1Who we are
Pandect is provided by Pandect Systems Limited, a private company limited by shares, registered in England and Wales under company number 17426420 (“Pandect”, “we”, “us”).
In these terms, “Customer” means the organisation that has contracted with us for the service, and “User” means an individual whom the Customer authorises to use it.
2What these terms cover
These terms govern access to and use of the Pandect software and the associated hosted service. They set the rules that apply to everyone who uses Pandect. They do not set the commercial terms on which Pandect is supplied.
Pandect is supplied to organisations under a separate written agreement. That agreement, together with any order form, service level agreement and data processing agreement made under it, is where fees, term, service levels, data protection terms and the allocation of liability between us and a Customer are settled. Those documents are agreed with each Customer and differ between Customers.
Order of precedence. As between us and a Customer, that Customer's agreement prevails over these terms to the extent of any inconsistency. These terms are not varied by an agreement to which a User is not a party, and continue to apply to every User in all other respects.
By accessing Pandect, a User agrees to these terms. A User who does not agree should not access the service.
3The service
Pandect is a workspace for corporate records: statutory registers, officers and appointments, ownership and group structure, compliance obligations, and the documents and activity history attached to those records.
Dedicated deployment. Each Customer is served by its own dedicated instance, with its own application, its own database and its own storage. Customers are not placed in a shared multi-tenant database. A Customer's records are not commingled with, and are not accessible from, another Customer's instance.
Interfaces. The service is provided through a web interface and a versioned JSON API. Users with the necessary permission may mint scoped, expiring bearer tokens for automated agents. A token carries no more authority than the User who issued it, and the Customer is responsible for tokens issued from its instance.
We may add, change or withdraw features. Where a change materially reduces functionality the Customer relies on, we will give reasonable notice.
4Accounts and access
Provisioning is controlled by the Customer. Accounts are created by a Customer administrator, or by invitation. Pandect operates a deny-by-default authorisation model: a User can perform only what has been explicitly granted.
Microsoft Entra ID. Where a Customer enables federated sign-in, Users authenticate through Microsoft Entra ID. Signing in through Entra does not grant Pandect any authority over a Microsoft account or tenant beyond confirming identity at the moment of sign-in. We request only the openid, profile and email scopes. We do not read a directory, mailbox, calendar or files, and membership of a Microsoft group is never by itself treated as a Pandect permission.
Users must keep credentials confidential and must not share an account. The Customer must tell us promptly of any suspected unauthorised access. We may suspend an account where we reasonably believe it has been compromised or is being used in breach of clause 6 (Acceptable use).
5Customer data
The Customer's data remains the Customer's. We claim no ownership of the records, documents or other content a Customer places in Pandect. The Customer grants us only the limited licence needed to host, process, back up and display that content in order to provide the service.
The Customer is responsible for the accuracy and lawfulness of what it enters, and for having a lawful basis for any personal data it records about officers, shareholders and other individuals.
Our role. In respect of that content we act as a processor on the Customer's documented instructions. How personal data is handled is described in the Privacy Statement, which forms part of these terms.
History is preserved by design. Pandect records change rather than overwriting it: entries carry the date from which they took effect, and superseded values are retained so the register can be read as it stood on a past date. Customers should understand that correcting a record ordinarily supersedes rather than erases the earlier value. Permanent removal is handled as described in the Privacy Statement.
6Acceptable use
A User must not:
- use the service unlawfully, or to store or transmit unlawful content;
- upload material containing malicious code, or attempt to introduce it;
- attempt to gain access to another Customer's instance, or to any account, data or system they are not authorised to reach;
- probe, scan or test the security of the service except with our prior written consent;
- circumvent or attempt to circumvent authentication, authorisation, rate limiting or audit logging;
- reverse engineer, decompile or disassemble the software, except to the extent that this restriction cannot lawfully be excluded;
- resell, sublicense or make the service available to a third party except as the Customer's agreement permits; or
- use the service to build a competing product.
We may suspend access where use presents a material risk to the service, to other Customers, or to us. Where practicable we will give notice first, and we will restore access once the cause is resolved.
7Availability and support
We aim to keep the service available and to make maintenance unobtrusive, but we do not promise that it will be uninterrupted or error free. This page gives no availability commitment. Any committed availability target, support hours, response times or service credits are agreed individually with each Customer in its own agreement, and differ between Customers. If you use Pandect through your organisation, the service levels that apply are the ones in your organisation's agreement, not the ones on this page.
Support is provided to the Customer. A User should raise problems through their own organisation's Pandect administrator.
We may take the service down for planned maintenance, giving reasonable notice where the work is likely to be noticeable. Emergency maintenance may be carried out without notice where security or integrity requires it.
