Last updated 1 August 2026. The terms on which LedgerFlow processes personal data on behalf of your business.
This Data Processing Agreement (DPA) forms part of the Terms of Service between LedgerFlow ("Processor") and the customer business that operates a LedgerFlow workspace ("Controller").
The Controller determines the purposes and means of processing the records held in its workspace. LedgerFlow processes those records only on the Controller's documented instructions, which include use of the service's features.
For its own account, billing and marketing data, LedgerFlow acts as a controller; that processing is described in the Privacy Policy.
Subject matter: provision of accounting, invoicing, payables, banking reconciliation, tax preparation and reporting software.
Duration: for as long as the Controller's workspace is active, plus the limited retention period described in clause 9.
Storing, organising, calculating, reconciling and presenting the Controller's business records; generating documents such as invoices, quotes, credit notes and tax summaries; producing financial reports; and providing support.
Automated bookkeeping suggestions may be generated to assist categorisation. Controller records are not used to train third-party models without the Controller's explicit written consent.
Data subjects: the Controller's owners, employees and workspace members; its customers and vendors; and, where applicable, employees included in payroll records.
Categories of data: identity and contact details, KRA PIN and other tax identifiers, transactional and financial records, payment and mobile-money references, and usage metadata.
The service is not designed for the processing of special-category personal data; the Controller must not upload such data except where strictly required for payroll.
Process personal data only on the Controller's instructions and not for any independent purpose.
Ensure that personnel with access are bound by confidentiality obligations and receive appropriate training.
Implement and maintain the technical and organisational measures described in our Security Policy, and not materially reduce them during the term.
Assist the Controller, at the Controller's cost where the effort is substantial, with data protection impact assessments and enquiries from a supervisory authority.
The Controller authorises LedgerFlow to engage sub-processors for hosting, database, email delivery, analytics and payment processing.
Each sub-processor is bound by written terms imposing protection obligations no less protective than this DPA, and LedgerFlow remains responsible for their performance.
A current sub-processor list is available on request. LedgerFlow will give the Controller reasonable prior notice of a new sub-processor; the Controller may object on reasonable data protection grounds, in which case the parties will discuss a remedy and, failing one, the Controller may terminate the affected service.
Measures include TLS in transit and AES-256 at rest, tenant isolation through row-level security, role-based access control, append-only audit logging of privileged actions, restricted and logged production access, encrypted backups with point-in-time recovery, and monitored infrastructure.
Full detail is set out in the Security Policy, which is incorporated into this DPA by reference.
LedgerFlow will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide the information reasonably required for the Controller to meet its own notification duties.
Where required, LedgerFlow will notify the Office of the Data Protection Commissioner in line with the Data Protection Act, 2019 and will cooperate in containment and remediation.
The Controller may export its ledger, documents and reports at any time from within the application.
On termination, LedgerFlow retains the workspace data for a limited grace period so the Controller can export it, then deletes or irreversibly anonymises it, except where retention is required by Kenyan tax, company or other applicable law.
Backups are purged in line with the standard rotation schedule.
The service provides functionality for the Controller to access, correct, export and delete records itself.
Where a data subject contacts LedgerFlow directly, LedgerFlow will refer them to the Controller and will assist the Controller in responding within statutory timelines.
Data is hosted in regions selected for performance and legal compliance. Where personal data is transferred outside Kenya, LedgerFlow ensures an appropriate safeguard is in place as permitted by the Data Protection Act, 2019, including contractual protections with the receiving sub-processor.
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority, LedgerFlow will provide documentation demonstrating compliance with this DPA.
On-site audits may be arranged where legally required, subject to confidentiality, reasonable notice and minimal disruption to the service.
In the event of a conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data.
To execute a countersigned copy of this DPA or request the sub-processor list, contact privacy@ledgerflow.africa, LedgerFlow, Nairobi, Kenya.