Ledig privacy policy
Website and services
Last updated 30 September 2026
This Privacy Policy explains how Ledig collects, uses, shares and protects personal information when you visit our website, contact us, apply for an account or use our services. It also explains how long we keep information and how you can exercise your privacy rights.
Our services are for businesses and organisations. We nevertheless handle personal information about their owners, directors, authorised users, employees and other representatives, and about people involved in their transactions. This Policy applies to that information as well as information about website visitors and prospective customers.
You can contact us about privacy at legal@ledig.io. Reading this Policy or accepting our service terms does not, by itself, constitute consent to optional marketing, tracking or biometric processing.
1 Who is responsible for your information
1.1 Ledig operates through LEDIG TECHNOLOGIES INC, incorporated in Montana, United States, and LEDIG CANADA INC., incorporated in Ontario, Canada. In this Policy, “Ledig”, “we”, “us” and “our” refer to the entity responsible for the relevant handling of personal information.
1.2 LEDIG TECHNOLOGIES INC is responsible for personal information collected through the general Ledig website. For an account, application or service, the responsible Ledig entity is identified in the onboarding information or applicable service agreement. Each entity is responsible for the processing it determines and carries out. You may use legal@ledig.io for either entity, including to ask which entity handles your information.
1.3 Where we decide why and how personal information is used, we act as its controller or the equivalent accountable organisation under applicable law. Where we process information solely on a business customer's instructions, the relevant data processing agreement governs that work. This does not cover processing for our own compliance, security or other independently determined purposes.
1.4 This Policy covers our website, onboarding, accounts, dashboards, application programming interfaces, customer support, payments, conversions, settlements, virtual accounts, wallets and related services. Product or collection notices may provide more specific details. Our customer agreements and this Policy do not limit rights that applicable privacy law gives you.
2 Information we collect
2.1 Identity and contact information. This includes names, business and residential addresses, email addresses, telephone numbers, dates of birth, nationality, identity document details and copies, and information needed to verify a person's identity or authority to act.
2.2 Business and ownership information. This includes a person's role, directorships, ownership interests, beneficial ownership, signing authority and relationship with a customer, together with relevant company documents. Information about a company may also identify an individual, particularly an owner, representative or sole trader.
2.3 Verification and compliance information. This includes identity checks, verification results, screening matches, risk assessments, source of funds or wealth information, transaction explanations and supporting documents. Checks may involve sanctions lists, politically exposed person information, relevant adverse media, public registers and blockchain transaction information. Some records may concern alleged offences or other sensitive matters where their processing is lawful and necessary.
2.4 Verification images. Identity verification takes place through specialist providers. Depending on the check, it includes identity document images, selfies, video or liveness information and comparison results. A provider may derive facial or other biometric information to establish that the person is present and matches the identity document. Section 4 explains how this information is handled.
2.5 Account and transaction information. This includes account identifiers, user permissions, bank and virtual account details, wallet addresses, payment instructions, payer and beneficiary information, transaction amounts, currencies, digital assets, exchange rates, fees, balances, funding sources, transaction references and settlement records. Wallet addresses and transaction identifiers may be personal information when linked to a person.
2.6 Technical and usage information. This includes IP addresses, device and browser information, approximate location derived from technical information, access times, login and security events, pages viewed, interactions with our website or platform and cookie or similar identifiers. The information collected through optional analytics depends on the tools and choices that apply to your visit.
2.7 Communications and preferences. This includes enquiries, support correspondence, complaints, information you provide in forms, marketing preferences, consent records and records of privacy requests. Please avoid sending personal information that is unrelated to the matter you are contacting us about.
3 Where information comes from
3.1 We obtain information directly from you, through your use of the website or services, and from the business you represent, its authorised users, transaction counterparties and people providing payment instructions.
3.2 We also obtain information from identity and business verification providers, screening and fraud prevention providers, banks, fintechs, payment and custody providers, liquidity providers, public company registers, official sanctions sources, relevant public reporting and public blockchain records. The sources used depend on the service, transaction and checks required.
3.3 If you provide information about another person, you must have a lawful basis to do so, provide accurate information and make this Policy available to them where appropriate. We remain responsible for any notice or consent obligations that the law places on us. A business representative cannot automatically consent to every use of another person's information.
4 Identity checks and biometric information
4.1 We collect verification information through specialist providers to establish identity, verify authority, detect impersonation and fraud, and meet applicable compliance requirements. Collection through a provider does not remove Ledig's responsibility for information processed on its behalf. This Policy covers that processing even where the underlying files are held by the provider.
