Privacy Policy
Last updated: June 2026
1. Who we are
Yali Shimon Reichental (ABN 94 634 739 186), trading as Suki Systems, operates Ledgerly at ledgerlyaccountancy.com. We build automation tools that help small businesses collect, organize, and send their financial documents to their accountants.
Business address: 2a Cable Close, Esperance WA 6450, Australia.
Contact us at gil@suki-systems.com or yali@suki-systems.com.
2. What data we collect
We collect the following categories of personal information:
- Identifiers (CCPA category): your email address and name when you create an account.
- Business information: your business name and VAT/tax identification number. Tax identification numbers are treated as sensitive information under Israeli law and are collected only because they are necessary to provide the service.
- Accountant details: your accountant's name and email address, which you enter during onboarding.
- Commercial information (CCPA category): invoice data — vendor name, invoice date, amount, VAT, and invoice number — extracted from your supplier invoices.
- Original invoice files: PDF and image files of your invoices, stored privately in a secure storage bucket accessible only to your account, retained for as long as your account is active so they can be included in your accountant reports.
- Internet or electronic network activity (CCPA category): Credentials for the accounts you connect, all encrypted at rest (AES-256-GCM): OAuth tokens (Gmail, Outlook), IMAP server credentials (host, username, and password) if you connect a generic mailbox, API credentials for invoicing/payment platforms you connect (Morning/Green Invoice API key and secret, Stripe restricted API key, iCount company ID and login), and your WhatsApp phone number.
Providing your business name, VAT number, and accountant details is voluntary but necessary to use the service. Without this information, the service cannot function.
3. Legal basis for processing
We process your personal information on the following legal bases:
- Performance of contract: to provide the Ledgerly bookkeeping service you signed up for.
- Legal obligation: to comply with applicable tax record-keeping requirements in your jurisdiction.
- Legitimate interests: to improve service reliability and security.
- Consent: where required by applicable law, we will obtain your explicit consent before processing sensitive information.
4. How we use Gmail access
When you connect your Gmail account, we request read-only access to your inbox (the gmail.readonly scope only). We do not request access to send mail, modify messages, access contacts, or any other Gmail function. Here is exactly how we use it:
- We scan your inbox for emails that contain financial attachments (PDF invoices, receipts, credit notes).
- We download and analyse only those attachments. Email body text and unrelated emails are never stored.
- We extract structured data: vendor name, date, total amount, VAT amount, and invoice number. The original file is stored in a private storage bucket accessible only to your account, so it can be included in your accountant package.
- We never read, store, or process your personal emails, drafts, sent mail, or any email that does not contain a financial document.
- No human access: no Ledgerly employee or contractor reads or accesses your Gmail-derived data. All processing is fully automated.
- Invoice content extracted from Gmail attachments is sent to Anthropic's API solely to perform structured data extraction on your behalf. Anthropic acts as a sub-processor that delivers this feature under a Data Processing Agreement, does not train on API data, and does not retain your data after processing.
- We do not sell or share your Gmail data with any third party for advertising, profiling, or any commercial purpose. Gmail-derived data is retained only for as long as your account is active.
Ledgerly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4a. How we use Outlook and IMAP access
When you connect a Microsoft Outlook account, we request read-only mailbox access (the Microsoft Graph Mail.Read permission only). We never send, modify, or delete email. Outlook data is processed exactly like Gmail data as described in Section 4 — attachment scanning, automated extraction, no human access, no advertising use — and our use complies with the Microsoft APIs Terms of Use and the Microsoft Services Agreement.
If you connect a generic mailbox via IMAP, you provide your mail server address, username, and password. These credentials are encrypted at rest (AES-256-GCM) and used only to read your inbox for financial documents in the same read-only manner.
4b. Invoicing and payment platforms
When you connect an invoicing or payment platform (Morning/Green Invoice, Stripe, or iCount), you provide API credentials which we store encrypted at rest. We use them solely to read the invoices you issued so they can appear in your books; we never create, modify, or delete anything in those platforms.
5. How we use WhatsApp access
When you connect your WhatsApp Business number, we use the official Meta Cloud API to receive incoming messages on your behalf. We store the WhatsApp phone number you register so we can match incoming documents to your account.
- We monitor your incoming messages for PDF or image attachments that appear to be supplier invoices.
- Personal messages and non-financial attachments are never stored or processed.
- Attachment content is sent to Anthropic's API solely to extract invoice data. Anthropic does not retain or train on this data. The original file may be stored in your private storage bucket so it can be included in your accountant reports.
- WhatsApp message data is routed through Meta's Cloud API infrastructure in the United States. See Section 7 for cross-border transfer safeguards.
- You can disconnect your WhatsApp at any time from the Connectors page.
6. How we store your data
- All data is stored on Supabase (PostgreSQL), hosted in the EU (Frankfurt region).
- OAuth tokens and API keys are encrypted at rest using AES-256-GCM before being written to the database.
- Invoice files are stored in a private Supabase Storage bucket. Signed URLs are minted on demand and expire after a short period.
