Skip to main content
Ledja™.

Calm in every number.

Powered by Ledja Ltd

Legal information

Ledja Privacy Policy

Effective date
22 August 2026
Version
1.0

1. Who we are

Ledja is a cloud accounting and financial-management service for local councils in England and Wales.

Ledja is provided by Ledja Ltd, a company registered in England and Wales under company number 13067612, whose registered office is at 3 Royal Crescent, Cheltenham, Gloucestershire, GL50 3DA. In this policy, “Ledja”, “we”, “us” and “our” mean Ledja Ltd.

Ledja Ltd is registered with the Information Commissioner’s Office under registration reference ZB611356.

For privacy questions or to exercise your data-protection rights, email [email protected] or write to us at the registered office above.

Ledja and ACCLC are separate brands of Ledja Ltd. ACCLC provides professional services under separate engagements. This policy concerns the Ledja software service and the Ledja website. ACCLC information is not used for Ledja merely because both brands are operated by the same company. If an ACCLC team member is separately authorised by a council to use Ledja, that person uses Ledja under the council’s authority in the same way as any other authorised council user.

2. When Ledja is controller and when it is processor

Ledja has two main data-protection roles.

  • Ledja as controller. We decide why and how to use personal data needed to operate our business and service, including website enquiries, customer and user administration, contracts and billing, account security, service communications, support administration, product feedback, and our own legal and regulatory compliance.
  • Ledja as processor. A council normally decides why and how personal data in its accounting records is used. For that customer content, the council is the controller and Ledja processes the data only on the council’s documented instructions under our contract and data-processing terms.

For clarity, Service Administration Data means subscription, billing, business-contact, platform-security, availability, abuse-prevention and support-case metadata for which Ledja determines the purposes and means. It excludes council accounting records and workspace content. Ledja is controller for Service Administration Data. Ledja is processor for user profiles, permissions and audit records to the extent they are processed solely to operate the Customer’s workspace. Where the same field is used for both purposes, each party’s role is determined separately for that processing.

If your question concerns personal data in a council’s accounting records, you should usually contact that council first. We will assist the council in responding. If your question concerns Ledja’s own use of your account, contact, security, support or business information, contact us directly.

HM Revenue & Customs (“HMRC”) is responsible for its own services and records. Where a council authorises Ledja to exchange VAT information with HMRC, Ledja acts on the council’s instructions. The user signs in directly with HMRC. Ledja does not collect or store HMRC sign-in credentials.

3. Whose personal data we process

Depending on how Ledja is used, we may process personal data about:

  • council employees, members, office holders, contractors and authorised users;
  • suppliers, payees, customers, residents and other people identified in council financial records or supporting evidence;
  • prospective and current customer contacts;
  • people who ask for support, submit feedback, report a security concern or exercise a legal right; and
  • visitors to our website.

Ledja is intended for organisational use and is not directed at children. A council may nevertheless hold lawful accounting records concerning a child or another vulnerable person. In that case, the council remains responsible for deciding whether and how that information is used, and Ledja processes it only under the council’s instructions.

4. Personal data we process

The information we process may include:

  • identity and contact data: name, work email address, telephone number, organisation, job title or council role;
  • account and permissions data: user identifier, council or workspace membership, assigned role, invitations, authentication state and multi-factor authentication events;
  • technical and security data: IP address, device and browser information, timestamps, request and event identifiers, security and audit logs, session and cookie identifiers, and HMRC-required fraud-prevention header data;
  • contract and commercial data: Order Forms, subscription information, billing contacts, invoices, payment status and business correspondence;
  • council accounting data: ledger entries, budgets, reserves, bank transactions, reconciliation information, suppliers, customers, payees, payment and receipt details, invoices, documents, notes and audit history;
  • VAT and HMRC data: VAT registration number, obligations, returns, liabilities, payments, submission status, HMRC correlation or receipt information and encrypted OAuth authorisation tokens;
  • migration and evidence data: information imported from an authorised source system, bank statement or document, together with validation results, provenance and review history;
  • support and feedback data: messages, case details, recordings or notes where notified, attachments, consent and delegated-access records, and product feedback; and
  • website and communications data: enquiries, communication preferences and basic web-server logs.

