Skip to main content
Ledja™.

Calm in every number.

Powered by Ledja Ltd

Legal information

Ledja SaaS Terms

Effective date
22 August 2026
Version
1.0

1. About these Terms

These Terms govern an organisation’s subscription to the Ledja cloud accounting and financial-management service. Ledja is intended for local councils in England and Wales, not consumers acting wholly or mainly outside their trade, business, craft or profession.

Ledja is provided by Ledja Ltd, a company registered in England and Wales under company number 13067612, whose registered office is at 3 Royal Crescent, Cheltenham, Gloucestershire, GL50 3DA. “Ledja”, “we”, “us” and “our” mean Ledja Ltd. “Customer” means the organisation identified in an Order Form. “User” means an individual whom the Customer authorises to use the Service.

These Terms do not themselves create a subscription. No contract is formed by website use, account creation, a trial, quotation, purchase order, email or conduct. The Agreement forms only when Ledja and the Customer sign the same Order Form, including by approved electronic signature or counterparts, and that Order Form expressly incorporates the applicable version of these Terms. The contract consists of the signed Order Form, these Terms, the Data Processing Schedule in section 20, and any other document that the Order Form expressly incorporates (together, the “Agreement”).

An unsigned demonstration or trial may use only synthetic, anonymised or other non-production information and must not accept Customer Personal Data. A pilot, controlled-onboarding activity or trial using Customer Personal Data requires a signed Order Form that incorporates the Data Processing Schedule before Ledja receives the data.

The Order Form takes priority over these Terms for a stated commercial or service-specific matter. The Data Processing Schedule takes priority for the processing of Customer Personal Data. A negotiated document takes priority only to the extent it expressly identifies the provision it changes.

Each Order Form must identify the parties and authorised signatories, the subscribed modules and their production/pilot status, term and renewal, fees and payment terms, implementation and acceptance, support and service levels, data region, current subprocessors, standard export format, applicable security schedule, HMRC production status and the agreed liability allocation. An Order Form missing a required item is incomplete and does not form an Agreement.

ACCLC is a separate professional-services brand of Ledja Ltd. ACCLC services are governed by a separate engagement and are not included in the Ledja subscription unless the Customer separately agrees them in writing. Neither an ACCLC engagement nor these Terms silently governs the other service.

2. The Service

Ledja will provide the modules, plan, environments and support described in the Order Form (the “Service”) for the subscription term. The Service may include council accounting, VAT, reporting, document and bank-statement processing, migration, training and support features only where the signed Order Form identifies them as enabled and states their production, pilot or preview status.

Ledja will:

  • provide the Service with reasonable skill and care;
  • maintain safeguards appropriate to the nature of the Service and Customer Data;
  • use reasonable efforts to keep the Service available, subject to maintenance, security action, internet and supplier dependencies, and any service level stated in the Order Form;
  • provide support through the notified support route and during the service hours stated in the Order Form or support policy; and
  • not materially reduce the core subscribed functionality during a paid fixed term without a lawful, security or urgent operational reason.

Preview, beta, pilot or controlled-onboarding functionality will be identified in the Order Form or Service. It may be incomplete or changed more frequently, but it remains subject to the confidentiality, security and data-protection commitments in the Agreement. A pilot does not become a production subscription unless the agreed acceptance and go-live conditions are met.

3. Accounts and authorised use

The Customer must:

  • appoint an authorised contract contact and at least one appropriate administrator;
  • ensure each User has an individual account and only the permissions needed for that person’s role;
  • keep User information current and remove or change access promptly when responsibilities change;
  • protect its devices, email accounts, authentication factors and credentials;
  • not share passwords or HMRC sign-in credentials; and
  • notify Ledja promptly of suspected unauthorised access, data loss or security weakness.

The Customer is responsible for its Users’ use of the Service and for deciding which people may act for the council. Ledja may rely on instructions from a properly authenticated User acting within assigned permissions, unless Ledja knows that the instruction is unauthorised or unlawful.

4. Acceptable use

The Customer and Users must not:

  • use the Service unlawfully, fraudulently or for a purpose outside the Customer’s authorised activities;
  • attempt to gain access to another customer’s data, bypass security, probe or disrupt the Service, except under a Ledja-approved security-testing arrangement;
  • introduce malware or upload material they do not have the right to use;
  • use automated means in a way that unreasonably degrades the Service or circumvents documented limits;
  • reverse engineer, decompile or copy the Service except to the limited extent that applicable law does not permit that restriction;
  • remove proprietary notices or misrepresent Ledja, the Service or its relationship with HMRC; or
  • allow a third party to use the Service as a bureau or outsourced service for another organisation unless the Order Form expressly permits it.

