Privacy policy
Effective date: 27 July 2026
1. About Us
Kikin Financial Limited ("Kikin", "we", "our", or "us") protects and respects your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data, and sets out your rights under UK data protection law.
Kikin Financial Limited (company no. 14569152) is the data controller of the personal information we hold about you. Our registered address is 4th Floor, 14 Museum Place, Cardiff, CF10 3BH.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Email: hello@kikin.io
- Data Controller / DPO: Antony Woods — antony@kikin.io
- Post: Kikin Financial Ltd, 4th Floor, 14 Museum Place, Cardiff, CF10 3BH
You have the right to make a complaint to the Information Commissioner's Office (ICO) at any time — ico.org.uk / 0303 123 1113. We would appreciate the opportunity to address your concerns first, so please contact us before approaching the ICO.
2. Who This Policy Applies To
This policy applies when you use https://www.kikin.io/ (the "Website") or our services, and to individuals who are associated with a company that uses our services — including shareholders, directors, persons with significant control (PSC), beneficial owners, attorneys under a power of attorney, employees, workers, and contractors of any such company (each an "Engaging Entity").
We use the information we collect to correspond with you, perform our agreements with you, comply with our regulatory responsibilities (including Know Your Client and anti-money laundering requirements), carry out marketing activities, and operate our business day to day.
3. What Personal Data We Collect and Why
We collect and process the following categories of personal data about you. Where processing is based on legitimate interests, we have carried out a balancing test and concluded that our interests are not overridden by your rights and interests. You may request details of this assessment by contacting us.
| Category |
Examples |
Lawful basis |
| Identity |
Full name, date of birth, nationality, shareholding percentage |
Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (KYC/AML under Money Laundering Regulations 2017) |
| Contact |
Email address, phone number, postal address |
Art. 6(1)(b) — performance of a contract |
| Financial |
Bank account details, credit history, loan amounts, invoice data, repayment history, open banking transaction data |
Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interests (credit assessment, fraud prevention) |
| Identity documents |
Passport, driving licence, and other documents submitted for identity verification |
Art. 6(1)(c) — legal obligation (MLR 2017; FCA requirements) |
| Behavioural |
IP address, browser and device information, how you navigate the Website, session data |
Art. 6(1)(f) — legitimate interests (security, fraud detection, product improvement) |
| Business information |
Company registration details, director and PSC data, Companies House filings |
Art. 6(1)(c) — legal obligation (AML/KYC); Art. 6(1)(f) — legitimate interests (credit assessment) |
Where the provision of certain personal data is required for us to provide a service, we will indicate this. If you choose not to provide it, we may be unable to provide the service requested.
4. How We Collect Your Personal Data
We collect personal data from the following sources:
Directly from you, when you:
- Register for an account or use our services
- Submit invoices, bank account details, or other documents
- Contact us by email, phone, or through the Website
Automatically, when you use the Website:
- Device and browser information, IP address, and usage data collected via cookies and analytics tools (see Section 13)
From third-party data sources — we receive personal data about directors, persons of significant control, and your Engaging Entity from the following sources. This is disclosed under Article 14 UK GDPR:
| Source |
What we receive |
Lawful basis |
| Companies House (UK statutory register) |
Director names, partial dates of birth, registered addresses, PSC information |
Art. 6(1)(c) — legal obligation (MLR 2017); Art. 6(1)(f) — legitimate interests |
| Creditsafe Group (credit reference agency) |
Business credit reports containing director names, credit scores, and payment history |
Art. 6(1)(f) — legitimate interests (credit assessment); Art. 6(1)(c) — legal obligation (MLR 2017) |
| Wiserfunding Limited |
Risk assessment data and financial metrics used in underwriting |
Art. 6(1)(f) — legitimate interests (credit assessment) |
| Open banking providers |
Bank transaction history and account balances, with your authorisation |
Art. 6(1)(b) — performance of a contract |
| GoCardless Ltd |
Bank account verification results (confirmed beneficiary name) |
Art. 6(1)(b) — performance of a contract |
Note on publicly available data: Director names, partial dates of birth, and registered addresses obtained from Companies House are personal data even though they appear on a public register. We use them solely for credit assessment and compliance with our anti-money laundering obligations.
