Privacy policy
Pactivo handles names, email addresses, IP addresses and signature images — the raw material of a legal record. This page says exactly what we do with them, why we are allowed to, and what you can ask us to do. In plain English, because you should not need a lawyer to read a privacy policy.
Last updated 9 August 2026
This policy is published so that our processing is transparent from day one. It has been drafted in-house and has not yet been signed off by a qualified solicitor. Highlighted items marked [CONFIRM: …] are open points awaiting legal or business confirmation. If anything here matters to a decision you are making, email hello@pactivo.com and we will answer directly.
1. Who we are
Pactivo is an e-signature platform for UK regulated work — accountancy, legal, property and immigration firms. We are part of the Rajoka portfolio and operate from the United Kingdom.
The legal entity behind Pactivo is [CONFIRM: registered company name, company registration number and registered office address]. Our data protection contact is [CONFIRM: data protection contact name, role and email — and whether a DPO is required under Art 37]. We are registered with the Information Commissioner’s Office under [CONFIRM: ICO registration number].
This policy covers pactivo.com, the console at app.pactivo.com, the signing ceremony at sign.pactivo.com, and our API.
2. Controller, processor, and the third role
Pactivo plays three different roles depending on which data you mean, and which one applies changes who you should approach about it. This is the single most important thing on this page.
For our own account holders — the firms and individuals who sign up for Pactivo. Your account details, billing records, support conversations and product usage are ours to answer for. We decide why and how they are processed.
For the content of an envelope: the documents, the values typed into fields, the signature images and the sender’s covering message. The sending customer is the controller. We act on their instructions and do not use that content for our own purposes.
For the integrity record alone: the hash-chained event metadata around a signature — IP address, user agent, timestamps, consent records and OTP verification records. Pactivo decides what evidence is captured, and no customer can switch it off or alter it. That makes us a controller for it in our own right.
The third role is not a technicality. A tamper-evident record only means anything if the party creating it is not taking instructions on what to record — so the contents of the chain, and the fact that it cannot be edited, are our decision and not the sender’s. That is the core function of the product, and it is why we are a controller for that narrow set of data even though we are only a processor for the document it describes.
Our lawful basis for the evidential record is legitimate interests. Our balancing test, in one sentence: capturing who signed, from where and when is exactly what any signer or sender would expect an e-signature service to do, the data is narrow, technical and never used for profiling, marketing or training, and the alternative — a signature with no evidence behind it — would harm the very people whose data it is.
Senders who need a written data processing agreement can have one — see the data protection section of our terms of service.
3. If you are a signer — where we got your data (Article 14)
You did not give us your details. The firm or person who sent you the document did, when they created the envelope. UK GDPR Article 14 says we have to tell you that plainly, so here it is.
- Where it came from — the sender supplied your name, email address and, where they chose to use a passcode, your mobile number. We did not obtain it from any public source or data broker.
- What we hold — those contact details, whatever you type or draw into the document, and the evidential record of the ceremony: IP address, browser user agent, event timestamps, your consent to sign electronically, and the record of any one-time passcode check.
- Why — to deliver the document to you, let you sign or decline it, and produce a record that shows what happened. For the document itself we act on the sender’s instructions as their processor. For the evidential record we are the controller, relying on legitimate interests as described in §2.
- Who else sees it — the sender and the other parties to the envelope, and the sub-processors in §9. We do not sell it, market to you off the back of it, or use it to train anything.
- How long — see §6. The evidential record is kept for as long as the signed document could reasonably be disputed.
Your rights, and who to ask. For anything about the document — why you were sent it, what it is for, whether it can be deleted — the sending firm is the controller and the right first port of call. We will not delete or alter their envelope content on a signer’s instruction alone, because it is not ours to alter; tell us anyway if you cannot reach them and we will route it to them and confirm that we have. For the evidential record we are the controller, so ask us directly and we will handle it ourselves — see §8.