Ledja may use proportionate technical controls to protect the Service and enforce documented limits. We will explain a material restriction unless doing so would create a security or legal risk.

5. Customer Data and customer responsibilities

“Customer Data” means information, files and records submitted to, stored in, generated for, or retrieved through the Service on the Customer’s behalf. It excludes Service Administration Data. “Service Administration Data” means subscription, billing, business-contact, platform-security, availability, abuse-prevention and support-case metadata for which Ledja determines the purposes and means. As between the parties, the Customer retains all rights in Customer Data. The Customer grants Ledja the limited right to host, copy, transmit, transform and otherwise process Customer Data only as needed to provide, secure and support the Service, follow documented instructions, and comply with law.

The Customer is responsible for:

  • the lawfulness, quality and accuracy of Customer Data and its instructions;
  • deciding its accounting policies, tax treatment, coding, authorisations and statutory responsibilities;
  • retaining source documents and records for the periods that apply to the Customer;
  • reviewing opening balances, imports, extracted information, reconciliations, reports and returns before approval or submission; and
  • maintaining any independent records or exports required by its own continuity, audit or records-management policy.

Ledja provides accounting tools and workflow controls. Unless separately agreed under an ACCLC engagement, Ledja does not provide the Customer with legal, audit, tax or accountancy advice and does not act as the Customer’s responsible financial officer, internal auditor or external auditor.

6. VAT and HMRC services

If Ledja has been granted the required HMRC production access and the signed Order Form enables the production VAT integration, Ledja may allow an appropriately authorised User to connect the Customer to HMRC, retrieve VAT information, prepare and review a VAT return, and submit a return after final confirmation. Until those conditions are met, HMRC functionality is test or pilot functionality and does not submit live returns. Ledja will not describe the Service as HMRC ready, compatible, integrated or recognised unless HMRC permits that description.

The Customer acknowledges that:

  • the User authenticates directly with HMRC using OAuth 2.0, and must not give HMRC sign-in credentials to Ledja;
  • the Customer is responsible for ensuring that each person using the connection has authority to act;
  • the Customer must check the figures, period, declarations and supporting records before submission;
  • HMRC controls its systems, authorisations, response times and decisions, and may change or withdraw an interface;
  • Ledja cannot guarantee HMRC availability, acceptance of a submission, tax treatment, repayment or regulatory outcome; and
  • Ledja will not enable production submission until its required production access and operational controls are in place.

Ledja is not part of HMRC. Ledja will not describe the Service as HMRC approved, accredited or certified. If Ledja later completes HMRC’s formal software-recognition process, it may use only the terminology HMRC then permits.

7. Imports, document extraction, AI assistance and bank information

The Service may import data from another accounting system, statement file or document. It may extract candidate information, suggest a match, identify a possible duplicate or flag an inconsistency.

Imports and extraction are assistance tools. They do not replace the Customer’s review and do not silently create final accounting truth. The Customer must review validation results, source provenance, opening balances, overlaps, duplicates, coding, VAT treatment and reconciliation before committing or relying on the result.

Coverage and quality depend on the source system, bank, file, image and information supplied. Ledja will document supported formats and material limitations. A third-party provider’s coverage or outage does not remove Ledja’s obligation to provide any fallback expressly included in the Order Form, but Ledja is not responsible for a third party’s independent service or decision outside Ledja’s reasonable control.

Where the Order Form enables an artificial-intelligence or machine-learning feature, its output is assistance rather than verified source evidence and may be incomplete or wrong. An authorised User must review relevant input, output and provenance before relying on the result for accounting, payment, VAT or another material action. Ledja will not use Customer Data, or permit a provider to use it, to train or improve a general-purpose, shared or customer-specific model.

8. Support and delegated access

Ordinary support does not authorise Ledja personnel to browse Customer Data without need. Where access to Customer Data is required to resolve a case, Ledja will use a named, purpose-limited, time-limited and auditable support route with the Customer’s authorisation, except where emergency access is strictly necessary to protect the Service or comply with law. Ledja will restrict access to trained personnel and record material support access.

