Privacy policy

How LegaSum handles your data

Last updated 22 September 2026. Covers legasum.dk, legasum.com and everything behind login. Written to be read, and to match what the system actually does.

1. Who is the controller

LegaSum is operated by LegaSum Ltd, London, United Kingdom. Questions about your data: info@legasum.com.

Most of our customers are companies in Denmark, so the EU General Data Protection Regulation (GDPR) applies to the processing, alongside the UK GDPR.

2. Two roles: your data, and your customers' data

When you create a company at LegaSum we process data about you as a user, and we are the controller of that data. When you then keep books, send invoices and store receipts, we process data about your customers, suppliers and employees on your behalf; there you are the controller and LegaSum is the processor. The data processing agreement is part of the terms, and sections 6 and 7 below describe how we protect that data.

3. Data about you as a user

  • Account: name, e-mail, password (hashed only), language, login times.
  • Company: name, country, CVR or registration number, address, and what we fetch from the Danish CVR register when you give a CVR number (via cvrapi.dk; only the number is sent).
  • What you write to us: your wish on the front page ("I want to start a company"), questions and answers in the CRM, e-mail enquiries.
  • LegaSum Pay: the status of your Stripe payout account (connected or not, country). Identity and bank details you enter with Stripe; we never see them.
  • Technical: IP address and browser at login and on forms, server logs, a cookie that remembers your language and your session.

Legal basis: the agreement with you (GDPR art. 6(1)(b)), legal obligations (art. 6(1)(c)) and our legitimate interest in security and operations (art. 6(1)(f)). Marketing only with your consent.

4. Data you process in LegaSum (your customers, suppliers, employees)

  • Customers and suppliers: name, CVR, address, e-mail, phone, notes, follow-up dates, stage in your pipeline.
  • Invoices, credit notes, agreements, payments, reminders and the e-mails we send for you.
  • Receipts: the files you upload or forward to your receipts address (only attachments are used; the mail text is not read), bank transactions you import, and what the system reads out of them.
  • Payroll, once live: employees' names, CPR numbers, salary, tax cards. Until then no payroll data is processed.

We process this data only on your instructions, that is, to provide the service to you.

5. Automatic reading of receipts

LegaSum reads receipts by machine to find supplier, amount, date and VAT. For this we use a language model from Anthropic (the Claude API). The receipt is sent to Anthropic, which processes it on our behalf and does not use it to train models. The model proposes; posting follows the system's rules and your answers, and every entry points to the receipt it rests on.

6. Processors and where data lives

  • Amazon Web Services, Stockholm (EU): hosting, database and document store (encrypted, one key per company).
  • Amazon SES: sending e-mail (invoices, reminders, login links) and receiving receipts by e-mail.
  • Anthropic (USA): machine reading of receipts, see section 5.
  • Licensed account-information provider (PSD2), when you connect your bank: provides read access to transactions and balances after your consent at the bank. We never see or store your bank login.
  • Stripe (EU/USA): card payments on your invoices and payouts through LegaSum Pay.
  • cvrapi.dk: lookups in the Danish CVR register.

Transfers to the USA rest on the EU Commission's standard contractual clauses and/or the EU-US Data Privacy Framework. We do not sell data and do not share it with anyone beyond the above unless the law requires it.

7. Security

Encrypted connections, passwords stored as hashes only, login links that expire, the document store encrypted at rest, backups, and logged access for staff and systems. The books are append-only: an entry is corrected with a reversing entry, never by deletion.

8. Retention

  • Accounting records (entries, receipts, invoices): 5 years from the end of the financial year they relate to (the Danish Bookkeeping Act), also if you close the account during that period.
  • Account data, CRM notes and to-dos: while the account is active, and up to 3 years after.
  • Login links and sessions: expire automatically (login link 15 minutes, session 30 days).
  • Server logs: at most 90 days.

9. Your rights, and deletion

You have the right of access, rectification, erasure, restriction, data portability and objection, and to withdraw consent. Write to info@legasum.com from the e-mail your account was created with. We confirm within 5 working days and answer within a month at the latest. Accounting records we are obliged to keep are deleted when the period expires; everything else is deleted. In the app the same option is under Account → Delete account, which sends the request for you. Consent for a bank connection can also be withdrawn directly at your bank.

If you are a customer of a company that uses LegaSum, contact that company; we help them answer.

Complaints can be lodged with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk, or with the ICO in the United Kingdom.

10. Cookies

We use only necessary cookies: your session behind login and your language choice. No analytics or marketing cookies, no third-party tracking.

11. Changes

The date at the top shows the current version. Material changes are announced by e-mail to users with an account.