4. What personal data we handle
Grouped by what it is for, not by which database table it sits in.
- Account data — name, work email address, password (hashed, never stored in readable form), organisation name, role and team membership, and — where you sign in with Rajoka ID — the identifier that links the two accounts.
- Billing data — plan, usage counts and the billing contact. Paid plans are not yet live and Pactivo does not take card payments today. When they launch, card details will be handled by a payment provider and will never touch our servers, and we will name that provider here before the first payment is taken. [CONFIRM: payment provider name, launch date for paid plans, and whether card data is fully out of scope (SAQ-A)]
- Envelope and document content — the files a sender uploads and anything personal inside them. We do not read, mine or train on them.
- Signer identity data — the name, email address and (where used) mobile number the sender supplies for each recipient, plus the name a signer types to confirm intent.
- Signature images — the drawn or typed signature applied to a document, and its placement.
- Evidential metadata — IP address, browser user agent, timestamps for every event (sent, viewed, signed, declined, completed, voided, expired), the consent to sign electronically, and document fingerprints (SHA-256). An IP address can indicate approximate location; we record the address itself and do not currently run geolocation lookups against it.
- Verification records — for one-time passcodes: the channel used, when the code was issued and expired, whether it was verified, and each attempt with its IP address and user agent. Codes themselves are stored only as a hash, never in readable form. The same is true of signing links and API keys.
- Support and enquiry data — what you send us by email or through the contact form.
We do not run identity or document verification checks, and we hold no identity documents or biometric data. Certivus identity binding belongs to the Advanced (AES) tier, which is on our roadmap and not part of the service today; this policy will be updated before any such check processes anyone’s data.
We do not knowingly ask for special category data. Documents sent through Pactivo may contain it — health, immigration or financial detail is common in the work our customers do. Where that happens, the sender is the controller and is responsible for having a lawful basis and an Article 9 condition for it.
5. Why we process it, and our lawful basis
| Purpose | Whose data | Lawful basis |
|---|---|---|
| Running your account and the console | Account holders (senders) | Contract — we cannot give you the service without it. Pactivo is the controller. |
| Envelope content — the documents, the field values, the sender’s message | Signers and other recipients | Pactivo is the processor and acts on the sender’s instructions. The sender is the controller and chooses the lawful basis; usually contract or legitimate interests. |
| Building the evidential record — IP address, user agent, timestamps, consent, OTP checks | Signers, senders | Legitimate interests, with Pactivo as an independent controller — see §2. An e-signature is worthless without evidence that it happened. |
| Transactional email to account holders — service, account and billing notices | Account holders (senders) | Contract. |
| Transactional email to signers — invitations, reminders, confirmations, copies | Signers and other recipients | The sender’s instruction, with Pactivo as processor. Where a message forms part of the evidential record — a completion copy, for example — Pactivo’s legitimate interests. |
| Security, abuse prevention and rate limiting | Everyone | Legitimate interests: keeping the platform and your documents safe. |
| Taking payment and issuing invoices | Account holders | Contract. |
| Keeping accounting records | Account holders | Legal obligation — the Companies Act 2006 and the VAT and tax record-keeping rules. |
| Aggregate analytics on the marketing site | Website visitors | Plausible processes the visitor’s IP address transiently to derive an anonymous daily identifier, and retains no personal data. To the extent any personal data is processed, legitimate interests. |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is what a reasonable person would expect — you cannot have a trustworthy signature without a record of who signed and from where. You can object at any time (see §8) and we will explain our reasoning, stop, or restrict processing where the record itself cannot be altered.
We do not sell personal data, we do not use it for advertising, and we do not use customer documents to train machine learning models.
6. How long we keep it
- Account data — for as long as the account is open, then [CONFIRM: retention period after account closure — proposed 12 months].
- Envelopes and documents — for as long as the sender keeps them. There is no self-serve retention setting today; deletion and export are handled on request. On a valid deletion instruction from the sender, or on account closure, we export or delete within 30 days.
