Trust centre

The controls and suppliers behind Pactlyra

A concise starting point for security, privacy and procurement review. Product-specific answers and contractual commitments are confirmed in the order form and DPA.

Security

Subprocessors and AI

Provider classPurposeData/location note
RailwayApplication hostingDeployment region is confirmed for the customer environment.
NeonManaged PostgreSQLDatabase region is confirmed before production onboarding.
Microsoft 365Transactional and support emailMessage metadata and content needed for delivery.
StripePayment processingCard data is entered with Stripe, not Pactlyra.
Configured AI providerOptional drafting assistance outside the evidence pathProvider/model is disclosed before enablement; document content is not used to decide whether a signature counts.

Retention and data location

Agreement records, evidence, audit events and backups follow the customer retention schedule and documented legal-hold requirements. Hosting and database locations, cross-border transfer mechanism and deletion timetable are recorded contractually; they are not inferred from the visitor's location.

DPA and data-protection contact

The DPA is in legal-review draft and is not published. Request it, the current subprocessor schedule, or a security review through [email protected]. Use the same address for data-protection questions.

Related detail: privacy, subprocessors, and retention.