LEGAL

Privacy Policy

Last updated 21 July 2026Celestial Software LLC

Template pending review by counsel. This document is a working draft prepared for a pre-launch product. It has not been reviewed by an attorney, is not legal advice, and should not be relied on as a final policy. If your procurement or privacy review needs the executed version, ask us for it.

1Who this covers

This policy explains how Celestial Software LLC (“Celestial Software”, “we”, “us”) handles information in connection with LedgerLock, our vendor-invoice audit service, and this website.

It covers two audiences with different relationships to us: visitors to this site and people who hold LedgerLock accounts, whose information we handle as a controller; and the organizations whose documents are processed in the service, whose information we handle as a processor on their instruction.

2Two kinds of data

Account Data is information about you and your organization as our customer: names, work email addresses, organization name, role assignments, authentication records, billing details, support correspondence, and technical logs generated when you use the product.

Customer Data is what you upload for auditing: invoices, contracts and rate sheets, purchase orders, work orders, field tickets, timesheets, receipts, approvals, and vendor records. Customer Data belongs to your organization. We process it to run audits for you, on your instruction, and for no independent purpose of our own.

Customer Data is business documentation, but it can contain personal information incidentally — a driver's name on a field ticket, an approver's email address. We treat that information with the same protection as the rest of the document.

3What we collect and why

Account and identity information, to create your account, authenticate you, apply your role's permissions, and communicate with you about the service. Authentication is handled by our identity provider; we do not store your password.

Billing information, to charge for subscriptions and pilot success fees. Card details are handled by our payment processor and are not stored on our systems.

Usage and device logs — pages requested, actions taken, timestamps, IP address, browser and device type — to operate the service, investigate errors, and detect abuse.

Documents and records you upload, to perform the audit you have asked for, produce findings and evidence citations, and maintain your audit history.

Messages you send us, to answer them.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

4We do not train models on your data

Customer Data is never used to train, fine-tune, or evaluate machine-learning models, whether ours or a third party's. There is no opt-out setting because there is no such use to opt out of.

Where the service uses AI to read a document or explain a finding, it processes your data to answer your question in that moment. Our AI subprocessors are engaged under terms that prohibit training on data we send them.

5Cookies and analytics

We use cookies that are strictly necessary to sign you in and keep your session secure. These cannot be turned off without breaking authentication.

We use privacy-respecting product analytics to understand which features are used and where the product fails. We do not run advertising trackers, and we do not build advertising profiles of visitors to this site.

6Who else touches the data

We rely on a small set of subprocessors to run LedgerLock: application hosting and content delivery, a managed Postgres database, object storage for uploaded documents, an identity provider for authentication, a payment processor, an email provider for transactional messages, and AI providers for document reading and drafting.

Each is bound by contract to protect the data, to process it only on our instruction, and — for AI providers — not to train on it. We will provide the current list of subprocessors, naming each and its role, on request.

We disclose information otherwise only where required by law or valid legal process, where necessary to protect rights and safety, or in connection with a merger or sale of assets, in which case the acquirer remains bound by this policy or gives notice before changing it.

7Security

Data is encrypted in transit over TLS and at rest by our underlying platforms. Uploaded documents are stored privately and are never publicly addressable; they are served only to an authenticated member of the owning organization, through short-lived links that expire.

Every organization's records are scoped to that organization at every query. Access within an organization is governed by role-based permissions across seven roles. Meaningful actions are written to an append-only, hash-chained audit log that cannot be edited or deleted afterwards.

No system is perfectly secure. Our security practices, including an honest account of what we have and have not certified, are described in full on our security page, linked below.

8How long we keep it

Customer Data is retained for as long as your account is active, or for a retention period you specify. Account Data is retained while your account is active and for a reasonable period afterwards for legal, tax, and accounting purposes. Usage logs are retained on a rolling basis for operations and security.

Audit-log entries are append-only by design and are retained for the life of the account so that a past approval remains provable. They are deleted with the account.

9Deletion and your rights

You may request deletion of Customer Data at any time. Deletion removes the stored objects, not merely a database flag, and propagates to backups on our platforms' standard backup rotation. Tell us what to keep and for how long, and that is what we will do.

Depending on where you live you may have rights to access, correct, delete, or receive a portable copy of personal information we hold about you, to object to or restrict certain processing, and to withdraw consent. Email privacy@ledgerlock.co and we will respond within the period applicable law requires.

Where we hold personal information as a processor on behalf of a customer organization, we will refer your request to that organization and support them in answering it.

We will never charge you for making a request, and we will not treat you differently for exercising a right.

10International transfers and children

LedgerLock is operated from the United States and data is processed there. If you access the service from elsewhere, you are transferring information to the United States, and we rely on appropriate safeguards where required for such transfers.

LedgerLock is a business product and is not directed to children. We do not knowingly collect personal information from anyone under 16, and we will delete it if we learn we have.

11Changes and contact

We may update this policy. Material changes will be notified by email or in the product before they take effect, and the “Last updated” date above will change.

Celestial Software LLC — privacy@ledgerlock.co for privacy requests, security@ledgerlock.co for security reports.

See also the Terms of Service and our security practices.