- Access to your data is protected by Row Level Security (RLS) — only your own account can read your records.
- We maintain a written security policy and access logs. An Information Security Officer at Suki Systems is responsible for data protection compliance.
7. International data transfers
We use third-party services that process data outside your country. We have implemented appropriate safeguards for each transfer:
- Supabase (EU — Frankfurt): data is hosted in Germany under a Data Processing Agreement that includes Standard Contractual Clauses, providing protections equivalent to the Australian Privacy Principles and Israeli data protection law.
- Anthropic, Inc. (USA): invoice document content is sent to Anthropic for structured data extraction under a Data Processing Agreement. Anthropic does not train on API data and does not retain your data after processing.
- Meta Platforms (USA): if you connect WhatsApp, messages are routed through Meta's Cloud API infrastructure in the United States. Meta processes this data under its own terms of service and privacy policy.
- Vercel (USA): application hosting. Vercel processes request data under a Data Processing Agreement.
- Google LLC (USA): sign-in with Google and, if you connect Gmail, the Gmail API. Google processes this data under its own terms and privacy policy.
- Microsoft Corporation (USA): if you connect Outlook, mailbox access via the Microsoft Graph API. Microsoft processes this data under its own terms and privacy policy.
For Australian users (APP 8): transfers to Anthropic, Supabase, and Vercel are conducted under contractual arrangements that impose privacy obligations substantially similar to the Australian Privacy Principles.
For Israeli users: cross-border transfers to Anthropic (USA) are conducted under a contractual framework ensuring your data is protected in accordance with the Israeli Privacy Protection Law 5741-1981.
8. Data sharing
We do not sell, trade, or share your personal data or financial data with any third party, except:
- Your accountant: when you click "Send to accountant", we send a report to the accountant email address you provided. You control when and whether this happens.
- Infrastructure providers: Supabase (database and storage) and Vercel (hosting) — both under strict data processing agreements.
- AI processing: invoice document content is sent to Anthropic's API for structured data extraction under a Data Processing Agreement. Anthropic does not train on API data. No personal account information is included in API calls.
- Data sources you connect: Google (Gmail), Microsoft (Outlook), Meta (WhatsApp), and the invoicing platforms you link (Morning/Green Invoice, Stripe, iCount) each receive the API requests necessary to read your data at your instruction. We only ever read from these services.
We do not sell or share personal information as defined under the California Consumer Privacy Act (CCPA/CPRA). California residents may submit a "Do Not Sell or Share" request to us, though we do not engage in these activities. We will not discriminate against you for exercising your privacy rights.
9. Your rights and controls
You have the following rights under applicable privacy law, including the Israeli Privacy Protection Law 5741-1981, the Australian Privacy Act 1988 (APPs 12 and 13), and the California Consumer Privacy Act (CCPA/CPRA):
- Access your data: request a copy of all personal information we hold about you.
- Correct your data: request correction of inaccurate, out-of-date, or incomplete information.
- Export your data: we will provide a CSV export of all your extracted invoice records.
- Delete your account: email us and we will delete all your data within 30 days, subject to the tax retention requirements in Section 10.
- Object to direct marketing: we do not use your data for marketing. You have the right to object if this changes.
- Revoke Gmail access: go to myaccount.google.com/permissions and remove Ledgerly. We will stop syncing immediately.
- Disconnect any source: from the Connectors page inside the Ledgerly app at any time.
To verify your identity before processing a privacy request, we will ask you to confirm details associated with your account. We will respond to verified requests within 45 days (extendable to 90 days with notice where permitted by law).
Australian users — complaints: if you have a privacy concern, email us at gil@suki-systems.com with "Privacy Complaint" in the subject line. We will acknowledge within 5 business days and resolve within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. Data retention
We retain your invoice data and files for as long as your account is active. If you delete your account, all data is permanently deleted within 30 days.
Tax retention exception: invoice records may be retained for longer periods to comply with statutory tax record-keeping requirements: up to 7 years under Israeli VAT Law (Section 25, Value Added Tax Law 5736-1975) for Israeli users; up to 5 years under the Taxation Administration Act 1953 for Australian users; and up to 7 years under IRS guidance for US users. During any extended retention period, data access is restricted to legal compliance purposes only.
11. Data breaches
In the event of a data breach affecting your personal information, we will notify you and relevant regulatory authorities as required by applicable law within the timeframes those laws specify.
For Australian users: Suki Systems complies with Australia's Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. In the event of an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
12. Cookies
We use session cookies only for authentication — to keep you signed in. These cookies are strictly necessary for the service to function and do not require separate consent. We do not use advertising cookies or third-party tracking cookies.
13. Changes to this policy
If we make material changes to this policy, we will notify you by email and update the "Last updated" date at the top of this page at least 30 days before changes take effect.
14. Contact
Questions about this policy or to exercise your privacy rights? Email us at gil@suki-systems.com or yali@suki-systems.com.
Information Security Officer: gil@suki-systems.com