1In short
- This website collects nothing. pandect.io is a static page. It sets no cookies, runs no analytics, embeds no third-party scripts and has no forms.
- Signing in with Microsoft tells us who you are and nothing more. We request only
openid,profileandemail. We never read your directory, mailbox, calendar or files. - Each customer has its own dedicated instance. Records are not held in a shared database with other customers.
- For the records inside Pandect we are a processor, not the controller. The customer organisation decides what is held and why.
- We do not sell personal data, and we do not use it for advertising or to train machine-learning models.
2Who we are
Pandect is provided by Pandect Systems Limited, a private company limited by shares, registered in England and Wales under company number 17426420.
Registered with the Information Commissioner's Office under registration number [ICO registration number]. Data protection contact: hello@pandect.io. We handle data protection enquiries by email.
3Our two roles
Which rules apply depends on the data, so it is worth being precise.
We are a processor for everything a customer organisation puts into its Pandect instance — entities, officers, appointments, people, ownership, documents and the activity trail. The customer is the controller. It decides what to record, why, and for how long, and we act on its documented instructions under a data processing agreement.
We are a controller for a narrower set: visitors to this website, the business contact details of people we deal with at customer and prospective customer organisations, and the operational records we keep to run and secure the service.
If you are an officer or employee whose details appear in a Pandect register and you want them changed or removed, the organisation that maintains that register is the right first point of contact. It decides; we act on its instruction. We will help you reach them if you are not sure who they are.
4This website
pandect.io is a static site served from Cloudflare's network. It sets no cookies of its own, runs no analytics, contains no tracking pixels and loads no fonts, scripts or images from other domains.
Cloudflare processes the technical details inherent in serving any web page — your IP address, the request, and your browser's user agent — to deliver the page and to protect the site from attack. Cloudflare may set a cookie of its own where it needs to distinguish a person from an automated request. See Cloudflare's own privacy documentation for how it handles that data.
If you email the address on this site, we hold your message and address in order to reply and to keep a record of the correspondence.
5Microsoft Entra ID sign-in
Where a customer enables it, users sign in to Pandect with a Microsoft work or school account. This section describes exactly what that involves.
What we ask Microsoft for
We request three standard OpenID Connect scopes and nothing else:
| Scope | What it gives us |
|---|---|
openid | Confirmation that you signed in, and a durable identifier for your account. |
profile | Your display name. |
email | The email address associated with the account. |
What we do not ask for
We hold no Microsoft Graph permissions. We cannot read your organisation's directory, your mailbox, your calendar, your contacts, your Teams messages or your files, and we cannot act on your behalf in any Microsoft service. Access to Pandect is not granted by Microsoft group membership: a Pandect administrator must grant permissions explicitly inside Pandect, and the system denies anything not granted.
What we keep
From the identity token we store the tenant identifier (tid), the account object identifier (oid), the token issuer and subject, the email address recorded when the account was first linked, and the time you last signed in. Microsoft recommends the tenant and object identifiers as the durable key for an account, which is why we use them rather than the email address — so that a change of name or address does not detach you from your records.
We do not store your Microsoft password, and we do not retain Microsoft access or refresh tokens after sign-in completes. One further value, the sign-in hint, is carried through the session so that signing out of Pandect can tell Microsoft which account to sign out.
Microsoft processes your sign-in as an independent controller under its own privacy statement. Your organisation's Microsoft tenant administrator controls whether Pandect may be used at all.
6Data in the register
Acting as a processor, we hold whatever the customer organisation records. In practice this includes:
- Entities — names, registered numbers and identifiers, legal forms, jurisdictions, addresses, status history.
- People — name, and optionally email address, telephone number, date of birth, nationality and free-text notes.
- Appointments — offices held, the dates they began and ended, and the entity concerned.
- Ownership — shareholdings and the structure derived from them.
- Documents — files uploaded against a record, together with their extracted text where document processing is enabled.
- Activity — who changed what, when, through which channel, and the before-and-after values of the change.
Date of birth and nationality are treated as sensitive within Pandect and are hidden on screen and in the API unless a user holds the specific permission to see them.
Pandect is not designed to hold special category data as defined by the UK GDPR, and customers are asked not to place such data in free-text fields.
7Account and usage data
To run the service we hold each user's name, email address, permission grants, and whether the account is active or has an access expiry. Session records hold an IP address and browser user agent so that a session can be attributed and revoked.
