Skip to content
Nella.
How it works Pricing Security Blog Start free

Data Processing Addendum

Nella Finance AI Ltd · Version 1.0 · Effective 11 September 2026

How this works

This Data Processing Addendum ("DPA") is incorporated into and forms part of the Nella Terms of Service (the "Agreement") between Nella Finance AI Ltd ("Nella", "we", "us") and the customer who has accepted them (the "Customer", "you").

You do not need to sign or return anything. This DPA applies automatically from the moment you accept the Agreement and begin using Nella. It is published here so you can read it, save it and rely on it.

If your organisation requires a signed counterpart on Nella's paper, email privacy@nellafinance.co.uk and we will provide one. We will countersign this document unchanged; we do not negotiate bespoke terms at standard subscription tiers.

Where this DPA conflicts with the Agreement on the processing of personal data, this DPA governs.

1. Definitions

"Data Protection Laws" means privacy and data protection laws applicable to Nella's processing of Customer Personal Data under the Agreement, including, where applicable, the UK GDPR, Data Protection Act 2018, EU GDPR, Australian Privacy Act 1988 and applicable US state privacy laws. For the avoidance of doubt, a law is included only to the extent that it applies to the relevant processing or party.

Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings given in the UK GDPR, and equivalent terms in other Data Protection Laws are read accordingly. Where US state privacy laws apply, "controller" includes "business", "processor" includes "service provider" or "contractor", and "personal data" includes "personal information".

Customer Personal Data — personal data that Nella processes on your behalf under the Agreement, as described in Annex 1.

Subprocessor — a processor engaged by Nella to process Customer Personal Data.

Standard Contractual Clauses or SCCs — the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.

2. Roles of the parties

2.1 Two distinct relationships. The Agreement involves two categories of personal data, and our role differs between them.

2.2 Where we are the processor. Nella acts as processor for Customer Personal Data submitted or made available by the Customer for Nella to process on its behalf. This includes personal data in connected accounting records, uploaded documents and prompts or instructions relating to the Customer's customers, suppliers, employees, contractors or other third parties.

2.3 Where we are the controller. Nella acts as controller for account registration, authentication, billing, subscription management, direct support communications, security monitoring and technical service-usage information. Nella's processing of this data is governed by the Privacy Policy.

2.4 Not joint controllers. Nothing in this DPA makes the parties joint controllers of any personal data.

2.5 Your responsibilities as controller. You warrant that you have a lawful basis for the processing you instruct, that you have provided any notice and obtained any consent required from the data subjects whose data appears in your accounting records, and that your instructions do not require us to breach Data Protection Laws. You are responsible for the accuracy of the data in your own accounting software; Nella reads it and does not correct it.

3. Scope and purpose of processing

3.1 Documented instructions. We process Customer Personal Data only: (a) as necessary to provide, secure and support the Nella service under the Agreement; (b) as set out in Annex 1; (c) as further instructed by you through your use of the service — including which accounting software you connect, which permissions you grant, which channels you enable, and which reports you generate; and (d) as required by law, in which case we will tell you first unless the law prohibits it.

Where legally permitted, we will notify you before disclosing Customer Personal Data in response to a binding legal request. We will disclose only the information legally required and will reasonably challenge requests we consider unlawful or disproportionate.

3.2 Read-only access. Nella accesses your connected accounting software in read-only mode. We do not write to, alter or delete records in your accounting software.

3.3 No independent use. We do not sell Customer Personal Data, share it for cross-context behavioural advertising, retain or use it outside the direct business relationship with you, or combine it with data from other sources except as permitted by Data Protection Laws.

3.4 No AI training. We do not use Customer Personal Data to train, fine-tune or improve any machine learning model, and our AI subprocessors are contractually prohibited from doing so with data we send them.

3.5 Aggregated data. We may create and use statistical or aggregated data derived from the operation of the service, provided it does not identify you, any data subject or any individual business, and cannot reasonably be used to re-identify them.

3.6 Unlawful instructions. If we consider that an instruction from you infringes Data Protection Laws, we will tell you without undue delay and may suspend that processing until the instruction is withdrawn, amended or confirmed.

4. Confidentiality

We ensure that every person authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality that survives the end of their engagement, and that access is limited to those who need it to perform the Agreement.

5. Security

5.1 Measures. We implement appropriate technical and organisational measures to protect Customer Personal Data, as described in Annex 2 and at nellafinance.co.uk/security.

5.2 Changes. We may update our security measures, provided the overall level of protection is not reduced.

5.3 Your side of the line. You are responsible for the security of your own credentials, your accounting software connections, your users' access to your Nella account, and any AI assistant or messaging platform you choose to connect.