5. Data Retention
We will store your personal data for no longer than necessary for the purposes set out in this policy.
Personal data processed for anti-money laundering and customer due diligence purposes is retained for 6 years from the date of collection, in line with the Money Laundering Regulations 2017.
For other personal data, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised disclosure, the purposes for which we process it, whether we can achieve those purposes through other means, and applicable legal, regulatory, tax, accounting, or other requirements.
6. Who We Share Your Personal Data With
We share your personal data with the categories of recipients set out below. Where a recipient acts as a processor on our instructions, we have a written data processing agreement in place. Where a recipient is an independent controller, they process your data under their own legal obligations and privacy notice.
6a. Service Providers Acting on Our Instructions (Processors)
These organisations process your personal data only on our documented instructions:
| Provider |
Purpose |
Personal data shared |
Location |
Transfer mechanism |
| GALAMIAN PTY LTD (trading as eSignatures) |
Digital signing of lending contracts |
Signatory names, email addresses, loan terms, signed contract documents |
Australia |
UK Addendum to EU SCCs |
| Xero (UK) Limited |
Accounting and invoice data integration |
Invoice data, account balances, supplier and customer contact data |
UK / US |
UK Addendum to EU SCCs (US storage) |
| Apideck bv |
Multi-platform accounting data integration |
Accounting and financial data, contact data |
EU (Belgium) |
UK adequacy decision (EU entity) |
| HubSpot Inc. |
Customer relationship management |
Names, email addresses, deal information, interaction records |
US |
UK Addendum to EU SCCs + UK-US Data Bridge |
| SuprStack Inc. (trading as SuprSend) |
Notification delivery (email, SMS, WhatsApp) |
Email addresses, phone numbers, names |
US |
UK Addendum to EU SCCs + UK-US Data Bridge |
| Amazon Web Services Inc. (AWS SES) |
Transactional email delivery |
Email addresses, names in email headers |
UK (London) |
UK storage — no restricted transfer |
| Functional Software Inc. (Sentry) |
Error monitoring and performance tracking |
IP addresses, technical request context |
US |
UK Addendum to EU SCCs + UK-US Data Bridge |
| PostHog Inc. |
Product analytics and feature management |
User behaviour events, user and company identifiers |
EU (Germany) |
UK IDTA + UK-US Data Bridge |
| Better Stack Inc. (Logtail) |
Application log management |
IP addresses, technical log data |
EU |
UK Addendum to EU SCCs |
| Pipedream LLC |
Event streaming and workflow integration |
User, financial, and document event data |
US |
UK Addendum to EU SCCs |
| Supabase Inc. |
Secure document storage |
Invoice PDFs, KYC identity documents, receipts, disbursement records |
UK (London) |
UK SCCs; UK storage |
| Google Cloud EMEA Limited |
Data analytics and document storage |
Financial analytics data, documents |
EU (Ireland) |
UK adequacy decision (EU entity) |
| Upstash Inc. |
Rate limiting and session caching |
Session identifiers, IP addresses |
EU |
UK Addendum to EU SCCs; EU storage |
| Inngest Inc |
Background job and workflow orchestration |
Names, contact details, financial event data |
US |
UK Addendum to EU SCCs |
| Anthropic Ireland Limited |
AI-assisted document analysis and underwriting |
Financial documents, director and company names in AI prompts |
EU (Ireland) |
UK Addendum to EU SCCs |
| OpenAI OpCo LLC |
AI-assisted analysis |
Financial and identity data in AI prompts |
US |
UK Addendum to EU SCCs |
| Google LLC (Gemini API) |
AI-assisted invoice parsing, fraud detection, and underwriting analysis |
Invoice content, financial metrics, director and company names |
US |
EU SCCs + UK SCC variant |
| Groq Inc. |
AI inference |
Financial and identity data in AI prompts |
US |
UK IDTA |
| Perplexity AI Inc. |
AI-assisted research and information retrieval |
Financial and identity data in AI prompts |
US |
UK IDTA + UK-US Data Bridge |
| X.AI LLC (Grok) |
AI-assisted analysis |
Financial and identity data in AI prompts |
US |
UK Addendum to EU SCCs |
| Cerebras Systems Inc. |
AI inference |
Financial and identity data in AI prompts |