8Security
We maintain technical and organisational measures appropriate to the service, including dedicated per-Customer instances, encryption in transit, deny-by-default authorisation, an append-only activity trail, and administrative access restricted to named personnel over a private network rather than the public internet.
Security is shared. The Customer is responsible for managing its own Users and permission grants, for the security of its Microsoft tenant where federated sign-in is used, and for the custody of any agent tokens issued from its instance.
Suspected vulnerabilities should be reported to hello@pandect.io. Please allow us a reasonable opportunity to remedy an issue before disclosing it.
9Fees and charges
Pandect is licensed to organisations under a separate written agreement. Fees, billing period, payment terms, taxes and any uplift are dealt with in that agreement and not on this page.
No charge is made to an individual User for access granted by their organisation.
10Intellectual property
The Pandect software, its design system, documentation, name and marks belong to us or our licensors. Nothing in these terms transfers any of that to a Customer or User beyond the right to use the service during the term.
Where a Customer or User sends us suggestions or feedback, we may use it to improve the service without obligation or payment. Feedback should not include a Customer's confidential information.
11Confidentiality
Each party may receive information the other treats as confidential. Each will use the other's confidential information only to perform its obligations, will protect it with at least reasonable care, and will not disclose it except to personnel and advisers who need it and are under equivalent duties.
These duties do not apply to information that is public through no breach, was already lawfully held, is independently developed, or must be disclosed by law or a competent authority — and in that last case, the disclosing party will give notice where it is lawful to do so.
12Term and termination
These terms apply while a Customer holds a subscription and while any User accesses the service. Term, renewal and notice periods are governed by the Customer's agreement.
Either party may terminate for material breach that remains unremedied 30 days after written notice, or immediately if the other becomes insolvent.
On termination. Access ends. For 30 days afterwards the Customer may request an export of its data in a machine-readable format. After that period we will delete the Customer's data from live systems, and from backups in accordance with the backup cycle described in the Privacy Statement. We will confirm deletion in writing on request.
Clauses 5 (Customer data), 10 (Intellectual property), 11 (Confidentiality), 13 (Warranties), 14 (Liability) and 16 (Governing law) survive termination.
13Warranties
We warrant that we will provide the service with reasonable care and skill, and that the service will perform materially as described in its documentation.
Beyond that, and to the extent the law allows, the service is provided as is and we exclude all other warranties, whether express or implied. In particular, Pandect is a record-keeping tool and not a source of legal, tax or accounting advice. Compliance calculations, deadline projections and structure charts are aids to the Customer's own judgement. Responsibility for statutory filings and for the accuracy of registers remains with the Customer and its advisers. No output of Pandect is advice, and no one should rely on it as a substitute for their own professional judgement or that of their advisers.
14Liability
Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.
Subject to that, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill or business opportunity, in each case whether direct or indirect.
Subject to the two paragraphs above, each party's total liability arising out of or in connection with these terms is limited to the fees paid by the Customer in the twelve months before the claim arose. That limit is an aggregate across all Users of a Customer's instance, and is not applied separately to each User.
Nothing in this clause limits a Customer's obligation to pay fees due under its agreement, or its liability for breach of clause 6 (Acceptable use).
The Customer will indemnify us against claims arising from content it places in the service that infringes a third party's rights or breaches applicable law.
Where a Customer's agreement states a different limit, or a different allocation of liability, that agreement applies in place of this clause. Nothing on this page increases or reduces the liability allocated by a Customer's agreement.
Each limitation and exclusion in this clause operates separately. If one is held unenforceable, the others continue to apply.
15Changes
We may amend these terms. The version in force is the one published at this address, and the version number and effective date at the top of this page identify it.
Where a change materially affects a User's obligations we will give notice in the service. Change control for a Customer's commercial terms is governed by the Customer's agreement.
An amendment to clause 13 (Warranties) or clause 14 (Liability) does not apply to a Customer, or to that Customer's Users, before the start of that Customer's next renewal term.
16Governing law
These terms and any dispute arising out of them, including a non-contractual one, are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction.
These terms are the entire agreement between us and a User on their subject matter. They do not supersede, vary or limit a Customer’s agreement, which remains the entire agreement between us and that Customer. A person who is not a party has no right to enforce them.
17Contact
Questions about these terms, and any notice given under them, should be sent by email to hello@pandect.io. We do not take enquiries by post or by telephone.
A notice sent by email is treated as given at the time of transmission if sent between 9am and 5pm on a business day, and otherwise at 9am on the next business day. We will give notice to a Customer at the email address it nominates for the purpose.
This clause governs notices under these terms. It does not apply to the service of legal proceedings.