6. Subprocessors

6.1 General authorisation. You give us general authorisation to engage subprocessors to process Customer Personal Data.

6.2 Current list. The current subprocessors are published at nellafinance.co.uk/subprocessors.

6.3 Notice of changes. We will publish a notice of a new subprocessor on that page at least 30 days before it begins processing Customer Personal Data. Customers subscribed to subprocessor notifications will also receive notice by email.

6.4 Objection. You may object to a new subprocessor on reasonable data protection grounds within 30 days of notice. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Agreement without penalty and receive a pro-rata refund of prepaid fees for the unused term.

6.5 Our responsibility. We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

6.6 Channel platforms. Where you choose to use Nella through a third-party AI assistant or messaging platform, that platform receives the results Nella returns to you so it can display them. That platform's processing of the resulting conversation is governed by its own terms with you, not by this DPA. You are responsible for deciding whether to connect it. For clarity, a channel platform is not acting as Nella's subprocessor to the extent it independently determines how it processes the Customer's account, prompts, conversation history and displayed results under its own agreement with the Customer.

7. Assistance to you

7.1 Data subject requests. Nella provides self-service controls that let you access, export, correct and delete data within the service. If a data subject contacts us directly about data for which you are the controller, we will not respond substantively but will refer them to you and tell you promptly. Where the self-service controls are insufficient, we will provide reasonable assistance, at no charge for a reasonable volume of requests. We will also provide reasonable assistance where Customer Personal Data must be corrected or completed and the Customer cannot do so through the connected source system or available service controls.

7.2 Impact assessments and consultation. We will provide reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to us.

8. Personal data breach

8.1 Notification. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and, where reasonably practicable, within 72 hours.

8.2 Content. The notice will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.

8.3 Assistance. We will provide reasonable assistance with your own notification obligations to supervisory authorities and data subjects.

8.4 Not an admission. Notifying you of a breach is not an acknowledgement of fault or liability.

9. Deletion and return

9.1 During the term. You can export and delete data at any time using the controls in the service, including by instructing Nella to delete your data. Any returned copy will be provided in a commonly used, machine-readable format where technically feasible.

9.2 On termination. On expiry or termination of the Agreement you may ask us in writing, within 30 days, to return a copy of Customer Personal Data. We will delete Customer Personal Data within 90 days of expiry or termination, subject to any such return request and to clause 9.3.

9.3 Exceptions. We may retain Customer Personal Data where required by law, and in routine backups until they are overwritten on the normal backup cycle (within 90 days). Customer Personal Data retained solely in backups will not be actively processed and will be deleted when those backups are overwritten, except where restoration is necessary for disaster recovery or security purposes.

10. International transfers

10.1 Where we process. Nella is hosted in the United Kingdom (Amazon Web Services, London region). Some subprocessors process personal data outside the UK and EEA, principally in the United States, as set out at nellafinance.co.uk/subprocessors.

10.2 Transfer mechanisms. Where an adequacy decision or equivalent lawful transfer arrangement covers a transfer, that mechanism applies and no additional contractual safeguard is required. Where no such mechanism applies and a transfer requires an appropriate safeguard, the following provisions apply automatically and without further action by either party:

(a) From the EEA — the SCCs are incorporated by reference. Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are yourself a processor. Docking clause: applicable. Clause 9: Option 2, general written authorisation, with the notice period in clause 6.3. Clause 11: the optional independent dispute resolution body is not used. Clause 17: governed by the law of Ireland. Clause 18: the courts of Ireland. Annexes I, II and III are populated by Annexes 1, 2 and the subprocessors page of this DPA. Clause 13: the competent supervisory authority is determined in accordance with Clause 13 of the SCCs.

(b) Nella's onward transfers. Where Nella makes a restricted transfer from the United Kingdom to a subprocessor, Nella will ensure that the transfer is covered by applicable UK adequacy regulations or another mechanism permitted under UK Data Protection Laws. These safeguards are contained in Nella's agreements with the relevant subprocessors.

(c) From Australia — we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.

10.3 Assessments. We will provide information reasonably necessary for you to complete a transfer risk assessment.

11. Audit

11.1 Documentation first. We make available the information necessary to demonstrate compliance with this DPA, including our security documentation and any third-party certifications or audit reports we hold.

11.2 Audits. Where that information is not sufficient to satisfy a requirement under Data Protection Laws, you may audit our compliance no more than once in any twelve-month period (and additionally following a personal data breach affecting your data), on at least 30 days' written notice, during normal business hours, subject to confidentiality, and without unreasonably disrupting our business or the security or privacy of other customers. You bear your own costs and, where the audit is conducted by a third party, that third party must not be our competitor.

12. General

12.1 Term. This DPA applies for as long as we process Customer Personal Data, and clauses that by their nature should survive do so.

12.2 Changes to this DPA. We may update this DPA where required by Data Protection Laws, to reflect a change in the service, or to improve it, provided the change does not materially reduce your protections. We will publish the updated version at this address and, for material changes, notify you at least 30 days in advance. Previous versions remain available on request.

