Effective date: 1 May 2026
1 · Introduction
This Privacy Policy is issued by LDGERS House Consultancy L.L.C., the Dubai-incorporated operator of the LDGERS platform and provider of hospitality finance and platform services. It explains how we handle personal data when individuals interact with our services.
LDGERS House Consultancy L.L.C. (“House of LDGERS”, “we”, “our” or “us”) is the data controller responsible for personal data processed through the LDGERS platform, our websites and our finance-function services. We are committed to handling personal data lawfully, transparently and securely.
By accessing the LDGERS platform, our websites, or by engaging us for finance-function services, you confirm that you have read and understood this Privacy Policy.
2 · Scope and applicability
This Privacy Policy applies to personal data processed in connection with:
- The LDGERS platform and its modules — CashUp, Procure, PayDesk, Insights and Finance Hub;
- Our websites and marketing properties, including ldgers.com and any sub-domains;
- Our finance-function services delivered to client entities; and
- Communications with prospects, clients, employees of clients, vendors, candidates and visitors — by email, phone, messaging, ticketing or in person.
It does not apply to third-party websites or applications linked from our properties, nor to data processed by clients in their own systems outside the LDGERS platform.
3 · Definitions
- House of LDGERS / we / our / us — LDGERS House Consultancy L.L.C., the Dubai-incorporated entity that operates the LDGERS platform and provides finance-function services.
- Platform — the LDGERS software platform and its modules, together with our websites, dashboards, mobile and web applications, and supporting tooling.
- Personal Data — any information relating to an identified or identifiable natural person, as defined under applicable law.
- Processing — any operation performed on personal data: collection, storage, use, disclosure, transfer or deletion.
- User / you — any individual who accesses the Platform or interacts with our services, including clients, their employees, vendors, candidates and visitors.
- Client — a legal entity that has engaged House of LDGERS for finance-function services or platform access.
- Sub-processor — a third party engaged by House of LDGERS to process personal data on our behalf.
4 · Information we collect
We collect and process the following categories of personal data:
Identity and contact data. Name, email address, phone number, job title, employer and similar identifiers required to engage with the Platform or our services.
Account and access data. Login credentials (managed via single sign-on where applicable), system roles, permissions, access logs, IP address, session identifiers and audit trails.
Business and financial data. Supplier invoices, payment instructions, bank file metadata, sales reconciliation records, expense documents, and any business or financial documentation uploaded to the Platform or shared with our finance team for the purpose of delivering services.
Technical data. Device information, browser type, operating system, language settings, time-zone, referring URL, and cookies and similar identifiers — see Section 13.
Communication data. Messages, emails, support tickets, call logs, transcripts of meetings where lawfully recorded with notice, and feedback or survey responses.
Recruitment data. Where you apply for a role with House of LDGERS, we process CV data, employment history, references and assessment results for the purpose of evaluating your application.
We do not intentionally collect special-category data such as health, religion, political opinions or biometric identifiers. If such data is ever required for a specific lawful purpose, it will be processed only with explicit consent and under strict access controls.
5 · How we collect personal data
- Directly from you — when you register, log in, submit documents, raise a support ticket, attend an event, or otherwise interact with our services.
- From your employer — where your employer is our client and grants you access to the Platform on its behalf.
- From integrated systems — where your organisation authorises connections between the Platform and third-party tools (e.g. Xero, point-of-sale systems, reservation systems, banking portals).
- Automatically — through cookies, server logs and analytics when you use the Platform or our websites.
- From public or authorised sources — such as commercial registries, sanctions and PEP screening databases, and professional networks, in the context of due diligence and recruitment.
6 · How we use your information
We use personal data only for the purposes set out below:
- To provide access to the Platform and to authenticate users;
- To deliver our finance-function services — including accounts payable, accounts receivable, reconciliations, and management reporting;
- To operate and secure the Platform, including monitoring, logging, intrusion detection and incident response;
- To communicate with you on service matters, releases, planned maintenance, security alerts and policy updates;
- To support and improve our services, including diagnosing issues and analysing usage patterns in aggregate;
- To comply with legal, tax, regulatory and audit obligations, including anti-money-laundering, counter-terrorism financing and statutory recordkeeping;
- To respond to enquiries, complaints and requests from data subjects and authorities; and
- To manage recruitment and assess applicants for roles with the group.