- Completed envelopes and their audit trails — retained as evidence for [CONFIRM: default evidential retention period for completed envelopes — proposed to track the limitation periods under the Limitation Act 1980: section 5, six years for a simple contract, and section 8, twelve years for a deed; confirm per document type]. See §7 for why these cannot simply be edited.
- One-time passcodes — hashed, and expire in minutes. The fact that a check happened stays in the evidential record; the code does not.
- Billing and accounting records — at least six years, because the Companies Act 2006 and the VAT and tax record-keeping rules require it.
- Support correspondence — [CONFIRM: support mailbox retention period — proposed 24 months].
- Server and security logs — [CONFIRM: infrastructure log retention — confirm the Supabase and Vercel log windows actually in force].
Which rule wins. A sender’s deletion instruction overrides the default evidential retention period: if the controller of an envelope tells us to delete it, we delete it and its chain together, even if the default period has not expired. The only exception is where Pactivo is separately required to retain something — a legal obligation, or a live or reasonably anticipated legal claim — in which case we keep only what that requires, tell you we are doing it, and say why.
7. The audit trail, and why it cannot be edited
Every event on an envelope is written to an append-only chain. Each entry carries a SHA-256 hash of the entry before it, so the chain verifies as a whole. Change one byte anywhere in it and verification fails — visibly, and for every entry after it.
That is not a technical curiosity. It is the entire value of the product. A signature is only worth something if the record around it can be shown not to have been touched, including by us. So we designed the system so that we cannot quietly edit or remove a single event, and we will not pretend otherwise when someone asks us to.
What this means in practice:
- We cannot surgically remove one person’s data from a completed envelope’s audit chain. Doing so would destroy the evidential value of the whole record, including for the other people in it.
- We can delete an entire envelope and its chain together, on the sender’s instruction or at the end of its retention period.
- We can restrict processing — keeping the record purely as evidence, and stopping any other use of it — where erasure is not possible.
Whose refusal this is. The position above applies only to the evidential record — the hash-chained event metadata for which Pactivo is the independent controller (§2). Where we decline an erasure request over that record, we rely on UK GDPR Article 17(3): retention necessary for compliance with a legal obligation, and for the establishment, exercise or defence of legal claims. We will always tell you which one, and why, rather than going quiet. [CONFIRM: solicitor to confirm this Art 17(3) position and the wording above]
For envelope content — the document, the field values, the signature image — the decision is not ours to make. The sending customer is the controller; we act on their instruction and will carry out a deletion they instruct. If you ask us to erase envelope content, we route the request to them and tell you we have.
8. Your rights
Under UK GDPR you can ask us to:
- Access — give you a copy of the personal data we hold about you.
- Rectify — correct anything inaccurate or incomplete.
- Erase — delete your data, subject to §7 and to legal retention.
- Restrict — keep the data but stop using it, while a dispute is resolved.
- Port — hand over the data you gave us in a machine-readable format.
- Object — to processing we base on legitimate interests.
- Withdraw consent — where consent was the basis, without affecting what came before.
To exercise any of these, email hello@pactivo.com with enough detail for us to find your data. It is free, and we respond within one month. There is no self-serve export or account-deletion button in the console today — we handle these by hand on request, and action them within 30 days. [CONFIRM: dedicated privacy contact address, e.g. privacy@pactivo.com, and the postal address for written requests]
Signers: who answers. If your request concerns the content of an envelope someone sent you, the sender is the controller — tell us who they are and we will route it to them and confirm to you that we have. If it concerns the evidential record — the event metadata, the consent record, the passcode verification record — we are the controller and we answer it ourselves, subject to §7.
There is no automated decision-making with legal or similarly significant effect in Pactivo. Bot protection may block a request it judges automated; a human will review it if you tell us.
