Privacy Policy

CoralLedger Comply · Version 1.0 (Beta) · Effective date: 16 July 2026

CoralLedger Comply is operated by Carib Digital Labs Ltd., a Bahamian company ("we", "us"). We are the data controller for the personal information described in this policy. This policy explains what we collect, why, how long we keep it, and the choices you have. It is written to align with the principles of the Data Protection (Privacy of Personal Information) Act of The Bahamas, as amended.

This policy covers the CoralLedger Comply application and the account you hold with us. Our Cookie Policy is separate and lives at /legal/cookies.

What we collect

Account information. Your name, email address, sign-in credentials (stored as a secure hash, never in plain text), your role, and, for accounting firms, your firm and client-workspace relationships.

Business and compliance records you provide. The records the service exists to keep: business names and addresses, Taxpayer Identification Numbers (TINs), VAT registration details, transaction records (which may include the names of your customers and suppliers, invoice details, and amounts), imported files, bank statement references where you use reconciliation features, and practitioner attestation records, including the practitioner name declared on an attestation. Attestation and filing records are part of a permanent, tamper-evident audit trail; that permanence is a feature of the service and is described in the Terms of Service.

Information generated when you use the service. Technical logs (IP address, browser and device information, timestamps), usage events, and audit-trail entries that record who did what and when inside your workspace. The audit trail exists so that your compliance records are defensible; it necessarily includes the names of the people who act in your account.

We do not ask for, and you should not enter, personal information that the service does not need.

Why we use it

We use personal information only to:

  1. Provide the service you have contracted for: keeping VAT records, preparing filing-ready returns, and maintaining the audit trail that evidences them.
  2. Operate and secure the platform: authentication, fraud and abuse prevention, diagnostics, and support.
  3. Meet legal obligations that apply to us, and support the record-keeping obligations that apply to you under Bahamian VAT law.
  4. Communicate with you about your account, the service, and, only where you have agreed, product news. You can opt out of non-essential email at any time.

We collect personal information fairly and for the purposes stated here, we keep it adequate and not excessive for those purposes, we take reasonable steps to keep it accurate, and we do not keep it longer than the periods described below. Those are the standards the Bahamian data protection regime sets, and they are the standards we hold ourselves to.

What we never do

  • We never sell your personal information or your business records.
  • We never use your records to train artificial-intelligence models. The categorization engine in this product is deterministic and rule-based; your data is not training material.
  • We never display advertising inside the service or share your information with advertisers.
  • Our staff do not access the contents of your workspace except to provide support you have requested, to investigate a security incident, or where the law requires it. Access of that kind is itself logged.

Who we share it with

We use a small number of service providers ("sub-processors") to run the platform. Each processes data only on our instructions and under contractual confidentiality and security commitments:

  • DigitalOcean (cloud hosting)
  • Microsoft Azure (cloud hosting and platform services)
  • Mailgun (transactional email delivery)
  • Cloudflare (network security and content delivery)

We may also share information with professional advisers under confidentiality, and where we are required to by law, a court, or a regulator. If we are ever involved in a merger or sale of the business, records may transfer with it under this policy's protections, and we would notify you.

Where your data lives

The platform runs on infrastructure operated by the providers above, with data stored and processed outside The Bahamas, including in the United States. Where your information leaves The Bahamas, it remains protected by this policy and by our contracts with those providers.

How long we keep it

Retention is layered, because different data serves different obligations:

  • VAT and transaction records, filings, attestations, and the audit trail that evidences them: retained for seven years. Bahamian VAT law sets a shorter statutory minimum for record retention; seven years is our deliberately longer platform policy, because the record is what protects you in an audit. These records are retained even after account closure for the remainder of the period, then deleted.
  • Account personal information (your name, email, credentials, settings): kept while your account is active, then deleted or anonymized within 90 days of account closure, except where it is embedded in the compliance records above (for example, your name inside audit-trail entries), in which case it is retained with those records.
  • Technical logs: kept for up to 90 days and then deleted or aggregated.

When you close your account, you can export your records first; the Terms of Service describe the export window.

How we protect it

Data is encrypted in transit and at rest. Access is role-based and logged. Compliance records are kept in a tamper-evident audit trail, which means changes leave evidence. No system is perfectly secure, and we do not promise otherwise, but security failures are treated as incidents, not inconveniences, and we will notify you of a breach affecting your personal information as the law and good practice require.

Your rights

You may ask us for a copy of the personal information we hold about you, ask us to correct information that is inaccurate, and object to uses of your information that go beyond what this policy describes. Business records that the law requires to be retained cannot be deleted on request during their retention period; that is a feature of a compliance record, not an oversight.

To exercise any of these rights, email privacy@digitalcarib.com. We respond within a reasonable period and never charge for a first request. If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner of The Bahamas.

Children

CoralLedger Comply is a business tool. It is not directed at, and may not be used by, anyone under 18.

Changes to this policy

This policy is versioned. If we make a material change, we will tell you inside the service or by email before it takes effect, and the version number and effective date at the top of this page will change. We will never weaken the "what we never do" section quietly.

Contact

Carib Digital Labs Ltd. Privacy requests: privacy@digitalcarib.com · General support: support@digitalcarib.com