Ledgers Technology, Inc. ("Ledgers," "we," "us," or "our") is a Delaware corporation (Newark, Delaware, USA). Its wholly owned subsidiary, Ledgers Technologies FZ-LLC (Dubai, United Arab Emirates), supports our operations in the Gulf region. This Privacy Policy explains what information we collect when you use the Ledgers platform, website and mobile applications (together, the "Service"), how we use it, who we share it with, and the choices and rights you have. It applies to founders, team members, guests and partners who use the Service, to visitors of our website, and, in the specific ways described in Section 5, to people whose information our customers bring into the Service.
Where you use Ledgers on behalf of a company, that company decides what business data is entered into the Service and is responsible for it. For that data we act as a processor on the company's instructions, and our Data Processing Agreement applies. This Privacy Policy describes the information for which Ledgers itself decides the purposes and means of processing.
1. Information We Collect
1.1 Information You Provide
- Account information: your name, email address, password, phone number, company name, role and job title. Your name, email address and phone number are stored encrypted at rest.
- Identity verification through LinkedIn: when you verify your identity or sign in with LinkedIn, we receive the profile information LinkedIn makes available to us, such as your name, photo, headline, location and current and past positions. Your LinkedIn name is the name shown on your Ledgers profile. LinkedIn work history is shown as LinkedIn provides it and is refreshed from time to time.
- Profile information: anything you choose to add to your profile, such as an About section, links, companies you add, what you are looking for, and, if you take it, your answers to the Ledgers working-style assessment and the "Your story" questions.
- Business and financial data: the invoices, bills, expenses, journal entries, contacts, deals, tasks, documents, team and payroll records, cap table entries and other business records you or your team enter or upload, and the financial data you connect through integrations (see 1.3).
- Content you create: messages, files and pictures you post in Rooms, task descriptions and comments, announcements, notes, meeting notes, emails you compose in Ledgers, and your conversations with Ledgie, our assistant.
- Billing information: your billing address and the plan you choose. Payment card details are collected and stored by Stripe, our payment processor, not by Ledgers.
- Support and feedback: what you write when you raise an issue, rate a Ledgie answer, answer a feedback question, or contact us.
1.2 Information Collected Automatically
- Usage data: which parts of the Service you use, when, and from which module, recorded without the content you type.
- Device and log data: IP address, browser and operating system, device identifiers, the times you sign in and from where, and server logs. Where you install our mobile application and allow notifications, the push notification token for your device.
- Approximate location and time zone: derived from your IP address and browser settings, to show times correctly and to understand where our users are. We do not collect precise location.
- Assistant usage records: how much and which parts of Ledgie you use, so that we can meter usage and improve reliability. These records do not contain the words you typed.
- Cookies and local storage: as described in our Cookie Policy.
1.3 Information from Connected Services and Other Sources
- Banks and payment providers: when you connect a bank account through Plaid, or a Stripe or Wise account, we receive account names, balances and transactions for the accounts you select.
- Accounting software: when you connect QuickBooks or Xero, we receive the accounts, contacts, invoices and bills needed to keep your books in step. These connections are read-only.
- Google: as described in Section 3.
- Public professional information: to show your network's news inside Ledgers, we collect publicly available professional information about people and companies already in your workspace, such as public posts and current roles, from public sources and third-party data providers. Section 5 explains this in more detail.
- Partners: if you join Ledgers through an accelerator, incubator or other partner, that partner tells us that you belong to its programme so that its benefits apply to your account.
2. How We Use Your Information
- To provide, operate, secure and support the Service, including keeping your books, running your pipeline, your team, your calendar and your workspace.
- To generate the reports, signals, briefings, suggestions and answers the Service produces from your own business data, including through Ledgie.
- To personalise how the Service and Ledgie work with you, including from your assessment answers and from how you use the Service. You can pause this personalisation, correct what Ledgie has inferred, or delete it, in Settings.
- To process payments, meter usage and credits, and send receipts and account notices.
- To send you product updates and information about the Service. You can opt out of marketing messages at any time; we will still send messages required to operate your account.
- To detect, investigate and prevent fraud, abuse, security incidents and violations of our Terms.
