Your data, explained plainly.

LtdRecord handles the working record of a company. This notice explains what personal data sits inside that work, why it is used, who can receive it and where your choices begin.

CurrentLast reviewed 14 August 2026

The short version

Two roles, stated clearly

9S Labs is controller for account, billing, support, security and product-operation data. Your company is usually controller for personal data inside its own records; we process that content for it.

AI has a defined job

Relevant text, document extracts, images and company context may be sent to an AI provider to classify, extract or prepare work. Authority does not pass to the model.

No advertising model

There are no advertising cookies, data sales or cross-site behavioural profiles. Necessary sign-in, security and in-progress-work storage still exists.

You can ask and complain

You can exercise data-protection rights or make a data complaint by email. We investigate complaints and you can also go to the ICO.

Who is responsible for the data?

The answer depends on why the information is being used.

LtdRecord is a trading name of 9S Labs Limited, registered in England and Wales under company number 17296207. You can check the company on the Companies House register. 9S Labs Limited is registered with the Information Commissioner’s Office as a data protection fee payer under reference ZC188999.

We are a controller when we decide why and how to use account, sign-in, billing, contact, support, security, service-usage and product-quality data. That means we are responsible for the uses described in this notice.

When a customer puts personal data into company books, bank records, invoices, mail, payroll records or evidence, that customer’s company is usually the controller and 9S Labs Limited acts as its processor on your behalf to provide LtdRecord. If we separately use a limited service interaction for security, reliability or product improvement, we are controller for that separate use.

What data do we receive?

We collect what is needed to identify the account, understand the company and carry out the work you ask the Operator to handle.

  • Account and sign-in data: name, email address, one-time sign-in records, session data and, if you choose Google sign-in, the verified account details Google supplies.
  • Company and people data: company name and number, registered office, directors, shareholders, people with significant control, invited co-directors and accountants, authority confirmations and signatures.
  • Financial and operating records: bank statements and transactions, invoices, receipts, bookkeeping entries, director-loan and VAT information, payroll or employee information where you use those features, and year-end working data.
  • Mail and evidence: company letters, emails and attachments, document text and images, replies, filing evidence and receipts you upload or forward. If you connect a company Gmail account, this includes messages and attachments read from that inbox and approved messages sent through it.
  • Operator activity: your messages, answers, corrections, company context used in a task, work the Operator proposes or completes, review states and the audit trail around evidence and authority.
  • Billing and contact: subscription status, Stripe customer and invoice references, plan history, contact-form messages, support requests and collaboration or enterprise enquiries. Stripe, not LtdRecord, receives full card details.
  • Technical and security data: IP-derived security signals, request and error information, rate-limit records, browser/session information and logs of important account or record actions. Security logs are designed not to contain raw record content.

Most data comes from you or another authorised user of the same company. We also read public company information from Companies House, receive transaction and subscription events from service providers, and may receive a message or document from an address your company has chosen to use with LtdRecord.

Why do we use it?

UK data-protection law requires a purpose and a lawful basis, not a vague permission to do anything useful later.

Purposes and lawful bases for personal data
PurposeWhat this coversMain lawful basis
Run LtdRecordCreate the account; organise company records; operate books, mail and supported year-end workflows; display, export and share work with authorised users.Contract. Where the customer is a company rather than the individual concerned, our legitimate interests and the customer's instructions also apply.
Authenticate and secureSend sign-in codes, maintain sessions, check company/role access, prevent abuse, investigate faults and protect users and the service.Legitimate interests in operating a secure service; legal obligation where the law requires security or incident handling.
Bill and administerCreate Stripe checkout and billing records, apply plan limits, issue service messages and keep tax/accounting records for 9S Labs.Contract and legal obligation.
Answer and supportRespond to contact, support, enterprise, careers and accountant-collaboration messages.Steps at your request before a contract, contract, or legitimate interests in answering you.
Improve reliabilityStudy classifications, corrections, failures and bounded examples to improve prompts, deterministic rules, evaluations and product design.Legitimate interests in making the service accurate and reliable, balanced against the sensitivity of company content and your right to object.
Meet legal dutiesHandle rights requests, data complaints, disputes, fraud, lawful requests and records 9S Labs must retain.Legal obligation and, where relevant, legitimate interests in establishing or defending legal claims.

We do not currently send general marketing newsletters. Transactional messages about sign-in, work you requested, billing, security or material service changes are part of operating LtdRecord rather than advertising.

How does AI use company content?

AI is used inside specific workflows; it is not given a standing right to decide for the company.

LtdRecord currently uses the OpenAI API for bounded tasks such as understanding an Operator message, classifying transaction descriptions, extracting invoice data, decoding company mail and preparing structured work. Depending on the task, the request may include text you supplied, a document image or extract, relevant company facts and a limited amount of recent workflow context.

We use OpenAI’s business/API service, not a consumer ChatGPT account. OpenAI states that API inputs and outputs are not used to train its models by default. We do not opt customer content into provider model training. OpenAI may retain abuse-monitoring data under its API controls; its current default is described in its API data-controls documentation.

LtdRecord keeps its own operational record of some inputs, results, corrections and escalation signals so a task can be traced and the product can be improved. The database copy may contain the original text. Material exported from that store for evaluation or human product review goes through deterministic redaction of common identifiers such as names, emails, phone numbers, account-like numbers and UK postcodes. Redaction reduces risk but is not a guarantee that every identifying detail will be removed.

