Privacy policy

Effective date: 27 July 2026  

1. About Us

Kikin Financial Limited ("Kikin", "we", "our", or "us") protects and respects your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data, and sets out your rights under UK data protection law.

Kikin Financial Limited (company no. 14569152) is the data controller of the personal information we hold about you. Our registered address is 4th Floor, 14 Museum Place, Cardiff, CF10 3BH.

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

  • Email: hello@kikin.io
  • Data Controller / DPO: Antony Woods — antony@kikin.io
  • Post: Kikin Financial Ltd, 4th Floor, 14 Museum Place, Cardiff, CF10 3BH

You have the right to make a complaint to the Information Commissioner's Office (ICO) at any time — ico.org.uk / 0303 123 1113. We would appreciate the opportunity to address your concerns first, so please contact us before approaching the ICO.

2. Who This Policy Applies To

This policy applies when you use https://www.kikin.io/ (the "Website") or our services, and to individuals who are associated with a company that uses our services — including shareholders, directors, persons with significant control (PSC), beneficial owners, attorneys under a power of attorney, employees, workers, and contractors of any such company (each an "Engaging Entity").

We use the information we collect to correspond with you, perform our agreements with you, comply with our regulatory responsibilities (including Know Your Client and anti-money laundering requirements), carry out marketing activities, and operate our business day to day.

3. What Personal Data We Collect and Why

We collect and process the following categories of personal data about you. Where processing is based on legitimate interests, we have carried out a balancing test and concluded that our interests are not overridden by your rights and interests. You may request details of this assessment by contacting us.

Category Examples Lawful basis
Identity Full name, date of birth, nationality, shareholding percentage Art. 6(1)(b) — performance of a contract; Art. 6(1)(c) — legal obligation (KYC/AML under Money Laundering Regulations 2017)
Contact Email address, phone number, postal address Art. 6(1)(b) — performance of a contract
Financial Bank account details, credit history, loan amounts, invoice data, repayment history, open banking transaction data Art. 6(1)(b) — performance of a contract; Art. 6(1)(f) — legitimate interests (credit assessment, fraud prevention)
Identity documents Passport, driving licence, and other documents submitted for identity verification Art. 6(1)(c) — legal obligation (MLR 2017; FCA requirements)
Behavioural IP address, browser and device information, how you navigate the Website, session data Art. 6(1)(f) — legitimate interests (security, fraud detection, product improvement)
Business information Company registration details, director and PSC data, Companies House filings Art. 6(1)(c) — legal obligation (AML/KYC); Art. 6(1)(f) — legitimate interests (credit assessment)

Where the provision of certain personal data is required for us to provide a service, we will indicate this. If you choose not to provide it, we may be unable to provide the service requested.

4. How We Collect Your Personal Data

We collect personal data from the following sources:

Directly from you, when you:

  • Register for an account or use our services
  • Submit invoices, bank account details, or other documents
  • Contact us by email, phone, or through the Website

Automatically, when you use the Website:

  • Device and browser information, IP address, and usage data collected via cookies and analytics tools (see Section 13)

From third-party data sources — we receive personal data about directors, persons of significant control, and your Engaging Entity from the following sources. This is disclosed under Article 14 UK GDPR:

Source What we receive Lawful basis
Companies House (UK statutory register) Director names, partial dates of birth, registered addresses, PSC information Art. 6(1)(c) — legal obligation (MLR 2017); Art. 6(1)(f) — legitimate interests
Creditsafe Group (credit reference agency) Business credit reports containing director names, credit scores, and payment history Art. 6(1)(f) — legitimate interests (credit assessment); Art. 6(1)(c) — legal obligation (MLR 2017)
Wiserfunding Limited Risk assessment data and financial metrics used in underwriting Art. 6(1)(f) — legitimate interests (credit assessment)
Open banking providers Bank transaction history and account balances, with your authorisation Art. 6(1)(b) — performance of a contract
GoCardless Ltd Bank account verification results (confirmed beneficiary name) Art. 6(1)(b) — performance of a contract

Note on publicly available data: Director names, partial dates of birth, and registered addresses obtained from Companies House are personal data even though they appear on a public register. We use them solely for credit assessment and compliance with our anti-money laundering obligations.

5. Data Retention

We will store your personal data for no longer than necessary for the purposes set out in this policy.

Personal data processed for anti-money laundering and customer due diligence purposes is retained for 6 years from the date of collection, in line with the Money Laundering Regulations 2017.

For other personal data, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorised disclosure, the purposes for which we process it, whether we can achieve those purposes through other means, and applicable legal, regulatory, tax, accounting, or other requirements.

6. Who We Share Your Personal Data With

We share your personal data with the categories of recipients set out below. Where a recipient acts as a processor on our instructions, we have a written data processing agreement in place. Where a recipient is an independent controller, they process your data under their own legal obligations and privacy notice.

