Data Processing Agreement
This DPA governs how Ledgers processes personal data on your behalf, as your processor, under Article 28 of the UK GDPR. It forms part of the Terms of Service.
1. Roles & scope
You are the controller and we are the processor of the personal data contained in the data you upload or connect to Ledgers ("Customer Personal Data"). We process it only to provide the service under the Terms and on your documented instructions.
2. Subject matter & details
- Subject matter: provision of AI-assisted bookkeeping/accounting software.
- Duration: the term of your subscription, plus deletion/return periods.
- Nature & purpose: storing, organising, categorising, analysing and reporting on financial records.
- Data subjects: your customers, suppliers, employees, contractors and contacts.
- Categories of data: names, contact details, financial transactions, and other data you choose to include.
3. Our obligations
- Process Customer Personal Data only on your documented instructions (including for transfers), unless required by law.
- Ensure persons authorised to process it are under confidentiality obligations.
- Implement appropriate technical and organisational security measures (Art 32) — see §6.
- Engage sub-processors only under §4.
- Assist you, taking account of the nature of processing, with data-subject requests and with your obligations under Arts 32–36.
- Notify you without undue delay on becoming aware of a personal-data breach.
- At your choice, delete or return Customer Personal Data at the end of the service, unless retention is required by law.
- Make available information needed to demonstrate compliance and allow for audits per §7.
4. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our Sub-processors page. We impose data-protection terms on each that are no less protective than this DPA, and we remain liable for their performance. We will give notice of intended changes so you can object on reasonable data-protection grounds.
5. International transfers
Where we transfer Customer Personal Data outside the UK, we use a lawful transfer mechanism — adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU SCCs.
6. Security
We maintain measures appropriate to the risk, including encryption in transit and at rest, tenant isolation (row-level security), access controls and least privilege, audit logging, and regular review. Details are summarised on our Trust page.
7. Audits
On reasonable prior notice and no more than once a year (or after a breach), we will provide the information reasonably necessary to demonstrate compliance with Art 28, which may take the form of summaries, certifications or responses to a security questionnaire.
8. Data-subject requests
Ledgers gives you self-service tools to access, export and delete data. Where a data subject contacts us directly about Customer Personal Data, we will refer them to you and assist you in responding.
9. Liability & conflict
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails.
10. Signing
Accepting the Terms of Service incorporates this DPA — no separate signature is required. If your organisation needs a countersigned copy, email legal@ledgers.work.
Questions about this document? Contact legal@ledgers.work or book a call.