LF LedgrFlow
Features How it works Pricing FAQ
Sign in Create your free company
Features How it works Pricing FAQ
Sign in Create your free company
Legal

Privacy Policy

Last updated: September 2026 · A&T Business Services (Pty) Ltd

1. Who We Are and When This Policy Applies

A&T Business Services (Pty) Ltd ("A&T", "we", "us", or "our") provides LedgrFlow. This Privacy Policy explains how personal information is collected and processed when you visit our website, create or use a LedgrFlow account, contact us, or otherwise interact with the service.

For account, billing, support, security, and service administration information, A&T is the responsible party under the Protection of Personal Information Act 4 of 2013 ("POPIA"). Where a customer uploads or records personal information about its customers, suppliers, employees, or other persons in LedgrFlow, that customer generally determines why the information is processed and A&T processes it as an operator on the customer's instructions.

2. Personal Information We Collect

Depending on how you use LedgrFlow, we may collect:

  • Account and profile information: your name, contact details, role, authentication information, and account preferences.
  • Business and subscription information: company details, billing details, subscription records, and payment status.
  • Customer content: accounting records, transactions, documents, reports, and personal information about contacts or other persons that authorised users enter into the service.
  • Communications: information provided in support requests, enquiries, feedback, and other correspondence.
  • Technical and usage information: device and browser information, IP address, access logs, session activity, and security events.
  • Integration information: information received from services that you choose to connect to LedgrFlow, subject to your instructions and the permissions you grant.

We collect information directly from you, from authorised users acting for your organisation, from services you choose to connect, and automatically when the service is used. Information required to create an account, provide the service, process payment, or meet legal obligations is mandatory for those purposes. If it is not provided, we may be unable to provide the relevant service. Other information is voluntary.

3. How and Why We Use Personal Information

We process personal information only where permitted by POPIA and other applicable law. This includes processing necessary to:

  • provide, administer, support, and secure LedgrFlow;
  • authenticate users and manage access permissions;
  • process subscriptions, payments, and account communications;
  • generate and maintain the records, reports, and documents requested by authorised users;
  • detect, investigate, and prevent fraud, misuse, and security incidents;
  • comply with legal, regulatory, accounting, and tax obligations;
  • protect our legitimate interests and those of our customers, provided those interests do not unjustifiably infringe privacy; and
  • improve the service using aggregated, de-identified, or otherwise lawfully processed information.

Where processing relies on consent, you may withdraw that consent at any time. This does not affect processing that took place before the withdrawal or processing justified on another lawful ground.

4. Data Storage and Security

We use reputable cloud, infrastructure, authentication, communications, payment, and support providers to operate LedgrFlow. These providers may process personal information only for the services they provide to us and subject to appropriate confidentiality, security, and data-protection obligations.

We maintain appropriate and reasonable technical and organisational safeguards designed to protect personal information against loss, damage, unauthorised destruction, unlawful access, and unlawful processing. These safeguards include access restrictions, authentication controls, monitoring, backup and recovery measures, and protection of information during storage and transmission, where appropriate.

We review our safeguards and update them as risks and generally accepted security practices change. No internet-based service can eliminate every security risk, and users must also protect their login details, devices, and authorised-user access.

5. When We Share Personal Information

We do not sell or rent personal information. We may disclose it only where reasonably necessary to:

  • service providers supporting hosting, data storage, authentication, communications, payment processing, customer support, security, monitoring, and related operations;
  • professional advisers, auditors, insurers, and other parties bound by confidentiality obligations;
  • law-enforcement bodies, regulators, courts, or other authorities where disclosure is required or permitted by law;
  • a successor or prospective successor in connection with a lawful merger, reorganisation, financing, or sale of all or part of the business, subject to appropriate safeguards; or
  • another person where you, or the relevant customer responsible for the information, authorise or instruct us to do so.

Service providers receive only the access reasonably necessary for their function and must process information under applicable contractual and legal safeguards.

6. Processing Outside South Africa

Some service providers may process or store personal information outside South Africa. Where personal information is transferred across borders, we take reasonably practicable steps to ensure that the transfer complies with section 72 of POPIA, including through applicable law, binding agreements, consent, or another lawful basis recognised by POPIA.

7. Retention and Deletion

We retain personal information only for as long as it is needed for the purpose for which it was collected, to provide the service, to follow a customer's lawful instructions, to resolve disputes or enforce agreements, or to meet applicable legal, regulatory, accounting, and tax obligations.

When we are no longer authorised or required to retain personal information, we delete, destroy, or de-identify it as soon as reasonably practicable. Residual copies may remain temporarily in protected backups and are removed through the ordinary backup-retention cycle.

8. Your Rights

Subject to POPIA and any lawful limitations, you may:

  • ask whether we hold personal information about you and request access to it;
  • request correction or deletion of information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained;
  • object, on reasonable grounds, to certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of direct marketing at any time; and
  • lodge a complaint with the Information Regulator (South Africa).

To protect personal information, we may need to verify your identity before acting on a request. Where LedgrFlow holds your information only on behalf of one of our customers, we may refer the request to that customer or assist it in responding.

Requests may be sent to privacy@ledgrflow.co.za. POPIA request forms and complaint information are available from the Information Regulator.

9. Browser Storage and Service Monitoring

LedgrFlow uses local and session storage in your browser for functions including authentication sessions, company selection, draft recovery, report settings, and safe recovery after application updates. Clearing or disabling browser storage may sign you out, remove locally saved drafts or preferences, or prevent parts of the service from working correctly.

We also use error and performance monitoring to diagnose faults, maintain reliability, and protect the service. This may collect the technical and usage information described in section 2. LedgrFlow does not currently use advertising cookies or behavioural marketing trackers.

10. Security Compromises

If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and notify the Information Regulator and affected data subjects as required by POPIA. Notices will include information reasonably necessary to help affected persons take protective steps.

11. Children's Privacy

LedgrFlow is intended for business use and is not directed at children. Customers must not enter personal information about children unless they have a lawful basis and all required authorisations to do so.

12. Changes to This Policy

We may update this policy to reflect changes in the service, our processing activities, or applicable law. The current version and effective date will be published on this page. We will give additional notice where a change materially affects how personal information is processed.

13. Contact

Questions, objections, requests, or concerns about this policy or our handling of personal information may be sent to:

A&T Business Services (Pty) Ltd
Information Officer
Physical address: Olea View Houses, 15 Elm Avenue, Fourways, Sandton, Gauteng, 2191
Email: privacy@ledgrflow.co.za

You may also lodge a complaint directly with the Information Regulator (South Africa).

See also our Terms of Service.

© 2026 A&T Business Services (Pty) Ltd. All rights reserved.

LF LedgrFlow

Accounting software for South African businesses and bookkeepers. A product of A&T Business Services (Pty) Ltd.

Product
Features How it works Pricing FAQ
Legal
Terms of Service Privacy Policy
Get started
Sign in Create account Support
© 2026 A&T Business Services (Pty) Ltd. All rights reserved. Made in South Africa