1. Scope of this policy
This Privacy Policy applies to the public LedgerPH website, subscriber registration, account administration, support, billing records, and the use of LedgerPH modules and mobile workspaces.
It covers website visitors, prospective subscribers, subscribers, authorized company users, employees using a company workspace, contact persons, and other individuals whose personal data may be processed through LedgerPH.
2. LedgerPH and subscriber privacy roles
The party that decides why and how personal data is processed is generally the personal information controller. A party processing data under the instructions of that controller may act as a personal information processor.
LedgerPH may separately act as a personal information controller for its own website inquiries, subscriber accounts, billing, service administration, security, and support records.
3. Personal data we may collect
Website and inquiry information
- Name, email address, contact number, company name, and inquiry message.
- IP address, browser information, access date and time, and security logs.
Subscriber and authorized-user information
- Account name, username, email address, mobile number, company assignment, role, and permissions.
- Subscription, plan, billing, payment-reference, support, and account-activity information.
Company operational information
- Company, branch, registration, tax, contact, bank, and business-profile information.
- Accounting, sales, purchasing, inventory, customer, supplier, payee, and document records.
Employee and payroll information
- Identity, contact, employment, compensation, attendance, payroll, benefits, loans, and government-membership information.
- Attendance photographs, timestamps, device information, and location information when a company enables those features and the user grants the required permission.
- Employee requests, payslips, records, and uploaded supporting documents.
The exact information collected depends on the modules, settings, permissions, and workflows enabled by the subscriber.
4. How personal data may be used
- Provide, operate, maintain, secure, and improve LedgerPH.
- Create and administer subscriber and user accounts.
- Apply company, branch, role, module, and permission restrictions.
- Process attendance, payroll, accounting, sales, inventory, purchasing, document, and reporting workflows selected by the subscriber.
- Generate reports, payslips, summaries, exports, and compliance working data.
- Provide technical support, onboarding, training, notices, and service communications.
- Manage subscriptions, payments, renewals, account status, and billing records.
- Detect fraud, unauthorized access, abuse, errors, and security incidents.
- Comply with lawful requests, legal obligations, and the establishment, exercise, or defense of legal claims.
5. Bases for processing
Depending on the circumstances, personal data may be processed based on consent, performance of or steps related to a contract, compliance with a legal obligation, protection of vital interests, lawful functions of public authority, or legitimate interests that do not override the rights and freedoms of the data subject.
Subscriber companies are responsible for identifying and documenting the proper basis for the personal data they upload or process through LedgerPH, including employee and customer data.
6. When information may be shared
Personal data may be disclosed only when reasonably necessary to:
- Authorized users of the correct subscriber company, subject to assigned roles and permissions.
- Hosting, email, communications, payment, backup, security, and technical service providers supporting LedgerPH.
- Professional advisers, auditors, insurers, or contractors subject to appropriate confidentiality obligations.
- Government agencies, regulators, law-enforcement bodies, courts, or other persons when required or permitted by law.
- A successor or acquiring organization in a legitimate restructuring, merger, acquisition, or transfer, subject to applicable safeguards.
LedgerPH does not authorize one subscriber company to view another subscriber company's information. Company-scoped access controls should be applied to users assigned to more than one company.
7. Security safeguards
LedgerPH uses reasonable organizational, physical, and technical measures intended to protect personal data against accidental loss, unauthorized access, alteration, disclosure, destruction, or other unlawful processing.
Measures may include account authentication, permission controls, company-level data separation, activity logs, secure connections, backups, software updates, vulnerability correction, confidentiality obligations, and incident-response procedures.
No online system can guarantee absolute security. Subscribers and users must protect their credentials, use supported devices and browsers, assign only necessary access, and promptly report suspected compromise.
8. Retention and deletion
Personal data is retained only for as long as reasonably necessary for the declared purpose, contractual obligations, legitimate business needs, security, backups, dispute handling, legal claims, or periods required by applicable law.
At the end of service, data may be returned, exported, deleted, anonymized, or retained for a limited period depending on the subscription agreement, lawful instructions of the subscriber, backup cycles, and legal requirements.
9. Data-subject rights
Subject to applicable law and proper identity verification, a data subject may have rights to be informed, access personal data, object to certain processing, correct inaccurate data, request erasure or blocking in appropriate cases, withdraw consent when consent is the basis, obtain data portability when applicable, and lodge a complaint with the National Privacy Commission.
For employee, customer, supplier, or transaction information controlled by a subscriber company, requests should normally be directed first to that company. LedgerPH may assist the subscriber when technically and legally appropriate.
10. Cookies, sessions, and technical logs
LedgerPH may use essential cookies or similar technologies for login sessions, account security, preferences, form protection, and service operation. Technical logs may record access events, errors, browser or device details, and IP addresses for diagnostics and security.
Optional analytics or marketing technologies should not be enabled without providing any notice or consent required by applicable law.
11. Service providers and data location
LedgerPH may use third-party infrastructure or service providers located in the Philippines or other jurisdictions. Where personal data is transferred or processed by another party, reasonable contractual and technical safeguards should be used to provide an appropriate and comparable level of protection.
12. Children and minors
LedgerPH is intended for businesses and authorized workplace users. It is not directed to children for independent consumer use. Where information about a minor is lawfully required for employment, dependent, benefit, or compliance records, the subscriber must ensure the proper authority and safeguards.
13. Changes to this policy
This policy may be revised when LedgerPH features, legal requirements, service providers, or processing activities change. The updated version will show a new effective date. Material changes may also be communicated through the website, system, or subscriber contact details.
14. Privacy questions and requests
Send privacy questions, requests, or suspected privacy incidents to support@ledgerph.com .