How Ledger Lens uses your data (UK GDPR)
- Controller
- Ledger Lens Limited, Newcastle upon Tyne, UK.
- Data we process
- Account details (email, practice name, hashed password), filings you upload, figures and findings extracted from them, and audit records including sign-in events and consent choices.
- Purposes
- Delivering the QA and HMRC enquiry-risk service, securing your account, generating per-filing reports, and improving model quality on aggregated, de-identified signals.
- Lawful basis
- Article 6(1)(b) contract (account and service delivery), 6(1)(f) legitimate interests (security, fraud prevention, service improvement), and 6(1)(a) consent for optional marketing emails.
- Recipients / processors
- Supabase (EU region) for authentication, database and file storage; Lovable AI Gateway (Google Gemini) for on-demand document extraction. No data is sold or shared with advertisers.
- Retention
- Account and filing data are retained for the life of your account plus 30 days after deletion. Consent audit records are retained for 6 years to meet accountability duties.
- Your rights
- Access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. Contact privacy@myledgerlens.co.uk. You may also complain to the ICO.
Full detail: Privacy Policy · Terms of Service · Trust & Security