1In short
- This website sets no cookies of its own. pandect.io is a static page. It runs no analytics, embeds no third-party scripts and has no forms. Cloudflare, which serves it, processes the technical details inherent in delivering any page — see section 4.
- Signing in with Microsoft tells us who you are and nothing more. We request only
openid,profileandemail. We never read your directory, mailbox, calendar or files. - Each customer has its own dedicated instance. Records are not held in a shared database with other customers.
- For the records inside Pandect we are a processor, not the controller. The customer organisation decides what is held and why.
- We do not sell personal data, and we do not use it for advertising or to train machine-learning models.
2Who we are
Pandect is provided by Pandect Systems Limited, a private company limited by shares, registered in England and Wales under company number 17426420.
We are registering with the Information Commissioner's Office; our registration number will be published here once it is issued. Data protection contact: hello@pandect.io. We handle data protection enquiries by email.
3Our two roles
Which rules apply depends on the data, so it is worth being precise.
We are a processor for everything a customer organisation puts into its Pandect instance — entities, officers, appointments, people, ownership, documents and the activity trail. The customer is the controller. It decides what to record, why, and for how long, and we act only on its documented instructions.
We are a controller for a narrower set: visitors to this website, the business contact details of people we deal with at customer and prospective customer organisations, and the operational records we keep to run and secure the service.
If you are an officer or employee whose details appear in a Pandect register and you want them changed or removed, the organisation that maintains that register is the right first point of contact. It decides; we act on its instruction. We will help you reach them if you are not sure who they are.
Which law applies. Pandect Systems Limited is established in the United Kingdom, and this statement describes our own processing under the UK GDPR and the Data Protection Act 2018. Where we act as a processor, the law governing the register's contents is the law that applies to the customer organisation as controller, and that organisation publishes its own privacy information to the people whose details it records. Where a customer's data processing agreement addresses a point covered here, that agreement governs for that customer's data. We publish one statement rather than a version for each country, so that there is a single description of what we do.
4This website
pandect.io is a static site served from Cloudflare's network. It sets no cookies of its own, runs no analytics, contains no tracking pixels and loads no fonts, scripts or images from other domains.
Cloudflare processes the technical details inherent in serving any web page — your IP address, the request, and your browser's user agent — to deliver the page and to protect the site from attack. Cloudflare may set a cookie of its own where it needs to distinguish a person from an automated request. See Cloudflare's own privacy documentation for how it handles that data.
If you email the address on this site, we hold your message and address in order to reply and to keep a record of the correspondence.
5Microsoft Entra ID sign-in
Where a customer enables it, users sign in to Pandect with a Microsoft work or school account. This section describes exactly what that involves.
What we ask Microsoft for
We request three standard OpenID Connect scopes and nothing else:
| Scope | What it gives us |
|---|---|
openid | Confirmation that you signed in, and a durable identifier for your account. |
profile | Your display name. |
email | The email address associated with the account. |
What we do not ask for
We hold no Microsoft Graph permissions. We cannot read your organisation's directory, your mailbox, your calendar, your contacts, your Teams messages or your files, and we cannot act on your behalf in any Microsoft service. Access to Pandect is not granted by Microsoft group membership: a Pandect administrator must grant permissions explicitly inside Pandect, and the system denies anything not granted.
What we keep
From the identity token we store the tenant identifier (tid), the account object identifier (oid), the token issuer and subject, the email address recorded when the account was first linked, and the time you last signed in. Microsoft recommends the tenant and object identifiers as the durable key for an account, which is why we use them rather than the email address — so that a change of name or address does not detach you from your records.
We do not store your Microsoft password, and we do not retain Microsoft access or refresh tokens after sign-in completes. One further value, the sign-in hint, is carried through the session so that signing out of Pandect can tell Microsoft which account to sign out.
Microsoft processes your sign-in as an independent controller under its own privacy statement. Your organisation's Microsoft tenant administrator controls whether Pandect may be used at all.
6Data in the register
Acting as a processor, we hold whatever the customer organisation records. In practice this includes:
- Entities — names, registered numbers and identifiers, legal forms, jurisdictions, addresses, status history.
- People — name, and optionally email address, telephone number, date of birth, nationality and free-text notes.
- Appointments — offices held, the dates they began and ended, and the entity concerned.
- Ownership — shareholdings and the structure derived from them.
- Documents — files uploaded against a record, together with their extracted text where document processing is enabled.
- Activity — who changed what, when, through which channel, and the before-and-after values of the change.
Date of birth and nationality are treated as sensitive within Pandect and are hidden on screen and in the API unless a user holds the specific permission to see them.
Pandect is not designed to hold special category data as defined by the UK GDPR, and customers are asked not to place such data in free-text fields.
7Account and usage data
To run the service we hold each user's name, email address, permission grants, and whether the account is active or has an access expiry. Session records hold an IP address and browser user agent so that a session can be attributed and revoked.
The activity trail records the acting user, the event, a description, the changed values, the channel (web, API or command line) and a correlation identifier. It is designed to be appended to rather than edited, because its purpose is to evidence what happened to a statutory record.
