Security & data
Your numbers stay yours.
Nella connects to your accounting software read-only, stores what it needs to answer your questions, and lets you delete all of it at any time. This page sets out exactly what happens to your data.
Can Nella change my accounting data?
No. Nella connects to Xero, QuickBooks, Sage and FreeAgent in read-only mode. It can read permitted accounting data, but it cannot create, edit or delete transactions, invoices or journals in your books. Write permissions are not requested during sign-in, so there is nothing to switch on later without asking you again.
When you connect, your accounting provider shows you a consent screen listing exactly what Nella is asking for. Every permission on that screen is a read permission. If Nella ever needed to write to your books, your provider would have to ask you for that separately — you would see it, and you would have to approve it.
What data does Nella read?
Nella reads the accounting records needed to answer questions about your numbers: contacts, organisation settings, invoices and bills, bank transactions, payments, manual journals, budgets, and the standard reports — profit and loss, balance sheet, trial balance, aged receivables and payables, bank summary and tax reports. Where payroll access is granted, it reads employee pay setup and pay-run amounts.
Nella asks for granular, named permissions rather than blanket access. Some data stays closed to it entirely — system-generated journal lines, for example, are not available to Nella on Xero.
Where is my data held?
Nella runs on Amazon Web Services in the London region (eu-west-2). Your accounting data and the reports built from it are processed and stored in the United Kingdom.
How is my data protected?
Encrypted in transit
Connections to your accounting software, and between you and Nella, use TLS. The site is served over HTTPS only.
Access tokens encrypted at rest
The credential that lets Nella read your ledger is encrypted before it is stored, using authenticated encryption with key rotation, so a retired key can still decrypt older records while new writes use the current one.
Separated by account
Every connection is scoped to the business that authorised it. Your figures are only ever used to answer your own questions and build your own reports.
Read-only by design
The read-only boundary is enforced at the permission level by your accounting provider, not merely by Nella’s own code.
Uploads scanned
Every document uploaded to Nella is virus-scanned before it is made available. The scan fails closed: if the scanner cannot run, the file is rejected rather than accepted unchecked.
Access logged
Access to your data and administrative actions are logged, so there is a record of what was read and when.
Backed up and restorable
Regular encrypted backups with documented restoration procedures, so the service can be brought back after an incident. Backups are purged on the normal cycle within 90 days.
Is my data used to train AI models?
No. Nella uses Anthropic’s Claude models through Anthropic’s commercial API. Under Anthropic’s commercial terms, data submitted through the API is not used to train its models. Nella does not train, fine-tune or build any model on your business data.
When you ask Nella a question, the figures needed to answer it are sent to the model to generate that answer, and the answer comes back to you. That is the extent of it.
How long is my data kept?
Trial data — the connection, the reports built from it and the associated record — is retained for 90 days from the point your pack is delivered, then removed automatically by a scheduled housekeeping process. You do not have to wait for that: you can delete everything yourself at any time.
How do I delete my data?
Disconnecting stops access immediately. Requesting deletion runs a full erasure: the access token is revoked with your accounting provider and deleted, every messaging connection (WhatsApp, ChatGPT, Claude and Slack pairings) is removed, and the reports, scores and personal details held by Nella are erased.
To request deletion, email security@nellafinance.co.uk from the address on your account. You can also disconnect from within Nella at any time without emailing anyone.
Who else processes my data?
Nella uses a small number of third parties to operate the service. This list is maintained and dated — if it changes, this page changes.
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting and storage (London, eu-west-2) | All application and report data |
| Anthropic | The AI model that generates answers | The figures needed to answer your question |
| Xero, Intuit QuickBooks, Sage, FreeAgent | The accounting platform you choose to connect | Read-only access to your ledger |
| Cloudflare | Serves standard web assets to your browser | Your IP address |
| OpenAI | The ChatGPT channel, if you use it | The results Nella returns to you in that conversation |
| Google (Workspace) | Relays transactional and service email | Your email address and message content |
| HubSpot | Customer records and communication | Your name, email and account status |
| Meta (WhatsApp) | The WhatsApp channel, if you use it | Your messages to and from Nella on WhatsApp |
| Stripe | Payment processing on paid plans | Billing details; card data is handled by Stripe, not Nella |
The full, maintained subprocessor list — including where each provider processes data — is published at nellafinance.co.uk/subprocessors. We publish a new subprocessor there at least 30 days before it begins processing personal data.
Last reviewed 25 August 2026.
What happens if there is a breach?
If a personal data breach occurs that is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours where required, and tell affected users without undue delay where the risk is high. Where Nella acts as your processor, we notify you without undue delay and, where reasonably practicable, within 72 hours of becoming aware.
The notice sets out what we know: the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, what we have done about it, and who to contact. Where we cannot provide all of that at once, we provide it in phases rather than waiting.
What are Nella’s contractual commitments?
The security measures described on this page are also given contractually. Annex 2 of our Data Processing Addendum sets them out as binding commitments, alongside our obligations on subprocessors, deletion, audit and international transfers. The DPA applies automatically when you accept the Nella Terms of Service — you do not need to sign anything.
What Nella does not claim
Nella does not hold SOC 2, ISO 27001 or any comparable security certification, and does not display badges for controls it has not been independently assessed against. The controls described on this page are the ones actually in place.
Nella provides financial information and education, not accounting or tax advice. Nella Finance AI Ltd develops the Nella software. Accounting, tax and advisory services are provided separately by AccTek Ltd under a separate engagement.
Is Nella registered with the ICO?
Yes. Nella Finance AI Ltd is registered with the Information Commissioner’s Office as a data controller under registration reference ZC224350. The registration can be checked on the ICO’s public register of fee payers.
Registration records that we pay the data protection fee and are identified on the ICO’s register. It is not a security certification — the controls actually in place are the ones described above.
Reporting a security concern
If you believe you have found a vulnerability or have a question about how your data is handled, email security@nellafinance.co.uk. Please include enough detail to reproduce the issue. We will acknowledge your report and keep you informed while we investigate.
FAQ