Skip to main content

Legal · Privacy

Privacy notice

Pact is built consent-first: every personal record carries an explicit basis for processing, and every export honors the active consent state at the moment the data leaves the platform.

Version 1.0.0 · Effective August 14, 2026

1. Who is responsible

Pact plays two different roles, and which one applies determines who you contact to exercise your rights.

  • For CRM data, Pact is a processor. Contact, account, engagement, and call records are processed on behalf of the customer whose tenant holds them. That customer is the controller and decides why the data is held and for how long. If you are a contact in someone's Pact tenant, your rights run against that organization first; we support them in answering you, and we will route a request we receive directly to the right controller.
  • For our own account and website data, Pact is the controller. That covers the account you sign in with, billing details, support correspondence, and product telemetry.

2. What we collect, and why

We collect the following categories of personal information. Each is collected for the stated purpose and no other; where the basis is consent, the activity does not begin until consent is recorded.

  • Account identity — name, work email, phone number, and authentication credentials. Used to sign you in, secure the account, and contact you about the service. Basis: performance of the contract.
  • CRM records — the contact and company data a tenant loads or captures, including names, business contact details, job titles, and engagement history. Used to provide the CRM itself. Basis: the controller's, on their instruction.
  • Communications content — email and message bodies sent through Pact, and, where the tenant enables it, call recordings and transcripts. Used to deliver the messaging and calling features and the AI summaries the tenant turns on. Basis: consent for recording; contract for the rest.
  • Consent and preference records — the channel, purpose, jurisdiction, lawful basis, and proof of each consent or withdrawal. Used to enforce suppression and to evidence that an activity was authorized. Basis: legal obligation.
  • Usage and device telemetry — pages viewed, features used, IP address, and browser or device type. Used to keep the service running, investigate abuse, and understand which features earn their place. Basis: legitimate interests.

We do not sell personal information, and we do not use tenant CRM content or call content to train AI models.

3. How long we keep it

Retention is enforced by scheduled jobs, not by intention. The periods below are the ones the code applies.

Data classRetentionHow it is applied
Account and user recordsLife of the account, then 30 daysDeleted on account closure after a 30-day grace window during which closure can be reversed.
CRM records (contacts, accounts, opportunities)Controlled by your tenantHeld for as long as the tenant that controls them retains them. Pact does not independently expire tenant business records.
Call recordings and voice transcripts90 days by default; 1 day to 7 years configurablePer-tenant setting with a 30-day grace window before permanent disposal. Recording is off unless the tenant enables it, and callers hear a disclosure.
Audit and security event logs84 months (7 years) by defaultPer-tenant setting. Retained long to support security investigation and the audit trail an assurance report depends on.
AI tool-invocation ledger90 daysOperational troubleshooting and abuse investigation only.
Consent recordsRetained beyond the underlying recordConsent and withdrawal events are an append-only log. They are kept as proof that processing was authorized, which is the only way to evidence a lawful basis after the fact.

When a retention period expires, records are deleted rather than archived. Where a record must survive for a legal reason but its personal content need not, we redact the personal fields and keep the skeleton.

4. Who we share it with

Pact uses sub-processors in these categories: application hosting, managed Postgres database, managed cache, secrets management, CDN and DNS, frontend hosting, transactional email, telephony, and an AI inference provider used only for features a tenant explicitly enables. Each is bound by a data-processing agreement and may process personal data only on our documented instructions.

The current schedule naming each provider, its location, and its certifications is available to customers under their order form — write to legal@pact.place. We give at least 30 days' notice before adding a sub-processor that materially expands the scope of processing, so a customer can object before it takes effect.

We otherwise disclose personal information only where we are legally compelled, and we tell the affected controller unless we are prohibited from doing so.

5. International transfers

Personal data may be processed in the United States and the European Union. Standard Contractual Clauses cover EU-to-US transfers; UK and Swiss addenda are available on request via legal@pact.place. See the Data Processing Addendum for the contractual detail.

6. Your rights

You can ask us to:

  • Access — tell you what personal information we hold about you and give you a copy, including call recordings and transcripts where they exist.
  • Correct — fix information that is wrong or incomplete. Corrections are logged, and we pass them to the controller when the record is theirs.
  • Delete — erase your information, subject to records we must keep by law. Deletion runs on a 30-day grace window and is irreversible after it closes.
  • Port — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, for anything we do on the basis of consent. Withdrawal is as easy as granting it, and it takes effect across sending, segmentation, and export within minutes.
  • Object or restrict — challenge processing we carry out on the basis of legitimate interests.

Signed-in users can exercise access, export, and deletion directly from Profile → Privacy. Everyone else can write to privacy@pact.place. We acknowledge within 5 business days and respond within 30 days; if a request is complex enough to need longer, we tell you why before the 30 days are up. We do not charge for a request, and we do not require an account to make one. We will ask you to verify your identity before we act, because handing data to the wrong person is itself a breach.

7. How we protect it

Data is encrypted in transit with TLS 1.2 or better and at rest with AES-256. Records are scoped to a tenant at the row level and do not cross tenants in queries, exports, AI features, or backups. Access to production data is limited to the people who need it, requires multi-factor authentication, and is logged. Secrets live in a managed secret store, never in source control.

8. Breaches, complaints, and how to reach us

Where Pact is a processor — which is how we handle almost all personal data, on a customer’s instructions — the law requires us to tell that customer “without undue delay” and sets no clock. We commit to a clock anyway: within 72 hours of becoming aware, even if what we know is incomplete. That is our commitment, not the statutory minimum, and it is the same 72 hours written into our DPA. We then support the customer in notifying you where the risk requires it.

Where Pact is the controller, we notify the relevant supervisory authority within 72 hours of becoming aware, and we notify you directly, without undue delay, when the breach is likely to result in a high risk to your rights and freedoms. We do not promise to contact every affected person within 72 hours regardless of risk: that is not what the law asks for, and a promise we could not keep at scale would be worth less to you than one we can.

Privacy questions, complaints, and data subject requests go to privacy@pact.place. The accountable privacy contact is Dean Turetsky, Pact. We would rather hear a complaint directly and fix it, but you also have the right to complain to your local data protection authority, and nothing here removes that right.

9. Changes to this notice

We keep prior versions and record what changed. Where a change materially expands how we use personal information, we notify affected users before it takes effect rather than after.

VersionDateChange
1.0.0August 14, 2026First full notice. Replaces the placeholder that stood at this URL, and states the collection categories, retention periods, and rights process in full.