Privacy Policy
Last updated: August 20, 2026
Please also read our Terms of Use and our Data & Compliance statement.
PrimeLedger Consultancy FZCO ("PrimeLedger", "we", "us", "our") operates the website at primeledgerconsultancy.com and the PrimeLedger Private client portal. This policy explains what personal data we collect, why we collect it, who processes it on our behalf, how long we keep it, and the rights available to you.
We have written this policy to be read rather than skimmed past. If anything in it is unclear, or you want to know specifically what we hold about you, contact us using the details at the end and we will answer plainly.
1. Summary
The short version, with the detail in the sections that follow:
| Question | Answer |
|---|---|
| Do you sell my data? | No. We do not sell, rent or trade personal data to anyone. |
| Do you use advertising trackers? | No. There are no third-party advertising or cross-site tracking cookies on this website. |
| Can your staff read my portal entries? | Your entries are scoped to your own account and are not browsed by us in the ordinary course. See section 8 for the limited exceptions. |
| Do you keep documents I upload? | No. They are parsed in memory and discarded; only figures you confirm are saved. |
| Is my data sent outside the UAE? | Yes — our infrastructure providers operate internationally. See section 9. |
| How do I delete everything? | Ask us, or delete entries yourself in the portal. See section 11. |
2. Scope of This Policy
This policy covers:
- the public website, including the free calculators, downloads, blog and contact form;
- the PrimeLedger Private portal; and
- our AI assistants, PRIMA (public site) and MATRIX (inside the portal).
It does not cover third-party websites we link to, or the separate terms of any professional engagement you may enter into with us. Where we act for you under a signed engagement, that engagement letter governs the handling of your engagement records and prevails over this policy to the extent of any conflict.
Using this website or the portal does not by itself create a client, advisory or other professional relationship between you and PrimeLedger.
3. Who Is Responsible for Your Data
PrimeLedger Consultancy FZCO is the controller of the personal data described in this policy. Our registered address is IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates. Privacy enquiries can be directed to info@primeledgerconsultancy.com.
4. Personal Data We Collect
4.1 Information you provide directly
- Contact form. Your name, email address, phone number (if given) and the content of your message.
- Portal account. Your name and email address, collected and held through our authentication provider, Clerk. Where you sign in through a third-party identity provider, we receive only the basic profile information that provider releases. We never receive or store your password.
- Information you record in the portal. Any financial information you choose to enter — assets, liabilities, income and expense entries, tax profile details, budgets and financial goals.
- Documents you upload. Files submitted for automatic extraction, such as bank, credit card, loan or mortgage statements. See section 7.
- Correspondence. Emails and messages you send us, and our replies.
4.2 Information collected automatically
- Interface preferences. Your chosen language, theme and similar settings, stored in your browser's local storage on your own device.
- Technical and security data. Standard request data handled by our hosting provider and our own protective measures — IP address, user agent, requested URL, timestamps and referring page — used for delivering the page, rate limiting, abuse prevention and diagnosing faults.
- Authentication session data. Session cookies set by Clerk so you stay signed in.
4.3 What we ask you not to send us
Please do not submit passwords, full card numbers, or unnecessary copies of identification documents through the contact form or the AI assistants. If you send information we do not need, we will delete it.
5. Why We Process Your Data, and on What Basis
We process personal data only where there is a proper basis for doing so — your consent, the performance of a contract or steps taken at your request before entering one, compliance with a legal obligation, or our legitimate interest in operating and securing our own services in a way that does not override your rights.
| Purpose | Data used | Basis |
|---|---|---|
| Replying to an enquiry | Contact details, message | Your request / steps before a contract |
| Creating and securing your account | Name, email, session data | Performance of a contract |
| Running portal features you use | Entries you record | Performance of a contract |
| Generating AI assistant responses | Your message, context you choose to attach | Your request / consent |
| Security, abuse prevention, fault diagnosis | Technical request data | Legitimate interests |
| Meeting legal and regulatory obligations | As required by the obligation | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not build advertising or behavioural profiles.
6. AI Assistants (PRIMA and MATRIX)
Messages you send to PRIMA or MATRIX are transmitted to our AI inference provider, Groq, to generate a response. Please note the following:
- You control what is sent. Only what you type is transmitted, together with the assistant's instructions and the visible conversation.
- "Send to MATRIX". Where a portal feature offers to attach a summary of your recorded figures, that summary is shown to you in full before it is sent, and you can edit or remove it first.
- Voice input. Where you use the microphone, speech recognition is performed by your own browser. We receive only the resulting text.
- Accuracy. AI responses are generated text and may be wrong or incomplete. They are general information, not advice specific to your circumstances.
- Please do not paste sensitive identifiers — such as full card or passport numbers — into either assistant.
7. Document Uploads
Documents you upload for automatic extraction are processed to read the relevant figures and are then discarded. We do not retain the original file, and it is not written to durable storage. Only the figures you review and confirm are saved to your account, and you can edit or delete those at any time.
