Last updated 1 August 2026. This policy describes how LedgerFlow handles your business and personal information.
LedgerFlow is a financial operating system for African businesses, operated from Nairobi, Kenya. This policy explains how we handle personal and business data when you use our website and application.
We act as a data controller for account information, and as a data processor for the accounting records you upload or generate inside your workspace.
Account data: name, business name, email address, phone number, KRA PIN and role within your organisation.
Financial data: invoices, quotes, bills, expenses, payments, bank and M-Pesa transaction records, journal entries and tax filings you create or import.
Usage data: device and browser information, IP address, pages viewed and feature interactions, used to keep the service secure and to improve it.
Marketing data: information you voluntarily submit through demo request and contact forms.
To provide the service: maintaining your ledger, generating reports, preparing tax summaries and reconciling payments.
To secure the service: authentication, fraud prevention, audit trails and abuse detection.
To support you: responding to enquiries, onboarding and troubleshooting.
To improve the product: aggregated, de-identified analytics. We never sell your data, and we do not use your financial records to train third-party models without your explicit consent.
We process data under the Data Protection Act, 2019 (Kenya) on the bases of contract performance, legitimate interest, legal obligation and — where applicable — your consent.
Where records must be retained for tax purposes, we follow the retention periods required by the Kenya Revenue Authority and the Tax Procedures Act.
We share data only with sub-processors necessary to run the service, such as cloud hosting, database, email delivery and payment providers. Each is bound by contractual confidentiality and security obligations.
We may disclose data where required by law, court order or a lawful regulatory request.
Data is encrypted in transit and at rest. Access is scoped per business through row-level security, and privileged actions are recorded in an immutable audit trail.
Access to production data by our team is restricted, logged and granted only where required for support or incident response.
You may request access to, correction of, or deletion of your personal data, object to certain processing, and request a portable export of your records.
Account owners can export their full ledger at any time from within the application. To exercise any other right, contact us using the details below.
We keep account and financial data for as long as your workspace is active, and thereafter for the period required by applicable tax and company law. Backups are rotated on a fixed schedule.
We will notify workspace owners by email before any material change to this policy takes effect.
Questions or requests: privacy@ledgerflow.africa, LedgerFlow, Nairobi, Kenya.