Legal
Privacy Policy
Version 0.2 · Last Updated: 17 July 2026
1. Introduction
FiqhEngine Ltd ("we", "our", or "us") is committed to protecting the privacy and security of your data. This Privacy Policy describes how we collect, use, and process personal and proprietary information in connection with our Shariah Governance Platform.
2. Data Controller vs. Data Processor
Customer Data (The "Processor" Role): When you (the Bank or Advisory Firm) upload documents, fatwas, or customer lists to the Platform, you are the Data Controller. We act as the Data Processor, processing this data solely on your instructions to provide the Service.
Account Data (The "Controller" Role): We act as the Data Controller for your account registration details (e.g., admin names, billing emails) used to manage our business relationship.
3. The Data We Collect
- User Content: Documents, workflows, and decisions input into the system.
- Usage Data: Logs of how you interact with the Platform (e.g., login times, features used).
- Platform Learnings: Anonymised, aggregated, non-attributable insights about platform usage and workflow patterns, used solely to improve the Platform.
4. How We Use Your Data
To Provide the Service: To manage your workflows and generate reports.
To Improve the Platform (Platform Learnings):
- We derive anonymised, aggregated, non-attributable insights about platform usage and workflow patterns ("Platform Learnings"), used solely to improve the Platform.
- Platform Learnings do not identify you, your organisation, or your underlying clients.
- FiqhEngine does not train machine-learning models on customer content, and never uses one customer's content for the benefit of another customer.
5. Data Sovereignty & Hosting
- Location: Your data is hosted on Railway in the US East (Virginia, USA) region.
- International Transfers: Transfers from the United Kingdom rely on the UK International Data Transfer Addendum and the Standard Contractual Clauses under Railway's Data Processing Agreement. We support customers subject to equivalent local data protection regimes in their own jurisdictions.
6. Security
We implement enterprise-grade security measures to protect your data:
- Encryption: All sensitive data is encrypted at rest using AES-256-GCM encryption and in transit using TLS 1.2+ (TLS 1.3 supported).
- Secure Cookies: Session cookies use HttpOnly, Secure, and SameSite flags with encrypted values.
- Access Controls: Role-based access control (RBAC) and multi-factor authentication (2FA) available.
- Audit Logging: All data access and security events are logged for compliance monitoring.
- Security Review: We completed an internal codebase security review in July 2026, with all high-severity findings remediated. Third-party penetration testing is planned prior to external commercial launch.
7. Cookie Policy
We use cookies and similar technologies to enhance your experience and analyse site usage. You can control which cookies you accept through our cookie consent banner.
7.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us remember your preferences and understand how you use our platform.
7.2 Types of Cookies We Use
Necessary Cookies (Always Active)
Essential for the website to function properly. These cookies enable core functionality such as security, authentication, and accessibility features. They cannot be disabled.
Examples: Session tokens, authentication cookies, security tokens, CSRF protection
Analytics Cookies (Optional)
Help us understand how visitors interact with our website by collecting and reporting information anonymously. Used for Google Analytics 4 (with IP anonymisation) and performance monitoring. These cookies are blocked until you grant Analytics consent.
Examples: Google Analytics 4 (_ga, _ga_*), page view tracking, performance metrics
Preference Cookies (Optional)
Remember your preferences and settings such as language, region, and display options to provide a personalized experience.
Examples: Language preferences, theme settings, UI customizations
7.3 Managing Your Cookie Preferences
When you first visit our website, you'll see a cookie consent banner with the following options:
- Accept All: Enable all cookies for the best experience
- Reject All: Only necessary cookies will be used
- Customize: Choose which cookie categories to enable
Changing Your Preferences: You can update your cookie preferences at any time by:
- Visiting your Privacy Dashboard (for authenticated users) - includes a dedicated Cookie Preferences section
- Clicking "Manage Cookies" in the footer of any page
- Clearing your browser cookies and revisiting our website to see the banner again
- Using your browser's cookie settings to manage cookies directly
7.4 Third-Party Cookies
Some cookies are placed by third-party services that appear on our pages. We do not control these cookies. Please review the privacy policies of these third parties for more information:
7.5 Cookie Retention
Different cookies have different retention periods:
- Session Cookies: Deleted when you close your browser
- Persistent Cookies: Remain on your device for a set period (typically 30 days to 2 years)
8. Data Retention
- During Subscription: We retain your data for the duration of your contract.
- After Termination: You have 60 days to export your data. After this period, we will securely delete your User Content. Residual copies expire from our backup archives within approximately 35 days after deletion, consistent with our point-in-time recovery window. Platform Learnings may be retained as they are anonymised and no longer personal data.
9. Third-Party Services & Data Processors
We use carefully selected third-party services to provide our platform. All processors have signed Data Processing Agreements (DPAs) compliant with GDPR Article 28.
Infrastructure
- Railway - Application and database hosting in the US East (Virginia, USA) region, on SOC 2 Type II / ISO 27001 certified infrastructure with point-in-time recovery backups.
- PostgreSQL - Database, with sensitive fields additionally encrypted at the application layer using AES-256-GCM.
Email Services
Transactional emails (account, security, and notification messages) are delivered through:
- SendGrid (Twilio) - Transactional email delivery, under the Twilio Data Processing Addendum.
Where a customer provides their own mail server, transactional emails may instead be routed through that customer-configured SMTP service.
Connected Calendar Integrations (Optional)
FiqhEngine offers optional calendar integrations with Google Calendar and Microsoft Outlook. These integrations are off by default; you enable them per user account from the Calendar widget by clicking "Connect Google" or "Connect Microsoft" and granting consent on the respective provider's OAuth screen.
