Draft. This text describes how PrimerLedger works today and is waiting for review by our lawyer before launch. Details marked “to be confirmed” will be filled in then.
Scope
This policy explains how To be confirmed (“PrimerLedger”, “we”) handles personal data on www.primerledger.com, in the PrimerLedger app and when you write to us, in line with the Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules and the issuances of the National Privacy Commission (NPC).
Who is responsible
- For account data (your name, e-mail, sign-in activity, billing) and for messages you send us, PrimerLedger is the personal information controller.
- For the business records your company enters (customers, suppliers, invoices, attachments), your company is the controller and PrimerLedger processes that data on its behalf, under the Data Processing Addendum.
- Data Protection Officer: To be confirmed, hello@primerledger.com.
- NPC registration: To be confirmed.
What we collect
- Account: name, e-mail address, password (stored only as a one-way hash), your theme and tour preferences, and the date and version of the terms you accepted.
- Company: company name, TIN, address, VAT status, bank details, logo and signature image you upload.
- Sign-in and activity: time, IP address and browser of sign-ins and sessions; a log of changes made in your company with who made them.
- Billing: subscription status, invoices we issued to you, payment references and proof-of-payment images you upload. We do not receive or store card numbers.
- Messages: what you send us by e-mail or with the contact form on our website (your name, e-mail address, and the business name and mobile number if you give them).
- Help assistant: the questions you type and the answers given (see below).
- Abuse protection: for the contact form and the assistant we keep a scrambled form of the IP address (a one-way hash), never the address itself.
Where it comes from
From you when you sign up, use the app or write to us; from a member of your company who invites you (your name and e-mail address); and automatically from your browser when you sign in (IP address, browser, time).
Why we use it, and on what basis
- To provide the service you signed up for: your account, your companies, sign-in, invitations and support. Basis: the contract with you (RA 10173, Section 12(b)).
- To keep it secure and prevent abuse: sign-in records, lockouts, the activity log, spam protection. Basis: our legitimate interest in a safe service (Section 12(f)).
- To bill you and keep the records the law requires of us: invoices and payments. Basis: legal obligation (Section 12(c)).
- To send service e-mails: verification, password reset, invitations, trial and payment reminders. Basis: the contract. We do not send marketing e-mails without your consent, and you can withdraw consent at any time.
- To answer your messages and improve our help guide. Basis: legitimate interest, and your consent when you write to us.
We do not process sensitive personal information for our own purposes, and we never sell personal data or use it for advertising.
Records you enter
Customer and supplier details, invoices, expenses and attachments are used only to run your company's books. Each company's records are kept apart from every other company's at the database level. We do not look at them except to help you when you ask, to keep the service working, or when the law requires it, and we do not use them to train artificial intelligence models. Our own administration console shows companies, people and subscriptions, not your books.
The help assistant
“Ask PrimerLedger” answers questions with an artificial intelligence model provided by Anthropic. What it receives: your question, the earlier questions of the same chat, the page you are on and, in the app, your role (for example Accountant). It never receives your company's records. Under Anthropic's commercial terms, these messages are not used to train its models. We keep the conversations to answer follow-up questions and to improve our help guide; please do not type personal or confidential details into it.
Who we share it with
Only the service providers we need to run PrimerLedger (our sub-processors), each bound by contract to protect the data and use it only for us. The current list, with what each one does and where, is on the Sub-processors page. We also disclose data when the law or a lawful order requires it. If PrimerLedger is ever sold or merged, the data moves with the service under the same protections, and we will tell you first.
Data stored outside the Philippines
Some providers process data outside the Philippines, for example e-mail delivery and the help assistant in the United States. We use them only under contracts that require protection comparable to the Data Privacy Act, and we remain responsible for the data. Where our main servers are: To be confirmed.
How long we keep it
- Your company's records stay for as long as the company exists, including when it is read-only for non-payment.
- When a company is closed, its Owner can ask for an export for 30 days; we erase its records after To be confirmed, except what the law requires us to keep.
- Your account stays until you ask us to delete it. We keep the record of the terms you accepted and of the invoices we issued to you for as long as the law requires.
- Billing records (invoices we issued to you and their payments) are kept for as long as Philippine tax law requires.
- Contact-form messages and assistant conversations: To be confirmed. Until then, we delete them when you ask.
- Backups are overwritten on a rolling cycle: To be confirmed.
How we protect it
HTTPS everywhere, hashed passwords, account lockout after repeated wrong passwords, roles checked by the server on every request, separation of companies in the database, an activity log that cannot be edited, nightly backups, and access to production limited to the people who run it. See Security & privacy.
If something goes wrong
If a personal data breach is likely to put people at real risk, we will notify the National Privacy Commission and the people affected within 72 hours of knowing about it, as the NPC requires, and tell them what happened and what we are doing. For breaches involving the records in your company, we will also tell your company's Owners without delay so you can meet your own duties.
Your rights
Under the Data Privacy Act you have the right:
- to be informed about how your personal data is used;
- to access it and get a copy;
- to object to its processing, and to withdraw consent where we rely on consent;
- to have it corrected if it is wrong or out of date;
- to have it erased or blocked when it is no longer needed or was processed unlawfully;
- to data portability, in a common electronic format (Excel, CSV or PDF);
- to claim damages, and to file a complaint with the National Privacy Commission.
How to use your rights
Most account details can be changed in the app, and your company's records can be exported at any time. For anything else, e-mail hello@primerledger.com from the address on your account. We may ask you to confirm who you are, and we answer within 30 days. If a customer or supplier of your business asks about their data in your records, send us their request and we will help you answer it.
Cookies and analytics
The app uses one cookie, needed to keep you signed in. The website sets no cookies. Your theme and motion choices on the website, and the step you reached in a product tour, are saved only in your own browser. The website does not use analytics today; if we add visit counting, it will be cookieless and will not identify you, and we will update this page first.
Children
PrimerLedger is for businesses. Accounts are for people aged 18 and over, and we do not knowingly collect data from children. If you think a child has given us personal data, write to us and we will delete it.
Automated decisions
We do not make decisions about you based solely on automated processing. The help assistant only answers questions; it cannot change your account or your records.
Changes to this policy
We will update this page when what we do changes. For changes that matter to you, we will e-mail the Owners of your companies before they apply. The date at the top shows the latest version.
Contact and complaints
Write to our Data Protection Officer at hello@primerledger.com. If you are not satisfied with our answer, you may complain to the National Privacy Commission (privacy.gov.ph).