Council documents can sometimes contain special-category data or information about criminal offences even though Ledja does not require that information for ordinary accounting. Customers should avoid uploading unnecessary personal data and must ensure they have a lawful basis and any additional legal condition needed for the information they place in Ledja.

5. Where the data comes from

We obtain personal data:

  • directly from you when you contact us, enter into a contract, accept an invitation, use Ledja or ask for support;
  • from the council or another organisation that authorises your use of Ledja;
  • from files, documents, accounting systems, banks or other sources that an authorised customer chooses to connect or import;
  • from HMRC when an authorised user connects the council’s account and requests VAT information;
  • from service providers that help us deliver, secure or administer Ledja; and
  • from public sources where this is necessary to verify an organisation or business contact.

Where Ledja, as controller, obtains your personal data indirectly, we will provide or actively direct you to the relevant privacy information within one month, or by our first communication or disclosure if earlier, unless a lawful exception applies. Where Ledja holds information only as a council’s processor, the council is responsible for the privacy information and Ledja assists it.

Contact, account and authentication information identified as required is necessary to enter into or administer an Agreement and provide secure access. If it is not provided, Ledja may be unable to contract with the organisation, create an account or provide support. Marketing information and preferences are optional.

6. Why we use personal data and our lawful bases

When Ledja acts as controller, we use personal data as follows.

Purpose Personal data typically used Lawful basis
Respond to enquiries, prepare an Order Form, administer a subscription and provide the service identity, contact, contract, account and billing data Article 6(1)(f): legitimate interests in administering an organisational customer relationship; Article 6(1)(b) only where the individual is personally party to the contract or requests pre-contract steps
Create accounts, authenticate users, enforce permissions, prevent misuse and maintain audit evidence identity, account, technical, security and audit data Article 6(1)(f): legitimate interests in providing a secure, accountable multi-customer service
Deliver service messages, training, support, incident communications and product feedback handling identity, contact, account, support and feedback data Article 6(1)(f): legitimate interests in supporting Users, administering the organisational customer relationship and improving the service; Article 6(1)(b) only where the individual is personally party to the contract
Bill customers, maintain financial records, manage disputes and meet company, tax and regulatory duties contract, billing, correspondence and relevant audit data Article 6(1)(c): compliance with applicable company and tax record-keeping duties; Article 6(1)(f): legitimate interests in administering contracts and establishing, exercising or defending legal claims
Maintain, monitor, troubleshoot and improve reliability, accessibility and security technical, security, audit, support and appropriately minimised usage data Article 6(1)(f): legitimate interests in operating, protecting and improving Ledja; Article 6(1)(c) only where specific data-protection, security or regulatory law requires the processing
Send relevant business-to-business information about Ledja identity, business contact and communication-preference data Article 6(1)(f): legitimate interests for proportionate marketing to named organisational contacts; Article 6(1)(a) where consent is used. Electronic marketing to an individual subscriber is sent only with PECR consent or a valid soft opt-in. Every message identifies Ledja and provides an opt-out
Respond to privacy requests, complaints, legal demands and security reports identity, contact, correspondence, verification and relevant service data Article 6(1)(c): compliance with applicable data-protection complaint, rights and lawful-authority duties; Article 6(1)(f): legitimate interests in demonstrating compliance and protecting legal rights

Where we rely on legitimate interests, those interests are to operate and secure Ledja, support organisational customers, improve the service, prevent fraud and misuse, and protect our and others’ legal rights. We assess those interests against the rights and reasonable expectations of the people affected.

Where Ledja acts as a processor, the council determines the lawful basis for processing customer content. We process that information only to provide, secure and support the subscribed service, follow documented customer instructions, and comply with law.

7. VAT and HMRC authorisation

If Ledja has been granted the required HMRC production access and the Customer has subscribed to the VAT integration, an authorised User may connect Ledja to HMRC using OAuth 2.0. Until those conditions are met, HMRC functionality is test or pilot functionality and does not submit live returns. Ledja will not describe the Service as HMRC ready, compatible, integrated or recognised unless HMRC permits that description.

When the production integration is enabled, the User is redirected to HMRC and authenticates there. Ledja receives an authorisation result and protected access credentials that allow the Service to perform the VAT actions the Customer has authorised. Ledja then uses those credentials to request VAT information and, only after an authorised User has reviewed and confirmed the return, to submit VAT information. We retain submission and audit evidence needed to show what was requested, reviewed and sent. We do not use HMRC information for advertising and do not sell it.

