ledger.

Privacy notice

Version 1 · draft for review · effective from [date]
Draft. Highlighted parts need your details or a decision. As a controller of personal data you will need to be registered with the ICO (the data protection fee, £40–£60 a year for a small business) before this goes live.

This notice explains what personal information Ledger holds, why, and what you can do about it. It is written to be read, not to be scrolled past. If anything is unclear, ask: [email].

Who is responsible

[Company name] Limited (company number [00000000], registered office [address]) is the controller for the personal data described in the first table below — information about you as a user of Ledger.

For the personal data inside your books — the names and details of your customers, suppliers and staff — you are the controller and we are the processor. We hold that data on your instructions and under your account's terms, and we do nothing with it except run the service for you. The second table covers it.

ICO registration number: [ZA000000].

Information about you, as a user

WhatWhyLawful basisKept for
Your name and email addressTo create your account, sign you in, and contact you about the service (a password reset, a receipt, notice of a change).ContractWhile your account is open, then [90] days.
Your passwordTo sign you in. Stored only as a one-way hash; we cannot see it.ContractAs above.
Two-factor authentication secret and recovery codesTo verify it is you. Stored encrypted.Contract, and our legitimate interest in keeping accounts secureAs above.
Sign-in records: the time, the IP address, the browser, and whether a device was rememberedTo keep your account secure, spot unusual access, and let you see and end sessions.Legitimate interest — securitySessions for 30 days after last use; sign-in history for [12 months].
The business you keep books for: its name, company number, VAT number, addressesTo print on your invoices and returns, and to file with HMRC.ContractWhile the account is open, then [90] days.
The audit trail: what each user did, and whenSo that a set of books can show who changed what. This is a core feature of the software, not incidental logging.Contract, and legal obligation (accounting records)With the books.
Your HMRC connection: the tokens HMRC issues when you connect, and the receipts for returns filedTo submit VAT returns on your instruction and prove they were received.Contract, and legal obligationTokens until you disconnect or they expire; receipts for six years, as HMRC requires.
Fraud-prevention data required by HMRC (device type, browser, IP address, screen size, time zone) sent with each submissionHMRC requires this from all Making Tax Digital software. It goes to HMRC, not to us.Legal obligationNot stored by us.
Payment detailsTo charge for your plan. Handled entirely by [Stripe]; we hold only the last four digits and the expiry, to show you which card is on file.ContractWhile the subscription runs, then [6 years] for our own accounting records.
Emails you send us, and our repliesTo help you.Legitimate interest — support[2 years].

We do not use cookies for tracking or advertising. Ledger uses browser storage only to keep you signed in and to remember which set of books you had open. There is no third-party analytics script, no advertising pixel, and no third-party tracking of any kind.

We do record how the software itself is used — which screens are opened, which features are used, and where something was refused or abandoned — so that we can improve it. This is sent only to our own servers, kept only in aggregate, and never used to identify or profile you as a person.

Information inside your books

Your books contain personal data about other people: your customers and suppliers (names, addresses, emails, bank details for payment runs), the people you invite to your books, and anyone named in a description. You are the controller of this data. We process it only to run the service, as your processor.

What we do with itWhat we do not do with it
Store it, encrypted at rest, in the United Kingdom.Sell it, share it, or show advertising against it.
Display it to the people you have given access to your books.Use it to train any model, or to build any product.
Send emails you ask us to send — an invoice, a statement, a reminder — to the addresses you provide.Contact your customers or suppliers for any purpose of our own.
Include it in exports you request.Look at it, except to provide support you have asked for or to investigate a fault, under confidentiality.
Delete it when you close your account, on the schedule below.Keep it after you have left, beyond that schedule.

If one of your customers or suppliers asks you what data you hold about them, Ledger's export lets you answer. If they ask us directly, we will refer them to you, as their controller.

Who we share data with

Only the companies needed to run the service. Each is bound by a contract that limits what they may do with the data to providing their service to us.

WhoWhat they doWhere
Amazon Web ServicesHosts the software and the database, and holds the backups.London (eu-west-2). Data does not leave the UK.
[Resend] [via Cloudflare Workers]Delivers the emails you send from Ledger — invoices, statements, reminders — and our own account emails.[Confirm: EU or US region, and the safeguard — UK adequacy / IDTA]
HM Revenue & CustomsReceives VAT returns you file, with the fraud-prevention headers it requires.United Kingdom. A public authority, not a processor.
[Stripe]Takes payment for your plan.[Confirm region and safeguard]
Bank of England and the European Central BankPublish the exchange rates Ledger fetches. Nothing about you is sent to them.—

We will update this table before adding anyone to it. We do not share personal data with anyone else, except where the law requires — a court order, or a request from HMRC or the police that we are obliged to comply with — and then only what is required.

How long we keep things

Your rights

Under UK data protection law you can ask us to:

We will answer within one month. There is no charge. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first.

Security

Children

Ledger is for businesses. It is not intended for anyone under 18 and we do not knowingly hold data about children.

Changes to this notice

We will email you before any change that affects how your data is used. Minor clarifications may be made without notice; the date at the top always shows the current version.

Contact

[Company name] Limited
[Registered office address]
[email]

Data protection contact: [name or role]. (A formal Data Protection Officer is not required for a business of this size; naming someone responsible is still good practice.)