If ACCLC is separately appointed to provide accounting services, an ACCLC team member may instead be an ordinary User whom the Customer authorises under that separate engagement. That is Customer-directed service access, not Ledja supplier-support access, and must not be used to bypass either agreement’s controls.

9. Changes, maintenance and availability

Ledja may update the Service to improve it, fix defects, respond to security or legal requirements, or maintain compatibility with external services. We may perform planned maintenance and will give reasonable advance notice of material planned interruption where practicable. We may take immediate action without advance notice where needed to contain a security incident, prevent harm or comply with law.

Any committed availability target, service credit, recovery objective or support response time is stated in the Order Form or incorporated support policy. If none is stated, those items are operational targets rather than warranties, and service credits do not apply.

The Customer must use a currently supported browser and reasonable internet connection. Ledja is not responsible for failure caused by the Customer’s environment, unauthorised changes, or an external network or service outside Ledja’s reasonable control, although Ledja will use reasonable efforts to manage and communicate material supplier incidents affecting the Service.

10. Fees and taxes

The Customer will pay the fees and applicable taxes stated in the Order Form. Fees are exclusive of VAT unless the Order Form says otherwise. Invoices, payment dates, permitted expenses and any price review are governed by the Order Form.

Ledja will not introduce a new fee during a paid fixed term unless the Customer agrees it or the Agreement expressly provides for it. Failure to pay an undisputed amount by its due date may result in interest under applicable law and, after reasonable notice, suspension under section 16.

11. Intellectual property and feedback

Ledja and its licensors own the Service, software, designs, documentation, methods and all related intellectual-property rights. Ledja warrants that it has, and will maintain during the Agreement, the rights necessary to provide, support and develop the Service and to grant the Customer the rights stated in the Agreement. The Agreement gives the Customer a limited, non-exclusive, non-transferable right for its authorised Users to use the Service during the subscription term for the Customer’s internal functions.

Ledja grants the Customer a perpetual right to use reports and exports generated for it from its own Customer Data. This does not transfer Ledja’s software, templates or general methods.

If the Customer provides feedback, Ledja may use it to improve the Service without payment or attribution, but will not publish confidential information or identify the Customer without permission. Customer Data is not “feedback”.

12. Confidentiality and public-information law

Each party must protect the other’s confidential information, use it only for the Agreement, and disclose it only to people who need it and are bound by confidentiality. This obligation does not apply to information that is public through no breach, was already lawfully known, is independently developed, or is lawfully received without restriction.

A party may disclose information where law, a court or a competent authority requires it, normally after giving the other party notice where legally permitted.

Ledja recognises that a council may be subject to the Freedom of Information Act 2000, Environmental Information Regulations 2004, audit legislation and transparency duties. Ledja will notify the Customer within two working days of any request apparently concerning the Agreement, will not respond except as instructed or required by law, and will preserve and provide information held on the Customer’s behalf promptly and within any reasonable deadline set by the Customer. The Customer remains responsible for deciding whether information must be disclosed. Marking information “confidential” does not override the Customer’s statutory duties.

13. Data protection and security

Each party will comply with the data-protection law that applies to it. For Customer Personal Data, the Customer is normally controller and Ledja is processor. The Data Processing Schedule in section 20 applies.

Ledja will not enable production Customer accounting or HMRC processing until its relevant security controls have been implemented and evidenced. Once production processing begins, Ledja will maintain proportionate technical and organisational measures, including tenant separation, role-based access controls, encryption of Customer Personal Data in transit and at rest, protection of sensitive credentials and HMRC tokens, multi-factor authentication, audit logging, backup and restore testing, vulnerability management, penetration testing, controlled change and incident response.

The Customer will not instruct Ledja to process personal data unlawfully. The Customer must avoid unnecessary personal data in free text and uploads, and must identify any exceptional sensitivity or retention requirement that the standard Service is not designed to meet.

Ledja’s Privacy Policy at https://ledja.co.uk/privacy explains Ledja’s own controller processing and provides the privacy contact.

14. Warranties and service limitations

Each party warrants that it has authority to enter into the Agreement.

Ledja warrants that the Service will materially conform to the current documentation for the subscribed functionality and will be provided with reasonable skill and care. If the Customer reports a reproducible material failure, Ledja will use reasonable efforts to correct it. If Ledja cannot correct a serious continuing failure within a reasonable period, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused affected period. This is subject to the liability provisions below but does not limit any remedy that law says cannot be limited.

