Privacy Policy
How Radwanium Ltd ("Ledgers") collects, uses and protects personal data, and your rights under the UK GDPR and Data Protection Act 2018.
1. Who we are
Radwanium Ltd, 36 Scotts Road, Bromley, England, BR1 3QD (company no. 12953006), is the data controller. We are registered with the UK Information Commissioner's Office (ICO) under ZC195093. Data-protection contact: Hadi Radwan, privacy@ledgers.work.
2. What we collect
- Account data — name, email, company details, role.
- Billing data — plan, transactions count, billing contact. Card details are handled by our payment provider; we do not store full card numbers.
- Usage & device data — log data, IP address, actions taken, needed to run and secure the service.
- Support & comms data — messages you send us and your contact preferences.
- Your books — financial records you import. These may contain personal data about third parties, which we process as your processor (see the DPA).
3. Why we use it & our lawful basis
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Provide the service & your account | Contract (Art 6(1)(b)) |
| Billing & fraud prevention | Contract / Legal obligation |
| Securing & improving the platform | Legitimate interests (Art 6(1)(f)) |
| Service emails (e.g. daily briefing, alerts) | Contract |
| Marketing emails | Consent (Art 6(1)(a)) — opt-in, withdraw anytime |
| Meeting legal/accounting obligations | Legal obligation |
4. AI processing
We use AI models (including Anthropic's Claude) to categorise transactions, draft entries and answer questions. Data sent to our AI sub-processor is used only to generate your output and is not used to train third-party foundation models. We do not sell your data or make solely-automated decisions that produce legal effects about you — material AI output is surfaced for human approval.
5. Who we share it with
We share data with vetted sub-processors that help us run the service (hosting, database, email, payments, open banking, SMS, AI). They act on our instructions under contract. The current list is on our Sub-processors page. We also share data where required by law, or with your accountant/team members you grant access to.
6. International transfers
Some sub-processors operate outside the UK. Where data leaves the UK, we rely on adequacy regulations or appropriate safeguards (e.g. the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses).
7. How long we keep it
- Account & books: for the life of your account, then up to 30 days for export, then deletion.
- Records needed for legal/tax/accounting compliance: up to 6–7 years as required by UK law.
- Backups: cycled out on our standard backup schedule.
8. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port and object to processing, and to withdraw consent. You can:
- Export everything we hold about your business at any time from Settings → Your data.
- Request deletion of your account or organisation from the same screen.
- Manage data-sharing consents there too.
- Email privacy@ledgers.work for any other request — we respond within one month.
If you are unhappy with how we handle your data, you can complain to the ICO at ico.org.uk (we'd appreciate the chance to put it right first).
9. Security
We protect data with encryption in transit and at rest, row-level tenant isolation, access controls, audit logging and least-privilege service credentials. No system is perfectly secure; we notify you and the ICO of qualifying breaches as the law requires. More at our Trust page.
10. Cookies
We use a small number of strictly-necessary cookies (chiefly for sign-in). See the Cookie Policy.
11. Children
Ledgers is a business product and not intended for anyone under 18.
12. Changes
We may update this policy; material changes will be notified in-app or by email. The version and date are shown above.
13. Contact
Data-protection queries: privacy@ledgers.work · Radwanium Ltd, 36 Scotts Road, Bromley, England, BR1 3QD.
Questions about this document? Contact legal@ledgers.work or book a call.