Privacy Policy


Controller: Hugh Ledger Accounting Group

Privacy email: privacy@hughledger.com

We collect personal information you provide (name, email, postal address, phone), technical data (IP address, device, browser, cookies), and usage data (pages visited, referral source). We also collect any information you submit through contact forms or purchases.

We use data to respond to inquiries, provide services, process payments, improve the website, and send marketing (where you consent). For EU residents, processing is based on contract, consent, or legitimate interest as applicable; we document the legal basis for each processing activity. GDPR requires stating lawful bases for processing.

We use cookies and similar technologies for essential site functions, analytics, and marketing. You will be offered a cookie banner to accept or decline non‑essential cookies. We honor Global Privacy Control (GPC) and browser Do‑Not‑Sell signals where applicable. Implementing clear cookie categories and consent is best practice.

We do not sell or rent personal information. We share data with service providers (hosting, payment processors, analytics, email providers) who act as processors under contract and are only permitted to process data per our instructions. Disclosing categories of recipients is required by privacy laws.

Depending on your location you may have rights to access, correct, delete, restrict processing, portability, and to opt out of sale/sharing. California residents have a right to request disclosure of data collected in the prior 12 months and to request deletion; businesses must respond within 45 days (extensions allowed). Provide a simple web form, email, or toll‑free number to submit requests.

We retain personal data only as long as necessary for the purpose collected (e.g., contact form data retained for 3 years unless you request deletion). Specify retention periods or criteria for each category. Data minimization and retention limits are core GDPR principles.

We implement reasonable technical and organizational measures (encryption, access controls) to protect data. In the event of a security breach affecting personal data, we will notify affected individuals and regulators as required by law. Preparing a breach response plan is recommended.

We do not knowingly collect personal information from children under 13 (or higher age where local law requires). If we learn we have collected such data, we will delete it and require parental consent where applicable.

If EU personal data is transferred outside the EEA, we rely on adequacy decisions or standard contractual clauses and document safeguards.

We will post changes here and notify users of material changes by email or site notice.