Privacy Policy
Still to configure: Registered company name; Registered address; Governing law / jurisdiction; Contact email for legal and privacy enquiries.
1. Who is responsible
[Registered company name not set], of [Registered address not set], is responsible for the personal data described here. For privacy questions or to exercise any right below, write to [Contact email for legal and privacy enquiries not set].
2. What we collect
Account details. Your username, email address and display name. Your password is never stored — only a one–way hash of it, which cannot be turned back into the password.
What you enter. The contents of your books: contacts, invoices, bills, payments, bank transactions, items, time and expense entries, and so on. Some of this is personal data about other people — your customers, suppliers and staff. You decide what to put in; we process it for you.
Sensitive fields. Where the software offers a field for a national insurance or social security number, or a bank account number, that field is encrypted at rest rather than stored in readable form. The same applies to the credentials for a connected bank feed.
Technical details. When you register and when you accept these documents we record the IP address and browser user–agent string, because consent without a record of who gave it and when is not evidence of anything. We also record when you were last active.
An audit trail. Changes to records are logged with the user who made them, what changed, and when. This is a core accounting feature, not analytics: books you cannot audit are books you cannot trust.
3. Cookies
Ledgibly sets three kinds of cookie, all of them necessary for it to work:
- a session cookie, so the site knows you are signed in;
- a region preference, so dates and numbers are formatted the way you chose;
- a two–factor “remember this device” cookie, only if you use two–factor authentication and ask us to remember the device.
There are no analytics, advertising or tracking cookies, and no third–party scripts. The application loads no code, fonts or images from anyone else's servers — a content security policy blocks it — so no third party learns that you visited, and there is nothing to opt out of.
4. Why we process it
- To provide the service you signed up for — performance of our contract with you.
- To keep it secure and to investigate abuse — our legitimate interest, and yours.
- To bill you, where your plan carries a charge.
- To record consent, and to meet legal and accounting obligations.
We do not sell personal data. We do not use it for advertising. We do not use your books to train machine–learning models.
5. Who else sees it
Only the following, and only for the purposes given:
- Our hosting provider, which stores the database and files.
- A payment processor, where you pay for a plan or take card payments through Ledgibly. Card numbers are handled by the processor and do not reach our servers.
- A bank–feed provider, if you connect a bank account. We hold the access credential encrypted and use it only to fetch the transactions you asked for. Disconnecting stops it.
- An email provider, to deliver messages you or the system send.
- Anyone you share with. If you invite someone to a business, or link to another business, they see what that role or link allows. That sharing is your decision, not ours.
We will disclose data if the law compels us, and will tell you where we are permitted to.
6. How it is protected
- Passwords are hashed, never stored or recoverable.
- Two–factor authentication is available and we recommend it.
- Particularly sensitive fields — national insurance / social security numbers, bank account numbers, bank–feed credentials — are encrypted at rest.
- Every business's data is separated from every other's, and that separation is tested automatically on every change.
- Traffic is encrypted in transit.
- Backups are taken so your books survive a failure.
No system is perfectly secure, and we do not claim otherwise.
7. How long we keep it
We keep your books while your account is open, because that is what they are for. Accounting records often have to be retained for a period set by law — typically several years — and where that applies we keep them for that period even after closure, then delete them.
Consent records are kept as long as we may need to show what you agreed to.
8. Your rights
Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another provider. Ledgibly also has an export function you can use yourself at any time.
Write to [Contact email for legal and privacy enquiries not set]. We will respond within the period the law allows.
The precise rights, timescales, lawful bases and any supervisory authority depend on [Governing law / jurisdiction not set] and must be confirmed by a qualified lawyer before launch.
9. Data about other people
When you enter details of your customers, suppliers or staff, you are responsible for having a lawful reason to do so, and for telling them if you are required to. We process that data on your instructions.
10. Children
Ledgibly is business software and is not intended for anyone under 16. We do not knowingly collect their data.
11. Changes
This policy carries a version number. When we publish a new version we record it separately and ask you to review it; we keep a record of which version you accepted and when.
12. Contact
[Contact email for legal and privacy enquiries not set].