The Service is a tool supporting human-controlled accounting processes. It is not warranted to be uninterrupted or error-free, to identify every error or fraud, or to achieve a particular audit, tax, funding or regulatory outcome. No statement in the Service replaces the Customer’s professional judgement or statutory responsibility.

Except as expressly stated in the Agreement, all terms implied by law are excluded to the fullest extent permitted by law.

15. Liability

Nothing in the Agreement excludes or limits either party’s liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or anything else that cannot lawfully be excluded or limited. Nothing in the Agreement limits a Data Subject’s statutory rights or a regulator’s powers.

The parties’ financial caps, excluded categories of loss, enhanced data-protection/confidentiality/security allocation and treatment of related claims must be stated in the signed Order Form or a liability schedule that it expressly incorporates. An Order Form is not complete and no Agreement forms unless it includes that allocation. Ledja will not sign a Customer Order Form until the proposed allocation has been checked against the subscribed services, fees, current insurance position and the Customer’s procurement requirements.

Nothing in this section excuses either party from taking reasonable steps to mitigate loss or affects the Customer’s obligation to pay undisputed fees properly due.

16. Suspension

Ledja may suspend affected access where reasonably necessary to:

  • contain a security threat or material misuse;
  • prevent unlawful processing or harm to another customer, HMRC or the Service;
  • comply with law or a competent authority’s direction; or
  • address an undisputed overdue payment after giving reasonable notice and an opportunity to pay.

Ledja will limit suspension to what is necessary, tell the Customer the reason where lawful, and restore access promptly when the cause is resolved. Suspension does not allow Ledja to use Customer Data for another purpose.

17. Term and termination

The subscription starts and ends as stated in the Order Form. It renews only if the Order Form expressly says so. Any right to terminate for convenience is set out in the Order Form.

Either party may terminate the Agreement by written notice if the other party materially breaches it and, where the breach can be remedied, fails to remedy it within 30 days after written notice. The Customer may also terminate if Ledja becomes insolvent or ceases business. Ledja may exercise an insolvency-related termination right against the Customer only to the extent permitted by applicable insolvency law.

Ledja may terminate an affected integration or the Agreement if continuing it would be unlawful or if a required external authorisation is permanently withdrawn, but will give as much notice and offboarding assistance as reasonably possible.

18. Exit, export and deletion

During the subscription and for 30 days after it ends, the Customer may use available export functions or request a reasonable standard export of Customer Data. Ledja may charge only for material non-standard assistance agreed in advance. We will not withhold a standard export because an unrelated amount is disputed.

At the Customer’s choice, Ledja will return Customer Personal Data in the agreed standard export format and delete it, or delete it without return, after the Services end. The Customer may exercise that choice during the term or within the 30-day export period. Ledja will delete live copies within 90 days after that export period, and no later than 120 days after termination, unless the Customer lawfully instructs earlier deletion or law requires storage. Isolated backup copies will expire within a further 90 days, and no later than 210 days after termination. If a backup is restored for disaster recovery, the restored data remains subject to the Customer’s deletion instruction.

Ledja may retain its own minimal Service Administration Data in accordance with its Privacy Policy. It will not retain council accounting records under that controller purpose merely because they were once processed through the Service.

On termination, Ledja will disable future HMRC access and delete or render inaccessible active HMRC OAuth tokens, subject to protected backup expiry. Accounting and submission evidence already held for the Customer remains part of the export and retention process.

Sections intended to protect rights or regulate events after termination—including fees due, intellectual property, confidentiality, data protection, liability, export and deletion, and general legal terms—continue to apply.