US |
EU SCCs + UK Addendum |
| DING NEGOCE SAS (trading as Prelude) |
Phone number verification during onboarding |
Phone numbers, IP addresses |
France (EU) |
UK adequacy decision (EU entity) |
| Allies Computing Limited (Postcoder) |
Postcode address lookup |
Postcode queries |
UK |
UK entity — no restricted transfer |
| Vercel Inc. |
Web application hosting, CDN, and web analytics |
IP addresses, web analytics and performance data |
US |
UK IDTA + UK-US Data Bridge |
| Railway Corporation |
Infrastructure hosting for internal services |
All data processed by hosted services (infrastructure-level access) |
US |
UK Addendum to EU SCCs |
6b. Independent Data Recipients (Controllers)
These organisations receive your personal data and process it under their own legal obligations. They are not processors acting on our instructions:
| Recipient |
Why we share data |
Their privacy notice |
| GoCardless Ltd (FCA reg 597190) |
GoCardless collects direct debit mandate and bank account data directly from you to facilitate loan repayments. GoCardless is an independent FCA-authorised payment institution and processes this data under its own regulatory obligations. When setting up a payment mandate you will be presented with GoCardless's privacy notice. |
gocardless.com/legal/privacy/ |
| Wise Payments Limited (FCA reg 900507) |
Loan disbursements to borrowers or their vendors are made via Wise. Wise processes beneficiary payment data as an independent FCA-authorised payment institution under its own AML and regulatory obligations. |
wise.com/gb/legal/privacy-notice-business-en |
| Credas Technologies Ltd / Creditsafe Group |
We share your name and email address with Credas to initiate your identity verification journey as required by the Money Laundering Regulations 2017. Credas and Creditsafe Group collect additional identity verification data (including document images) directly from you under their own privacy notice. |
credas.com/privacy-notice/ |
6c. Phone Verification — Secondary Processing by Prelude
We use DING NEGOCE SAS (trading as Prelude) to verify your phone number during onboarding. Prelude acts as our processor for the verification service itself. However, under their terms, Prelude may also use your phone number and IP address as an independent controller for their own fraud prevention and algorithm improvement purposes. This secondary processing is carried out by Prelude under their own privacy notice: https://www.prelude.so/privacy.
6d. Credit Reference Agencies and Data Sources
As a responsible lender, we are required to assess the creditworthiness of our customers before providing services. We receive personal data about directors and persons of significant control from Creditsafe Group, Wiserfunding Limited, and Companies House (see Section 4).
If you would like contact details for these organisations so that you can access the data they hold about you, please contact us at hello@kikin.io.
6e. Other Permitted Disclosures
We may also share your personal data:
- With professional advisers (lawyers, auditors, insurers) where necessary for the conduct of our business
- In connection with a business transaction such as a merger, sale, financing, or reorganisation, subject to confidentiality obligations
- With law enforcement, regulators, or courts where required by law or to detect and prevent fraud and financial crime
- With investors or funders where required under funding arrangements, subject to appropriate confidentiality obligations
7. International Transfers
Some of the third parties listed in Section 6 are located outside the UK. Where we transfer your personal data to a country that does not have an adequacy decision from the UK, we ensure an appropriate safeguard is in place:
- UK Addendum to EU Standard Contractual Clauses (UK Addendum / UK IDTA) — the ICO-approved mechanism for restricted transfers under UK GDPR, based on the template issued under s.119A(1) of the Data Protection Act 2018
- UK-US Data Bridge — the UK extension to the EU-US Data Privacy Framework (DPF) for transfers to US organisations that have self-certified under the framework
Transfers to EU/EEA countries (including Ireland, Germany, France, and Belgium) are covered by the UK's adequacy decision for the EEA and require no additional mechanism.