- Google Calendar API (scope
calendar.events) — read your upcoming events to render the in-app schedule view, and write engagement and task due dates as all-day calendar events so deadlines surface in your existing workflow. - Google People API (scope
contacts.readonly) — autocomplete attendee email addresses when you schedule a meeting from within FiqhEngine. Contacts are fetched on demand and not copied to FiqhEngine's database. - Google OpenID (scope
userinfo.email) — display the connected Google account address in the calendar widget so you can see which account is connected. - Microsoft Graph API (scopes
Calendars.ReadWrite,Contacts.Read,offline_access,openid,profile,email) — equivalent functionality against Microsoft 365 / Outlook calendars and contacts.
What we store. Only the OAuth access and refresh tokens (encrypted at rest with AES-256-GCM), the connected account's email address, and a per-event identifier so we can later update or remove events we previously created on your behalf. Event bodies, attendee lists, and contact lists are fetched on demand and not persisted.
Disconnect at any time. Use the Calendar widget's Settings → Disconnect option to revoke FiqhEngine's access and delete the stored tokens immediately. You may also revoke the grant directly with the provider at myaccount.google.com/permissions or account.microsoft.com/privacy/app-access.
Google API Limited Use compliance. FiqhEngine's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we (a) only use Google user data to provide and improve the calendar and contact features described above; (b) do not transfer Google user data to third parties except as necessary to provide those features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with your prior notice; (c) do not use Google user data for serving advertisements; (d) do not allow humans to read Google user data unless we have your explicit affirmative consent, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or for internal operations where the data has been aggregated and anonymised; and (e) do not use Google user data to develop, improve, or train generalised or non-personalised AI or machine-learning models.
AI-Assisted Document Processing
FiqhEngine uses Google Gemini (via the Google AI API) to generate Shariah advisory suggestions and to analyse uploaded documents. Where features send content to Gemini, that content is processed to return results to you; FiqhEngine does not use it to train its own models.
- Google Gemini API — advisory suggestion generation and document analysis. Google does not use data submitted through the paid Gemini API to train its models.
Meeting & E-Signature Integrations (Optional)
Depending on the features your organisation enables, we may share the minimum necessary data with the following providers:
- Zoom, Microsoft Teams, and Google Meet — to schedule and host meeting links when you create a meeting from within FiqhEngine.
- Slack — to deliver notifications to your workspace where a customer enables the Slack integration.
- SignWell — to send documents for electronic signature where e-signature is enabled.
What We DON'T Use
- ❌ Advertising networks or data brokers
- ❌ Social media tracking pixels
- ❌ Profiling or automated decision-making services
We do use Google Analytics 4 (with IP anonymisation) on our marketing website only, and solely where you have granted Analytics-cookie consent. It is not used inside the authenticated application. See the Cookie Policy above.
International Data Transfers
Some services are located in the USA. We protect your data through:
- Standard Contractual Clauses (SCCs) approved by EU Commission
- Encryption in transit (TLS 1.2 minimum, TLS 1.3 supported) and at rest (AES-256-GCM)
- Access controls and authentication
- Regular security audits
For a complete list of our sub-processors, see our Sub-Processors page.
10. Email Communications & Legal Basis
We send different types of emails based on various legal grounds under GDPR. You have control over which emails you receive:
| Email Type | Legal Basis | Opt-Out | Default |
|---|---|---|---|
| Account creation | Contract | ❌ No | Enabled |
| Password reset | Contract | ❌ No | Enabled |
| Security alerts | Legitimate Interest | ❌ No | Enabled |
| Engagement updates | Contract | ✅ Yes | Enabled |
| Audit reminders | Contract | ✅ Yes | Enabled |
| Document uploads | Contract | ✅ Yes | Enabled |
| SSB decisions | Contract | ✅ Yes | Enabled |
| Advisory responses | Contract | ✅ Yes | Enabled |
| Weekly digest | Consent | ✅ Yes | Disabled |
| Marketing/newsletters | Consent | ✅ Yes | Disabled |
Contract: Emails necessary to fulfill our service agreement with you.
Legitimate Interest: Emails necessary for security and fraud prevention.
Consent: Optional emails that require your explicit opt-in.
You can manage your email preferences in your Privacy Dashboard.
11. Inactive Account Policy
To comply with GDPR data minimization principles, we automatically manage inactive accounts:
- Accounts with no login activity for 18 months receive a warning email (6 months until anonymization)
- Accounts with no login activity for 23 months receive a final warning email (1 month until anonymization)
- Accounts with no login activity for 24 months are automatically anonymized
- Anonymization removes all personal information while preserving audit trails for compliance
- You can prevent anonymization by simply logging in to your account
- Accounts under legal hold are exempt from automatic anonymization
If you no longer need your account, you can request immediate deletion through your Privacy Dashboard.
12. Your Rights
Under the UK GDPR, you have the following rights:
- Right to Access: Request a copy of your personal data via our Privacy Dashboard or by contacting us.
- Right to Rectification: Correct inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data (subject to legal obligations).
- Right to Data Portability: Export your data in JSON or CSV format via the Privacy Dashboard.
- Right to Object: Object to processing of your data for specific purposes.
- Right to Withdraw Consent: Withdraw consent for data processing at any time via Privacy Settings.
To exercise these rights, visit your Privacy Dashboard or contact privacy@fiqhengine.com.
13. Contact Us
FiqhEngine Ltd
128 City Road
London EC1V 2XN
United Kingdom
privacy@fiqhengine.com — privacy and data-rights enquiries
info@fiqhengine.com — general enquiries