19. General legal terms

  • Notices. Contract notices must be sent to the addresses in the Order Form. A notice of breach or termination must be in writing and clearly identified. Privacy enquiries should be sent to [email protected].
  • Public-sector invoicing and payment. Where sections 67, 68 or 88 of the Procurement Act 2023 apply, the applicable statutory electronic-invoicing and payment terms are incorporated into the Agreement and prevail over an inconsistent contractual term.
  • Changes to these Terms. Ledja may update these Terms for future Order Forms. For an existing paid term, a materially adverse change takes effect only at renewal unless it is required by law, needed to address an urgent security risk, or agreed by the Customer. We will give reasonable notice of a material change.
  • Assignment. Neither party may assign the Agreement without the other’s written consent, not to be unreasonably withheld or delayed, except to a successor in connection with a genuine corporate reorganisation or transfer of substantially all relevant business, provided the successor can perform the Agreement.
  • Subcontracting and group companies. Ledja may use subcontractors but remains responsible for their performance of Ledja’s obligations. A company does not gain a right to access or use Customer Data merely because it is affiliated with Ledja or owns intellectual property or other assets used by the Service. If a group company performs part of the Service or can process Customer Personal Data, it is subject to the same confidentiality, subcontracting and, where applicable, Subprocessor controls as an unrelated supplier. Subprocessors are governed by section 20.
  • Force majeure. Neither party is liable for delay caused by an event beyond its reasonable control, excluding payment obligations. The affected party must take reasonable steps to reduce the effect and resume performance. If a material interruption continues for 60 days, either party may terminate the affected Service.
  • Entire agreement. The Agreement is the entire agreement about the Service and replaces earlier proposals or statements about it. Neither party relies on a statement not included in the Agreement, but this does not exclude liability for fraud.
  • No partnership or agency. The Agreement does not create a partnership, joint venture, employment or agency relationship. Neither party can bind the other.
  • Third-party rights. A person who is not a party has no right to enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999.
  • Waiver and severance. A delay in enforcing a right is not a waiver. If a provision is invalid, it will be adjusted only as much as necessary and the rest remains effective.
  • Governing law and courts. English law governs the Agreement. The courts of England and Wales have exclusive jurisdiction, subject to any mandatory public-law requirement that applies to the Customer.

20. Data Processing Schedule

20.1 Definitions and scope

In this section, “Controller”, “Processor”, “Personal Data”, “Personal Data Breach”, “processing” and “Data Subject” have the meanings given by applicable UK data-protection law. “Customer Personal Data” means Personal Data contained in Customer Data that Ledja processes as Processor for the Customer. “Subprocessor” means another Processor engaged by Ledja to process Customer Personal Data.

The Customer is Controller and Ledja is Processor for Customer Personal Data, except where the parties’ actual roles differ under law. Each party remains responsible for its own controller processing.

20.2 Processing details

  • Subject matter: provision, security, support and offboarding of the subscribed Ledja Service.
  • Duration: the subscription term plus the export, deletion and protected-backup periods in the Agreement, unless a lawful instruction requires otherwise.
  • Nature and purpose: collecting, recording, organising, storing, retrieving, consulting, transmitting, reconciling, reporting, restricting, exporting and deleting data to provide the Customer’s accounting, VAT, migration, document, banking, support and audit functions.
  • Data subjects: Users and administrators; council employees, members and office holders; suppliers, contractors, customers, payees, residents and other people identified in Customer records; and people represented in support or evidence material.
  • Personal-data types: identity and contact information; account and role information; financial, transaction, supplier, customer, bank and invoice information; VAT identifiers and records; documents, notes, audit history and support material; and technical identifiers linked to use of the Customer workspace.
  • Special-category or criminal-offence data: not required for ordinary use, but it may appear incidentally in Customer-provided records. The Customer must identify and lawfully authorise any intended processing that requires additional safeguards.
  • Customer instructions: the Agreement, configured use by authorised Users, support requests, and other documented lawful instructions agreed by the parties. Where the signed Order Form enables the production VAT integration, the Customer instructs Ledja to transmit HMRC-required fraud-prevention header data with API requests and to provide HMRC with security-incident information required by the applicable HMRC Developer Hub terms. Ledja will minimise any Personal Data disclosed and inform the Customer unless prohibited by law or HMRC security requirements.

20.3 Ledja’s processor obligations

Ledja will:

  1. process Customer Personal Data only on documented Customer instructions, including for international transfers, unless UK law requires processing; where legally permitted, Ledja will inform the Customer before that required processing;
  2. tell the Customer promptly if Ledja reasonably believes an instruction infringes data-protection law, and pause the affected processing where necessary while the parties resolve it;
  3. ensure people authorised to process Customer Personal Data are subject to confidentiality obligations and receive appropriate security and data-protection guidance;
  4. maintain appropriate technical and organisational security measures having regard to the state of the art, implementation cost, processing context and risks to people;
  5. assist the Customer, taking account of the nature of processing, to respond to Data Subject requests. Ledja will not respond substantively on the Customer’s behalf unless instructed or legally required;
  6. provide reasonable assistance with security, breach assessment and notification, data-protection impact assessments and prior consultation obligations, taking account of the information available to Ledja;
  7. notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide available information needed for the Customer’s assessment and notifications. Notification is not an admission of fault;
  8. at the Customer’s choice, return Customer Personal Data and delete it, or delete it without return, as set out in section 18, unless law requires storage;
  9. make information reasonably necessary to demonstrate compliance with this schedule available to the Customer; and
  10. not use Customer Personal Data, or permit a Subprocessor to use it, to train or improve a general-purpose, shared or customer-specific AI or machine-learning model. AI input and output may be retained only for the documented Service purpose and retention period stated in the Agreement or current Subprocessor information.

