Data Processing Terms
Last updated 15 September 2026. These terms form part of the Terms of Service whenever Cognivault is used by or for an organisation (the “customer”). They set out the terms required by Article 28 of the UK GDPR for personal data in the customer’s workspace content, which Nikah AI Ltd (“we”) processes as processor for the customer as controller.
1. Scope of the processing
- Subject matter and purpose: hosting, storing, displaying and, when a user runs Ask or a Decision Brief review, AI analysis of workspace content, to provide the service.
- Duration: for as long as the workspace exists, then until deletion as described in section 7.
- Types of personal data: whatever personal data the customer’s users choose to type or paste into workspace records, such as names, roles and opinions of people involved in a decision, plus the names and email addresses of workspace members and invitees.
- Data subjects: the customer’s users and anyone the customer’s content is about.
- Special category data: the service is not designed for it and the customer must not enter it.
Account data, billing records and security logs are processed by us as controller and are covered by the privacy policy, not by these terms.
2. Instructions
We process the customer’s personal data only on its documented instructions, which are these terms, the Terms of Service and the customer’s use of the product’s features, including any transfer described in section 5, unless UK law requires otherwise, in which case we will tell the customer first unless the law forbids it. We will tell the customer if we think an instruction infringes data protection law. The customer is responsible for having a lawful basis for the personal data it puts into the service.
3. Confidentiality
Access to customer data is limited to the company’s director, who is bound by confidentiality, and is used only to run and support the service or where the customer asks us to.
4. Security
The measures in place are: traffic to the site is served over HTTPS; the database runs on our own server with its ports reachable only from that server; the server has a host firewall and accepts administrative sign-in by cryptographic key only, not by password; every workspace read and write is checked against workspace membership on the server; passwords are stored only as hashes; and the database is backed up nightly. We keep these measures under review. We do not hold ISO 27001 or SOC 2 certification.
5. Sub-processors and international transfers
The customer gives general authorisation for the following sub-processors:
- OVH — server infrastructure, located in England. OVH provides the machine; we operate the software on it.
- OpenCode Zen, operated by Anomaly (San Francisco, United States) — AI analysis, only when a user runs Ask or a Decision Brief review. It receives the question or brief and the matching workspace content, and passes it to the DeepSeek V4 Pro model. OpenCode states that all the models it serves are hosted in the United States; it does not name the company that hosts this model for it. OpenCode states that its providers keep no copy of requests and do not train on them; we have not verified this independently.
Stripe processes payment details as an independent controller and merchant of record and receives no workspace content.
Transfer to the United States. AI analysis involves a transfer of the content sent to the United States. OpenCode does not offer a data processing agreement or a UK transfer mechanism, and none is currently in place between us and OpenCode. We cannot therefore offer the contractual protections Article 28(4) and Chapter V of the UK GDPR expect for that sub-processor. The customer should not submit personal data to the AI features unless it has satisfied itself that the transfer is lawful for its purposes. Content that is never analysed is not sent.
We will update this page before adding or replacing a sub-processor. A customer that objects may stop using the affected feature or cancel under the billing terms.
6. Assistance
Taking into account the nature of the processing, we will help the customer respond to data subject requests (the customer’s users can edit many records and remove brief sources and profile entries themselves; we will make other corrections or deletions on the customer’s written request), and with security, breach notification, data protection impact assessments and consultation with the ICO. We will tell the customer without undue delay after becoming aware of a personal data breach affecting its data, at the account email of the workspace owner.
7. Deletion at the end
When a workspace is deleted — when its last member deletes their account, or by us on the customer’s written request — its content is deleted from the live database immediately. Copies in nightly backups are removed within up to 45 days. A customer that wants its content first can copy it out of the product before deleting.
8. Information and audits
On reasonable written request to info@nikah-ai.com, we will make available the information necessary to demonstrate compliance with these terms and will answer reasonable questions in writing. Any audit beyond that is by agreement, at the customer’s cost, on reasonable notice, and subject to confidentiality.
9. Liability and precedence
The limitation of liability in the Terms of Service applies to these terms. If these terms conflict with the Terms of Service on the processing of personal data, these terms prevail.