Ledgen
Login

Privacy Policy

Last updated: 26 August 2026

This policy explains how personal data is handled in Ledgen, a LinkedIn content and relationship platform. It covers both the ledgen.io website and the Ledgen application, including the Ledgen browser extension.

Ledgen ("Ledgen", "we", "us", "our") is based in the United Kingdom. For any question about this policy, or to exercise your rights, contact us at hello@ledgen.io.

The most important thing in this policy. Ledgen handles personal data in two distinct roles. For your account, we are the data controller. For everything you put inside your workspace — above all the contact records you import, create or enrich — you are the data controller and we act only as your processor. Sections 2 and 3 explain what that means for you in practice.

1. Definitions

We use the terms controller, processor, personal data and data subject as they are defined in the UK GDPR and the Data Protection Act 2018. A "workspace" is the container in Ledgen that holds one customer's contacts, content and activity. Workspaces are logically separated, so one customer's workspace data is not accessible to another customer.

2. Data we control (your account)

We are the controller for the data needed to run Ledgen as a business and to give you an account.

What we holdWhyLawful basis
Your name, email address and profile pictureTo create and secure your account and to contact you about the servicePerformance of a contract
Authentication data and session recordsTo sign you in and keep the account securePerformance of a contract
Workspace and team membership recordsTo determine who may access whatPerformance of a contract
Usage and credit consumption recordsTo meter the service, bill correctly and enforce plan limitsPerformance of a contract
Technical and diagnostic records generated when the service is usedTo detect, investigate and fix faults, and to protect the service from abuseLegitimate interests — running a reliable, secure service
Messages you send us through the contact formTo answer youLegitimate interests — responding to enquiries
Waitlist entries: email, and any name, company or note you choose to giveTo assess and contact prospective customersConsent, withdrawable at any time

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that the processing is limited to what a person would reasonably expect from a business application of this kind. You may object to it at any time using the contact details above.

We do not sell personal data, and we do not use it for advertising or profiling.

3. Data we process for you (your workspace)

Everything you create or import inside a workspace is yours. This includes:

  • Contacts — names, job titles, employers, locations, social profile links, and where you have obtained them, email addresses and phone numbers. Contact records can also hold a date of birth and a gender value.
  • Activity — the record of interactions with those contacts, including message and comment text.
  • Content — posts, drafts, ideas, campaigns and media you upload.
  • Author profiles — the identity, voice and background material used to write in someone's name.
  • Pipeline and task records — deals, stages and follow-up tasks tied to contacts.

You are the controller of this data and we are your processor. We process it only on your documented instructions, which are the actions you take in the product. We do not use your workspace data for our own purposes, we do not share it with other customers, and we do not use it to train artificial-intelligence models — neither ours nor a vendor's.

Because you are the controller, some responsibilities are yours and cannot be ours:

  • Deciding, and being able to demonstrate, a lawful basis for holding each contact record. For business-to-business prospecting this is usually legitimate interests, which requires you to carry out and keep a legitimate interests assessment.
  • Giving the people in your contact list the privacy information they are entitled to, and honouring their rights when they exercise them.
  • Deciding how long to keep records, and deleting what you no longer need.
  • Taking extra care with the date of birth and gender fields. Depending on how they are used these can attract a higher standard of protection, and most prospecting use cases do not need them at all.

If someone asks us to exercise their rights over data held in your workspace, we will not act on it ourselves. We will tell them to contact you and, where we can identify the workspace, notify you promptly so you can respond.

4. Contact enrichment

Ledgen can enrich a contact record by retrieving publicly available professional information — job title, employer, location, profile summary and, on request, a business email address — from a third-party data provider. This happens only when you ask for it, contact by contact or in a batch you select.

Enrichment brings personal data about a third party into your workspace. You remain the controller of it. In particular, retrieving someone's email address so that you can contact them is processing that person is entitled to know about, and the obligation to tell them sits with you, not with us. We provide the tool; the decision to use it on a given person is yours.

5. Artificial intelligence

Ledgen uses large language models from third-party providers to draft posts, comments and messages, and to summarise content. To do this we send the material relevant to the task to the model provider over an encrypted connection.

We use these providers under their commercial API terms, which do not permit customer content to be used to train their models. We do not send more than the task requires, and we do not send your contact list in bulk.

Model output is a draft. It can be wrong, and it is presented to you for review before anything is published. Nothing in Ledgen makes an automated decision that produces legal effects concerning a person or similarly significantly affects them.

6. Sub-processors

We use third-party providers to deliver the service. Each provider that handles personal data on our behalf is engaged under terms that require it to protect that data and to process it only on our instructions and for the purpose we engaged it for. We use providers in the following categories:

  • Infrastructure — cloud hosting, database and file storage providers that run the application and hold your data.
  • Artificial intelligence — language model providers that produce the drafts and summaries described in section 5.
  • Professional data — providers that retrieve publicly available professional information when you request enrichment.
  • Social publishing — providers that publish to, and read engagement from, the social accounts you connect.
  • Payments — a payment provider that processes subscriptions and handles card details, which never reach us.
  • Communications — providers used to send transactional email such as account and service notices.

These providers are established in the United Kingdom, the European Economic Area and the United States.

We will give notice before making a material change to the providers that handle workspace data, so that you have an opportunity to object.

7. International transfers

Some of the providers described above are established in the United States, so personal data is transferred outside the United Kingdom. Those transfers are made under a safeguard recognised by UK law, such as the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK extension to the EU-US Data Privacy Framework where the provider is certified. Copies of the relevant safeguards are available on request.

8. Retention

  • Account and workspace data — kept for as long as your account is open.
  • After you ask us to delete your account — a 30-day grace period runs, during which the account can be restored. At the end of it the account is closed and access ends permanently.
  • Technical and diagnostic records — retained for a limited period, normally no more than 90 days.
  • Waitlist entries — deleted on request, and reviewed periodically so that stale entries are removed.
  • Records we must keep by law, such as accounting records, are retained for the period the law requires and no longer.

Within your workspace, retention of contact records is your decision as controller. You can delete any record at any time.

9. Support access to your account

To investigate a problem you have reported, or to complete setup work you have asked for, we may need to access your workspace as your account. This access is limited in time, recorded, and used only for the purpose you raised. We will not use it to browse your data for any other reason.

10. Cookies

Ledgen sets only strictly necessary cookies: one that keeps you signed in, and one used during a support access session. We run no analytics, no advertising tags and no third-party tracking scripts of any kind. Because these cookies are essential to a service you have asked for, no consent banner is required. Blocking them in your browser will prevent you signing in.

11. Security

Data is encrypted in transit and at rest, workspaces are logically separated, and access to production systems is restricted to those who need it. We keep these measures under review and may change them as the service develops. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay, and the Information Commissioner's Office where the law requires it.

12. Your rights

In relation to the data we control, you have the right to access it, to have it corrected, to have it erased, to restrict or object to how we process it, to receive it in a portable format, and to withdraw consent where consent is the basis we rely on. To exercise any of these, write to hello@ledgen.io. We will respond within one month, and will tell you if we need longer, as the law allows where a request is complex or where several have been made.

If you are unhappy with how we have handled your data you may complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first so we can put it right.

13. Children

Ledgen is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version. Where a change materially affects how we handle your data we will tell you directly rather than relying on you to notice.

15. Contact

Ledgen
Email: hello@ledgen.io