Roles of the parties
For client personal data you enter, your practice is the controller and LedgerDue is the processor. Each party will comply with its obligations under applicable data protection law.
Scope and purpose of processing
We process personal data only to provide the service — storing your client records, generating deadlines, sending reminders, and supporting your account — for the duration of your subscription.
Our obligations
- Process personal data only on your documented instructions, including as set out in these terms.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see our Security page).
- Assist you, as far as reasonably possible, with data subject requests and your compliance obligations.
- Notify you without undue delay if we become aware of a personal data breach affecting your data.
- Delete or return personal data at the end of the service, subject to any legal retention requirements.
- Make available information reasonably necessary to demonstrate compliance.
Sub-processors
You authorise us to engage sub-processors to deliver the service. We currently use:
- Vercel — application hosting.
- Supabase — database and authentication hosting.
- Resend — email delivery.
- Stripe — payment processing.
We impose data protection obligations on our sub-processors and will give notice of intended changes so you can object on reasonable grounds.
International transfers
Where a sub-processor processes data outside the UK, we ensure an appropriate transfer mechanism is in place, such as UK adequacy regulations or standard contractual clauses.
Contact
For any question about this addendum or to raise a data protection matter, contact contact@ledgerdue.uk