1. Controller
Mariglen KercikuLedgerLift
Wielandstr. 4a
91080 Uttenreuth
Germany
Email: info@theledgerlift.com
2. Data we process
Account and workspace data
We process the identity and contact data needed to authenticate you and operate your workspace, such as your email address, name when supplied, account identifiers, organization membership, role, invitation status, and essential session information.
Statement and extraction data
When you submit a document, we process the PDF, an optional PDF password, extracted text, transaction data, page references, confidence information, review edits, and technical diagnostics needed to produce and validate the result. Bank statements can contain personal and financial information about you and other people.
Synchronous uploads are processed in memory. For background jobs, source files and any PDF password are encrypted at rest. Source files are removed after successful processing or a terminal failure. Job metadata and encrypted results are deleted when you delete the job or after the configured short retention window, normally no more than 24 hours.
Billing data
We receive limited purchase and subscription information from Paddle, including opaque customer, transaction and subscription identifiers, product or plan references, payment status, currency totals, and credit adjustments. Paddle is the merchant of record and processes card, billing-address, tax, invoice, and payment data under its own privacy notices. LedgerLift does not receive or store full card details.
Technical and support data
We process IP addresses, timestamps, request and security metadata, error codes, service health information, and messages you send to support. We design operational logs and metrics not to contain statement text, transaction descriptions, PDF passwords, or model prompts and responses.
3. Why we process data
- To provide authentication, workspaces, extraction, review, export, billing, and support.
- To protect accounts, prevent abuse, enforce limits, and investigate service failures.
- To reconcile purchases, credits, refunds, and subscriptions.
- To comply with accounting, tax, consumer-protection, and other legal obligations.
- To improve reliability using aggregated or privacy-safe operational information.
4. Legal bases
We process data as necessary to perform our contract with you or take requested pre-contractual steps (Article 6(1)(b) GDPR), to comply with legal obligations (Article 6(1)(c)), and for legitimate interests in operating, securing, supporting, and improving the service (Article 6(1)(f)). Where we specifically ask for consent, the basis is Article 6(1)(a), and you may withdraw that consent prospectively.
5. Service providers and recipients
We use providers only for functions needed to operate LedgerLift, including:
- Railway for application hosting, database, and encrypted object storage.
- WorkOS for authentication, sessions, organizations, and workspace membership.
- Paddle as merchant of record for checkout, payment, tax, invoices, and subscriptions.
- OpenRouter and the selected model provider when model-assisted document recovery is needed. Relevant document images or extracted content may be sent for that request.
We may also disclose data where required by law, necessary to protect legal rights or security, or as part of a business reorganization subject to appropriate safeguards.
6. International transfers
Some providers may process data outside Germany or the European Economic Area. Where the destination is not covered by an adequacy decision, we use or rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary security measures where required.
7. Retention
- Statement sources are kept only for processing and removed after completion or terminal failure; short-lived encrypted job results normally expire within 24 hours.
- Reviews saved locally stay in your browser until you remove them or clear browser data; they are not uploaded merely because you save them locally.
- Account and workspace records are retained while the account is active and for a limited period afterward when needed for security, dispute handling, or legal obligations.
- Billing and accounting records are retained for the periods required by applicable law.
- Security and operational records are retained only as long as reasonably needed for their stated purpose.
8. Cookies and browser storage
LedgerLift uses essential session and security cookies required for sign-in and workspace selection. Optional review drafts and export presets are stored locally only after you use the relevant feature. We do not currently use optional advertising or behavioral analytics cookies. If that changes, we will update this notice and request consent where required.
9. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interests. You may also withdraw consent prospectively and lodge a complaint with a data protection supervisory authority, including the authority for your habitual residence or place of work.
Send privacy requests to info@theledgerlift.com. We may need to verify your identity before fulfilling a request.
10. Security
We use access controls, tenant isolation, encryption for short-lived job objects, transport encryption, secret management, and logging controls designed to protect personal data. No online service can guarantee absolute security; please contact us promptly if you suspect an account or data incident.
11. Changes
We may update this notice when the service, providers, or legal requirements change. The current version and its update date will remain available on this page.