We do not use personal data for automated decision-making with legal or similarly significant effects. We do not sell personal data. We do not profile data subjects for advertising purposes.
7 · Legal bases for processing
We process personal data only where we have a valid legal basis to do so under applicable law. The principal bases on which we rely are:
- Contractual necessity — to provide the Platform and finance-function services to our clients and their authorised users.
- Legal obligation — to meet AML/CTF, tax, statutory and other obligations in the UAE and other relevant jurisdictions.
- Legitimate interests — to operate, secure and improve our services; to protect the group, our clients and our users from fraud and misuse; and to manage internal administration. Where we rely on legitimate interests, we balance them against your rights and freedoms.
- Consent — for specific, optional uses such as marketing communications, certain device permissions (e.g. camera or location) and optional cookies. Consent can be withdrawn at any time without affecting prior lawful processing.
- Public interest / vital interests — in limited circumstances such as cooperation with regulatory or law-enforcement authorities, or to protect the vital interests of an individual.
8 · Data sharing and sub-processors
We do not sell personal data, and we do not share personal data with third parties for their own marketing purposes. We share personal data only as set out in this section.
Within our operations. Personal data may be accessed by our operations team based in Ahmedabad, India, who provide back-office finance and technical support to LDGERS House Consultancy L.L.C. Access is strictly on a need-to-know basis, governed by the same access controls, confidentiality obligations and information-security standards that apply within the Dubai entity. The Dubai entity remains the controller and retains full responsibility for the personal data processed.
Authorised sub-processors. We engage a limited set of trusted technology providers as sub-processors. The current list includes:
- Amazon Web Services, Inc. — cloud hosting and infrastructure for the LDGERS platform (UAE / EU).
- Microsoft Corporation — Microsoft 365, SharePoint, OneDrive, Teams (EU / UAE / global).
- Zoho Corporation — Zoho People (HR records), Zoho Payroll (India / UAE).
- Xero Limited — general ledger and bookkeeping (EU / global).
- OCREX Limited (AutoEntry) — invoice and receipt scanning (EU).
- Freshworks Inc. (Freshdesk) — client-facing support and ticketing (EU / global).
- ClickUp (Mango Technologies, Inc.) — internal task management (US / global).
All sub-processors are bound by written contracts requiring them to process personal data only on our documented instructions and to maintain appropriate technical and organisational security measures. The list is reviewed periodically and updated as our service stack evolves.
Disclosures required by law. We may disclose personal data where we are required to do so by law, by a binding order of a competent court, or in response to a lawful request by a regulatory or law-enforcement authority — including, in the UAE, the UAE Financial Intelligence Unit (UAEFIU) and the Ministry of Economy.
Disclosures in corporate transactions. In the event of a merger, acquisition, restructuring or sale of all or part of our business, personal data may be transferred to the relevant counterparty as part of due diligence and completion. Any such transfer will be subject to confidentiality obligations and applicable law.
9 · International transfers
Personal data may be transferred from the United Arab Emirates to India, where our operations team provides back-office support, and to sub-processors located in other jurisdictions as listed in Section 8. Where data is transferred outside the country in which it was collected, we ensure that an adequate level of protection is in place. Our transfer safeguards include:
- Standard Contractual Clauses with sub-processors and intra-group recipients, where required by applicable law;
- Encryption in transit for all personal data crossing jurisdictions;
- Access controls that restrict access based on role and need-to-know; and
- Group-wide policies applying consistent privacy and security standards to operations in both Dubai and Ahmedabad.
10 · Data security
We apply technical and organisational measures designed to protect personal data, including:
- Encryption of personal data in transit and at rest, using industry-standard protocols;
- Multi-factor authentication for access to the Platform and to the systems used to deliver our services;
- Role-based access control, with permissions granted on a least-privilege basis;
- Logging and monitoring of access to personal data, with audit trails retained for the periods required by law;
- Regular security reviews and testing, including vulnerability assessments and penetration testing; and
- Incident response procedures covering detection, containment, notification and remediation of personal data breaches.
No method of transmission or storage is fully secure. While we apply controls proportionate to the sensitivity of the data, we cannot guarantee absolute security. We will notify affected data subjects and supervisory authorities of personal data breaches within the timeframes required by applicable law.