4.2 Before a check begins, we will provide or direct you to a verification notice explaining the information required, the checks performed, the relevant provider's role, the legal basis and any additional condition for biometric processing, and the applicable retention rules. Providers may process information on our instructions or, for identified purposes, meet their own legal obligations. Where a provider acts independently, its own privacy notice also applies.
4.3 Where a check uses biometric information to uniquely identify you, we and the provider must have the additional legal authority required for that use. Where the law requires explicit consent, written authorisation or a separate biometric notice, it must be obtained or provided before that processing begins. Agreement to our general service terms is not a substitute.
4.4 You may contact legal@ledig.io to ask about the check, the information held or an alternative verification method. Where we rely on explicit consent to biometric processing, you must have a genuine choice, including an appropriate alternative where required for consent to be valid. If we cannot complete a required identity check lawfully, we may be unable to open or maintain the account or process the transaction.
4.5 Raw biometric information is subject to purpose limits and any specific retention and destruction requirements that apply to it. The five-year compliance record period in section 11 does not automatically justify keeping every selfie, video or biometric template for five years. Verification records and the underlying biometric material may have different retention periods, as explained in the relevant verification notice.
5 How and why we use information
5.1 We use personal information for the purposes below. Where UK or European data protection law applies, the accompanying explanations identify the relevant legal bases. Other applicable laws may instead require consent or permit particular uses without consent.
5.2 Applications and account administration. We assess applications, establish authorised users, administer access and communicate about accounts. Where you are personally a party to the contract, we use information as necessary to enter into or perform it. For representatives of a business customer, we ordinarily rely on our legitimate interests in establishing and managing that business relationship, subject to your rights and interests. Applicable verification duties may also require processing.
5.3 Providing services. We use account, identity and transaction information to respond to quote requests, arrange conversions, process payments, coordinate custody and settlement, reconcile transactions and resolve errors. The legal basis is contractual necessity where the individual is a contracting party, or our legitimate interests in carrying out the business customer's instructions and providing the agreed service. We also comply with applicable reporting and recordkeeping duties.
5.4 Compliance and financial crime prevention. We verify identities and ownership, screen relevant parties and wallets, assess risks, monitor transactions, investigate concerns and make legally required reports. We rely on legal obligations where the relevant data protection law recognises that basis. Other lawful checks, including checks connected with overseas regulatory requirements, may rely on our legitimate interests in preventing financial crime and operating compliant services. Sensitive information requires any additional legal condition that applies; an ordinary legitimate interest alone is not sufficient for biometric identification or restricted offence information.
5.5 Security and service improvement. We use technical information and relevant account activity to authenticate users, prevent unauthorised access, investigate incidents, maintain our systems and improve functionality. We rely on our legitimate interests in protecting users and running reliable services, and on legal obligations where applicable. Optional website analytics are handled as explained in section 8, including obtaining consent where required.
5.6 Support and legal matters. We handle enquiries and complaints, keep appropriate business records, conduct necessary audits and establish, exercise or defend legal claims. We rely on our legitimate interests in resolving issues and protecting legal rights, contractual necessity where relevant, and applicable legal duties.
5.7 Ledig marketing. We use contact details and communication preferences to send relevant information about Ledig's products, services and events. We rely on consent where required, or a lawful permission to send marketing and our legitimate interests where applicable. Section 9 explains your choices. A legitimate interest does not replace a separate legal requirement for marketing consent.
5.8 Where we rely on legitimate interests, we consider the purpose, necessity and effect on individuals, and do not proceed on that basis where your rights and interests override the interest relied on. Where consent is required, we explain the relevant use and how to withdraw consent. Under Canadian privacy law, we obtain meaningful consent where required and limit collection, use and disclosure to appropriate purposes.
5.9 Identity, authority and transaction information may be required by law, our service arrangements or the checks necessary to provide a requested service. If required information is missing, we may be unable to approve an application, execute an instruction or continue a service. Optional marketing consent is not a condition of receiving our core services.
6 Who receives information
6.1 We share information only where needed for the purposes described in this Policy and permitted by applicable law. The information shared depends on the recipient's role and the service or transaction involved.
6.2 Ledig entities and personnel. Information may be shared between the Ledig entities where needed to provide services, administer accounts, support customers, manage security or meet compliance obligations. Access within Ledig is restricted to authorised personnel who need it for their responsibilities.
