LedgerMCP: Data Processing Agreement

LedgerMCP, LLC

Effective date: August 5, 2026

Last updated: August 5, 2026

This Data Processing Agreement ("DPA") applies when you use LedgerMCP to process

personal data that belongs to other people, and applicable data protection law

makes you the controller and LedgerMCP the processor. In plain terms:

your books may contain personal data about your customers, contractors, and

employees. This document says what we may do with it, and what we owe you.

It forms part of, and is governed by, the Terms of Service. Where this

DPA and the Terms conflict on the processing of personal data, this DPA wins.

You do not need to sign anything for this DPA to apply. If your organization

requires a countersigned copy, email support@ledgermcp.com.


1. Definitions

"Controller", "processor", "personal data", "processing", "data subject", and

"personal data breach" have the meanings given in the EU General Data Protection

Regulation (GDPR). "Customer Data" has the meaning given in the Terms. "Applicable

Data Protection Law" means the data protection laws that apply to your use of the

Service, which may include the GDPR, the UK GDPR, and US state privacy laws such

as the CCPA/CPRA.

2. Roles

You are the controller of the personal data contained in your Customer Data. We

are your processor and process that personal data only on your behalf.

For a small amount of data we determine the purposes of ourselves, we act as a

controller instead: your own account and login details, billing records, security

and audit logs, and aggregate website analytics. That processing is described in

our Privacy Policy and is not covered by this DPA.

3. What we may do with your data

We process personal data in Customer Data only:

actions of AI agents you authorize, and any support request you make; and

forbids it.

**We do not sell personal data. We do not use Customer Data for advertising. We

do not train machine-learning models on Customer Data.** LedgerMCP ships no AI of

its own; any AI agent that touches your books is one you connect, acting under

your authority, and is a third party governed by its own terms.

If we believe an instruction from you breaks Applicable Data Protection Law, we

will tell you.

4. Processing details

Subject matterProvision of double-entry bookkeeping software
DurationFor as long as your account is active, plus the retention periods in our Data Retention and Disposal Policy
Nature and purposeStoring, organizing, categorizing, reconciling, and reporting on financial records you or your authorized agents submit
Types of personal dataNames and contact details of customers, vendors, contractors, and employees as they appear in transactions, tags, invoices, receipts, and tax documents such as W-9 forms; bank account and transaction data you connect; any personal data you choose to put in a description, memo, note, or uploaded file
Categories of data subjectsYour customers, vendors, contractors, employees, and any other individual appearing in your books
Special categoriesNone requested or required. The Service is not designed for special-category data, and you should not put it in your books

5. Confidentiality

We keep Customer Data confidential. Access is limited to personnel who need it to

run or support the Service, who are bound by confidentiality obligations, and who

operate under least-privilege access controls.

6. Security

We maintain appropriate technical and organizational measures, including

encryption in transit and at rest, application-layer encryption of financial

access tokens, tenant isolation enforced in the database, least-privilege access,

hashed and scoped API keys, rate limiting, and an append-only audit log. Postings

to the ledger are immutable by database grant and correctable only by reversal,

so the record of what happened cannot be quietly rewritten.

Our Security page describes these in more detail. We may change

specific measures over time, but will not materially reduce overall protection.

7. Subprocessors

You give us general authorization to use subprocessors. Our current list, what

each does, and where it operates, is published at

/subprocessors.

Infrastructure vendors are listed there by function rather than by name. **If you

require the identity of each vendor for your own compliance, email us and we will

provide the full list under NDA.**

Each subprocessor is bound by a written contract imposing data protection

obligations no less protective than this DPA, and we remain liable to you for

their performance. We will update the subprocessors page before adding or

replacing a subprocessor that processes Customer Data. To be notified directly,

email support@ledgermcp.com with the subject "Subprocessor updates". If you

reasonably object to a new subprocessor on data protection grounds, tell us and

we will work with you in good faith; if we cannot resolve it, you may terminate

and we will refund any prepaid, unused fees.

8. Helping you meet your obligations

Taking into account the nature of the processing, we will help you with:

access, correct, export, and delete records directly in the Service, and every

book exports in full. If a request needs something the Service cannot do, email

us and we will assist.

information is available to us and you cannot obtain it yourself.

9. Personal data breach

If we become aware of a personal data breach affecting Customer Data, we will

notify you without undue delay and in any case within 72 hours, with the

information we have at that point: what happened, which data and roughly how many

records are involved, the likely consequences, and what we are doing about it. We

will keep you updated as we learn more. Notifying you is not an admission of

fault.

10. Deletion and return

You can export your Customer Data at any time, for every book, without asking us.

On termination, or on your written request, we will delete Customer Data in

accordance with our Data Retention and Disposal Policy, except

where we are required by law to keep it. Backups age out on their normal cycle;

data in backups is not restored to active use.

11. Audits

We will make available the information reasonably necessary to demonstrate

compliance with this DPA, and will respond to a reasonable security questionnaire

no more than once a year. Where you require an audit beyond that, we will agree

scope and timing with you in advance, and you will bear the reasonable cost.

12. International transfers

We operate in the United States and process Customer Data there. Where you

transfer personal data subject to the GDPR or UK GDPR to us, that transfer is

made under the European Commission's Standard Contractual Clauses (Module Two,

controller to processor), and the UK Addendum where applicable, which are

incorporated into this DPA by reference and completed with the details in §4, the

security measures in §6, and the subprocessor list in §7. Where those clauses

conflict with this DPA, the clauses prevail.

13. Liability

Each party's liability under this DPA is subject to the limitations and

exclusions in the Terms of Service.

14. Contact

LedgerMCP, LLC

Email: support@ledgermcp.com

Website: https://ledgermcp.com

Related: Privacy Policy · Subprocessors ·

Data Retention and Disposal Policy · Security