11 · Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including:
- Active client records — for the duration of the engagement and as needed thereafter for transition or run-off;
- Financial and statutory records — retained for the periods required by UAE tax and statutory law (typically a minimum of five years from the end of the relevant financial year);
- AML/CTF records — retained for at least five years following the end of the client relationship, in line with UAE regulatory requirements;
- Recruitment data — retained only for as long as required to evaluate the application, and thereafter only with the candidate’s consent for future opportunities; and
- System logs and audit trails — retained for periods consistent with security and compliance obligations.
When personal data is no longer required for a lawful purpose, we either anonymise it or securely delete it.
12 · Your rights
Depending on the data protection law that applies to you, you may have rights in relation to your personal data. We honour these rights regardless of where you are located, subject to the conditions and exemptions of the applicable law.
Rights recognised across regimes:
- Right of access — to obtain confirmation of whether we process your personal data and a copy of that data;
- Right to rectification — to have inaccurate or incomplete data corrected;
- Right to erasure — to have personal data deleted, where the legal basis no longer applies;
- Right to restrict or object to processing — in specified circumstances;
- Right to data portability — to receive your data in a structured, commonly used format;
- Right to withdraw consent — where processing is based on consent, without affecting the lawfulness of prior processing; and
- Right to lodge a complaint — with the supervisory authority of your jurisdiction.
United Arab Emirates — Federal PDPL. In the UAE, the processing of personal data by LDGERS House Consultancy L.L.C. is governed by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”) and its implementing regulations. The PDPL gives you rights of access, correction, erasure, restriction, objection and portability, broadly equivalent to those above. The supervisory authority is the UAE Data Office.
EU / EEA / UK — GDPR. If you are located in the European Economic Area or the United Kingdom, your rights are set out in the EU General Data Protection Regulation and the UK GDPR. You may lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement.
How to exercise your rights. To exercise any of the rights above, contact privacy@ldgers.com. We may need to verify your identity before responding. We will respond within the timeframes required by applicable law and in any event without undue delay.
13 · Cookies and analytics
We use cookies and similar technologies on our websites and within the Platform to:
- Maintain authenticated sessions and remember your preferences;
- Measure performance, error rates and aggregate usage patterns; and
- Improve user experience and dashboard interactions.
Where required, we obtain consent before setting non-essential cookies, and you may adjust your preferences through your browser settings or any cookie banner we present. Disabling certain cookies may limit functionality. We do not use third-party advertising cookies, and we do not allow analytics tools to combine data collected on our properties with data collected elsewhere for marketing purposes.
14 · Device permissions
The Platform may request limited device permissions for specific operational features — such as access to a device camera for invoice scanning, or location for site-based check-in where required by a client policy. We request such permissions only for the specific feature concerned, use the data only during the active session unless explicitly stated otherwise, and do not use device permissions for advertising, profiling or background tracking. You can decline or withdraw permissions through your device settings, though some features may then be unavailable.
15 · Marketing and communications
We may send service communications relating to onboarding, training, releases, security, billing and policy changes — these are necessary for the operation of the service and are not marketing.
For non-essential marketing communications such as newsletters, event invitations and product announcements, we rely on consent or, where permitted, on legitimate interests in respect of existing business contacts. You can opt out at any time using the unsubscribe link in our emails or by writing to privacy@ldgers.com.
16 · Children’s privacy
The Platform and our services are not intended for individuals under the age of 18, and we do not knowingly collect personal data from children. If you become aware that a child has provided personal data to us, please contact privacy@ldgers.com and we will take appropriate steps to delete it.
17 · Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, our services or our processing activities. The current version will always be available on our website. Material changes will be communicated through the Platform, by email, or by other appropriate means before they take effect.
18 · Contact and complaints
For questions, requests or concerns about this Privacy Policy, or to exercise any of your rights, contact us at privacy@ldgers.com, or write to the Privacy Office at LDGERS House Consultancy L.L.C., Dubai, United Arab Emirates.
If you are not satisfied with our response, you may lodge a complaint with the supervisory authority of your jurisdiction — including the UAE Data Office or the relevant EU / EEA / UK supervisory authority, as applicable.