Privacy notice
This notice explains what personal information Ledger holds, why, and what you can do about it. It is written to be read, not to be scrolled past. If anything is unclear, ask: [email].
Who is responsible
[Company name] Limited (company number [00000000], registered office [address]) is the controller for the personal data described in the first table below — information about you as a user of Ledger.
For the personal data inside your books — the names and details of your customers, suppliers and staff — you are the controller and we are the processor. We hold that data on your instructions and under your account's terms, and we do nothing with it except run the service for you. The second table covers it.
ICO registration number: [ZA000000].
Information about you, as a user
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| Your name and email address | To create your account, sign you in, and contact you about the service (a password reset, a receipt, notice of a change). | Contract | While your account is open, then [90] days. |
| Your password | To sign you in. Stored only as a one-way hash; we cannot see it. | Contract | As above. |
| Two-factor authentication secret and recovery codes | To verify it is you. Stored encrypted. | Contract, and our legitimate interest in keeping accounts secure | As above. |
| Sign-in records: the time, the IP address, the browser, and whether a device was remembered | To keep your account secure, spot unusual access, and let you see and end sessions. | Legitimate interest — security | Sessions for 30 days after last use; sign-in history for [12 months]. |
| The business you keep books for: its name, company number, VAT number, addresses | To print on your invoices and returns, and to file with HMRC. | Contract | While the account is open, then [90] days. |
| The audit trail: what each user did, and when | So that a set of books can show who changed what. This is a core feature of the software, not incidental logging. | Contract, and legal obligation (accounting records) | With the books. |
| Your HMRC connection: the tokens HMRC issues when you connect, and the receipts for returns filed | To submit VAT returns on your instruction and prove they were received. | Contract, and legal obligation | Tokens until you disconnect or they expire; receipts for six years, as HMRC requires. |
| Fraud-prevention data required by HMRC (device type, browser, IP address, screen size, time zone) sent with each submission | HMRC requires this from all Making Tax Digital software. It goes to HMRC, not to us. | Legal obligation | Not stored by us. |
| Payment details | To charge for your plan. Handled entirely by [Stripe]; we hold only the last four digits and the expiry, to show you which card is on file. | Contract | While the subscription runs, then [6 years] for our own accounting records. |
| Emails you send us, and our replies | To help you. | Legitimate interest — support | [2 years]. |
We do not use cookies for tracking or advertising. Ledger uses browser storage only to keep you signed in and to remember which set of books you had open. There is no third-party analytics script, no advertising pixel, and no third-party tracking of any kind.
We do record how the software itself is used — which screens are opened, which features are used, and where something was refused or abandoned — so that we can improve it. This is sent only to our own servers, kept only in aggregate, and never used to identify or profile you as a person.
Information inside your books
Your books contain personal data about other people: your customers and suppliers (names, addresses, emails, bank details for payment runs), the people you invite to your books, and anyone named in a description. You are the controller of this data. We process it only to run the service, as your processor.
| What we do with it | What we do not do with it |
|---|---|
| Store it, encrypted at rest, in the United Kingdom. | Sell it, share it, or show advertising against it. |
| Display it to the people you have given access to your books. | Use it to train any model, or to build any product. |
| Send emails you ask us to send — an invoice, a statement, a reminder — to the addresses you provide. | Contact your customers or suppliers for any purpose of our own. |
| Include it in exports you request. | Look at it, except to provide support you have asked for or to investigate a fault, under confidentiality. |
| Delete it when you close your account, on the schedule below. | Keep it after you have left, beyond that schedule. |
If one of your customers or suppliers asks you what data you hold about them, Ledger's export lets you answer. If they ask us directly, we will refer them to you, as their controller.
Who we share data with
Only the companies needed to run the service. Each is bound by a contract that limits what they may do with the data to providing their service to us.
| Who | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosts the software and the database, and holds the backups. | London (eu-west-2). Data does not leave the UK. |
| [Resend] [via Cloudflare Workers] | Delivers the emails you send from Ledger — invoices, statements, reminders — and our own account emails. | [Confirm: EU or US region, and the safeguard — UK adequacy / IDTA] |
| HM Revenue & Customs | Receives VAT returns you file, with the fraud-prevention headers it requires. | United Kingdom. A public authority, not a processor. |
| [Stripe] | Takes payment for your plan. | [Confirm region and safeguard] |
| Bank of England and the European Central Bank | Publish the exchange rates Ledger fetches. Nothing about you is sent to them. | — |
We will update this table before adding anyone to it. We do not share personal data with anyone else, except where the law requires — a court order, or a request from HMRC or the police that we are obliged to comply with — and then only what is required.
How long we keep things
- While your account is open: everything above, so the service works.
- After you close it: your books and account are kept read-only for [90] days, in case you return, then deleted. Backups are overwritten within a further [35] days.
- What we must keep longer: records of what we invoiced you (six years, for our own tax); HMRC filing receipts (six years, for yours). Nothing else survives closure.
Your rights
Under UK data protection law you can ask us to:
- Tell you what we hold about you (a subject access request). Most of it you can see in Settings; for the rest, email us.
- Correct anything wrong. Your own details you can change in Settings.
- Delete your data — by closing your account, which follows the schedule above. Note that accounting records you are legally required to keep are yours to export before you do.
- Export your data in a usable form. The software does this for your books at any time; for account data, email us.
- Object to processing based on legitimate interest, and we will stop unless we have a compelling reason not to.
We will answer within one month. There is no charge. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first.
Security
- All traffic is encrypted in transit; the database and backups are encrypted at rest.
- Each business's data is isolated at the database level: a query for one set of books cannot see another's.
- Passwords are hashed; two-factor secrets are encrypted; HMRC tokens are encrypted.
- Posted entries cannot be edited or deleted — corrections are further entries — so the record of what happened is permanent.
- If we ever discover a breach affecting your data we will tell you within 72 hours, and the ICO where required.
Children
Ledger is for businesses. It is not intended for anyone under 18 and we do not knowingly hold data about children.
Changes to this notice
We will email you before any change that affects how your data is used. Minor clarifications may be made without notice; the date at the top always shows the current version.
Contact
[Company name] Limited
[Registered office address]
[email]
Data protection contact: [name or role]. (A formal Data Protection Officer is not required for a business of this size; naming someone responsible is still good practice.)