- To understand how the Service is used, in aggregated or pseudonymised form, so that we can improve it. You can opt out of product-improvement analytics in Settings.
- To comply with law, respond to lawful requests, and establish, exercise or defend legal claims.
We do not sell your personal information, and we do not use your business or financial data for advertising.
3. Google User Data
Ledgers lets you connect your own Google account so that parts of the platform work with your Google Calendar, Google Drive and Gmail. Connecting is optional and is done by you, from your account settings, through Google's own consent screen. When you connect, we request only the following permissions and use them only as described here:
- Your Google identity (openid, email, profile): your name, email address and profile picture, used to create and sign in to your Ledgers account, and your email address to recognise which Google account you connected.
- Google Calendar (calendar.events): we read the events on your own calendars to show them inside the Ledgers calendar and to compute the free times you choose to share for booking, and we create, update and delete only the events you schedule from Ledgers (for example a meeting with a contact or a candidate), with the guests you invite and a Google Meet link. We never modify events that were not created from Ledgers.
- Google Drive (drive.file): Ledgers creates a folder in your company's Google Drive and files documents you create or upload in Ledgers into it. This permission only lets Ledgers see and manage files that Ledgers itself created or that you explicitly picked; it does not give access to the rest of your Drive.
- Gmail (gmail.send): emails you compose in Ledgers and choose to send from your Google address (such as invoices, follow-ups or candidate emails) are sent through your Gmail account so they carry your identity, appear in your Sent folder and replies reach your inbox. Ledgers only sends messages you write and explicitly send. We do not request, and cannot obtain, any permission to read, search or modify your mailbox.
Google user data is used solely to provide these features to you. We do not use it for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide the feature (for example, sending your email through Google's servers) or as required by law, and no human at Ledgers reads it except with your explicit permission for support or security purposes, or where required by law. The access tokens Google issues to Ledgers are stored on our servers, protected by the security measures described below, and are deleted when you disconnect your Google account from Ledgers, which you can do at any time from your account settings or from your Google Account permissions page. Calendar events mirrored into Ledgers from Google are removed when you disconnect.
Ledgers' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is never used to develop, train or improve any artificial intelligence or machine learning model, whether ours or a third party's. Where a feature you use passes Google-sourced information to our AI provider to produce an answer for you (for example, when Ledgie lists your upcoming meetings), it is processed only to deliver that feature to you, under contractual terms that prohibit the provider from training on it.
4. Ledgie and AI Features
Ledgie is the assistant built into Ledgers. When you ask Ledgie something, or when Ledgie prepares a briefing, a suggestion or a draft for you, the relevant parts of your workspace data, your message, and the conversation so far are sent to our AI model provider to generate the response. Some features also let Ledgie search the public web through the provider; in that case your query terms are used to run the search, and the pages found are read by the model, not stored by us as your data.
- Our AI model provider is a US-based company that processes this data only to return the response to you, under commercial terms that prohibit using customer content to train or improve its models. It is a sub-processor of ours under our DPA, and we will name it on request.
- In our mobile app, Ledgie can read its replies aloud. To do this, the text of Ledgie's reply is sent to our text-to-speech provider, which returns the audio. Only the reply text is sent, never your voice, your files or any Google user data, and the provider processes it only to produce the audio, with use of the text for training its models switched off. It is a sub-processor of ours under our DPA, and we will name it on request. When you speak to Ledgie in the mobile app, your phone's own speech recognition turns your voice into text; your voice is never sent to the text-to-speech provider.
- We do not use your data, your conversations with Ledgie or any Google user data to train or fine-tune AI models.
- Your Ledgie conversations are stored in your account so that Ledgie can continue where you left off. You can delete conversations, notes and threads, and pause or delete what Ledgie has learned about how you work, in Settings.
- Ledgie only reads what you are entitled to see in your workspace. A team member's Ledgie cannot reach data their role does not allow.
- Members of our team can see which features and tools Ledgie used and how often, never the words of your conversations, except the feedback notes and answers you write for us on purpose, and except where you ask us to look at a conversation for support.
