
Effective 15 August 2026.
This Privacy Policy is issued by Bechellente Limited ("Bechellente," "we," "us," "our"), a company registered in England and Wales under company number 15892202.
Bechellente is the data controller for the personal data described in this Policy, across all of our products and our website. This Policy applies to:
Where a section below applies to only one product, it says so explicitly. Everything else applies across all of them.
Contact us about privacy matters at: contact@bechellente.com
Visitors to bechellente.com. bechellente.com uses no cookies, no analytics, and no tracking scripts. The only personal data collected through the website is submitted voluntarily, through an early-access or waitlist registration form (name, email, phone number, organization, role) — used to notify you about upcoming product launches and to schedule an onboarding call if you request one.
Core Ledger accounts, administrators and authorized users. When your organization signs up for Core Ledger, we collect, via our shared Identity Service: your organization's name, registered address, phone number, email, tax identification number (TIN), registration number, industry, legal entity type, and logo; for each individual user we invite or who registers, first name, last name, email address, phone number, and profile photo (if provided); and role and permission assignments within your organization.
Employee/payroll data (processed on your organization's behalf). If your organization uses Core Ledger's payroll features, you may enter the following about your own employees. For this category of data, your organization is the data controller and Bechellente is the data processor — we process it strictly on your instructions, to provide the service.
This is sensitive financial and, in some cases, health-related data (e.g. NHIS enrollment), and it is handled under the access controls and confidentiality safeguards described in this Policy.
Customer and vendor data (processed on your organization's behalf). Also processed as a data processor on your instructions: names, emails, phone numbers, physical addresses, TINs, and (for vendors) a named contact person's details, entered by your organization to manage its own invoicing, purchasing, and withholding-tax obligations.
Financial and transactional records. Invoices, expenses, purchases, revenue records, journal entries, tax computations, fixed-asset and depreciation records, and bank transaction data, all scoped to your organization and processed as a data processor on your instructions.
Bank account data. If you connect a bank account via Core Ledger's Open Banking feature, the connection and consent are handled by our shared banking service and its Open Banking partner. Core Ledger does not request or store your bank login credentials. It does receive and store your bank account number and confirmed transaction details from the banking service, which are used to convert bank activity into accounting records. If you instead upload a bank statement file, that file and its parsed transaction lines are stored by Core Ledger directly.
Documents you upload. Receipts, invoices, and bank statements you upload are stored as files plus associated metadata (filename, size, who uploaded it, when). If you use our invoice/receipt auto-extraction feature, the uploaded document is sent to a third-party AI service to extract structured data (see Service Providers and Legal Disclosures below); you should not upload documents to this feature that you are not comfortable transmitting to it.
Payment information. We do not collect or store your card or bank payment details. Subscription payments are processed by Paystack, who collect your payment details directly on their own hosted checkout page.
Information we generate about you. Login/session activity, and a field-level audit trail of changes made to key records (who changed what, when, and the before/after values), used for security, accountability, and dispute resolution within your organization.
Where UK GDPR or equivalent law applies, we rely on:
For employee, customer, and vendor data entered by our customers, your organization determines the legal basis as the data controller for that data; Bechellente processes it only as instructed.
We do not sell your personal data, and we do not share it with anyone for their own independent purposes.
To operate Core Ledger, we use trusted third-party service providers for functions such as cloud infrastructure and storage, AI-assisted document processing, and email delivery. These providers act strictly on our instructions, under confidentiality and data-protection obligations, and are not permitted to use your data for their own purposes. For security reasons, we do not publicly list the specific identities of our infrastructure providers here; a list is available to customers on request at contact@bechellente.com, or as part of our data processing agreement.
Payments are handled directly by our payment partner, Paystack, who collect your payment details on their own platform. We do not receive or store your card details.
Within the Bechellente platform, Core Ledger, our identity service, subscription service, and banking service share the data necessary to operate a single account across our products.
We do not share your organization's data with other Bechellente customers. Each customer's data is kept separate and accessible only to that customer's own authorized users.
Legal disclosures. We may disclose personal data where required by applicable law or a valid legal process. Depending on your location, this could include disclosure to Nigerian authorities (such as the Federal Inland Revenue Service or the Nigeria Data Protection Commission), UK authorities (such as HMRC or the Information Commissioner's Office), or another regulator or court with jurisdiction over the relevant matter.
If you are in the UK, subject to UK GDPR, you have the right to: access your personal data; correct inaccurate data; request erasure; restrict or object to processing; data portability; and to withdraw consent at any time where we rely on consent. You can complain to the Information Commissioner's Office (ICO) at ico.org.uk.
If you are in Nigeria, subject to the Nigeria Data Protection Act (NDPA) 2023, you have equivalent rights: access, rectification, erasure, restriction, data portability, objection, and the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
To exercise any of these rights, contact us at contact@bechellente.com. Where you are an employee, customer, or vendor of one of our platform customers rather than our own direct customer, we recommend contacting that organization directly, as they are the data controller for that data; we will support them in fulfilling your request.