6.3 Financial and transaction providers. We share necessary information with banks, regulated fintechs, payment institutions, custody providers, liquidity providers and intermediaries involved in account provision, funding, conversion, settlement or payment execution. This may include identity and verification information, account details, transaction instructions and information about payers and beneficiaries. Providers may have their own verification, reporting and retention duties.
6.4 Verification and compliance providers. We use providers for identity and business checks, sanctions screening, fraud prevention, transaction monitoring, wallet analysis and related compliance support. They receive the information needed for the relevant checks, subject to applicable restrictions on sensitive information.
6.5 Technology and operational providers. We use providers for hosting, infrastructure, security, communications, customer support, analytics and delivery of Ledig's own marketing. Providers acting on our behalf are subject to appropriate confidentiality, security and processing obligations and may use the information only for authorised purposes, except where law requires otherwise.
6.6 Professional advisers and authorities. We may disclose relevant information to legal advisers, auditors and other professional advisers where necessary for their work, and to courts, regulators, law enforcement or other competent authorities where legally required or otherwise lawfully necessary. We assess requests and disclose information within the applicable legal limits. The law may prevent us from notifying you of a request or report.
6.7 Your business and transaction recipients. Authorised users of a business account may see information needed to administer that account. Payers, beneficiaries and their providers may receive information needed to complete, identify or investigate a transaction, including legally required originator and beneficiary information.
6.8 Public blockchain records. Where a requested service involves a public blockchain transaction, wallet addresses, transaction amounts, timestamps and other network records may be publicly visible and accessible worldwide. Those records can sometimes be linked to individuals. Public blockchain records generally cannot be changed or deleted by Ledig. This limitation does not remove our duties concerning information we hold separately or other rights that apply to our processing.
6.9 Some recipients act as independent controllers or accountable organisations for their own purposes, particularly financial institutions carrying out their own legal duties. Their privacy notices govern that processing. Where we jointly determine a use of information with another organisation, we provide the legally required explanation of our respective responsibilities.
6.10 We do not sell or rent personal information, share it for cross-context behavioural advertising, or provide it to other organisations for their own marketing. Using a provider to send Ledig communications or perform a service on our behalf does not permit that provider to market its own services to you using the information we supply.
7 Hosting and international access
7.1 Ledig customer data is hosted in Canada and the United States. Authorised Ledig personnel located in the United Kingdom, Germany, Canada and the United States may access it for their work. Access is limited according to responsibility and business need.
7.2 Our hosting locations do not mean that every recipient in a cross-border transaction processes information only in those countries. Verification providers, financial institutions and other recipients may process relevant information in countries connected with their operations or the requested transaction. Relevant provider and service notices give additional details; you may also contact us for information about the recipients and locations relevant to your data.
7.3 Information processed in another country may be subject to that country's laws and lawful access by its courts, law enforcement or national security authorities. Those laws may provide different protections from the laws where you live. We remain accountable for information processed on our behalf and require appropriate protection through contractual and other applicable safeguards.
7.4 Where European or UK law restricts a transfer, the transfer must have a lawful mechanism. Depending on the recipient and destination, this may be an applicable adequacy decision or approved contractual safeguards, such as the European Commission's Standard Contractual Clauses and, for a relevant UK transfer, the UK International Data Transfer Agreement or UK Addendum. Required assessments and additional safeguards must accompany the mechanism where necessary. A recipient's location in Canada or the United States does not, by itself, establish that an adequacy arrangement covers it.
7.5 Contact legal@ledig.io for details of the mechanism relevant to your information and to request a copy of applicable safeguards. We may redact confidential commercial information or information about other people, while providing the explanation required by law. This Policy is not a request for blanket consent to international transfers.
8 Cookies and website analytics
8.1 Optional analytics, including Google Analytics, are not currently enabled on this public website.
8.2 If we introduce optional website analytics, we will update this Policy and explain the technologies used, their providers, purposes, the information collected and how long it is kept. Analytics information is not necessarily anonymous merely because it does not include your name.
8.3 When optional website analytics are introduced, we will provide cookie settings so you can refuse or withdraw consent. Where consent is required, we will enable optional analytics only after you agree. Rejecting optional analytics will not prevent access to the core website or require you to agree to marketing.
