Draft. This text describes how PrimerLedger works today and is waiting for review by our lawyer before launch. Details marked “to be confirmed” will be filled in then.
This addendum is part of the Terms of Service. It applies automatically to every company that uses PrimerLedger; nothing needs to be signed. If you need a signed copy for your records, write to hello@primerledger.com.
Who is who
For the personal data in your company's records (for example the names, TINs, addresses and contact details of your customers and suppliers, and the people named on invoices and receipts), your company is the personal information controller and PrimerLedger is the personal information processor under the Data Privacy Act of 2012 (RA 10173).
What we process
- Purpose: storing, displaying, calculating, exporting and backing up your company's records so you can keep your books.
- People concerned: your customers, suppliers and their contact persons, and your members.
- Kinds of data: names, addresses, TINs, e-mail addresses, phone numbers, bank details you enter, amounts and documents you attach.
- Duration: for as long as your company uses PrimerLedger, then as set out under “When the service ends”.
Only on your instructions
We process this data only to provide the service as described in the Terms, and on your other documented instructions. Using the app (entering, changing, deleting or exporting records) is your instruction. If the law requires us to process it in another way, we will tell you first unless the law forbids it. We never use it for our own purposes, for advertising, or to train artificial intelligence models.
Our people
Only the people who run PrimerLedger can reach production systems, each bound to confidentiality, and only when needed to keep the service working or to help you when you ask.
Security
We apply organisational, physical and technical measures suitable for financial records, described on the Security & privacy page, including the separation of each company's records at the database level, roles checked on the server, an activity log, the recycle bin and nightly backups.
Sub-processors
You allow us to use the sub-processors on the Sub-processors page. Each is bound by contract to obligations no weaker than this addendum, and we remain responsible for them. We give at least 30 days' notice of a new one, and you may object as described on that page.
Helping you with requests
If one of your customers or suppliers asks to access, correct or erase their data, you can usually do it yourself in the app. If you need more, we will help you answer within the time the law allows. If such a request reaches us directly, we will pass it to you.
Breaches
If we learn of a breach affecting your company's records, we will tell your company's Owners without undue delay, and in any case in time for you to notify the National Privacy Commission within 72 hours where required, with what we know, what we are doing, and who to contact.
When the service ends
You can export your records at any time. After a company is closed, its Owner can still ask for an export for 30 days; then we erase the records, including from backups as they are overwritten, unless the law requires us to keep them.
Information and checks
We will give you the information you reasonably need to show that this addendum is followed, and answer written questions about our measures. On-site audits can be agreed in writing, at reasonable notice and at your cost.
Your part
As controller, you make sure you have a lawful basis to enter the personal data you put into PrimerLedger, that it is accurate, and that you tell the people concerned how you use it.