What this is
When your company uses Ledgeably Team, you control your employees' information and we process it for you. This addendum sets out the rules we follow when we do that. It applies automatically to every customer; there's nothing to sign. If your company needs a signed copy, email hello@ledgeably.com.
1. Definitions
"Customer Personal Data" means personal information in Customer Data that Ledgeably processes on the Customer's behalf. "Data Protection Laws" means the privacy laws that apply to that processing, including PIPEDA, BC PIPA, Alberta PIPA, Quebec's private-sector privacy act and, where applicable, other provincial or foreign privacy laws. "Security Incident" means a breach of security that leads to accidental or unlawful loss of, or unauthorized access to or disclosure of, Customer Personal Data. Other capitalized terms have the meanings in the Terms of Service.
2. Roles and instructions
- The Customer controls Customer Personal Data. Ledgeably processes it as the Customer's service provider.
- We process Customer Personal Data only to provide, secure and support the Service, and on the Customer's documented instructions. These Terms, and the Customer's use and configuration of the Service, are those instructions. We'll tell the Customer if we believe an instruction breaks the law.
- We don't sell Customer Personal Data, use it for advertising, or combine it with other data except as needed to provide the Service.
- The Customer is responsible for the lawfulness of the data and its instructions, and for any notices to, and consents from, its employees.
3. Our people
Only people who need access to provide or support the Service can access Customer Personal Data. Each is bound by confidentiality obligations and trained on handling personal information.
4. Security
We keep appropriate technical and organizational measures to protect Customer Personal Data, taking into account its sensitivity, including health information that may appear in notes and attachments. They're described in Annex 2. We may update them over time, but won't reduce the overall level of protection.
5. Subprocessors
- The Customer authorizes us to use the subprocessors listed on our Subprocessors page.
- Each subprocessor is bound by a written contract with data-protection obligations at least as protective as this addendum. We remain responsible for their work.
- We'll give at least 30 days' notice before adding or replacing a subprocessor that processes Customer Personal Data, by updating that page and emailing account administrators. If the Customer reasonably objects on data-protection grounds and we can't address the concern, the Customer may end its subscription and receive a refund of prepaid fees for the unused period.
6. Data location and transfers
We host Customer Personal Data in Canada (Toronto). Some subprocessors process limited data outside Canada, as listed on the Subprocessors page. When data is transferred, we use contracts and safeguards that give it comparable protection, and we support the Customer with any assessment Data Protection Laws require (including Quebec's assessment for transfers outside Quebec).
7. Requests from individuals
If an employee or other person asks us to access, correct or delete their Customer Personal Data, we'll pass the request to the Customer without undue delay and won't respond ourselves except to direct them to the Customer, unless the law requires otherwise. The Service lets the Customer view and correct most records, and we'll reasonably help with anything it can't do itself.
8. Security incidents
- We'll notify the Customer without undue delay, and in any case within 72 hours, after confirming a Security Incident that affects its Customer Personal Data.
- We'll describe what happened, the data and people likely affected, the likely consequences, and what we're doing about it, and update the Customer as we learn more.
- We'll reasonably help the Customer meet its own obligations to notify regulators and individuals. We keep a record of all Security Incidents.
- Notifying the Customer isn't an admission of fault or liability.
9. Return and deletion
When the subscription ends, the Customer may request an export of its Customer Personal Data for 30 days. We then delete it from the live service within 90 days of the account closing. Backups are overwritten within a further 30 days. We may keep data only where the law requires it, and we'll keep protecting it while we do.
10. Information and audits
On reasonable written request, no more than once a year, we'll answer the Customer's security questionnaire and provide the information reasonably needed to show we comply with this addendum. Where a regulator requires more, we'll cooperate reasonably, at the Customer's cost, with reasonable notice and under confidentiality.
11. Liability and precedence
Each party's liability under this addendum is subject to the limits in the Terms of Service. If this addendum conflicts with the Terms on the processing of Customer Personal Data, this addendum wins.
Annex 1: Details of the processing
| Subject matter and purpose | Providing Ledgeably Team: recording and approving leave, calculating balances, calendars and calendar sync, notifications, reports, support and security. |
|---|---|
| Duration | The subscription, plus the deletion periods in section 9. |
| People concerned | The Customer's employees, contractors, managers and administrators who are added to the Service. |
| Types of data | Name, work email, role, manager, department, teams, location, start date, work schedule, profile photo, leave requests, dates, types, approvals, balances and adjustments, notes and attachments, Company-tab documents, salary (if entered), and sign-in and security records. |
| Sensitive data | Notes and attachments may contain health information (such as medical notes). The Customer controls whether it's collected and who sees it. Salary may be entered for leave-liability reports. |
| Processing activities | Storage, hosting, calculation, display, email delivery, calendar sync the Customer turns on, backup, support and deletion. |
Annex 2: Security measures
- Hosting: DigitalOcean's Toronto data centre, operated under recognized security certifications.
- Encryption: HTTPS (TLS) for all traffic. The database and file storage are encrypted at rest. Calendar access tokens are also encrypted with AES-256-GCM.
- Separation between customers: Postgres row-level security restricts every query to one company.
- Access control: Microsoft 365 and Google Workspace single sign-in; passwords hashed with bcrypt; role-based permissions in the app; staff access limited to people who need it, using multi-factor authentication.
- Abuse protection: rate limits on sign-in and sensitive actions; signed, expiring links in emails.
- Files: stored privately, and served only through access-checked requests.
- Resilience: daily database backups with point-in-time recovery; a documented recovery process.
- Monitoring and records: security and sign-in records; an in-app audit log on the Complete plan.
- Development: code changes reviewed and tested before release; dependencies kept up to date.