The customer can disconnect the HMRC integration. HMRC may also expire or revoke an authorisation. Disconnecting stops future access but does not erase accounting records or submission evidence that the customer or Ledja must retain.

8. Document scanning, imports and AI-assisted processing

If a document-extraction feature is identified as enabled in the Customer’s Order Form, Ledja may extract candidate information from an invoice, bank statement or other Customer-provided document and may identify possible matches or duplicates. These are assistance features, not final accounting decisions. An authorised person must review and confirm the result before it becomes accounting truth or is submitted externally.

An enabled feature may use an artificial-intelligence or machine-learning provider to produce a candidate extraction, classification, match, explanation or other assistance. AI output can be incomplete or wrong. Ledja will not treat that output as verified source evidence, and an authorised person must review it before relying on it for accounting, payment, VAT or another material action.

No AI provider may process Customer Personal Data for a production feature until Ledja has completed and recorded the applicable data-protection, security, retention, subprocessor and international-transfer assessment; put the required written terms in place; updated the current subprocessor information; and enabled the feature in the Customer’s Order Form. Ledja does not use Customer Personal Data, or permit a provider to use it, to train or improve a general-purpose, shared or customer-specific model.

Ledja does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

9. Who we share personal data with

We share personal data only where necessary and subject to appropriate controls. Recipients may include:

  • the customer and its authorised users;
  • Ledja personnel who need access for their role, and specifically authorised support personnel using controlled, time-limited and audited access;
  • cloud hosting, storage, database, content-delivery and security providers, where required to host, protect or deliver the public website or an enabled Ledja service;
  • transactional-email providers, only where appointed and enabled to deliver account, security or service communications;
  • business email, collaboration, email-security and routing providers, for Ledja business, support and privacy correspondence;
  • customer-relationship-management and sales-operations providers, for Ledja-controlled prospective-customer, customer-relationship, sales-pipeline and relevant business-communication records. These providers are not given council accounting records merely because they support Ledja’s CRM or sales operations;
  • SMS verification and security-communications providers, only where appointed and enabled for multi-factor authentication or related security communications;
  • HMRC, when an authorised customer uses the VAT integration;
  • bank-statement, document-processing, extraction, AI/model and other integration providers, only where appointed and enabled for a Ledja feature and after the applicable privacy, security, contractual and transfer controls have been completed;
  • professional advisers, auditors, insurers and competent authorities where necessary; and
  • a buyer or successor if Ledja’s business or assets are reorganised or transferred, subject to confidentiality and data-protection safeguards.

These categories do not mean that every type of provider is currently appointed or that every related feature is enabled. The providers actually in use are identified in the controlled subprocessor information described in section 10.

We do not sell personal data. We do not share customer personal data with third parties for those third parties’ own marketing.

10. Subprocessors and international transfers

Before production Customer Personal Data is processed, Ledja will maintain a controlled subprocessor register recording the contracted legal entity, service, data categories, storage and support locations, subprocessor status and applicable transfer safeguard. A Customer receives the then-current register with its Order Form and may request it from [email protected]. No production feature that requires a supplier may process Customer Personal Data until the relevant register entry, contract and transfer assessment are complete. Contract Customers will be told before an intended addition or replacement, as set out in the Ledja SaaS Terms.

Some suppliers or their support operations may process personal data outside the United Kingdom. A supplier's statement that data is stored in the UK does not by itself establish that all processing, support access, metadata or onward processing remains in the UK. We do not permit an international transfer unless a lawful transfer mechanism and appropriate safeguards are in place. Depending on the destination, these may include UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with a transfer-risk assessment and supplementary measures where required. You may request a copy of the relevant safeguard from [email protected], subject to necessary security and confidentiality redactions.

11. How long we keep personal data

We keep personal data only for as long as needed for the purpose for which it was collected, to follow the customer’s instructions, and to meet legal, accounting, security and dispute-resolution requirements.