6a. Service Providers Acting on Our Instructions (Processors)

These organisations process your personal data only on our documented instructions:

Provider Purpose Personal data shared Location Transfer mechanism
GALAMIAN PTY LTD (trading as eSignatures) Digital signing of lending contracts Signatory names, email addresses, loan terms, signed contract documents Australia UK Addendum to EU SCCs
Xero (UK) Limited Accounting and invoice data integration Invoice data, account balances, supplier and customer contact data UK / US UK Addendum to EU SCCs (US storage)
Apideck bv Multi-platform accounting data integration Accounting and financial data, contact data EU (Belgium) UK adequacy decision (EU entity)
HubSpot Inc. Customer relationship management Names, email addresses, deal information, interaction records US UK Addendum to EU SCCs + UK-US Data Bridge
SuprStack Inc. (trading as SuprSend) Notification delivery (email, SMS, WhatsApp) Email addresses, phone numbers, names US UK Addendum to EU SCCs + UK-US Data Bridge
Amazon Web Services Inc. (AWS SES) Transactional email delivery Email addresses, names in email headers UK (London) UK storage — no restricted transfer
Functional Software Inc. (Sentry) Error monitoring and performance tracking IP addresses, technical request context US UK Addendum to EU SCCs + UK-US Data Bridge
PostHog Inc. Product analytics and feature management User behaviour events, user and company identifiers EU (Germany) UK IDTA + UK-US Data Bridge
Better Stack Inc. (Logtail) Application log management IP addresses, technical log data EU UK Addendum to EU SCCs
Pipedream LLC Event streaming and workflow integration User, financial, and document event data US UK Addendum to EU SCCs
Supabase Inc. Secure document storage Invoice PDFs, KYC identity documents, receipts, disbursement records UK (London) UK SCCs; UK storage
Google Cloud EMEA Limited Data analytics and document storage Financial analytics data, documents EU (Ireland) UK adequacy decision (EU entity)
Upstash Inc. Rate limiting and session caching Session identifiers, IP addresses EU UK Addendum to EU SCCs; EU storage
Inngest Inc Background job and workflow orchestration Names, contact details, financial event data US UK Addendum to EU SCCs
Anthropic Ireland Limited AI-assisted document analysis and underwriting Financial documents, director and company names in AI prompts EU (Ireland) UK Addendum to EU SCCs
OpenAI OpCo LLC AI-assisted analysis Financial and identity data in AI prompts US UK Addendum to EU SCCs
Google LLC (Gemini API) AI-assisted invoice parsing, fraud detection, and underwriting analysis Invoice content, financial metrics, director and company names US EU SCCs + UK SCC variant
Groq Inc. AI inference Financial and identity data in AI prompts US UK IDTA
Perplexity AI Inc. AI-assisted research and information retrieval Financial and identity data in AI prompts US UK IDTA + UK-US Data Bridge
X.AI LLC (Grok) AI-assisted analysis Financial and identity data in AI prompts US UK Addendum to EU SCCs
Cerebras Systems Inc. AI inference Financial and identity data in AI prompts US EU SCCs + UK Addendum
DING NEGOCE SAS (trading as Prelude) Phone number verification during onboarding Phone numbers, IP addresses France (EU) UK adequacy decision (EU entity)
Allies Computing Limited (Postcoder) Postcode address lookup Postcode queries UK UK entity — no restricted transfer
Vercel Inc. Web application hosting, CDN, and web analytics IP addresses, web analytics and performance data US UK IDTA + UK-US Data Bridge
Railway Corporation Infrastructure hosting for internal services All data processed by hosted services (infrastructure-level access) US UK Addendum to EU SCCs

6b. Independent Data Recipients (Controllers)

These organisations receive your personal data and process it under their own legal obligations. They are not processors acting on our instructions:

Recipient Why we share data Their privacy notice
GoCardless Ltd (FCA reg 597190) GoCardless collects direct debit mandate and bank account data directly from you to facilitate loan repayments. GoCardless is an independent FCA-authorised payment institution and processes this data under its own regulatory obligations. When setting up a payment mandate you will be presented with GoCardless's privacy notice. gocardless.com/legal/privacy/
Wise Payments Limited (FCA reg 900507) Loan disbursements to borrowers or their vendors are made via Wise. Wise processes beneficiary payment data as an independent FCA-authorised payment institution under its own AML and regulatory obligations. wise.com/gb/legal/privacy-notice-business-en
Credas Technologies Ltd / Creditsafe Group We share your name and email address with Credas to initiate your identity verification journey as required by the Money Laundering Regulations 2017. Credas and Creditsafe Group collect additional identity verification data (including document images) directly from you under their own privacy notice. credas.com/privacy-notice/

6c. Phone Verification — Secondary Processing by Prelude

We use DING NEGOCE SAS (trading as Prelude) to verify your phone number during onboarding. Prelude acts as our processor for the verification service itself. However, under their terms, Prelude may also use your phone number and IP address as an independent controller for their own fraud prevention and algorithm improvement purposes. This secondary processing is carried out by Prelude under their own privacy notice: https://www.prelude.so/privacy.

