LilaCRM is business software made and operated by Lila Software Development Ltd ("we"). This page explains what personal data we hold when you use it, why, and what your rights are. It is written to be read, not skimmed; if anything is unclear, e-mail info@liladevelopment.com.
Who is responsible
Lila Software Development Ltd is the data controller for the accounts and sign-in data of people who use LilaCRM. For the business records a customer keeps inside LilaCRM — their own customers, suppliers, invoices, bank transactions and documents — that customer is the controller and we are their processor, acting only on their instructions under our terms of service. We are registered with the Information Commissioner's Office, registration number ZC250958.
What we hold and why
Data: Your name, e-mail address, sign-in method (Google account identifier or a password hash), passkey public keys, session records. Why: To let you sign in securely and know who did what. Basis: Contract; legitimate interest in security.
Data: The books you belong to and your role in each. Why: To show you only the businesses you are a member of. Basis: Contract.
Data: Business records you or your colleagues enter — customers, contacts, properties, quotes, jobs, invoices, bills, time, documents, notes. Why: To provide the service. Basis: Contract (as processor for the business).
Data: Bank account details and transactions you connect through open banking or import from a statement. Why: To reconcile your books. Basis: Your explicit consent, given to your bank for up to 90 days and revocable at any time.
Data: Audit log — which user changed what, when, from which request. Why: Accountability, HMRC record-keeping and fraud prevention. Basis: Legal obligation; legitimate interest.
Data: Usage of AI features (counts, model used, cost) — not the content of your questions beyond what is needed to answer them. Why: Plan allowances and billing. Basis: Contract.
Data: Technical data — IP address, browser, device, timestamps in server logs. Why: Security, brute-force protection, diagnosing faults. Basis: Legitimate interest.
Open banking
When you connect a bank, you are sent to your bank's own website to approve READ-ONLY access to the accounts you choose. LilaCRM never sees your bank login. Access is provided by an authorised account information service provider acting under your consent — TrueLayer Limited (UK, FCA-authorised) , Plaid Financial Ltd (UK, FCA-authorised), Yapily Connect Ltd (UK, FCA-authorised) or Finexer Ltd (UK, FCA-authorised, FRN 925695) for UK bank accounts, and Enable Banking Oy (Finland) for EU accounts — for at most 90 days, after which you are asked again. You can withdraw consent in LilaCRM or at your bank at any time; transactions already imported remain in your books because they are your accounting records. We cannot move money.
Where data lives and who else sees it
LilaCRM runs on servers in London, United Kingdom (Amazon Web Services, eu-west-2), with encrypted backups in the same region. Your data does not leave the UK except as follows: Google (sign-in and, where you use them, AI features), TrueLayer (open banking, UK), Plaid (open banking, UK), Yapily (open banking, UK), Finexer Ltd (open banking, UK, FCA-authorised, FRN 925695), Enable Banking (open banking, EU), Resend (sending e-mail you ask us to send, US/EU), and Apple or Google (if you use the iPhone or Android app: app-store and on-device services). Each acts under a contract that limits them to the purpose named. Where a transfer leaves the UK it relies on the UK adequacy decision or the UK International Data Transfer Addendum.
AI features in LilaCRM send only the data needed to answer the request to the model provider configured for your book (Google Gemini by default, or a provider and key you supply). Providers are contractually barred from training on your data. On the phone, some reading and drafting runs entirely on the device and nothing leaves it.
How long
Account data: for as long as you have an account, then deleted within 30 days of closure. Business records: for as long as the business keeps its book; when a book is deleted, its database file and documents are removed from live systems immediately and from backups within 35 days. Because they are accounting records, a business may be obliged by HMRC to keep them for six years — that is the business's decision and export is always available. Server logs: 30 days.
Security
All traffic is encrypted in transit. Sign-in is protected by a second factor (passkey). Bank and provider secrets are encrypted at rest with a key that is not stored with the data. Access to servers is over a private network only. Every change to your books is recorded in an audit log. We will tell you and, where the law requires, the ICO, without undue delay if a breach affects your data.
Your rights
You can ask us for a copy of your personal data, ask us to correct or delete it, object to or restrict processing, and take your data elsewhere — a full export of a book is available from within LilaCRM at any time. Write to info@liladevelopment.com; we answer within one month. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk. Where we act as processor for a business, requests about that business's records are passed to the business, which is responsible for answering.
Cookies
LilaCRM sets one cookie to keep you signed in and one to remember which book you were last in. Nothing is used for advertising or tracking, and there are no third-party cookies.
Changes
When this policy changes we update the date at the top of this page and, for material changes, tell signed-in users on their next visit.
Contact
Lila Software Development Ltd, company 17461121, registered in England and Wales at
Hampshire, United Kingdom.