The activity trail records the acting user, the event, a description, the changed values, the channel (web, API or command line) and a correlation identifier. It is designed to be appended to rather than edited, because its purpose is to evidence what happened to a statutory record.
Web server access logs are written with sensitive path segments redacted — invitation tokens, for example, are replaced before the line is stored, and callback query strings are not logged at all.
8Lawful bases
Where we act as a controller we rely on:
- Legitimate interests — running, securing and improving the service, keeping business contact records, and defending legal claims. We have considered these against your interests and rights.
- Contract — providing the service to a customer and administering the relationship.
- Legal obligation — meeting our accounting, tax and regulatory duties.
Where we act as a processor the lawful basis for the register's contents is the customer's to determine and document. For most corporate registers a customer will rely on legal obligation or legitimate interests.
9Where data is held
Each customer's instance runs on a dedicated virtual machine hosted on Microsoft Azure in [Azure region — e.g. UK South]. The database and uploaded documents sit on that machine's own storage. There is no shared application database across customers.
Day-to-day administrative access reaches the server over a private Tailscale network rather than the public internet; public exposure is the exception and is documented per deployment.
International transfers. Where a processor we use handles data outside the UK, we rely on the UK's adequacy regulations or on the International Data Transfer Addendum to the European Commission's standard contractual clauses. [Confirm the position for each provider once regions are fixed.]
10Who else processes it
We keep the list of sub-processors deliberately short.
| Provider | Purpose | Applies |
|---|---|---|
| Microsoft Azure | Hosting of the dedicated customer instance and its storage | Always |
| Microsoft Entra ID | Authentication of users at sign-in | Where federated sign-in is enabled |
| Azure AI Document Intelligence | Extracting text from uploaded documents | Only where document processing is switched on — it is off by default |
| [Transactional email provider] | Delivering service email such as invitations and notifications | Where outbound email is configured |
| Cloudflare | DNS, and serving this public website | Always, for the website |
| Tailscale | Private network access for administration | Always, for operations |
We will give customers notice of a new or replacement sub-processor and an opportunity to object, as set out in the data processing agreement. We do not sell personal data, and we do not use customer content to train machine-learning models.
We may disclose data where the law requires it. Where we are permitted to tell the customer first, we will.
11Retention and erasure
This section deserves care, because Pandect is built to preserve history.
Correction supersedes; it does not overwrite. A statutory register is only useful if it can be read as it stood on a past date, so entries carry the date from which they took effect and superseded values are retained. Correcting a director's name will not, by itself, remove the earlier name from the history.
Erasure is therefore a deliberate operation. Where a customer instructs us to erase personal data, and no legal obligation requires it to be kept, we act on that instruction. Because the effect reaches into historical records, erasure is performed by us on the customer's documented instruction rather than as a self-service action, and we confirm what was removed.
Retention periods. Register content is retained for as long as the customer's subscription continues, and is dealt with on termination as the Terms of Service describe. Backups are retained for [backup retention period] and are overwritten on that cycle, so erased data may persist in a backup until it ages out. Activity records are retained for [activity log retention period]. Our own business records are kept for six years, to meet the accounting record requirements of the Companies Act 2006 and the ordinary limitation period.
12Security
The measures we consider material:
- A dedicated instance, database and storage for each customer.
- Encryption in transit using current TLS.
- Deny-by-default authorisation: a user can do only what has been explicitly granted.
- Sensitive personal fields gated behind a separate permission.
- An append-only activity trail recording who changed what and when.
- Administrative access over a private network, limited to named personnel.
- Agent tokens stored only as hashes, scoped, and expiring.
- Redaction of sensitive values from access logs.
If a personal data breach occurs we will notify affected customers without undue delay and support their own notification duties, and we will report to the Information Commissioner where required.
13Your rights
Under the UK GDPR you may request access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. You may also withdraw consent where consent is the basis.
Where to send a request. If your data is in a customer's register, address the request to that organisation as controller; we will assist it in responding. If the request concerns data we hold as controller — a website visitor, a business contact, or your Pandect account itself — send it to hello@pandect.io.
We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We do not charge unless a request is manifestly unfounded or excessive.
Pandect performs no automated decision-making producing legal or similarly significant effects.
14Changes
The version in force is the one published at this address, identified by the version number and effective date at the top of this page. Where a change materially affects how we handle personal data we will tell affected customers directly.
15Contact and complaints
Please contact us by email at hello@pandect.io. That is the address for privacy enquiries and for requests to exercise your rights; we do not take them by post or by telephone.
If you are unhappy with how we have handled your personal data you may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to resolve it first.