Skip to main content

Interim draft — prepared for legal review (August 24, 2026).

This document is an honest, plain-language description of our current data practices. It has not yet been reviewed or approved by legal counsel, and items marked [TO CONFIRM: ...] are still being verified. Please do not treat it as final, counsel-approved text. If anything here is unclear or looks wrong, email hello@genledge.ai and we will answer directly.

GenLedge - Privacy Policy

Last Updated: August 24, 2026

This Privacy Policy explains how Cuckoo Technologies Inc., trading as GenLedge ("GenLedge," "we," "us," or "our"), collects, uses, shares and protects personal information in connection with our website at www.genledge.ai.

GenLedge builds AI agents for finance and accounting teams. This policy covers the marketing website — the pages you are reading now, the free AI workshop form, our newsletter sign-up, our booking flow, and the analytics we run on those pages. It does notdescribe any customer platform or product environment; where a customer engagement involves processing data on a client's behalf, that processing is governed by the separate written agreement and data processing terms for that engagement, not by this policy.

We do not collect, request or process mortgage, lending, credit, property or consumer-credit information through this website. We do not sell personal information.

1. Who Is Responsible for Your Data

The controller of personal information collected through this website is:

Cuckoo Technologies Inc. (trading as GenLedge)

United States: Wilmington, Delaware, USA — [TO CONFIRM: full registered office street address and postal code]

Canada: Toronto, Ontario, Canada — [TO CONFIRM: full street address and postal code]

Email: hello@genledge.ai

Phone (US): +1 972 951 2687

Phone (CA): +1 437 873 7345

Website: www.genledge.ai

Privacy questions and requests are handled by our team at hello@genledge.ai. We have not appointed a Data Protection Officer and we are not claiming one. [TO CONFIRM: whether a Data Protection Officer, an EU/UK Article 27 representative, or a Quebec Law 25 "person in charge of the protection of personal information" is legally required for us, and who that person is.]

2. What We Collect and Why

2.1 Free AI Workshop Form

If you request a free AI workshop, the form asks for:

  • Company name
  • Your name
  • Your role or job title
  • Company size (a band, not a precise headcount)
  • Business email address
  • Annual revenue band
  • The accounting software you use
  • Which GenLedge solution you are interested in

The form also contains a hidden "honeypot" field that is invisible to you and is normally only filled in by automated bots. We use it to discard spam submissions. It collects no information about you.

Why: to contact you about the workshop, to prepare for the conversation, and to follow up about our services. We ask for the revenue band, company size and accounting software so the session is relevant to your situation rather than generic.

2.2 Newsletter

If you subscribe to our newsletter we collect your email address, and our email provider records standard delivery and engagement events (for example whether a message was delivered, opened or clicked).

Why: to send you the content you asked for. Every email includes an unsubscribe link, and unsubscribing takes effect for all marketing email.

2.3 Booking a Call

When you move from the workshop form to booking a time, we hand you to Calendly. So that you do not have to type them again, we pass the following details to Calendly in the booking link: your name, your email address, your company name, your company size band, your role and your accounting software. Because these are passed in the URL, they are visible to Calendly and are processed under Calendly's own privacy policy in addition to this one. Anything else you enter while booking — including the time you choose and any notes — is collected by Calendly directly.

2.4 Analytics and Usage Data

When you browse the site, our analytics tools record technical and behavioural data, including:

  • Pages viewed, referring page or campaign, and time on page
  • Approximate location derived from your IP address (typically city or region level)
  • Browser, operating system, device type and screen size
  • Date and time of your visit
  • Events such as clicking a call-to-action or submitting a form
  • A randomly generated identifier stored in a cookie so repeat visits can be recognised

Why: to understand which pages are useful, to measure whether our marketing works, and to find and fix problems. The tools that do this are named in section 5 and described in detail in our Cookie Policy.

2.5 Email and Other Direct Contact

If you email or call us, we keep that correspondence and your contact details so we can respond and keep a record of what was discussed.

2.6 What We Do Not Collect

This website does not ask for and does not knowingly collect: financial account numbers, income, assets, credit history, government-issued identification, dates of birth, property details, payment card data, health data, or any other special-category or sensitive personal information. Please do not send us such information through this site. We also do not read or access your Gmail, Google Calendar or Google Drive from this website.

3. Legal Bases for Processing

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Consent (Art. 6(1)(a)) — for newsletter subscriptions, and for analytics and advertising technologies that are not strictly necessary. You can withdraw consent at any time.
  • Legitimate interests (Art. 6(1)(f)) — for responding to a workshop request or enquiry you sent us, for business-to-business follow-up about the service you asked about, for spam prevention, and for keeping the site secure and working. Our interest is in operating and improving a business service; we weigh it against your privacy, and you can object at any time.
  • Contract (Art. 6(1)(b)) — where processing is necessary to arrange and hold a meeting or engagement you have requested.
  • Legal obligation (Art. 6(1)(c)) — where we must keep or disclose information to comply with the law.

