UK GDPR & DPA 2018

Privacy Policy & Data Protection Statement

Last Updated: 14 August 2026 • LedgerHQ Technologies Ltd

1. Introduction & Overview

LedgerHQ Technologies Ltd ("LedgerHQ", "we", "our", or "us") provides a practice management, accounting CRM, and HMRC Making Tax Digital compliance platform hosted at app.ledgerhq.uk and corporate website at ledgerhq.co.uk.

We are dedicated to safeguarding the privacy and confidential financial data of UK accounting practices, tax advisers, and their underlying client entities in accordance with the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018.

2. Data Controller vs Data Processor

When you use LedgerHQ as an accounting firm or tax adviser:

  • Data Controller: Your accounting practice is the Data Controller of your clients' personal, financial, and tax records.
  • Data Processor: LedgerHQ acts as the Data Processor, storing and processing data strictly under your instruction to perform tax preparation, MTD digital filings, and Companies House synchronisation.

3. Data We Process

We process only the data strictly necessary to deliver practice management and HMRC filing services:

  • Accountant Account Data: Name, professional email, practice address, phone number, and authentication tokens.
  • Client Entity Data: Entity name, entity type, Unique Taxpayer Reference (UTR), National Insurance Number, GB VAT Registration Number, Companies House CRN, director names, and registered office addresses.
  • Financial & Tax Data: Transaction ledger details, invoice records, VAT box totals, Self Assessment income schedules, and uploaded receipt images.

4. UK Data Residency & Storage

All data processed by LedgerHQ is stored exclusively within secure cloud data centres located in the United Kingdom (London data centre region). We do not transfer practice or client financial data outside the UK or EEA without statutory safeguards.

5. HMRC Submissions & Security Telemetry

When submitting tax returns to HMRC via our digital API, we transmit mandated HMRC anti-fraud headers (e.g. client IP address, device fingerprints, timestamped submission tokens) in strict adherence to HMRC Agent API compliance regulations.

6. Your Data Rights

Under UK GDPR, authorised users have the right to request access to, rectification of, or erasure of their personal data, as well as the right to data portability. You can export complete practice records at any time.

7. Contact the Data Protection Officer

If you have questions regarding our data protection policies or wish to exercise your statutory rights, please contact our Data Protection Officer at:

Email: [email protected] / [email protected]
LedgerHQ Technologies Ltd — United Kingdom