Who can receive the data?

We use a small set of providers to host and operate the service. The exact data depends on the job each provider performs.

Main service providers and recipients
RecipientRole
VercelHosts and delivers the web application and its server-side functions.
NeonHosts the managed PostgreSQL database used for accounts and structured company records.
CloudflareProvides private R2 object storage for supported files and Turnstile abuse checks when enabled.
OpenAIProcesses the bounded AI requests described above.
ResendSends sign-in, service and contact emails and handles supported inbound company mail.
StripeProcesses checkout, subscriptions, invoices and payment events. Full card details do not pass through our servers.
GoogleProvides optional Google sign-in and, when you connect it separately, Gmail inbox reading and company-email sending.
Authorised company usersA director or co-director can see data only after the relevant account, invitation and company-role checks; LtdRecord no longer grants new standing accountant access. The customer controls those invitations.
Public bodies and advisersWe may disclose data where law requires it or where reasonably necessary to establish, exercise or defend legal claims.

Companies House is also a source of public company information. LtdRecord may link you to HMRC or Companies House services, but it does not receive or store your Government Gateway password, Companies House authentication code or personal code as part of those guided steps.

LtdRecord’s use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Gmail access is used only to provide the connected Mailroom and company-email features; disconnecting the mailbox removes LtdRecord’s stored Google refresh credential.

Does data leave the UK?

Yes, some providers can process data in the EEA, United States or other countries.

A transfer outside the UK does not remove UK data-protection duties. Where a restricted transfer occurs, we use an applicable legal mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement, or standard contractual clauses with the UK Addendum, together with the assessment required for that transfer.

For example, OpenAI’s current data-processing addendum states that UK data transferred to its US entity is covered by standard contractual clauses amended by the UK Addendum. Provider locations and contractual arrangements can change; emailinfo@9s-labs.com if you need current information about a particular transfer or a copy of the relevant safeguards where available.

How long do we keep it?

Retention follows the reason for the data, not one blanket number.

  • Company records and evidence remain while the relevant company account remains open so the books and evidence chain stay usable. An individual leaving a shared company does not automatically erase the company’s business record.
  • Account-linked quality logs remain while needed to trace and improve the service and are included in the account-erasure workflow. Anonymous quality records cannot automatically be connected to a later account; we retain them only while needed for reliability and remove identifiable material on a verified request where we can locate it.
  • Contact and support messages remain while we answer the request and for a reasonable period afterwards to keep the history of what was agreed, handle follow-up and resolve disputes.
  • Billing, tax, security and legal records remain for the period required by legal obligations or reasonably needed to prevent abuse, investigate incidents and establish or defend claims.
  • One-time-offer controls may retain a one-way hash derived from a normalised email address after account deletion. It is pseudonymous data, not the address itself, and is retained while needed to stop repeated use of lifetime free offers.
  • Account-identity controls retain a keyed one-way code derived from each verified sign-in identity after account deletion. It is pseudonymous data, not the address itself, kept only to prevent repeated use of one-time free benefits.

A confirmed self-service account deletion cancels live subscriptions, removes the account and its owned company rows, and attempts an authoritative sweep of objects stored under each company. Company file-encryption keys are removed with the company. Some provider logs, legal records and backups can age out on separate schedules, and a failed external-storage sweep may require a retry. We do not promise that every copy disappears instantly.

Before deleting an account, export the company records you must keep. A data-rights request can cover categories that are not included in the workspace’s convenience export.

Cookies and storage on your device

LtdRecord uses necessary browser storage; it does not currently run advertising or behavioural analytics.

  • Auth.js cookies maintain sign-in, verification and security state. They are necessary for an authenticated workspace.
  • A short-lived human-verification cookie can be set after a Cloudflare Turnstile check when guest AI protection is enabled.
  • Local or session storage can hold in-progress work, interface state and a safe return point during sign-in. Signing out clears the product stores designed to contain company draft data.
  • Google or Cloudflare may set their own necessary state if you choose Google sign-in or complete a Turnstile check. Their notices govern that provider-side processing.

There are no third-party advertising pixels or cross-site marketing cookies in the current site. If that changes, this notice and any required consent control must change before the new tracking is enabled.

Your rights and how to complain

Rights depend on the data and lawful basis, but asking does not require legal language.

You may have the right to access personal data, correct it, receive a portable copy, ask for erasure or restriction, and object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without changing the lawfulness of earlier processing. Some rights have exceptions, including where a company must keep a business record or we must retain data by law.

Email info@9s-labs.com with Data rights request in the subject. We may need to confirm identity and authority before disclosing company or personal information. We normally respond within one month. For a complex request or several requests, the law may allow up to two further months; if so, we will tell you within the first month and explain why.

Contact and policy changes

Privacy questions should reach a person, not disappear into the Operator.

Contact 9S Labs Limited at info@9s-labs.com. Please do not email bank statements, identity documents, passwords, authentication codes or other sensitive evidence; use the authenticated workspace for company material.

We may update this notice when the product, providers or law changes. The reviewed date at the top shows the current version. If a change materially affects how we use existing account data, we will provide a more prominent notice through the service or by email where appropriate.

Book a demo with LtdRecord

Begin with the awkward bit

Start with one workflow.

A rough account of the work is enough.

Where records arriveWhere people step inWhat slows the work down
0 / 4,000

We’ll reply within 24 hours to arrange a working session.