20.4 Security measures

Before production processing begins, Ledja will implement and evidence the measures applicable to the subscribed Service. Once production processing begins, Ledja’s measures include:

  • access control based on individual identity, role and least privilege;
  • multi-factor authentication and secure session controls;
  • tenant separation and tests designed to prevent cross-customer access;
  • encryption of Customer Personal Data in transit and at rest, including protection of sensitive credentials and HMRC OAuth tokens;
  • secure development, code and dependency review, controlled release and change records;
  • logging, monitoring, audit trails and incident response;
  • backup, restoration and continuity controls;
  • vulnerability assessment, penetration testing and remediation; and
  • supplier due diligence, confidentiality and access restrictions.

Ledja may update measures to reflect risk and technology, but will not materially reduce the overall security of the Service during a subscription term.

20.5 Subprocessors

The Customer gives Ledja general written authorisation to use Subprocessors needed to provide the Service. Ledja will:

  • maintain a current list available to the Customer;
  • give at least 30 days’ prior notice before an intended addition or replacement begins processing Customer Personal Data. Where urgency makes 30 days impracticable, Ledja will give as much prior notice as reasonably possible, but the Subprocessor will not begin processing before notice has been given. The Customer’s objection and termination rights below remain available;
  • impose by written contract the same data-protection obligations as apply to Ledja under this Schedule, in particular sufficient guarantees of appropriate technical and organisational measures; and
  • remain responsible to the Customer for the Subprocessor’s performance of those obligations.

The Customer may object on reasonable data-protection grounds during the notice period. The parties will work in good faith on a reasonable alternative. If none is reasonably available, either party may terminate the affected Service, and Ledja will refund prepaid fees for the unused affected period.

20.6 International transfers

Ledja will not transfer Customer Personal Data outside the United Kingdom unless the transfer is permitted by UK data-protection law. Where required, Ledja will put in place a UK International Data Transfer Agreement, UK Addendum to approved standard contractual clauses, adequacy mechanism or another lawful safeguard, carry out a proportionate transfer-risk assessment, and apply supplementary measures. Ledja will provide relevant safeguard information on reasonable request, subject to confidentiality and security restrictions.

20.7 Audits

Ledja will answer reasonable written compliance questions and provide relevant independent reports or summaries where available. If that evidence is insufficient, the Customer may audit Ledja’s compliance with this schedule no more than once in any 12-month period, or more often following a material Personal Data Breach, where the Customer reasonably suspects material non-compliance, or where a regulator requires it.

An audit must be on reasonable notice, during normal business hours, minimise disruption, protect other customers and Ledja security, and be conducted by the Customer or an independent auditor bound by confidentiality. The Customer bears its audit costs unless the audit identifies a material breach by Ledja. No audit gives access to another customer’s data, penetration-test exploit detail that would create risk, or information protected by another legal duty.

20.8 Customer obligations

The Customer will:

  • provide lawful, fair and transparent instructions and have all notices, lawful bases and permissions needed for Customer Personal Data;
  • minimise the data supplied and configure retention and access appropriately;
  • keep User and administrator permissions current;
  • assess whether the Service is suitable for any unusually sensitive processing and tell Ledja about agreed additional measures; and
  • respond to Ledja’s reasonable request to clarify an instruction that may create legal or security risk.

21. Contact

Contract and support contacts are set out in the Order Form or Service. Data-protection enquiries may be sent to [email protected]. Formal post may be sent to Ledja Ltd, 3 Royal Crescent, Cheltenham, Gloucestershire, GL50 3DA.

Privacy Terms Accessibility Security Contact Support

Ledja Ltd is registered in England and Wales under company number 13067612. Registered office: 3 Royal Crescent, Cheltenham, Gloucestershire GL50 3DA.

© 2026 Ledja Ltd and/or its licensors. All rights reserved.

Ledja™ is operated by Ledja Ltd. Ledja™ and ACCLC are trading names of Ledja Ltd and are used under licence.