Last updated:
1.Who we are and what this policy covers
Ledgeriano ("we", "us") operates the website at ledgeriano.com, the Ledgeriano web application and the Ledgeriano API at api.ledgeriano.com (together, the "service"). This policy applies to personal data we process when you visit the site, create an account, use the service or contact us.
The service holds accounting records that you and your team enter, which can include personal data about other people, such as the names and contact details of your customers, suppliers or employees. For that data, you (or the business you work for) decide what is recorded and why, and we process it on your behalf to provide the service. Section 6 explains how we treat it.
2.Data we collect
We collect only what we need to run an accounting service. Depending on how you use it, that includes:
- Account data: your name, email address, password (stored only as a one-way hash), optional phone number and profile picture, preferred language and time zone, and whether two-factor authentication is on.
- Business and accounting data you enter: business profiles and logos, charts of accounts, fiscal years, journal entries and attachments, parties (customers and suppliers) and their details, cost centers, projects, workflows and webhook settings.
- Team data: the email addresses of people you invite, their roles and membership status.
- Billing records: credit purchases and consumption, the package and payment method chosen, payment status and identifiers returned by our payment processor, and, for bank transfers, the reference and receipt you upload.
- Technical and security data: sign-in times and IP addresses, the device or browser name attached to each session, audit trail entries (action, time, IP address, browser), API request logs (method, path, status, IP address, duration) and webhook delivery logs (payload sent and the response from your endpoint).
- Messages you send us, for example support emails, and any details you include in them.
We do not ask for payment card numbers and never receive them.
4.How we use data and our legal bases
Where data protection law requires a legal basis, we rely on the following:
- To provide the service you signed up for (performance of our contract with you): creating your account, storing and processing your accounting data, running reports, workflows, API calls and webhooks, and charging credits for actions.
- To send service messages (contract): email verification, password resets, team invitations, payment confirmations and low-credit notices.
- To keep the service secure and reliable (our legitimate interest in protecting you, other customers and the service): sign-in throttling, audit trails, request logs, fraud and abuse prevention, debugging and backups.
- To keep billing and financial records (legal obligation, and contract): recording purchases and credit transactions as tax and accounting rules require.
- To answer your messages (contract, or our legitimate interest when you are not a customer).
- To improve the product (legitimate interest): understanding which features are used, based on service records, without selling or sharing your data for advertising.
- Optional communications (consent): we do not send marketing emails unless you have agreed to receive them, and you can withdraw that consent at any time.
6.Accounting data you enter about others
For accounting records you enter about your customers, suppliers, employees or other people, we act as your service provider (a "processor" under laws such as the GDPR). We:
- process that data only to provide the service and according to your instructions and settings;
- do not sell it or use it for advertising;
- limit access by our staff to what is needed to operate the service, answer your support requests, or investigate security issues and abuse. When support staff sign in as a user to help, that access is time-limited and recorded in our audit log;
- help you respond when someone asks you to access, correct or delete their data.
If someone asks us directly about data held in your books, we will refer them to you where we can.
7.International data transfers
Our servers and service providers may be located in a country other than yours. When personal data is transferred across borders, we rely on the safeguards that applicable law requires, such as contractual protections with our providers.
8.How long we keep data
We keep data only as long as it is needed for the purposes above or as the law requires:
| Data | Retention |
|---|---|
| Account data | While your account exists. |
| Accounting data and its audit trail | While the business exists in your account, and afterward only as long as needed to meet record-keeping duties. |
| Deleted businesses | Archived and hidden from the app first. You can ask us to erase an archived business permanently. |
| Billing and credit records | As long as tax and accounting law requires us to keep them. |
| API request logs | 90 days. |
| Webhook delivery logs | 30 days. |
| Workflow run history | 180 days. |
| Expired session tokens | Deleted about one day after they expire. |
| Unpaid payment requests | Crypto invoices expire after 2 days and bank transfer requests without proof after 7 days. The expired record stays in your billing history. |
Deleted data can remain in backups for a limited time until those backups are replaced in the normal cycle.
9.How we protect data
We use HTTPS, bcrypt password hashing, optional two-factor authentication, hashed API keys, role-based permissions for each business, private file storage and a full audit trail. The security page describes these controls in detail. No system is perfectly secure, so please also protect your password and API keys.
10.Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Export your data. Reports can be exported to CSV in the app, the API gives programmatic access to your ledgers, and we can provide a copy of your account data on request.
- Correct inaccurate data. Most account details can be edited in your profile.
- Delete data. Owners can delete a business in the app. To close your account and erase your data, email us.
- Object to or restrict processing based on our legitimate interests.
- Withdraw consent where we rely on it, without affecting earlier processing.
- Complain to your local data protection authority.
To use any of these rights, email support@ledgeriano.com from the address linked to your account. We may need to confirm your identity, and we will answer within the time the law allows. We may keep some records where the law requires it, for example billing records.
11.Children
Ledgeriano is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
12.Changes to this policy
We may update this policy when the service or the law changes. The date at the top shows the latest version. If a change materially affects how we use your personal data, we will tell you by email or in the app before it takes effect.
13.Contact
Questions about this policy or your data: support@ledgeriano.com. To report a security issue: security@ledgeriano.com. You can also use the options on our contact page.