8.4 Consent to analytics does not automatically authorise advertising tracking, disclosure for other organisations' marketing or a new use of identity and financial records. Any new tracking purpose requiring consent must be explained and separately authorised before it is used.
9 Marketing choices
9.1 We may send newsletters, product announcements, invitations and other relevant Ledig marketing where permitted. We obtain consent where required and respect any limits on an existing business relationship or other lawful permission to contact you. We do not treat providing compliance information or accepting our service terms as general marketing consent.
9.2 You can stop marketing emails through the unsubscribe option in the message or by contacting legal@ledig.io. We action requests promptly and within applicable legal deadlines. You may object to direct marketing at any time, including related profiling, and we will stop that use.
9.3 We may retain a limited suppression record to respect your preference and avoid contacting you again. Unsubscribing from marketing does not stop necessary account, transaction, security, legal or service messages. We distinguish those messages from promotional communications.
10 Automated checks and human decisions
10.1 Our systems and providers use automated checks to help verify identity, identify screening matches, detect unusual transactions and assess fraud or security risks. These checks may compare identity details against records, evaluate verification results, or examine transaction patterns, amounts, destinations, wallet activity and access signals.
10.2 An automated check may temporarily hold a transaction, restrict account activity or refer an application for review. This can delay a payment, onboarding or access to a service. A match or risk signal does not, by itself, establish wrongdoing.
10.3 Ledig's final decisions arising from these compliance or risk reviews, including application rejection, transaction refusal or continuing account restriction, are made by an authorised person. Human review must be meaningful and consider the relevant circumstances, supporting information and the possibility of error. Temporary restrictions are reviewed promptly in light of their impact; the fact that a restriction is temporary does not remove any legal protections that apply to it. Independent providers may also make decisions under their own legal duties and privacy notices.
10.4 You may contact legal@ledig.io to request human review, provide further information or challenge a decision affecting you. We explain the relevant decision and reasons to the extent permitted by law, without disclosing information that would unlawfully prejudice an investigation, breach another person's rights or compromise security. Any use that amounts to a solely automated decision with a legal or similarly significant effect must meet the additional conditions and safeguards of the law that applies.
11 How long we keep information
11.1 Our usual retention period for necessary customer verification, transaction and associated compliance records is five years, measured from the event relevant to the record. This is a baseline for those records, subject to applicable legal requirements and the qualifications below. It is not a promise to keep every category of personal information for five years or to delete records that the law requires us to retain longer.
11.2 Identity, ownership and relationship records. We keep necessary verification records while needed for an active relationship. The usual five-year period then runs from the relevant last business transaction or the end of the relationship, according to the applicable recordkeeping rule and continuing purpose. For example, Canadian rules measure the period for specified business information, ownership and service agreement records from the last business transaction. Records whose purpose and required period have ended are not retained simply because another record remains necessary.
11.3 Transaction and reporting records. We ordinarily keep necessary transaction records for five years from the transaction or creation of the record, as applicable. Regulatory reports and supporting records follow the period and starting event required for the particular report. Linked identity information is retained where needed to understand or substantiate a retained transaction.
11.4 Applications that do not proceed. Necessary application and screening records may be retained for up to five years after rejection, withdrawal or closure where this is justified by compliance, fraud prevention or legal needs. Information with no continuing lawful purpose is deleted earlier. This does not impose a general five-year period on raw biometric material.
11.5 Relevant legal requirements include the US Bank Secrecy Act and FinCEN recordkeeping regulations, including 31 CFR 1010.430(d), and applicable Canadian requirements under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, including section 148 of the recordkeeping regulations. Those regimes impose five-year periods on specified records, with different starting events. They do not require every piece of personal information to be kept on an identical schedule.
11.6 Longer legal periods. We retain relevant records for longer where sanctions, tax or other law requires it, or where a properly limited legal hold is necessary for an investigation, dispute or claim. For example, where US Office of Foreign Assets Control rules apply, 31 CFR 501.601 requires relevant transaction records for at least ten years after the transaction, and records of blocked property while it remains blocked and for at least ten years after unblocking. Extended retention is limited to the information and period needed for the applicable requirement.
11.7 Other information. Routine enquiries are kept for as long as needed to answer and resolve them; communications that form part of a compliance record, complaint or claim follow the relevant retention requirement. Identifiable analytics information is kept only for the period needed for the stated measurement purpose, as reflected in the applicable cookie and analytics information. Security logs follow the period needed to detect and investigate incidents and meet relevant duties. Marketing contact information is kept while we have a lawful basis to use it; limited consent and suppression records may be kept to demonstrate and respect your choices.
