Pactlyra Request early access

Privacy Notice

What Pactlyra holds, why it holds it, where it goes, and the choices available to customers and signers.

Who this notice covers

This notice applies to Pactlyra's website, customer workspace, signing pages, support forms and related services. “Pactlyra”, “we” and “us” mean the service operator identified as the merchant on your checkout receipt, invoice or order form. Questions and privacy requests go to [email protected].

Pactlyra serves two different groups. A customer account holder or workspace member chooses to use the service. A signer or other recipient usually receives an agreement because a Pactlyra customer supplied their email address. The customer is responsible for having a lawful reason to provide recipient information and send the document.

Information we collect

Person or sourceInformation
Website visitor or support contactContact details and the content of a request; consent choices for optional public-site analytics; short-lived security and rate-limit data
Customer account holderName, email address, authentication and session data from Clerk or a chosen identity provider; workspace, role and membership records
Customer workspaceUploaded documents, document versions, templates, recipients, placed fields, workflow state, audit events, usage, API-key hashes, webhook and storage configuration, and support records
Signer or recipientEmail address, optional name, role, routing order, authentication result, timestamps, consent and completion state, and information entered into document fields
Billing contactPlan, seats, usage, invoices, payment status and Stripe customer references; Pactlyra does not receive complete card numbers

Document contents may contain information the customer chooses to upload. Customers should not upload information they do not have authority to process.

Why we use information

We use information to create and secure accounts; provide, route, sign, verify and preserve agreements; deliver transactional messages; operate support; prevent abuse; maintain audit evidence; calculate usage and billing; meet legal obligations; and improve reliability. We do not use signer information for advertising or sell it.

Depending on the person, location and activity, the legal basis may be performance of a contract, steps requested before a contract, the customer's instructions as controller, legitimate interests in operating and securing the service, compliance with law, or consent where the interface specifically asks for it. A customer is normally the controller of the documents and recipient information it submits; Pactlyra normally processes that information on the customer's instructions. Pactlyra acts as controller for its own account, security, billing and support records.

Where information goes

Information is disclosed only to operate the service, follow a customer's configured instruction, protect people or comply with law. Active service providers are listed on the Subprocessor List. A customer may separately direct data to its own webhook or storage destination. Those destinations are controlled by that customer.

Microsoft 365 receives recipient addresses, message content and signing links to deliver transactional email. Clerk and an optional Google identity connection process customer authentication. Stripe processes subscription and payment information. Railway hosts the application and scanner, Neon hosts the production database and snapshots, and Cloudflare provides DNS and enabled edge or security functions.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising. The public website does not load optional analytics until a visitor opts in, and private signing and workspace pages do not use advertising pixels.

International use and transfers

Pactlyra can be reached globally, but its providers may process information outside the country where a user lives. Transfer locations and safeguards depend on the customer's contract, provider account and applicable law. We do not claim a particular adequacy decision, certification or contractual transfer mechanism unless it is documented in the applicable order or data-processing agreement.

Security

Pactlyra uses hashed access credentials and signing links, workspace-scoped authorization, append-only evidence events, upload malware scanning, rate limits, encrypted HTTPS connections and restricted administrative access. Payment-card details are collected by Stripe rather than Pactlyra. No service can guarantee absolute security. Send suspected security issues through the contact form without including passwords, keys, signing links or confidential documents.

Retention

The current retention rules are stated in the Retention Policy. Pactlyra does not presently run automatic lifecycle deletion for agreements, documents, evidence, workspace records or support tickets. Executed agreements and their evidence remain available until a lawful deletion or contractual retention process is implemented or applied. Short-lived authentication, one-time-code and abuse-prevention records expire according to their operational windows. Bounce and complaint suppression records are retained to avoid contacting an address again.

Your choices and rights

Depending on applicable law, a person may request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and may complain to a privacy regulator. Rights are subject to identity verification, the customer's role as controller, other people's rights, evidentiary duties and legal retention exceptions. A signer request may need to be handled by the customer that sent the agreement.

Email [email protected] with “Privacy request” in the subject. State whether you are an account holder, workspace member, signer or support contact and identify the relevant customer or agreement without sending the document itself. Pactlyra will acknowledge the request, verify authority and explain what can be completed. The product does not yet offer a self-service account-erasure workflow, so we will not promise deletion that the system cannot perform.

Children

Pactlyra is a business document service and is not directed to children. A customer account holder must be at least 18 and able to enter a contract. Customers must not intentionally use Pactlyra to collect information from a child unless they have verified that the use and required consent are lawful.

Changes

We will update this notice before materially expanding how personal information is used. The effective date at the bottom identifies the current version. If a change materially affects an account holder, Pactlyra will provide notice through the service or the account email where reasonably practicable.

Effective and last updated 2026-09-21. These pages describe Pactlyra's current production practices. Contact [email protected] with questions or rights requests.