12.3 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.

12.4 Governing law. This DPA is governed by the law stated in the Agreement, except where clause 10.2 requires otherwise.

12.5 Precedence. In case of conflict: this DPA prevails over the Agreement on the processing of personal data; the SCCs prevail over this DPA to the extent of any conflict.

Annex 1 — Details of processing

Parties. Data exporter: the Customer, as controller or processor, as applicable. Data importer: Nella Finance AI Ltd, 128 City Road, London, England, EC1V 2NX, United Kingdom, as processor. Contact: privacy@nellafinance.co.uk.

Subject matter. Provision of the Nella financial information and reporting service.

Duration. The term of the Agreement, plus the deletion period in clause 9.

Nature and purpose. Reading data from the Customer's connected accounting software; calculating financial figures, indicators and forecasts from it; generating written explanations, reports and packs; storing generated reports and documents for the Customer; and making all of the above available to the Customer through the Nella portal and any channel the Customer enables.

Categories of data subject. The Customer's customers, suppliers, contacts, and — where they appear in the Customer's accounting records — its employees and contractors.

Categories of personal data.

CategoryExamples
Identity and contactName, business name, email address, telephone, address
TransactionalInvoices, bills, credit notes, payments, amounts, dates, references, narrative descriptions
BehaviouralPayment history, ageing, days-to-pay patterns
Document contentWhere the Customer uses document features, the contents of invoices, bills and attachments retrieved from the connected accounting software
Employment-relatedWhere present in the Customer's ledger or payroll records, pay run amounts and employee identifiers
Prompt and instruction contentPersonal data included in questions, prompts, instructions or requests submitted by Customer users for Nella to process on the Customer's behalf

Special category data. Nella does not require customers to provide special category or sensitive personal data. However, such data may be included incidentally in accounting records or documents supplied by the Customer. Where this occurs, Nella processes it only on the Customer's documented instructions and solely to provide the service. Customers must not provide such data unless they have a lawful basis and it is necessary for their use of Nella.

Children's data. Not intentionally collected. Nella is a business service not directed at children, and does not request data relating to children. Such data may nevertheless be included incidentally in Customer Personal Data — for example in an invoice, customer record or uploaded document — in which case Nella processes it only on the Customer's documented instructions and solely to provide the service.

Competent supervisory authority. Determined in accordance with Clause 13 of the SCCs.

Frequency. Continuous, for the duration of the Agreement, on the Customer's use of the service.

Retention. As set out in clause 9 and in the Privacy Policy.

Subprocessors. As published at nellafinance.co.uk/subprocessors.

Annex 2 — Technical and organisational measures

Encryption. Data encrypted in transit using TLS. Accounting software credentials and access tokens encrypted at rest, with separated key sets between the trial and client token stores.

Access control. Access to production systems and Customer Personal Data limited to personnel who require it; authentication required; access reviewed periodically.

Scoped access to your data. Connections to accounting software use OAuth with the narrowest permissions the platform offers for the features in use, are read-only, and can be revoked by the Customer at any time.

Tenant isolation. Customer data is segregated so that one customer's data is not accessible to another; access tokens are scoped to a single customer.

Logging. Access to Customer Personal Data and administrative actions are logged.

Malware scanning. Documents uploaded to Nella are scanned before they are made available.

Resilience. Regular backups; restoration procedures; the ability to restore availability after an incident.

Patching and vulnerability management. Systems and dependencies patched on a regular cycle; a security contact published at security@nellafinance.co.uk for vulnerability reports.

Deletion. Self-service deletion controls, and a documented erasure process covering conversations, memory, generated reports and stored documents.

Personnel. Personnel bound by confidentiality obligations; access removed on termination.

Testing. Security measures reviewed and tested on a regular basis.

Contact

Nella Finance AI Ltd, 128 City Road, London, England, EC1V 2NX, United Kingdom. Company number 17336736 · ICO registration ZC224350. Email privacy@nellafinance.co.uk.

Nella.

The AI finance assistant for UK businesses. Your numbers, answered in plain English.

Product
Start free trial Pricing Security & data How it works Nella Score Cash-flow forecast Management accounts MTD for Income Tax For directors For hospitality For startups For landlords For contractors For locum doctors
Company
About Contact Privacy Terms
Nella provides financial information and education, not accounting or tax advice.
Nella Finance AI Ltd develops the Nella software. Accounting, tax and advisory services are provided separately by AccTek Ltd under a separate engagement. AccTek Ltd is an ICPA member firm, AML-supervised by HMRC.
Nella Finance AI Ltd is registered in England and Wales, company number 17336736, ICO registration ZC224350, registered office 128 City Road, London, EC1V 2NX.
© 2026 Nella Finance AI Ltd. All rights reserved.
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}