Ledgie can be wrong. Its answers, figures, drafts and suggestions are produced automatically from your data and are for your information; they are not accounting, tax, legal, investment or other professional advice, and you should verify anything you rely on. See our Terms of Service.
5. People Who Are Not Ledgers Users
Our customers bring information about other people into the Service: contacts and deals in their pipeline, team members and candidates, clients and suppliers, guests invited into a Room, and people named in documents and emails. That information belongs to the customer's workspace. The customer is responsible for having the right to collect and use it, and for answering questions from the people concerned. We process it on the customer's behalf and under our DPA.
To make the Service useful, we also enrich some of that information from public sources. When a contact has a public professional profile, we may collect that person's publicly available professional information, such as their current role, employer and public posts, from public sources and third-party data providers, and show it to the customer who holds that contact. We rely on our legitimate interest, and our customers' legitimate interest, in keeping business relationships current. We do not collect private communications, and we do not collect this information about people who are not already in a customer's workspace or network.
If you are not a Ledgers user and believe a Ledgers customer holds information about you, you may contact that customer directly or write to us at privacy@ledgershq.com. We will help you reach the right customer and will honour your rights under applicable law, including your right to object to enrichment from public sources.
6. Legal Bases and Regional Rights
6.1 Legal bases (EEA, UK, Switzerland and jurisdictions with similar laws)
- Performance of a contract: providing the Service, managing your account, processing payments and responding to your requests.
- Legitimate interests: securing the Service, preventing fraud and abuse, improving the Service, enriching business contacts from public sources, and communicating with you about the Service, where these interests are not overridden by your rights.
- Consent: marketing messages, personalisation from your assessment answers, optional analytics, and connecting third-party accounts. You can withdraw consent at any time without affecting processing that took place before.
- Legal obligation: keeping accounting and tax records, responding to lawful requests, and meeting security and reporting duties.
6.2 United States
If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use and share it, to access and correct it, to delete it, to receive a copy of it, and to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes other than providing the Service. We will not discriminate against you for exercising your rights. You may appoint an authorised agent to act for you; we will verify the request before acting on it.
6.3 Gulf Cooperation Council countries
If you are in the United Arab Emirates, the Kingdom of Saudi Arabia, Bahrain, Qatar, Kuwait or Oman, we process your personal data in line with the data protection law that applies to you, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the DIFC Data Protection Law 2020 and the ADGM Data Protection Regulations 2021 where they apply, and the Saudi Personal Data Protection Law. You have the rights of access, correction, deletion, restriction, portability and objection described in Section 11, and the right to complain to your data protection authority. Where the law that applies to you requires consent for a transfer of your personal data outside your country, your connecting to the Service and continuing to use it is how that consent is given, and Section 8 explains where your data goes and why.
6.4 Everywhere else
We apply the same practices to everyone. Where local law gives you rights beyond those listed here, we will honour them.
7. How We Share Information
We share personal information only in the following ways.
- With the people you work with in Ledgers: your profile is visible to the members of the workspaces you belong to, to the people you connect with, and, where you choose, to other Ledgers users. Room messages are visible to the members of that Room. Announcements are visible to the audience you pick. What you post is your choice.
- With service providers (sub-processors) that host or help us run the Service and act only on our instructions: Hetzner Online GmbH (application and database hosting, Germany), Vercel Inc. (website hosting), our AI model provider (a US-based company; named on request), our text-to-speech provider (converts Ledgie's replies to audio in our mobile app; named on request), Stripe, Inc. (payments and payment feeds), Plaid Inc. (bank connections), Google LLC (sign-in, Calendar, Drive, Gmail, when you connect them), LinkedIn Corporation (identity verification), Apple Inc. (push notifications on iOS), third-party providers of public professional data, and our email delivery provider. Our current list is in our DPA and we will update it there.
- With the services you connect: when you connect a bank, an accounting package, Google, Wise, Stripe or another service, we exchange with that service the data needed to make the connection work. Their handling of your data is governed by their own terms and privacy policies.
- With a partner programme you join: an accelerator, incubator or other partner you join through Ledgers can see the companies in its portfolio, the public profiles of their teams, and activity counts. A partner can see your company's financial headline only when it holds an agreement with you on file or your founders agree to it in Settings. Your founders can turn that off at any time.