You can request further information about the specific safeguards applied to any particular transfer by contacting us at hello@kikin.io.
8. Credit Reference Checks
As a responsible lender, Kikin has a legal obligation to assess the creditworthiness and suitability of our customers before providing services.
We share information with and receive information from credit reference agencies and other third-party data providers as part of this assessment. These providers give us information about a customer's or prospective customer's credit history and financial standing.
For details of the specific credit reference agencies we use and how to access the information they hold about you, please contact us at hello@kikin.io.
9. Marketing and Advertising
From time to time we may contact you with information about our products and services.
Where you are an individual subscriber with a non-corporate email address and we have not previously provided services to you, we will obtain your consent before sending marketing emails. You may withdraw consent at any time without affecting the lawfulness of any processing before withdrawal.
Where consent is not required under applicable law (for example, marketing to corporate email addresses, or to existing customers who have not opted out), we rely on our legitimate interests in promoting our services. We consider this proportionate and not prejudicial to your interests.
You can opt out of marketing at any time by clicking the unsubscribe link in any marketing email or by contacting us at hello@kikin.io.
10. Security
We implement appropriate technical and organisational measures — including encryption, access controls, and regular security reviews — to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
All personal information we collect is stored on secure servers. We will never send you unsolicited communications requesting your account password, bank account details, national identification numbers, or any other credentials.
11. Your Rights
Under UK data protection law, you have the following rights in relation to the personal data we hold about you:
| Right |
Description |
| Access |
To obtain a copy of the personal data we hold about you |
| Portability |
To receive your data in a structured, machine-readable format, or to have it transferred to another controller |
| Rectification |
To have inaccurate or incomplete data corrected without undue delay |
| Erasure |
To have your data deleted where continued processing is not justified |
| Restriction |
To restrict how we process your data in certain circumstances, such as where its accuracy is disputed |
| Object |
To object to processing based on legitimate interests, or to opt out of direct marketing at any time |
| Withdraw consent |
To withdraw consent at any time where processing is consent-based, without affecting prior lawful processing |
| Automated decisions |
To not be subject to a decision made solely by automated means that significantly affects you (see Section 12) |
These rights are not absolute and exceptions may apply. To exercise any of these rights, please contact us at hello@kikin.io. You may also review and amend some personal data by logging into your account on the Website.
12. Automated Decision-Making
We use automated systems to assist with certain decisions. You have the right to request a human review of any automated decision that significantly affects you by emailing hello@kikin.io.
Account application assessment. Our systems assess your suitability for an account based on information from Companies House, credit reference agencies, sanctions screening providers, identity verification providers, and open banking providers. We may automatically determine that you present a fraud, money-laundering, or financial sanctions risk, in which case your application may be declined.
Fraud detection. Our systems may suspend a transaction or account where fraud or money-laundering is suspected, based on signals from our monitoring and open banking providers.
13. Cookies and Similar Technologies
Our Website uses cookies and similar technologies to distinguish you from other users and to improve your experience. For full details of the cookies we use and how to manage them, please see our Cookie Policy available on the Website.
14. Links to Third-Party Sites
Our Website may contain links to third-party websites. Those websites have their own privacy policies and we accept no responsibility or liability for them. Please check each site's policy before submitting personal data.
15. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you directly. We encourage you to review this policy periodically.
16. Contact Us
Kikin Financial Limited
4th Floor, 14 Museum Place
Cardiff
CF10 3BH
Email: hello@kikin.io
Data Controller / DPO: Antony Woods — antony@kikin.io
To make a complaint to the supervisory authority:
Information Commissioner's Office (ICO) — ico.org.uk | 0303 123 1113