LedgerMCP: Data Processing Agreement
LedgerMCP, LLC
Effective date: August 5, 2026
Last updated: August 5, 2026
This Data Processing Agreement ("DPA") applies when you use LedgerMCP to process
personal data that belongs to other people, and applicable data protection law
makes you the controller and LedgerMCP the processor. In plain terms:
your books may contain personal data about your customers, contractors, and
employees. This document says what we may do with it, and what we owe you.
It forms part of, and is governed by, the Terms of Service. Where this
DPA and the Terms conflict on the processing of personal data, this DPA wins.
You do not need to sign anything for this DPA to apply. If your organization
requires a countersigned copy, email support@ledgermcp.com.
1. Definitions
"Controller", "processor", "personal data", "processing", "data subject", and
"personal data breach" have the meanings given in the EU General Data Protection
Regulation (GDPR). "Customer Data" has the meaning given in the Terms. "Applicable
Data Protection Law" means the data protection laws that apply to your use of the
Service, which may include the GDPR, the UK GDPR, and US state privacy laws such
as the CCPA/CPRA.
2. Roles
You are the controller of the personal data contained in your Customer Data. We
are your processor and process that personal data only on your behalf.
For a small amount of data we determine the purposes of ourselves, we act as a
controller instead: your own account and login details, billing records, security
and audit logs, and aggregate website analytics. That processing is described in
our Privacy Policy and is not covered by this DPA.
3. What we may do with your data
We process personal data in Customer Data only:
- to provide, secure, and maintain the Service under the Terms;
- on your documented instructions, which include your use of the Service, the
actions of AI agents you authorize, and any support request you make; and
- where required by law, in which case we will tell you first unless the law
forbids it.
**We do not sell personal data. We do not use Customer Data for advertising. We
do not train machine-learning models on Customer Data.** LedgerMCP ships no AI of
its own; any AI agent that touches your books is one you connect, acting under
your authority, and is a third party governed by its own terms.
If we believe an instruction from you breaks Applicable Data Protection Law, we
will tell you.
4. Processing details
| Subject matter | Provision of double-entry bookkeeping software |
| Duration | For as long as your account is active, plus the retention periods in our Data Retention and Disposal Policy |
| Nature and purpose | Storing, organizing, categorizing, reconciling, and reporting on financial records you or your authorized agents submit |
| Types of personal data | Names and contact details of customers, vendors, contractors, and employees as they appear in transactions, tags, invoices, receipts, and tax documents such as W-9 forms; bank account and transaction data you connect; any personal data you choose to put in a description, memo, note, or uploaded file |
| Categories of data subjects | Your customers, vendors, contractors, employees, and any other individual appearing in your books |
| Special categories | None requested or required. The Service is not designed for special-category data, and you should not put it in your books |
5. Confidentiality
We keep Customer Data confidential. Access is limited to personnel who need it to
run or support the Service, who are bound by confidentiality obligations, and who
operate under least-privilege access controls.
6. Security
We maintain appropriate technical and organizational measures, including
encryption in transit and at rest, application-layer encryption of financial
access tokens, tenant isolation enforced in the database, least-privilege access,
hashed and scoped API keys, rate limiting, and an append-only audit log. Postings
to the ledger are immutable by database grant and correctable only by reversal,
so the record of what happened cannot be quietly rewritten.
Our Security page describes these in more detail. We may change
specific measures over time, but will not materially reduce overall protection.
7. Subprocessors
You give us general authorization to use subprocessors. Our current list, what
each does, and where it operates, is published at
Infrastructure vendors are listed there by function rather than by name. **If you
require the identity of each vendor for your own compliance, email us and we will
provide the full list under NDA.**
Each subprocessor is bound by a written contract imposing data protection
obligations no less protective than this DPA, and we remain liable to you for
their performance. We will update the subprocessors page before adding or
replacing a subprocessor that processes Customer Data. To be notified directly,
email support@ledgermcp.com with the subject "Subprocessor updates". If you
reasonably object to a new subprocessor on data protection grounds, tell us and
we will work with you in good faith; if we cannot resolve it, you may terminate
and we will refund any prepaid, unused fees.
8. Helping you meet your obligations
Taking into account the nature of the processing, we will help you with:
- Data subject requests. Most of what you need is self-service: you can
access, correct, export, and delete records directly in the Service, and every
book exports in full. If a request needs something the Service cannot do, email
us and we will assist.
- Security, breach notification, and impact assessments, to the extent the
information is available to us and you cannot obtain it yourself.
9. Personal data breach
If we become aware of a personal data breach affecting Customer Data, we will
notify you without undue delay and in any case within 72 hours, with the
information we have at that point: what happened, which data and roughly how many
records are involved, the likely consequences, and what we are doing about it. We
will keep you updated as we learn more. Notifying you is not an admission of
fault.
10. Deletion and return
You can export your Customer Data at any time, for every book, without asking us.
On termination, or on your written request, we will delete Customer Data in
accordance with our Data Retention and Disposal Policy, except
where we are required by law to keep it. Backups age out on their normal cycle;
data in backups is not restored to active use.
11. Audits
We will make available the information reasonably necessary to demonstrate
compliance with this DPA, and will respond to a reasonable security questionnaire
no more than once a year. Where you require an audit beyond that, we will agree
scope and timing with you in advance, and you will bear the reasonable cost.
12. International transfers
We operate in the United States and process Customer Data there. Where you
transfer personal data subject to the GDPR or UK GDPR to us, that transfer is
made under the European Commission's Standard Contractual Clauses (Module Two,
controller to processor), and the UK Addendum where applicable, which are
incorporated into this DPA by reference and completed with the details in §4, the
security measures in §6, and the subprocessor list in §7. Where those clauses
conflict with this DPA, the clauses prevail.
13. Liability
Each party's liability under this DPA is subject to the limitations and
exclusions in the Terms of Service.
14. Contact
LedgerMCP, LLC
Email: support@ledgermcp.com
Website: https://ledgermcp.com
Related: Privacy Policy · Subprocessors ·