms.
These organisations receive your personal data and process it under their own legal obligations. They are not processors acting on our instructions:
We use DING NEGOCE SAS (trading as Prelude) to verify your phone number during onboarding. Prelude acts as our processor for the verification service itself. However, under their terms, Prelude may also use your phone number and IP address as an independent controller for their own fraud prevention and algorithm improvement purposes. This secondary processing is carried out by Prelude under their own privacy notice: https://www.prelude.so/privacy.
As a responsible lender, we are required to assess the creditworthiness of our customers before providing services. We receive personal data about directors and persons of significant control from Creditsafe Group, Wiserfunding Limited, and Companies House (see Section 4).
If you would like contact details for these organisations so that you can access the data they hold about you, please contact us at hello@kikin.io.
We may also share your personal data:
Some of the third parties listed in Section 6 are located outside the UK. Where we transfer your personal data to a country that does not have an adequacy decision from the UK, we ensure an appropriate safeguard is in place:
Transfers to EU/EEA countries (including Ireland, Germany, France, and Belgium) are covered by the UK's adequacy decision for the EEA and require no additional mechanism.
You can request further information about the specific safeguards applied to any particular transfer by contacting us at hello@kikin.io.
As a responsible lender, Kikin has a legal obligation to assess the creditworthiness and suitability of our customers before providing services.
We share information with and receive information from credit reference agencies and other third-party data providers as part of this assessment. These providers give us information about a customer's or prospective customer's credit history and financial standing.
For details of the specific credit reference agencies we use and how to access the information they hold about you, please contact us at hello@kikin.io.
From time to time we may contact you with information about our products and services.
Where you are an individual subscriber with a non-corporate email address and we have not previously provided services to you, we will obtain your consent before sending marketing emails. You may withdraw consent at any time without affecting the lawfulness of any processing before withdrawal.
Where consent is not required under applicable law (for example, marketing to corporate email addresses, or to existing customers who have not opted out), we rely on our legitimate interests in promoting our services. We consider this proportionate and not prejudicial to your interests.
You can opt out of marketing at any time by clicking the unsubscribe link in any marketing email or by contacting us at hello@kikin.io.
We implement appropriate technical and organisational measures — including encryption, access controls, and regular security reviews — to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
All personal information we collect is stored on secure servers. We will never send you unsolicited communications requesting your account password, bank account details, national identification numbers, or any other credentials.
Under UK data protection law, you have the following rights in relation to the personal data we hold about you:
These rights are not absolute and exceptions may apply. To exercise any of these rights, please contact us at hello@kikin.io. You may also review and amend some personal data by logging into your account on the Website.
We use automated systems to make or assist with certain decisions as permitted under Article 22(2) UK GDPR.
Account application assessment. Our systems assess your suitability for an account based on information from Companies House, credit reference agencies, identity verification providers, and open banking providers. We may automatically determine that you present a credit, fraud, or financial crime risk, in which case your application may be declined.
We rely on Article 22(2)(a) UK GDPR (processing necessary for entering into a contract with you) for credit and suitability assessments. For fraud and financial crime risk determinations required under MLR 2017 and FCA rules, we rely on Article 22(2)(b) UK GDPR (processing authorised by law), with the safeguards required by DPA 2018 s.14 in place.
Logic and factors used: Creditworthiness signals (credit scores, payment history, open banking transaction patterns, financial statement analysis); identity verification (matching submitted identity documents against official records); sanctions and financial crime screening (checking your identity and connected parties against the OFSI and HM Treasury consolidated sanctions lists — this screening is performed internally and does not involve sharing your data with a third-party screening service); and fraud risk indicators (document analysis, behavioural signals, and open banking account stability). These signals are scored against risk thresholds set by our underwriting policy.
Fraud detection. Our systems may suspend a transaction or account where fraud or money-laundering is suspected. This processing is authorised by law under MLR 2017 (Art. 22(2)(b)) and DPA 2018 s.14 safeguards apply.
Your rights. You have the right to express your views and to obtain human review of any automated decision that significantly affects you. To request this, email hello@kikin.io. A human underwriter will review the decision and notify you of the outcome.
Our Website uses cookies and similar technologies to distinguish you from other users and to improve your experience. For full details of the cookies we use and how to manage them, please see our Cookie Policy available on the Website.
Our Website may contain links to third-party websites. Those websites have their own privacy policies and we accept no responsibility or liability for them. Please check each site's policy before submitting personal data.
We may update this policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you directly. We encourage you to review this policy periodically.
Kikin Financial Limited
4th Floor, 14 Museum Place
Cardiff
CF10 3BH
Email: hello@kikin.io
Data Protection Lead: Antony Woods — antony@kikin.io
To make a complaint to the supervisory authority:
Information Commissioner's Office (ICO) — ico.org.uk | 0303 123 1113