LLedgers
For accountantsFor foundersPricing
How it worksFeaturesFree toolsGuidesBlogTrust & securityOutside the UK?
Book a callSign inStart free →
Legal & compliance
Terms of ServicePrivacy PolicyCookie PolicyDisclaimerAcceptable UseData Processing AgreementSub-processorsWhat we send to the AI
Ledgers · Legal

Privacy Policy

How Radwanium Ltd ("Ledgers") collects, uses and protects personal data, and your rights under the UK GDPR and Data Protection Act 2018.

Last updated 24 September 2026 · Version 1.1

Two roles to keep straight: for personal data about you (your account, billing, support), Ledgers is the controller and this policy applies. For personal data inside your books (your customers, suppliers, employees), you are the controller and Ledgers is your processor — see the Data Processing Agreement.

1. Who we are

Radwanium Ltd, 36 Scotts Road, Bromley, England, BR1 3QD (company no. 12953006), is the data controller. We are registered with the UK Information Commissioner's Office (ICO) under ZC195093. Data-protection contact: Hadi Radwan, privacy@ledgers.work.

2. What we collect

  • Account data — name, email, company details, role.
  • Billing data — plan, transactions count, billing contact. Card details are handled by our payment provider; we do not store full card numbers.
  • Usage & device data — log data, IP address, actions taken, needed to run and secure the service.
  • Support & comms data — messages you send us and your contact preferences.
  • Your books — financial records you import. These may contain personal data about third parties, which we process as your processor (see the DPA).
  • Shopify store data — if you connect a Shopify store: its order, refund, payment and payout records, with no customer contact details. See section 6.

3. Why we use it & our lawful basis

PurposeLawful basis (UK GDPR)
Provide the service & your accountContract (Art 6(1)(b))
Billing & fraud preventionContract / Legal obligation
Securing & improving the platformLegitimate interests (Art 6(1)(f))
Service emails (e.g. daily briefing, alerts)Contract
Marketing emailsConsent (Art 6(1)(a)) — opt-in, withdraw anytime
Meeting legal/accounting obligationsLegal obligation

4. AI processing

We use AI models (including Anthropic's Claude) to categorise transactions, draft entries and answer questions. Data sent to our AI sub-processor is used only to generate your output and is not used to train third-party foundation models. We do not sell your data or make solely-automated decisions that produce legal effects about you — material AI output is surfaced for human approval.

5. Who we share it with

We share data with vetted sub-processors that help us run the service (hosting, database, email, payments, open banking, SMS, AI). They act on our instructions under contract. The current list is on our Sub-processors page. We also share data where required by law, or with your accountant/team members you grant access to.

HMRC. When you send a VAT return or an Income Tax update to HMRC through Ledgers, the law requires us to send HMRC fraud-prevention information with it: your IP address, a device identifier, your browser, screen and time-zone details, your Ledgers user ID and the email you sign in with, and whether you used two-step sign-in. HMRC uses it to protect your tax account (legal obligation).

6. If you connect a Shopify store

When you connect your Shopify store to Ledgers, Shopify gives us read-only access to your store. We use it only to keep your books.

  • What we read — your store's orders, refunds and payment transactions: order numbers and dates, the products sold (name, SKU, quantity, product type), prices, discounts, shipping charged, tax by rate, gift cards, refunds, and how each order was paid (for example card or PayPal) with the amounts and dates. If you use Shopify Payments, also your payouts and the fees Shopify deducted. And your store's name, currency, country and time zone.
  • What we don't read — your customers' names, email addresses, phone numbers or addresses. We never ask Shopify for them, and we can't change anything in your store.
  • Why — to book each trading day's sales, VAT and refunds into your books, and to show you that your books agree with Shopify's own totals. Our lawful basis is our contract with you (keeping your books). We don't use store data for marketing, advertising or profiling, and we don't sell or share it: it reaches only your own books and the people you invite to them, such as your accountant.
  • Where it's kept — in our database with the rest of your books (see section 7 for where our providers are). Your Shopify access keys are encrypted separately before they're stored.
  • How long we keep it — if you uninstall the app in Shopify, we forget your access keys at once, and when Shopify asks us to erase the store's data 48 hours later, we do. If you disconnect in Ledgers but keep the app installed, we forget your access keys at once and keep the orders already read until you uninstall the app. The journals booked from your store are daily totals, not individual orders, and hold no customer details; they're part of your accounting records and are kept like the rest of your books (section 8).
  • Your customers' rights — if one of your customers asks Shopify to see or erase their data, Shopify passes the request to us and we answer it automatically: we hold no personal details about your customers.

7. International transfers

Some sub-processors operate outside the UK. Where data leaves the UK, we rely on adequacy regulations or appropriate safeguards (e.g. the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses).

8. How long we keep it

  • Account & books: for the life of your account, then up to 30 days for export, then deletion.
  • Records needed for legal/tax/accounting compliance: up to 6–7 years as required by UK law.
  • Backups: cycled out on our standard backup schedule.

9. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, port and object to processing, and to withdraw consent. You can:

  • Export everything we hold about your business at any time from Settings → Your data.
  • Request deletion of your account or organisation from the same screen.
  • Manage data-sharing consents there too.
  • Email privacy@ledgers.work for any other request — we respond within one month.

If you are unhappy with how we handle your data, you can complain to the ICO at ico.org.uk (we'd appreciate the chance to put it right first).

10. Security

We protect data with encryption in transit and at rest, row-level tenant isolation, access controls, audit logging and least-privilege service credentials. No system is perfectly secure; we notify you and the ICO of qualifying breaches as the law requires. More at our Trust page.

11. Cookies

We use a small number of strictly-necessary cookies (chiefly for sign-in). See the Cookie Policy.

12. Children

Ledgers is a business product and not intended for anyone under 18.

13. Changes

We may update this policy; material changes will be notified in-app or by email. The version and date are shown above.

14. Contact

Data-protection queries: privacy@ledgers.work · Radwanium Ltd, 36 Scotts Road, Bromley, England, BR1 3QD.


Questions about this document? Contact legal@ledgers.work or book a call.

LLedgers

Books that keep themselves. Every decision logged, you approve the edges. Built for founders.

Product
How it worksPricingTrust & securityBlog
Compare
Ledgers vs XeroLedgers vs QuickBooksLedgers vs FreeAgentLedgers vs untiedLedgers vs GoSimpleTaxLedgers vs CoconutHow to switch
Resources
GuidesFree toolsMTD scope checkerRunway calculator
For
Pre-seed & seed foundersAgencies & consultanciesConstruction & CISE-commerceLandlords & propertyAngels, funds & acceleratorsOutside the UK?
Company
AboutBook a callSign inStart free
Legal
Terms of ServicePrivacy PolicyCookie PolicyDisclaimerSecurityAccessibilityAll legal & compliance
© 2026 Ledgers · ledgers.work · Built in the UK · Made for UK businesses