- With authorities and in legal matters: where required by law, subpoena or court order, to protect the rights, property or safety of Ledgers, our users or the public, or to enforce our Terms. Where the law allows, we will tell you before we disclose your data.
- In a business transfer: if Ledgers is involved in a merger, acquisition, financing or sale of assets, personal information may be transferred as part of that transaction, under this Privacy Policy.
- With your direction or consent in any other case.
8. Where Your Data Is Stored and International Transfers
The Ledgers application and its databases are hosted in data centres in Germany operated by Hetzner Online GmbH. Our website is served by Vercel. Some of our service providers, including our AI model provider, our text-to-speech provider, Stripe, Plaid, Google and LinkedIn, process data in the United States and in other countries where they operate. Ledgers Technology, Inc. and its staff, who are located in the United States, the United Arab Emirates and other countries, access data as needed to operate and support the Service.
This means your personal data will be transferred to, and processed in, countries other than your own, including countries whose data protection laws differ from yours. When we transfer personal data out of the EEA, the United Kingdom or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK Addendum or another lawful mechanism, together with the safeguards described in Section 10. When we transfer personal data out of a GCC country, we do so under contracts with our providers that require them to protect it to at least the standard described here, and, where the law applicable to you requires it, with your consent as described in Section 6.3.
9. Data Retention
We keep personal information for as long as your account is active and for as long as we need it for the purposes described above. In particular:
- Account and profile data is kept while your account exists. When you ask us to delete your account we will delete or anonymise it within a reasonable period, except as set out below.
- Business and financial records entered into a company's workspace belong to that workspace and are kept for as long as the company uses the Service. We keep accounting and tax records for the period the law requires, which is typically up to seven years, even after a workspace closes.
- Rooms and Boards that have been archived, including private Rooms and Boards whose members have all left, are retained in archived form rather than deleted, so that records exist if a legal dispute arises. They are not visible to anyone in ordinary use. A member of our team may open an archived space only with a recorded, written reason, and each such access is permanently logged.
- Usage and security logs are kept for up to 24 months.
- Support conversations and feedback are kept for up to three years.
- Backups of our databases are kept for a limited period and are overwritten on a rolling basis; data you delete may remain in a backup until it is overwritten.
We may keep information for longer where we are required to by law, where it is needed for a legal claim or investigation, or where we have anonymised it so that it no longer identifies you.
10. Security
We take reasonable technical and organisational measures to protect personal information, including: encryption of data in transit with TLS; encryption at rest of personal identifiers, credentials and integration tokens using AES-256; role-based access to workspaces and data, enforced on our servers; data scoped on our servers to the company it belongs to; throttling of sign-in attempts; logging of administrative and security-relevant actions; and regular database backups. Our hosting provider operates certified data centres with physical access controls.
We are an early-stage company and have not yet completed independent third-party security audits or certifications; we will update this section as we do. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential, for the people you invite into your workspace, and for the permissions you grant to connected services. If you believe your account has been compromised, contact us at once at privacy@ledgershq.com.
11. Your Rights and Choices
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy of it;
- correct information that is inaccurate or incomplete;
- delete your personal information, subject to the retention set out in Section 9;
- restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- receive your personal information in a structured, commonly used, machine-readable format;
- withdraw consent where we rely on it;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (Ledgie does not make such decisions about you); and
- lodge a complaint with a data protection authority.
Many of these you can do yourself: edit your profile, disconnect Google, banks and other services, delete Ledgie conversations and memory, pause personalisation, and change your privacy preferences, all from Settings. For anything else, email privacy@ledgershq.com from the address on your account. We will verify your identity, respond within the time the applicable law requires, and tell you if we cannot act on a request and why. Where your data sits in a customer's workspace (Section 5), we will pass your request to that customer and assist them.
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above and, for material changes, ask you to review and accept the new version when you next sign in, or give you other notice as the law requires. The version you accepted is recorded in your account.
14. Contact
Ledgers Technology, Inc.
Newark, Delaware, USA
Privacy: privacy@ledgershq.com
Legal: legal@ledgershq.com
