Legal

Data Processing Terms

How Nikah AI Ltd, trading as WatchTower, processes personal data on your behalf as your processor. These terms form part of the Terms of Service.

Last updated 15 September 2026.

1. Scope and roles

These terms apply when Nikah AI Ltd (trading as WatchTower, “we”) processes personal data on behalf of a customer (“you”) in providing WatchTower. They form part of the Terms of Service and are intended to meet Article 28(3) of the UK GDPR. You are the controller and we are your processor. Where they conflict with the Terms of Service on data protection, these terms win.

2. Details of the processing

  • Subject matter and duration: providing WatchTower for as long as you have a workspace, plus the deletion periods in section 9.
  • Nature and purpose: collecting, storing, analysing and displaying endpoint security telemetry; raising alerts; carrying out response actions you configure or request; sending alert emails; and, where you enable them, the optional features listed below. We process this data only to provide WatchTower to you.
  • Data subjects: your employees, contractors, pupils or other people who use devices on which you install the agent; your console users; recipients of phishing simulations you send.
  • Security telemetry (on by default): device name and identifiers, operating system and security posture, IP addresses, signed-in Windows or system user names, process names and command lines, file names, paths and hashes, network connections and domains, installed software and patches, and detection and response events.
  • Optional, off by default, switched on by you: application use and time tracking, document and window titles, web domains and full web addresses, USB device events, data-loss-prevention findings (with the matched content redacted), and phishing simulation results (whether an email was opened or a link clicked, with IP address and browser details).
  • Available unless you turn remote support off: screenshots of a device’s screen, taken every few seconds while an administrator has a remote session open and held briefly (10 minutes by default). WatchTower has no keylogging, microphone or webcam capture.
  • Special category data: WatchTower is not designed to collect it, but titles, file names, web addresses or data-loss findings can reveal it. You decide which features to enable.

3. Your instructions

We process the personal data only on your documented instructions, which are these terms, the Terms of Service and the settings and actions you choose in the console, unless UK law requires otherwise, in which case we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks data protection law.

4. Confidentiality

Access to your data is limited to Nikah AI Ltd personnel who need it to operate or support the service, and they are bound by confidentiality.

5. Security

We maintain the following measures, and will not reduce their overall level:

  • all traffic between browsers, agents and the server is encrypted with TLS;
  • agent requests are signed with a per-device key and checked for replay; agent secrets and integration credentials are encrypted in the database; passwords are hashed;
  • each workspace is logically separated, and only the platform operator can act across workspaces;
  • console roles, optional multi-factor authentication, and a hash-chained audit log of administrative actions;
  • the database is not reachable from the internet;
  • daily database backups, kept for up to 14 days on the server and copied to a backup computer in the UK controlled by Nikah AI Ltd, where they are kept for up to 30 days.

We do not currently hold ISO 27001, SOC 2 or Cyber Essentials certification.

6. Sub-processors

You give general authorisation for us to use sub-processors. The current list is:

  • OVHcloud — virtual server hosting. The server that runs the console and stores every workspace’s data is in the United Kingdom.
  • Stripe — payments and subscription billing. Receives the billing contact, organisation name and device count for a subscription; never endpoint telemetry. Stripe may process data outside the UK.
  • Zoho — hosts the info@nikah-ai.com mailbox. Receives notifications of contact-form messages and anything you email us, which may include personal data you choose to send. Zoho may process data outside the UK.

We will update this page, and tell you by email or in the console, at least 14 days before adding or replacing a sub-processor that will process your personal data, so you can object. If you object on reasonable data protection grounds and we cannot address it, you may cancel and we will refund any fees paid for the period after the change. We impose data protection obligations on each sub-processor equivalent in substance to these terms, and remain responsible to you for their performance.

Mail that WatchTower sends (alerts, account emails, phishing simulations) goes directly from our UK server to the recipient’s email provider; we do not use a third-party email delivery service. We do not send your data to any AI provider. If you connect your own AI provider, threat-intelligence account (such as VirusTotal, AbuseIPDB or AlienVault OTX), Microsoft 365 or Defender, PSA tool, single sign-on provider or webhook, data is sent to it on your instruction under your own agreement with that provider; it is not our sub-processor.

7. International transfers

Your workspace data is stored and processed on our server in the United Kingdom. Stripe and Zoho may process the limited data described above outside the UK under their own transfer safeguards. We will not otherwise transfer your personal data outside the UK without ensuring a lawful transfer mechanism under UK data protection law.

8. Helping you

  • Individuals’ rights: the console lets you export and erase data; where you need more, we will help you respond to requests from individuals. If we receive a request directly we will pass it to you and not respond ourselves unless you ask.
  • Breaches: we will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we have and further details as they become available, so you can meet your own reporting duties.
  • Assessments: we will give you information you reasonably need for a data protection impact assessment or consultation with the ICO; our summary is on the DPIA page.

9. Deletion at the end

Detailed telemetry and workforce activity are deleted automatically once older than the retention period for your workspace, which an administrator can view and change under Settings → Data retention. The period is set when the workspace is first used: 365 days for a workspace created during a trial, or your plan’s advertised history (14, 90 or 365 days) otherwise. Check it matches what you need. Alerts, incidents and the audit log are kept for the life of the workspace so investigations remain possible.

At the end of the service you choose whether to export your data; we delete the workspace when you ask, and in any case no later than 12 months after your subscription or trial ends, and confirm deletion in writing if you ask. Backup copies are overwritten within a further 30 days. We keep data longer only where UK law requires it (for example billing records).

10. Audits

We will make available the information reasonably needed to show that we meet these terms and answer reasonable written questions. Where that is not enough, you may carry out an audit, or have an independent auditor bound by confidentiality do so, no more than once a year, on 30 days’ notice, at your cost, and in a way that does not compromise other customers’ data.

11. Liability

Each party’s liability under these terms is subject to the limits in section 9 of the Terms of Service, except where the law does not allow liability to be limited.

Contact

Data protection questions: use the contact form (choose “Data protection”) or email info@nikah-ai.com.