Draft for legal review. This text must be reviewed by a lawyer (UK GDPR, consumer law and Sri Lankan requirements) before launch.

Privacy policy

This policy explains how Easy Ledger handles personal data. We follow UK GDPR standards, and Sri Lanka's Personal Data Protection Act as it comes into force.

What we collect

  • Account details: your name, email address and sign-in security settings.
  • Business records you enter: customers, suppliers, invoices, bills, bank statement lines, payroll and employee details. We process these on the business's behalf.
  • Usage and security logs, including an audit trail of changes.

How we protect it

  • Every business's data is isolated at the database level.
  • Bank account numbers and national identity numbers are encrypted.
  • Files are stored privately and shared only through short-lived links.
  • Two-factor authentication is available for every account; once you turn it on, it's needed every time you log in.

Who processes data for us

  • Supabase (database, sign-in and file storage, hosted in Mumbai, India)
  • Netlify (application hosting)
  • OpenAI (AI answers; provider-side storage is switched off for our requests)
  • Stripe (subscription payments; we never see full card numbers)
  • Resend (email delivery)

How long we keep it

  • AI conversations: 90 days after the last message, unless you delete them sooner.
  • Accounting and tax records: for the period Sri Lankan law requires after a business closes.
  • Exports: 7 days.

Your rights

You can access, correct, export or ask us to delete your personal data. Business owners can export all business data from Settings. To make a request, use Settings → Privacy or contact us. We respond within 30 days.