Under PIPEDA and Quebec Law 25 we rely on your consent — express where you complete a form or subscribe, and implied for the limited operational purposes described above. Under Quebec Law 25, consent for non-essential technologies is obtained separately. [TO CONFIRM: the exact consent model to be implemented for Quebec Law 25 alongside the cookie banner.]

We do not use your information for automated decision-making that produces legal effects for you, and we do not profile you for such decisions.

4. Where Your Data Is Stored — International Transfers

Your data is stored in the United States. Enquiries and form submissions from this website are written to Google Firestore in the USA. Our other service providers are also primarily located in the United States.

[TO CONFIRM: the specific Firestore region, and whether any replica exists outside the United States.]

If you are in the EEA or the UK:sending us information involves a transfer of your personal data to the United States. The United States is not covered by a general EU or UK adequacy decision, so such transfers rely on a transfer mechanism such as the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum), or on the EU–US / UK–US Data Privacy Framework where a provider is certified under it. US law may allow government authorities to seek access to data in ways that differ from EEA or UK law, and your ability to obtain redress may be more limited than at home. [TO CONFIRM: which transfer mechanism is in place for each processor listed in section 5, and whether a transfer impact assessment has been completed.]

If you are in Canada: your personal information is stored and processed outside Canada, in the United States, and is therefore subject to the laws of that country, including lawful access requests by US authorities. We tell you this so you can make an informed decision before sending us information.

5. Service Providers Who Process Your Data

We use the third-party providers below. This list is intended to be complete for the marketing website; if you believe something is missing, please tell us.

ProviderWhat it does for usData it can seeLocation
Google Firebase / Firestore (Google LLC)Database that stores workshop and enquiry submissionsAll form fields you submitUSA
Firebase Hosting (Google LLC)Serves this websiteIP address and standard server request logsUSA
Vercel Inc.Hosts the API endpoints that receive form submissionsForm contents in transit, IP address, request logsUSA
Calendly LLCMeeting bookingName, email, company, company size, role, accounting software, plus whatever you enter when bookingUSA
Kit (formerly ConvertKit)Newsletter deliveryEmail address, subscription status, email engagement eventsUSA
Google Analytics 4 (Google LLC) — measurement ID G-VNHB5V4P9YWebsite analyticsPages viewed, events, device and browser data, IP-derived approximate location, a cookie identifierUSA
Meta Pixel (Meta Platforms, Inc.) — pixel ID 1850584372470755Measures the effectiveness of our advertising. Loads on our main marketing pages, not on every page of the site.Page views and events, IP address, browser data, Meta cookie identifiersUSA
track.genledge.ai — our own first-party analytics endpointFirst-party page-view and event tracking served from our own domainPages viewed, events, referrer, IP address, browser dataOur own software, not a third-party analytics product. It runs on a subdomain we control, hosted on Vercel infrastructure, and records the pages visited and the referring site. Because it is first-party, this data is not shared with an external analytics vendor.
ButterCMSStores and serves our blog contentNo lead or contact dataUSA

We require these providers to use your information only to provide their service to us, or as required by law. [TO CONFIRM: whether a signed Data Processing Agreement is in place with each provider listed above.]

We may also disclose information where we are legally required to (a court order, a valid government or regulatory request, or to establish or defend legal claims), where it is needed to investigate fraud, abuse or a security incident, or in connection with a merger, acquisition or sale of assets — in which case we will give notice before your information becomes subject to a different privacy policy.

We do not sell your personal information, and we do not share it with data brokers.

6. How Long We Keep Your Data

We keep personal information only as long as we need it for the purposes described above, or as long as the law requires. Our retention periods are:

  • Workshop and enquiry submissions: 24 months from your last interaction with us. If you contact us again within that period, the clock restarts.
  • Newsletter subscriber records: kept until you unsubscribe or ask us to delete them.
  • Unsubscribe records: after you unsubscribe we keep your email address on a suppression list indefinitely. We need it to make sure we do not email you again, and deleting it would defeat the purpose of your request. Nothing else is retained.
  • Email and phone correspondence: 24 months from the last message, on the same basis as enquiry submissions.
  • Booking records held by Calendly: retained under Calendly's own retention policy for as long as our account is active. We delete our copy on the 24-month schedule above.
  • Analytics data: 14 months, which is the maximum Google Analytics permits. Meta retains pixel data under its own policy, which we do not control.
  • Email verification codes: one hour, after which they expire automatically.

You can ask us to delete your information sooner at any time using the contact details in section 1, and we will act on that request.

7. Security

The measures below are the ones actually in place.

  • Encryption in transit: this site and our form endpoints are served over HTTPS (TLS).
  • Encryption at rest: submissions stored in Google Firestore are encrypted at rest by the platform.
  • Restricted access: access to stored submissions is limited to the small number of people who need it, through individual authenticated accounts.
  • Managed infrastructure: we rely on the platform security of the providers named in section 5 rather than running our own servers.

