Data Processing Addendum
When you use Pacts to collect acceptances, you decide whose data goes in and why — so you are the controller and we are your processor. This addendum sets out the terms on which we handle that data.
Version 1.5 · Last updated 4 October 2026
1.Roles and scope
This addendum forms part of the Terms of Service. You are the controller of the personal data you upload or generate through the service; Vorcu Labs, LLC is the processor. Where the two conflict, this addendum takes precedence for matters of data protection.
If you use the service as a processor for your own clients, Vorcu Labs, LLC acts as your sub-processor, and you are responsible for holding the instructions and authorisations from your controller that this addendum requires.
It applies to personal data protected by the UK GDPR, the EU GDPR, or comparable legislation. It takes effect when you start using the service and continues while we hold data on your behalf.
2.What is processed
| Detail | |
|---|---|
| Subject matter | Providing the Pacts terms-acceptance service: publishing your terms, delivering personal links, recording acceptances, producing certificates, and keeping on file the agreements you import. |
| Duration | For as long as your account is open, subject to the retention position in section 8. |
| Nature and purpose | Storage, transmission by email, display to designated recipients, the creation of append-only acceptance records, storage of agreements you import, and — when your workspace's AI setting is on — automated extraction of an imported agreement's counterparty, type and dates for you to confirm. |
| Categories of data subject | Your contacts — the individuals you designate to accept terms; contacts of partner organisations granted read-only visibility; the people named in agreements you import; and your own workspace members. |
| Types of personal data | Name, email address, organisation, role or authority, IP address, browser user-agent, acceptance timestamps, the content of the terms you publish, and the contents of agreements you import, which may include personal data about the people named in them, together with the details extracted from them. |
| Special category data | None is required or requested. Do not place special category data in your terms, contact records or imported agreements. If you upload it by mistake, erase the contact or tell us at the address in section 12 and we will help you remove it. |
3.Our instructions
We process personal data only on your documented instructions, which are constituted by the Terms of Service, this addendum, and your use of the product’s features. We will tell you if we believe an instruction breaches data protection law, and we will not use your data for our own purposes — no profiling, no advertising, and no training of machine-learning models.
Automated extraction on import. When your workspace’s AI setting is on — it is on by default and you can turn it off in Settings — importing an agreement instructs us to send the complete PDF to Google Cloud’s Vertex AI service to suggest the counterparty, agreement type and dates. The file may include personal and confidential information beyond the fields extracted; you must be authorised to provide it for this processing. Suggested values may be inaccurate and are recorded only after a member of your workspace confirms them. Neither we nor the provider use your data to train machine-learning models.
If law requires us to process data otherwise, we will inform you first unless that law prohibits it.
4.Confidentiality
Anyone we authorise to access personal data is bound by a duty of confidentiality, and access is limited to those who need it to operate or support the service.
Concretely: staff access to the internal console requires a second authentication factor; designated privileged actions require that factor to have been confirmed within the previous ten minutes; and opening a workspace or a record, and every change made there, is written to a tamper-evident, hash-chained log.
5.Security measures
We implement appropriate technical and organisational measures under Article 32. Concretely, and not as aspiration:
- No client application can read or write the database directly. Database and storage rules deny all direct client access; every operation is mediated by our server, and file uploads use short-lived, server-authorised addresses.
- Acceptance metadata — IP address, user-agent, timestamp, content hash — is captured by our servers. It records what our systems observed, which supports attribution without by itself proving a person's identity or authority.
- Each stored version of your terms carries a SHA-256 hash of its exact content, recomputed and verified whenever a certificate is produced.
- Imported agreements are sealed into storage after upload, their SHA-256 fingerprint is recorded, and the file is checked against it every time it is served.
- Uploaded terms are sanitised against a strict allowlist before storage or display.
- Sessions are HTTP-only, HTTPS-only, expire after 14 days (1 day for our staff), and are revocable — signing out invalidates them server-side.
- One-time email verification codes, on by default, are stored only as hashes, are single-use, expire after 10 minutes, and are attempt-capped.
- Public endpoints are rate-limited. Pages carrying a personal link are excluded from search engines, cannot be framed, and do not leak their address via the referrer header.
- Data is encrypted in transit and at rest by our infrastructure providers.