Record Normal retention approach
Customer accounting content for the subscription term and 30-day export period; at the Customer’s choice, returned and deleted or deleted without return; live copies deleted within 90 days after the export period and no later than 120 days after termination, unless the Customer lawfully instructs earlier deletion or law requires storage
Residual backup copies of deleted customer content isolated from ordinary use and overwritten within a further 90 days, no later than 210 days after termination; if restored for disaster recovery, the data remains subject to the deletion instruction
User, contract, billing and core service-audit records for the relationship and normally 7 years after it ends, to meet accounting, accountability and legal-claims requirements
HMRC OAuth tokens until the connection is revoked, expires, is disconnected or is no longer required; then deleted or rendered inaccessible, subject only to protected backup expiry
General technical and security logs normally up to 12 months; relevant extracts may be kept longer where needed to investigate an incident, prevent abuse or establish legal claims
Support cases, complaints, privacy requests and security reports normally 6 years after closure where the record may be needed for accountability or legal claims; trivial operational enquiries may be removed earlier
Prospective-customer enquiries and business-to-business marketing records until you opt out or normally 24 months after the last meaningful interaction; a minimal suppression record may be kept to honour an opt-out

A customer’s Order Form or lawful written instruction may require a different retention period for customer content. If litigation, an investigation or a legal preservation duty applies, relevant data may be held until the matter is resolved. We document exceptions and remove data when the exception ends.

12. Security

The current public website uses HTTPS and collects only the limited information described in this policy. Ledja will not enable production Customer accounting or HMRC processing until the relevant production controls have been implemented and evidenced. The production security design includes encryption in transit, encryption of HMRC access tokens and identifiable Customer information at rest, tenant separation, role-based access controls, multi-factor authentication, audit trails, secure development and change controls, backups and restore testing, monitoring, vulnerability management, penetration testing, fraud-prevention-header validation, accessibility assurance, and HMRC/ICO incident procedures. A control is not treated as complete merely because it appears in this policy or design.

No internet service can promise absolute security. Customers also have responsibilities: they must nominate authorised users carefully, keep their own devices and accounts secure, use individual accounts rather than shared credentials, remove access promptly when roles change, and contact Ledja without delay if they suspect misuse or an incident.

13. Cookies and website technology

At the effective date, the public holding website does not use analytics or advertising cookies. When the Ledja application is enabled, it is designed to use strictly necessary cookies or similar storage for authentication, security, session continuity and user-requested functionality. Those technologies cannot be switched off through a consent tool where the service cannot operate securely without them. The exact production use will be verified before customer access and this policy will be corrected if the implementation differs.

If we introduce non-essential analytics or marketing technology, we will update the published information and, where required, ask for consent before it is used.

14. Your rights

Depending on the circumstances and lawful basis, you may have rights to:

  • be informed about how your personal data is used;
  • obtain a copy of your personal data;
  • correct inaccurate or incomplete data;
  • ask for deletion or restriction;
  • receive data you provided in a portable form;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing relies on consent; and
  • make a data-protection complaint directly to us.

You have an explicit right to object at any time to direct marketing. Email [email protected] to opt out. We may retain a minimal suppression record so that we continue to respect your choice.

These rights are not absolute. We may need to verify your identity and may retain information where law requires it. Where Ledja holds the information only as a council’s processor, we will refer the request to that council and assist it.

15. Complaints

You have the right to make a data-protection complaint to Ledja at [email protected]. We will acknowledge it within 30 days and, without undue delay, make appropriate enquiries, keep you informed and tell you the outcome.

You may also complain to the Information Commissioner’s Office (“ICO”), the UK supervisory authority; you do not need Ledja’s permission to do so:

  • website: https://ico.org.uk/make-a-complaint/
  • telephone: 0303 123 1113
  • post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

16. Changes to this policy

We may update this policy when the service, suppliers or law changes. We will publish the new version and effective date at https://ledja.co.uk/privacy. If a change materially affects current customers or how we use their personal data, we will also provide an appropriate notice through the service or by email.

Privacy Terms Accessibility Security Contact Support

Ledja Ltd is registered in England and Wales under company number 13067612. Registered office: 3 Royal Crescent, Cheltenham, Gloucestershire GL50 3DA.

© 2026 Ledja Ltd and/or its licensors. All rights reserved.

Ledja™ is operated by Ledja Ltd. Ledja™ and ACCLC are trading names of Ledja Ltd and are used under licence.