8. Access Within PrimeLedger
Portal records are scoped to the account that created them and are never shown to other users. We do not browse client entries in the ordinary course of running the service. Access by us is limited to circumstances where it is genuinely necessary — for example, investigating a fault you have reported to us, responding to a security incident, or where we are required to do so by law — and is limited to what the circumstance requires.
9. Service Providers and International Transfers
We keep our supply chain deliberately small. Each provider below processes data only to deliver its service to us, under its own contractual commitments, and not for its own purposes:
| Provider | Role | Data involved |
|---|---|---|
| Clerk | Authentication and account management | Name, email, session data |
| Neon | Database hosting | Entries you record in the portal |
| Groq | AI inference for PRIMA and MATRIX | Message content you submit |
| Resend | Delivery of contact-form email | Name, email, phone, message |
| Vercel | Website and application hosting | Technical request data |
These providers operate infrastructure outside the United Arab Emirates, so using our services involves the transfer of personal data across borders. Where we transfer personal data internationally we do so on the basis permitted under applicable law — including transfer to jurisdictions offering an adequate level of protection, or under contractual safeguards with the provider concerned.
We will update the table above when our providers change. We do not disclose personal data to any other third party except as described in section 10.
10. Other Disclosures
We may disclose personal data where:
- you ask or authorise us to;
- we are required to by applicable law, regulation, court order or a lawful request from a competent authority;
- it is necessary to establish, exercise or defend legal claims, or to investigate suspected fraud, abuse or a breach of our Terms of Use; or
- our business is reorganised, merged or transferred, in which case the recipient remains bound by the commitments in this policy.
11. Retention
We keep personal data only as long as there is a reason to, and then delete it or reduce it to a form that no longer identifies you:
| Data | Kept for |
|---|---|
| Contact-form enquiries | As long as needed to deal with the enquiry and any follow-up, then deleted |
| Portal account and entries | Until you delete them, or until your account is closed |
| Uploaded documents | Not retained — discarded immediately after extraction |
| AI conversations | Held in the session for context; not used to train models |
| Technical and security logs | Short retention periods set by our hosting provider |
| Engagement records | For the statutory period applicable to the records concerned |
Where a legal or regulatory obligation requires us to keep certain records for a minimum period, that obligation takes precedence over a deletion request for those specific records. We will tell you if that is the case.
12. Security
We take technical and organisational measures appropriate to the nature of the data we hold. In practical terms, and describing only what is actually in place:
- the site is served exclusively over encrypted connections, with HTTP requests redirected to HTTPS;
- strict transport security is enforced, so browsers that have visited us once will not attempt an unencrypted connection afterwards;
- a content security policy, framing restrictions and content-type protections are applied to every response;
- access to portal data requires authentication, and every database query is scoped to the requesting account;
- database queries are parameterised, which prevents the query-injection class of attack, and all submissions are validated on the server rather than trusting the browser;
- request-origin checks and rate limiting are applied to protect against cross-site request forgery and automated abuse;
- credentials for our providers are held server-side only and are never delivered to your browser.
No system can be guaranteed completely secure, and we do not claim otherwise. If we become aware of a personal-data breach that is likely to affect you, we will notify you and any competent authority as required by applicable law, and will tell you what happened and what we are doing about it.
13. Your Rights
Subject to applicable law and to any legal obligation that requires us to keep the data, you may:
- ask what personal data we hold about you and obtain a copy of it;
- have inaccurate or incomplete data corrected;
- ask us to delete data we no longer have a proper reason to keep;
- ask us to restrict how we process it, or object to processing based on our legitimate interests;
- ask for the data you provided to be given to you in a portable, machine-readable form;
- withdraw consent where processing relies on it, which does not affect anything done before the withdrawal; and
- complain to the relevant supervisory authority.
Much of this you can do yourself: entries in PrimeLedger Private can be viewed, edited and deleted from within the portal at any time. For anything else, email info@primeledgerconsultancy.com. We aim to respond within 30 days, and will tell you if a request will take longer or if we need to verify your identity first. We do not charge for these requests unless one is manifestly excessive or repetitive.
14. Cookies and Local Storage
We use only what the site needs to work:
- Local storage on your device, to remember your language, theme and similar interface preferences. This never leaves your browser.
- Authentication cookies set by Clerk when you sign in, so your session persists between pages. These are strictly necessary for the portal to function.
We do not set advertising cookies, analytics profiling cookies, or cross-site tracking identifiers. You can clear local storage and cookies through your browser settings at any time; doing so will reset your preferences and sign you out. Our Cookie Policy sets out the detail.
15. Children's Privacy
Our services are intended for adults and are not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Changes to This Policy
We may update this policy as our services or legal obligations change. The "Last updated" date above always reflects the current version. Where a change materially affects how we handle your personal data, we will take reasonable steps to bring it to your attention rather than relying on the date alone.
17. Contact
Questions, requests or complaints about this policy or your personal data can be sent to info@primeledgerconsultancy.com, or by post to PrimeLedger Consultancy FZCO, IFZA Business Park, DDP, Dubai Silicon Oasis, Dubai, United Arab Emirates.
If you are not satisfied with our response, you may raise the matter with the competent data protection authority in your jurisdiction.