6.Sub-processors
You give general authorisation for the sub-processors below. We impose data-protection obligations on each of them no less protective than those in this addendum, and we remain liable to you for their performance.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting: serves every page and request, runs our server code and scheduled jobs, and holds the operational logs those produce. | United States |
| Google Cloud / Firebase | Authentication (sign-in credentials and sessions) and the Firestore database where all records are stored. | United States (us-central1) |
| Google Cloud Storage | File storage for agreements you import and for your workspace logo. | United States (us-central1) |
| Google Vertex AI | Model inference on agreements you import, when your workspace's AI setting is on: the PDF is sent to suggest the counterparty, agreement type and dates. Nothing is used to train models. | United States (us-central1) |
| Resend | Delivery of transactional email: acceptance links, reminders, one-time verification codes, and notifications, account emails to workspace owners, and confirmation and change-alert emails to website visitors who ask for them, plus delivery events (delivered, bounced) it reports back to us. | United States |
| Stripe | Payment processing for paid plans: subscriptions, checkout, invoicing and the billing portal. Card details are entered directly with Stripe and never reach Pacts' servers. Stripe also acts as an independent controller for its own fraud-prevention and legal-compliance purposes. | United States |
| PostHog | Product analytics, event tracking, and session recording to understand user workflows and improve the application. Recipient signing surfaces (/a/* and /c/*) are completely excluded from tracking. | United States |
We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you raise a reasonable objection on data-protection grounds, we will work with you to resolve it. If no reasonable solution is available, you may terminate the affected services before the change takes effect, receive a refund of any unused prepaid fees for those services notwithstanding the no-refund wording in the Terms of Service, and use the return and deletion process in section 8.
7.Assisting you
Taking into account the nature of the processing, we will assist you with:
- responding to requests from data subjects exercising their rights — if one contacts us directly about your data, we will confirm who they are and refer the request to you, acting only on your instruction or where the law requires us to;
- data protection impact assessments and prior consultation with a supervisory authority;
- demonstrating compliance, by making available the information needed to do so.
Individual Certificates of Acceptance, as PDF or JSON, are available on every plan, and so is the exit archive — a download of every record, every version of your terms, imported agreements, contacts, companies and verification links. Bulk export of acceptance records and company evidence packs are features of paid plans. Those plan limits do not restrict our obligations to assist with data-protection requests or to return your data under section 8. On closure, the workspace stays readable and the archive downloadable for 90 days before scheduled deletion, subject to lawful restrictions and any legal hold.
8.Deletion and the limits of it
On termination you may export your data: the exit archive and individual certificates on any plan, bulk export and evidence packs on paid plans. The workspace owner closes the workspace from Settings › Account; it stays readable for a 90-day retrieval period, after which a scheduled job deletes the personal data we hold on your behalf — records, contacts, companies, published terms, imported files and logos — except where law requires us to keep it, and except where a legal hold has been placed on the workspace or a record. We keep the payment event records we receive from Stripe and our staff audit log.
Contacts. Removing a contact from active use disables their links and reminders but does not erase their details or existing records. Erasing a contact’s personal data clears their name, email address, search entries and personal link from the contact record and from every open request, campaign send and email-log entry that carried them; acceptance records keep the details recorded at acceptance. You can do both in the app, and we will perform the erasure on your written instruction.
9.Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and we aim to do so within 48 hours. An initial notice may be followed by further information in phases as it becomes available. The notice will describe what happened, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed. We will cooperate with you on containment, preserve the evidence, and not make public statements identifying you without your agreement unless legally required.
10.Audit
On reasonable written request we will provide the information necessary to demonstrate compliance with this addendum, in the first instance as documentation. Where documentation is not sufficient — including for a credible concern about non-compliance, after an incident, or where a supervisory authority or the law requires it — we will cooperate with an inspection by you or an auditor you mandate, on reasonable notice, during business hours, subject to confidentiality and without disrupting the service or exposing other customers’ data.
11.International transfers
Our providers process data in the United States. Where personal data is transferred out of the UK, EEA or Switzerland, the transfer is made under the Standard Contractual Clauses adopted by the European Commission, and the UK Addendum where applicable, together with any supplementary measures required. By entering into this addendum, the parties are deemed to have signed those clauses, with you as data exporter and us as data importer.
12.Contact
Questions, requests and notices under this addendum go to privacy@pacts.io, or by post to 2 Blue Slip, #31L, Brooklyn, NY 11222, United States.
Pacts is not a law firm and does not provide legal advice. These documents describe how the service operates; they are not advice about your own obligations.