Web server access logs are written with sensitive path segments redacted — invitation tokens, for example, are replaced before the line is stored, and callback query strings are not logged at all.
8Lawful bases
Where we act as a controller we rely on:
- Legitimate interests — running, securing and improving the service, keeping business contact records, and defending legal claims. We have considered these against your interests and rights.
- Contract — providing the service to a customer and administering the relationship.
- Legal obligation — meeting our accounting, tax and regulatory duties.
Where we act as a processor the lawful basis for the register's contents is the customer's to determine and document. For most corporate registers a customer will rely on legal obligation or legitimate interests.
9Where data is held
Each customer's instance runs on a dedicated virtual machine hosted on Microsoft Azure. Because each customer has its own machine, the hosting region is chosen per deployment — ordinarily the region nearest that customer — and is recorded in that customer's agreement. A customer that needs its data held in a particular region can be placed there. The database and uploaded documents sit on that machine's own storage. There is no shared application database across customers.
Day-to-day administrative access reaches the server over a private Tailscale network rather than the public internet; public exposure is the exception and is documented per deployment.
International transfers. A customer's instance is held in the region agreed with that customer. Two flows may reach outside it: Microsoft support and engineering access to the underlying platform, and delivery of outbound service email. Where a processor we use handles personal data outside the UK, we rely on the UK's adequacy regulations, or on the ICO's International Data Transfer Agreement, or on the International Data Transfer Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment.
10Who else processes it
We keep the list of sub-processors deliberately short.
| Provider | Purpose | Applies |
|---|---|---|
| Microsoft Azure | Hosting of the dedicated customer instance and its storage | Always |
| Microsoft Entra ID | Authentication of users at sign-in | Where federated sign-in is enabled |
| Azure AI Document Intelligence | Extracting text from uploaded documents | Only where document processing is switched on — it is off by default |
| Postmark | Delivering service email such as invitations and notifications | Where outbound email is configured |
| Cloudflare | DNS, and serving this public website | Always, for the website |
| Tailscale | Private network access for administration | Always, for operations |
We will give customers notice of a new or replacement sub-processor and an opportunity to object. We do not sell personal data, and we do not use customer content to train machine-learning models.
We may disclose data where the law requires it. Where we are permitted to tell the customer first, we will.
11Retention and erasure
This section deserves care, because Pandect is built to preserve history.
Correction supersedes; it does not overwrite. A statutory register is only useful if it can be read as it stood on a past date, so entries carry the date from which they took effect and superseded values are retained. Correcting a director's name will not, by itself, remove the earlier name from the history.
Erasure is therefore a deliberate operation. Where a customer instructs us to erase personal data, and no legal obligation requires it to be kept, we act on that instruction. Because the effect reaches into historical records, erasure is performed by us on the customer's documented instruction rather than as a self-service action, and we confirm what was removed.
Retention periods. Register content is retained for as long as the customer's subscription continues, and is dealt with on termination as the Terms of Use describe. Backups are retained on a rolling cycle and are overwritten as that cycle turns, so erased data may persist in a backup until it ages out; the cycle length for a customer's deployment is recorded in that customer's agreement. Activity records are retained for as long as the register they evidence, because their purpose is to show what happened to a statutory record. Our own business records are kept for six years, which reflects HMRC record-keeping requirements and the ordinary limitation period for a contract claim.
12Security
The measures we consider material:
- A dedicated instance, database and storage for each customer.
- Encryption in transit using current TLS.
- Deny-by-default authorisation: a user can do only what has been explicitly granted.
- Sensitive personal fields gated behind a separate permission.
- An append-only activity trail recording who changed what and when.
- Administrative access over a private network, limited to named personnel.
- Agent tokens stored only as hashes, scoped, and expiring.
- Redaction of sensitive values from access logs.
If a personal data breach occurs we will notify affected customers without undue delay and support their own notification duties, and we will report to the Information Commissioner where required.
13Your rights
Under the UK GDPR you may request access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. You may also withdraw consent where consent is the basis.
Where to send a request. If your data is in a customer's register, address the request to that organisation as controller; we will assist it in responding. If the request concerns data we hold as controller — a website visitor, a business contact, or your Pandect account itself — send it to hello@pandect.io.
We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We do not charge unless a request is manifestly unfounded or excessive.
You may also complain to us about how we have handled your personal data — see section 15.
Pandect performs no automated decision-making producing legal or similarly significant effects.
14Changes
The version in force is the one published at this address, identified by the version number and effective date at the top of this page. Where a change materially affects how we handle personal data we will tell affected customers directly.
15Contact and complaints
Please contact us by email at hello@pandect.io. That is the address for privacy enquiries and for requests to exercise your rights; we do not take them by post or by telephone.
If you are unhappy with how we have handled your personal data, you have the right to complain to us. Write to hello@pandect.io. We will acknowledge your complaint within 30 days, tell you what we are doing about it, and tell you the outcome.
You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. You do not have to come to us first, but we would welcome the chance to put it right.