A&T Business Services (Pty) Ltd ("A&T", "we", "us", or "our") provides LedgrFlow. This Privacy Policy explains how personal information is collected and processed when you visit our website, create or use a LedgrFlow account, contact us, or otherwise interact with the service.
For account, billing, support, security, and service administration information, A&T is the responsible party under the Protection of Personal Information Act 4 of 2013 ("POPIA"). Where a customer uploads or records personal information about its customers, suppliers, employees, or other persons in LedgrFlow, that customer generally determines why the information is processed and A&T processes it as an operator on the customer's instructions.
Depending on how you use LedgrFlow, we may collect:
We collect information directly from you, from authorised users acting for your organisation, from services you choose to connect, and automatically when the service is used. Information required to create an account, provide the service, process payment, or meet legal obligations is mandatory for those purposes. If it is not provided, we may be unable to provide the relevant service. Other information is voluntary.
We process personal information only where permitted by POPIA and other applicable law. This includes processing necessary to:
Where processing relies on consent, you may withdraw that consent at any time. This does not affect processing that took place before the withdrawal or processing justified on another lawful ground.
We use reputable cloud, infrastructure, authentication, communications, payment, and support providers to operate LedgrFlow. These providers may process personal information only for the services they provide to us and subject to appropriate confidentiality, security, and data-protection obligations.
We maintain appropriate and reasonable technical and organisational safeguards designed to protect personal information against loss, damage, unauthorised destruction, unlawful access, and unlawful processing. These safeguards include access restrictions, authentication controls, monitoring, backup and recovery measures, and protection of information during storage and transmission, where appropriate.
We review our safeguards and update them as risks and generally accepted security practices change. No internet-based service can eliminate every security risk, and users must also protect their login details, devices, and authorised-user access.
We do not sell or rent personal information. We may disclose it only where reasonably necessary to:
Service providers receive only the access reasonably necessary for their function and must process information under applicable contractual and legal safeguards.
Some service providers may process or store personal information outside South Africa. Where personal information is transferred across borders, we take reasonably practicable steps to ensure that the transfer complies with section 72 of POPIA, including through applicable law, binding agreements, consent, or another lawful basis recognised by POPIA.
We retain personal information only for as long as it is needed for the purpose for which it was collected, to provide the service, to follow a customer's lawful instructions, to resolve disputes or enforce agreements, or to meet applicable legal, regulatory, accounting, and tax obligations.
When we are no longer authorised or required to retain personal information, we delete, destroy, or de-identify it as soon as reasonably practicable. Residual copies may remain temporarily in protected backups and are removed through the ordinary backup-retention cycle.
Subject to POPIA and any lawful limitations, you may:
To protect personal information, we may need to verify your identity before acting on a request. Where LedgrFlow holds your information only on behalf of one of our customers, we may refer the request to that customer or assist it in responding.
Requests may be sent to privacy@ledgrflow.co.za. POPIA request forms and complaint information are available from the Information Regulator.
LedgrFlow uses local and session storage in your browser for functions including authentication sessions, company selection, draft recovery, report settings, and safe recovery after application updates. Clearing or disabling browser storage may sign you out, remove locally saved drafts or preferences, or prevent parts of the service from working correctly.
We also use error and performance monitoring to diagnose faults, maintain reliability, and protect the service. This may collect the technical and usage information described in section 2. LedgrFlow does not currently use advertising cookies or behavioural marketing trackers.
If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we will investigate and notify the Information Regulator and affected data subjects as required by POPIA. Notices will include information reasonably necessary to help affected persons take protective steps.
LedgrFlow is intended for business use and is not directed at children. Customers must not enter personal information about children unless they have a lawful basis and all required authorisations to do so.
We may update this policy to reflect changes in the service, our processing activities, or applicable law. The current version and effective date will be published on this page. We will give additional notice where a change materially affects how personal information is processed.
Questions, objections, requests, or concerns about this policy or our handling of personal information may be sent to:
A&T Business Services (Pty) Ltd
Information Officer
Physical address: Olea View Houses, 15 Elm Avenue, Fourways, Sandton, Gauteng, 2191
Email: privacy@ledgrflow.co.za
You may also lodge a complaint directly with the Information Regulator (South Africa).
See also our Terms of Service.
© 2026 A&T Business Services (Pty) Ltd. All rights reserved.