Privacy Policy

Effective Date: 23 July 2025

1. Introduction

DataLedger ("we", "us", or "our"), a company to be incorporated in Scotland, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use the DataLedger service ("Service").

This Privacy Policy applies to our API and web application. For information about our main website and marketing communications, please see the privacy policy on our main website at www.dataledger.uk.

2. Data Controller

We are the data controller for the personal information we collect through our Service. Once incorporated, our registered address will be ...

For privacy-related enquiries, please contact us at contact@dataledger.uk.

3. Information We Collect

3.1 Account Information

  • Email address (required for account creation and login)

  • Username/display name (if provided)

  • Account preferences and settings

3.2 Payment Information

  • Billing information is processed by Stripe (our payment processor)

  • We do not store your payment card details

  • We receive confirmation of successful payments and subscription status

3.3 Usage Information

  • API usage data (endpoints accessed, tokens consumed, request timestamps)

  • Login and session information

  • Service usage patterns and performance data

3.4 Technical Information

  • IP addresses

  • Browser type and version

  • Device information

  • Session identifiers

4. How We Use Your Information

We process your personal information for the following purposes:

4.1 Service Delivery (Legal basis: Contract performance)

  • Creating and managing your account

  • Providing access to our API and data services

  • Processing payments and managing subscriptions

  • Monitoring usage against your token allocation and rate limits

4.2 Business Operations (Legal basis: Legitimate interests)

  • Improving our Service and developing new features

  • Ensuring service security and preventing fraud

  • Analysing usage patterns to optimise performance

  • Providing customer support

4.3 Legal Compliance (Legal basis: Legal obligation)

  • Complying with applicable laws and regulations

  • Responding to legal requests and court orders

4.4 Marketing Communications (Legal basis: Consent)

  • Sending marketing emails about our services and updates

  • You can unsubscribe at any time using the link in our emails

  • Marketing consent is collected via our main website

5. Information Sharing

5.1 Third-Party Service Providers

We share information with trusted service providers who assist in operating our Service:

Auth0 (Authentication Services)

  • Processes email addresses and login credentials

  • Data may be stored in the US/EU under appropriate safeguards

  • Privacy policy: https://auth0.com/privacy

Stripe (Payment Processing)

  • Processes payment and billing information

  • Data may be transferred internationally under adequate safeguards

  • Privacy policy: https://stripe.com/privacy

5.2 Legal Requirements

We may disclose information if required by law, court order, or to protect our rights and safety.

5.3 Business Transfers

If we sell or transfer our business, personal information may be transferred to the new owner under equivalent privacy protections.

6. Data Retention

6.1 Account Information

  • Retained whilst your account is active

  • Deleted within 30 days of account closure (unless legal retention required)

6.2 Usage Data

  • API usage logs retained for 12 months for billing and support purposes

  • Aggregated, anonymised usage statistics may be retained indefinitely

6.3 Payment Information

  • Billing records retained for 7 years for tax and accounting purposes

  • Payment card details are not stored by us (handled by Stripe)

7. Your Rights

Under UK GDPR, you have the following rights:

7.1 Access Right

Request a copy of the personal information we hold about you.

7.2 Rectification Right

Request correction of inaccurate or incomplete information.

7.3 Erasure Right

Request deletion of your personal information (subject to legal retention requirements).

7.4 Portability Right

Request your data in a portable format to transfer to another service.

7.5 Restriction Right

Request that we limit how we use your information.

7.6 Objection Right

Object to processing based on legitimate interests.

7.7 Withdrawal of Consent

Withdraw consent for marketing communications at any time.

To exercise these rights, please contact us at contact@dataledger.uk. We will respond within one month.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption of data in transit and at rest

  • Regular security assessments

  • Access controls and authentication requirements

  • Secure hosting and infrastructure

However, no system is completely secure, and we cannot guarantee absolute security.

9. International Transfers

Some of our service providers (Auth0, Stripe) may transfer your data outside the UK. We ensure such transfers are protected by:

  • Adequacy decisions by the UK government

  • Standard contractual clauses approved by the UK authorities

  • Other appropriate safeguards

10. Cookies

10.1 Strictly Necessary Cookies

We use cookies that are essential for our Service to function:

  • Authentication cookies: To keep you logged in securely

  • Session cookies: To maintain your session state

  • Security cookies: To prevent fraud and unauthorised access

These cookies are necessary for the Service and do not require your consent.

10.2 Cookie Management

You can disable cookies in your browser settings, but this may prevent the Service from functioning properly.

11. Age Restrictions

Our Service is only available to users aged 18 and over. We do not knowingly collect information from individuals under 18. If you become aware that someone under 18 has provided us with personal information, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Email notification to your registered address

  • Prominent notice on our Service

  • Updating the "Effective Date" at the top of this policy

Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Data Protection Authority

You have the right to lodge a complaint with the UK's data protection authority:

Information Commissioner's Office (ICO)
Website: https://ico.org.uk
Telephone: 0303 123 1113

14. Contact Us

For any questions about this Privacy Policy or our privacy practices, please contact us:

Email: contact@dataledger.uk

Last updated: 23 July 2025