Who we are
LedgerBPO is the accounting and billing division of SS Support Network LLC, a business process outsourcing company registered in Vancouver, Washington, USA. We also operate a second office in Pakistan. In this policy, “we”, “us” and “our” mean SS Support Network LLC, including the LedgerBPO division.
This policy explains what personal information we collect through ledgerbpo.com, how we use it, who we share it with, and the rights you have. It applies to website visitors, people who contact us, prospective and current clients, and job applicants.
When we process personal information inside a client’s systems on the client’s instructions, the client is the controller and we act as a processor or service provider. That work is governed by the client’s contract and our data processing agreement, summarized on our DPA page. This policy covers the information we control ourselves.
Information we collect
We collect information in three ways: you give it to us, we collect it automatically, or a client gives it to us as part of an engagement.
Information you give us includes your name, work email, phone number, company name, country, the software you use, approximate transaction or invoice volumes, and anything you type into a form, email or chat. If you book a call, we receive the booking details you enter. If you apply for a job, we receive your CV, work history and contact details.
Information we collect automatically includes your IP address, device and browser type, pages viewed, referring page, approximate location derived from IP, and interaction data such as clicks and scroll depth. Some of this is collected by the analytics and advertising tools described in the cookies section, and only after you consent where consent is required.
Information a client gives us includes the names and contact details of the client’s staff, and any personal information contained in the financial records we work on, such as customer names on invoices, vendor details, employee payroll data, or patient details in healthcare billing. We process that information only as instructed by the client.
Our calculators and estimating tools run in your browser. The figures you enter are not sent to us; only the details you type into a quote or contact form are transmitted.
How we use information and our lawful bases
We use personal information to respond to enquiries and quote requests, to set up and deliver services under a contract, to send service communications, to run and improve the website, to measure marketing, to recruit staff, to meet legal and accounting obligations, and to protect our systems and rights.
Where UK GDPR or EU GDPR applies, we rely on the following lawful bases. Performance of a contract, or steps before entering one, covers quotes, onboarding and service delivery. Legitimate interests cover website security, basic analytics, business-to-business marketing to work contacts, and record keeping, balanced against your rights. Consent covers non-essential cookies, advertising tags and marketing emails to individuals where consent is required. Legal obligation covers tax, accounting, anti-fraud and regulatory record keeping.
We do not use personal information for automated decisions that produce legal or similarly significant effects. We do not sell personal information.
Cookies and consent
We use Google Tag Manager to load measurement tags. Google Analytics 4 measures site usage. Microsoft Clarity records anonymized session interactions such as clicks and scrolling. The LinkedIn Insight Tag and the Meta Pixel measure the results of our advertising and may be used to build audiences.
Analytics and advertising tags load only after you accept them in our consent banner, in every region where consent is required. Strictly necessary cookies, such as the one that remembers your consent choice, load without consent. You can change or withdraw your choice at any time using the cookie settings link in the footer. Where your browser sends a Global Privacy Control signal, we treat it as an opt-out of sharing for cross-context behavioral advertising.
Each tool has its own privacy documentation and retention settings. Our Google Analytics 4 data retention is set to 14 months.
Who we share information with
We share personal information with the people and companies that help us run the business, and only to the extent needed.
Our staff in the United States and at our second office in Pakistan access information to deliver services and answer enquiries. Access is limited to the people assigned to your account.
Our affiliates SS Support Network (healthcare BPO) and TransportBPO (ground-transportation BPO) share management, systems and staff with LedgerBPO, and may access information for the same purposes described here.
Service providers host our website, store email and documents, run our CRM, handle call booking and forms, and deliver analytics and advertising tools (Hostinger for hosting; Google Analytics 4, Google Tag Manager and Microsoft Clarity for analytics; Calendly for call booking; Cloudflare Turnstile for form protection; and our business email and document-storage providers, listed in the sub-processor schedule available on request). Each is bound by contract to use information only for the services it provides to us.