6d. Credit Reference Agencies and Data Sources

As a responsible lender, we are required to assess the creditworthiness of our customers before providing services. We receive personal data about directors and persons of significant control from Creditsafe Group, Wiserfunding Limited, and Companies House (see Section 4).

If you would like contact details for these organisations so that you can access the data they hold about you, please contact us at hello@kikin.io.

6e. Other Permitted Disclosures

We may also share your personal data:

  • With professional advisers (lawyers, auditors, insurers) where necessary for the conduct of our business
  • In connection with a business transaction such as a merger, sale, financing, or reorganisation, subject to confidentiality obligations
  • With law enforcement, regulators, or courts where required by law or to detect and prevent fraud and financial crime
  • With investors or funders where required under funding arrangements, subject to appropriate confidentiality obligations

7. International Transfers

Some of the third parties listed in Section 6 are located outside the UK. Where we transfer your personal data to a country that does not have an adequacy decision from the UK, we ensure an appropriate safeguard is in place:

  • UK Addendum to EU Standard Contractual Clauses (UK Addendum / UK IDTA) — the ICO-approved mechanism for restricted transfers under UK GDPR, based on the template issued under s.119A(1) of the Data Protection Act 2018
  • UK-US Data Bridge — the UK extension to the EU-US Data Privacy Framework (DPF) for transfers to US organisations that have self-certified under the framework

Transfers to EU/EEA countries (including Ireland, Germany, France, and Belgium) are covered by the UK's adequacy decision for the EEA and require no additional mechanism.

You can request further information about the specific safeguards applied to any particular transfer by contacting us at hello@kikin.io.

8. Credit Reference Checks

As a responsible lender, Kikin has a legal obligation to assess the creditworthiness and suitability of our customers before providing services.

We share information with and receive information from credit reference agencies and other third-party data providers as part of this assessment. These providers give us information about a customer's or prospective customer's credit history and financial standing.

For details of the specific credit reference agencies we use and how to access the information they hold about you, please contact us at hello@kikin.io.

9. Marketing and Advertising

From time to time we may contact you with information about our products and services.

Where you are an individual subscriber with a non-corporate email address and we have not previously provided services to you, we will obtain your consent before sending marketing emails. You may withdraw consent at any time without affecting the lawfulness of any processing before withdrawal.

Where consent is not required under applicable law (for example, marketing to corporate email addresses, or to existing customers who have not opted out), we rely on our legitimate interests in promoting our services. We consider this proportionate and not prejudicial to your interests.

You can opt out of marketing at any time by clicking the unsubscribe link in any marketing email or by contacting us at hello@kikin.io.

10. Security

We implement appropriate technical and organisational measures — including encryption, access controls, and regular security reviews — to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.

All personal information we collect is stored on secure servers. We will never send you unsolicited communications requesting your account password, bank account details, national identification numbers, or any other credentials.

11. Your Rights

Under UK data protection law, you have the following rights in relation to the personal data we hold about you:

Right Description
Access To obtain a copy of the personal data we hold about you
Portability To receive your data in a structured, machine-readable format, or to have it transferred to another controller
Rectification To have inaccurate or incomplete data corrected without undue delay
Erasure To have your data deleted where continued processing is not justified
Restriction To restrict how we process your data in certain circumstances, such as where its accuracy is disputed
Object To object to processing based on legitimate interests, or to opt out of direct marketing at any time
Withdraw consent To withdraw consent at any time where processing is consent-based, without affecting prior lawful processing
Automated decisions To not be subject to a decision made solely by automated means that significantly affects you (see Section 12)


These rights are not absolute and exceptions may apply. To exercise any of these rights, please contact us at hello@kikin.io. You may also review and amend some personal data by logging into your account on the Website.

12. Automated Decision-Making

We use automated systems to assist with certain decisions. You have the right to request a human review of any automated decision that significantly affects you by emailing hello@kikin.io.

Account application assessment. Our systems assess your suitability for an account based on information from Companies House, credit reference agencies, sanctions screening providers, identity verification providers, and open banking providers. We may automatically determine that you present a fraud, money-laundering, or financial sanctions risk, in which case your application may be declined.

Fraud detection. Our systems may suspend a transaction or account where fraud or money-laundering is suspected, based on signals from our monitoring and open banking providers.

13. Cookies and Similar Technologies

Our Website uses cookies and similar technologies to distinguish you from other users and to improve your experience. For full details of the cookies we use and how to manage them, please see our Cookie Policy available on the Website.

14. Links to Third-Party Sites

Our Website may contain links to third-party websites. Those websites have their own privacy policies and we accept no responsibility or liability for them. Please check each site's policy before submitting personal data.

15. Changes to This Policy

We may update this policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you directly. We encourage you to review this policy periodically.

16. Contact Us

Kikin Financial Limited
4th Floor, 14 Museum Place
Cardiff
CF10 3BH

Email: hello@kikin.io
Data Controller / DPO: Antony Woods — antony@kikin.io

To make a complaint to the supervisory authority:
Information Commissioner's Office (ICO) — ico.org.uk | 0303 123 1113