If we get it wrong, you can complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but the right is yours and we will not hold it against you.
9. Who else processes your data
These are the third parties that process personal data on our behalf. The list is complete, and it is the same list published on our trust page — both are generated from one source so they cannot disagree. Each is bound by a written contract that limits them to our instructions.
Planned, and not yet in use. The following are on the roadmap and process no customer data today. Each moves into the list above, with notice, before it handles anything.
We will publish changes to this list here before a new sub-processor starts handling customer data, so that customers with a data processing agreement have a chance to object.
We also disclose data where the law requires it — a court order, a regulator, or a lawful request we are obliged to answer — and to professional advisers under confidentiality. Where such a request covers a customer’s envelope data and the law permits us to say so, we will notify that customer before disclosing, so they can take their own advice. This is the undertaking required by Article 28(3)(a) UK GDPR. If Pactivo is ever sold or reorganised, data moves with the business under the same protections, and we will tell you.
10. Where your data lives
Documents, signatures and audit trails are stored and processed in the United Kingdom — AWS London (eu-west-2), via Supabase. That is the default and it is the point.
There is one exception worth stating plainly rather than burying. Transactional email — the invitation to sign, reminders, confirmations and copies — is delivered by Resend, which operates in the EU and the US. Sending an email necessarily hands the recipient’s name and email address, and the subject and body of that message, to the email provider. So for that narrow purpose, some personal data does leave the UK.
Asking us to email a signer is what puts their name and address in front of the email provider. Envelope documents themselves are not sent to Resend as attachments by default. [CONFIRM: confirm whether signed-copy emails attach the PDF, and whether that behaviour should be configurable]
Where personal data is transferred outside the UK, we rely on [CONFIRM: transfer mechanism — SCCs / UK IDTA / adequacy; confirm per sub-processor and complete a transfer risk assessment]. Cloudflare’s bot protection and Vercel’s hosting network both operate globally; the hosting region actually in force for our application is [CONFIRM: Vercel deployment region — confirm London (lhr1) and that no rendering falls back outside the UK/EU].
12. Security
The measures we take are set out in full on our trust page. In summary:
- TLS 1.3 in transit and AES-256 at rest, across the database and document storage.
- Every record is scoped to an organisation twice over — by database row-level security and by an explicit check in application code.
- Signing links, API keys and one-time passcodes are stored only as hashes. Raw values are shown once and never recoverable.
- Webhook signing secrets are held in an encrypted vault rather than in an application table.
- Role-based access within an organisation, and a fail-closed check on every API call.
- Append-only, hash-chained audit events that cannot be edited or deleted, including by us.
No system is perfect and we will not claim otherwise. What we can say is that the evidential parts of Pactivo are designed so that tampering is detectable rather than merely prohibited.
13. If something goes wrong
If a personal data breach occurs and it is likely to risk people’s rights and freedoms, we report it to the ICO within 72 hours of becoming aware. Where the risk is high, we tell the affected individuals directly and without undue delay.
Where we are the processor — anything inside an envelope — we notify the affected customer without undue delay so that they can meet their own obligations as controller, and we give them what they need to do it.
14. Children
Pactivo is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. A sender may lawfully send a document to a young person in some circumstances; where they do, they are the controller and responsible for that being appropriate.
15. Changes to this policy
We update this policy when what we do changes — a new sub-processor, a new feature, a change of retention. The date at the top always reflects the current version.
For material changes that affect how your personal data is used, we give notice to account holders by email or in the console at least [CONFIRM: notice period for material privacy policy changes — proposed 30 days] before they take effect. Minor clarifications take effect on publication. We keep previous versions and will send you one on request.
16. Contact and complaints
Email hello@pactivo.com or use the contact form. A real person reads it.
Postal address for formal notices: [CONFIRM: registered office address for service of privacy notices]
You can also complain to the Information Commissioner’s Office — Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — at ico.org.uk or on 0303 123 1113.