11.8 At the end of the applicable period, we delete information under our control securely or anonymise it so that it no longer identifies you. Where deletion from a backup cannot occur immediately, the information is kept out of ordinary use until the backup is overwritten or securely deleted. Providers acting independently may have their own lawful retention duties, and section 6.8 explains the limits concerning public blockchain records. Contact us for the period or criteria applicable to a particular record.
12 Protecting information
12.1 We use technical and organisational safeguards appropriate to the sensitivity of the information and the risks involved. These include restricting access to authorised personnel, confidentiality requirements and controls for our systems and providers. Access to identity, financial and other sensitive records is limited to people who need it for an authorised purpose.
12.2 No system can eliminate every security risk. If a personal information breach occurs, we assess it, take appropriate steps and notify affected individuals and authorities where the applicable legal requirements are met. This statement does not limit our responsibilities under privacy law.
12.3 Please protect your credentials, use the security controls available to your account and notify us promptly if you suspect unauthorised access. We will arrange a suitable channel if sensitive documents are needed for a privacy request; do not send identity documents in an initial email unless asked.
13 Your privacy rights
13.1 Depending on the law that applies to Ledig and the information concerned, you may have rights to learn whether we hold information about you, obtain access or a copy, correct inaccuracies, request deletion, restrict use or receive certain information in a portable form. You may also have rights to withdraw consent, challenge compliance, obtain information about disclosures and exercise safeguards concerning automated decisions.
13.2 Right to object. Where processing relies on legitimate interests, applicable UK or European law allows you to object on grounds relating to your situation. We must stop unless we demonstrate the legally required overriding grounds or need the information for legal claims. You may object to direct marketing at any time; that use will stop without requiring you to explain your circumstances.
13.3 Withdrawing consent does not affect processing that was lawful before withdrawal. It also does not require us to stop processing that has a separate lawful basis, such as keeping records required by law. If withdrawing consent prevents a necessary check or service, we explain the resulting effect where applicable.
13.4 Rights are subject to the conditions and exceptions in the relevant law. For example, we may need to retain compliance records, protect another person's information or withhold details where disclosure is legally restricted. An exception applies only to the extent justified; it does not automatically prevent us from responding to the rest of your request.
13.5 Send requests to legal@ledig.io with enough information to identify the relevant account or interaction and explain what you want us to do. We may reasonably verify your identity and an authorised representative's authority. We request only the additional information needed for that verification. We respond within the deadline set by the applicable law and explain any lawful extension, refusal or fee. Requests are normally handled without charge.
13.6 Where applicable US state privacy law provides additional rights, including an appeal against a refused request or an opt-out from covered processing, you may exercise them through the same contact address. We will explain the applicable appeal process. We do not unlawfully discriminate against you for exercising privacy rights.
14 Children
14.1 Our website and business services are not directed to children, and accounts may be used only by representatives of legal age and capacity. We do not knowingly collect children's information to market or provide accounts to them. If you believe a child has submitted information to us, contact legal@ledig.io so we can assess it and take appropriate action, including deletion where required.
15 Questions and complaints
15.1 Contact us at legal@ledig.io with a question, concern or complaint. We will direct it to the responsible entity. We acknowledge privacy complaints within 30 days or any shorter applicable deadline, take appropriate steps to investigate, keep you informed and communicate the outcome without undue delay. You may also use this address to request further information about our practices, providers, retention periods or international safeguards.
15.2 You may also complain to the competent privacy regulator. This may include the Office of the Privacy Commissioner of Canada or a relevant provincial regulator, the UK Information Commissioner's Office, the competent authority in the European Economic Area, or a relevant US authority. Under European law, this includes the authority where you habitually live or work, or where the alleged infringement occurred. You do not have to complete our complaints process before exercising a right to contact a regulator.
15.3 Regulator information is available at www.priv.gc.ca, ico.org.uk and the European Data Protection Board's member directory at www.edpb.europa.eu. We can help identify the appropriate authority if you contact us.
16 Changes to this Policy
16.1 We may update this Policy to reflect changes to our services, practices or legal requirements. We publish the revised version and its date on our website and provide additional notice of material changes where required.
16.2 If a new use requires consent or another specific legal step, we complete that step before starting the use. Continued use of the website does not replace required consent or remove your privacy rights.