Professional advisers, insurers, regulators, courts and law enforcement receive information where the law requires it or where we need to establish or defend legal claims. If the business is sold or restructured, information may transfer to the new owner under the same protections.
International transfers
We are based in the United States and operate a second office in Pakistan. Information from the UK, the EU, Canada and Australia is therefore transferred to and processed in those two countries.
For transfers from the UK, we use the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. For transfers from the EU, we use the EU Standard Contractual Clauses with the same assessment. Copies are available on request.
For information from Australia, we disclose personal information to our second office in Pakistan and to US service providers under Australian Privacy Principle 8. We take reasonable steps, including contractual terms and the security measures below, so that recipients handle information in line with the Australian Privacy Principles.
For information from Canada, we remain accountable under PIPEDA for information transferred to our offices and providers outside Canada, and we use contractual protections to achieve a comparable level of protection. For information from Quebec, we carry out a privacy impact assessment before transferring information outside Quebec, as required by Law 25, and we have designated a person in charge of the protection of personal information: our Chief Operating Officer, reachable at privacy@ledgerbpo.com.
How long we keep information
Enquiry and quote records are kept for 24 months after our last contact, unless you become a client. Client account records are kept for the life of the contract and then for the period required by tax and accounting law, which is typically seven years in the US and six years in the UK. Client financial data processed on the client’s instructions is returned or deleted at the end of the engagement in line with the DPA.
Job applications are kept for 12 months after the role closes unless you ask us to keep them longer. Analytics data is kept according to each tool’s retention setting. Backups are overwritten on a rolling schedule (30 days).
How we protect information
We apply the same controls to our own systems that we apply to client work. Multi-factor authentication is required on every account. Access follows least privilege, with staff seeing only the accounts assigned to them, and access is logged. Data is encrypted in transit and at rest. Staff work on managed devices with no local downloads of client data. All staff are background checked, trained in confidentiality and, for healthcare work, HIPAA trained. We sign an NDA for each client and a business associate agreement for US healthcare clients. We maintain an incident response plan and test it.
No method of transmission or storage is completely secure. If a breach affects your information and the law requires notice, we will notify you and the relevant regulator within the required timeframe.
Your rights
You can ask us for a copy of your personal information, ask us to correct it, ask us to delete it, object to or restrict certain processing, ask for a portable copy, and withdraw consent where processing relies on consent. We will respond within the time the applicable law allows, usually one month, and we may ask for proof of identity first. We will not treat you differently for exercising your rights.
United States
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and how we use and share it, to delete it, to correct it, to opt out of sale or sharing, to limit the use of sensitive personal information, and to be free from discrimination. We do not sell personal information. Advertising tags may count as “sharing” under California law; you can opt out through the cookie settings link or a Global Privacy Control signal. Residents of other states with privacy laws have comparable rights, and you can use the contact below to exercise them. You may appoint an authorized agent to act for you.
United Kingdom and European Union
Under UK GDPR and EU GDPR you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent. You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner’s Office at ico.org.uk. In the EU, it is the authority in the member state where you live or work. We would rather hear from you first so we can put things right. Where Article 27 requires a representative in the UK or the EU, the contact details are provided on request from privacy@ledgerbpo.com.
Canada
Under PIPEDA you can ask what personal information we hold about you, how it is used and who it has been disclosed to, and ask for corrections. You can complain to the Office of the Privacy Commissioner of Canada. In Quebec, Law 25 gives you additional rights, including to know when information is transferred outside Quebec, and you can complain to the Commission d’accès à l’information.
Australia
Under the Privacy Act 1988 and the Australian Privacy Principles you can ask for access to and correction of your personal information. If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner. We are subject to the Notifiable Data Breaches scheme for Australian information we hold.
Children
Our website and services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We review this policy at least once a year and whenever our practices or the law change. The date at the top shows the latest version. Material changes will be flagged on the website, and where required we will ask for your consent again.
Contact
Privacy questions, rights requests and complaints: privacy@ledgerbpo.com. Phone: +1-657-777-0006. Post: SS Support Network LLC, Vancouver, Washington, USA.