We hold no SOC 2, ISO 27001 or other security certification, and we do not claim one. No system is completely secure. If we become aware of a breach affecting your personal information we will notify you and the relevant authorities where the law requires it.

8. Your Rights

8.1 EEA and UK (GDPR / UK GDPR)

  • Access — a copy of the personal data we hold about you
  • Rectification — correction of inaccurate or incomplete data
  • Erasure — deletion, subject to legal exceptions
  • Restriction — limiting how we use your data
  • Portability — a machine-readable copy of the data you gave us
  • Objection — to processing based on legitimate interests, and at any time to direct marketing
  • Withdrawal of consent — at any time, without affecting processing already carried out
  • Complaint — to your national data protection authority, or to the UK Information Commissioner's Office

8.2 California (CCPA / CPRA)

  • Right to know — the categories and specific pieces of personal information we collected, where it came from, why we collected it, and who we disclosed it to
  • Right to delete — subject to legal exceptions
  • Right to correct — inaccurate personal information
  • Right to opt out of sale or sharing— we do not sell personal information. We do use analytics and advertising technologies, and use of the Meta Pixel may amount to "sharing" for cross-context behavioural advertising under the CPRA. You can opt out today using the methods in our Cookie Policy. [TO CONFIRM: whether a "Do Not Sell or Share My Personal Information" link and Global Privacy Control handling are legally required for us, and whether the CPRA business thresholds are met.]
  • Right to limit use of sensitive personal information — we do not collect sensitive personal information through this website
  • Right to non-discrimination — exercising these rights will never affect how we treat you

8.3 Canada (PIPEDA)

  • Access to the personal information we hold about you, and to know how it has been used and disclosed
  • Correction of inaccurate or incomplete information
  • Withdrawal of consent, subject to legal or contractual restrictions
  • A complaint to the Office of the Privacy Commissioner of Canada if you are not satisfied with our response

8.4 Quebec (Law 25)

  • Access to and correction of your personal information
  • Portability — a copy of the computerised personal information you gave us, in a structured, commonly used technical format
  • De-indexing / cessation of dissemination — you can ask us to stop disseminating your personal information or to de-index it, where the conditions in the law are met
  • Withdrawal of consent, including consent to non-essential cookies and tracking
  • Information about transfers of your data outside Quebec — see section 4; your data is stored in the United States
  • A complaint to the Commission d'accès à l'information du Québec

8.5 How to Exercise Your Rights

Email hello@genledge.ai with "Privacy" in the subject line, telling us what you would like us to do. You can also call +1 972 951 2687 (US) or +1 437 873 7345 (Canada). You do not need to use any particular form of words.

We will acknowledge your request and respond within the period the applicable law allows — generally one month for GDPR and UK GDPR requests, 45 days for CCPA/CPRA requests, and 30 days under PIPEDA and Quebec Law 25. We may ask for enough information to confirm who you are before we act, and we will use that information only to verify the request. If we cannot fully comply, we will tell you why. Exercising these rights is free; we will tell you in advance if a request is excessive and a fee applies.

9. Cookies and Tracking

We use cookies and similar technologies for essential site functions, analytics and advertising measurement. The specific vendors, purposes, indicative durations and the ways you can opt out today are set out in our Cookie Policy.

To be transparent: this site does not yet show a cookie consent banner, so analytics and advertising technologies currently load when you arrive. A consent mechanism that lets you accept or reject non-essential cookies before they load is being introduced. [TO CONFIRM: target date for the consent banner.] Until then, the browser and vendor opt-outs in the Cookie Policy are the way to stop this tracking.

10. Children's Privacy

This is a business-to-business website. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email hello@genledge.ai and we will delete it promptly.

11. Third-Party Links

Our site links to third-party websites and services, including our LinkedIn page and the booking page hosted by Calendly. Once you follow such a link, that site's own privacy policy applies. We do not control those sites and are not responsible for their practices.

12. Changes to This Policy

When we change this policy we will update the "Last Updated" date at the top of this page. If a change materially affects how we use your personal information, we will give additional notice — a prominent notice on the site, and an email to newsletter subscribers where we hold a valid address — and we will obtain fresh consent where the law requires it. This page is expected to change once the legal review it was drafted for is complete.

13. Contact Us

Questions, concerns or requests about this policy or our data practices:

Cuckoo Technologies Inc. (trading as GenLedge)

Email: hello@genledge.ai

Phone (US): +1 972 951 2687

Phone (CA): +1 437 873 7345

Wilmington, Delaware, USA · Toronto, Ontario, Canada

Website: www.genledge.ai

We would rather hear from you first and put things right. If you are not satisfied with our response, you are entitled to complain to your local data protection or privacy authority.

© 2026 Cuckoo Technologies Inc., trading as GenLedge. All rights reserved.