Privacy Policy
Last Updated: February 1, 2026
Data Controller: Nero L.D. Consulting LTD
Address: Mero 4, Alfe Menashe, Israel 44851
Company Registration: Israel
Privacy Contact: privacy@pactlio.com
Data Protection Officer: dpo@pactlio.com
Definitions
The following definitions apply throughout this Privacy Policy. Capitalized terms used in this policy have the meanings set forth below:
- "Company," "we," "our," or "us" means Nero L.D. Consulting LTD, an Israeli company.
- "Service" means the Pactlio website at pactlio.com and all related applications, tools, and document generation services.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined under GDPR, UK GDPR, CCPA/CPRA, and other applicable data protection laws.
- "Sensitive Personal Information" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation, or (under CCPA/CPRA) government identifiers, precise geolocation, and financial account credentials.
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, dissemination, or erasure.
- "AI Providers" means third-party artificial intelligence services including Anthropic (Claude), OpenAI (GPT), Google (Gemini), and Perplexity that process your data to generate documents.
- "Documents" means the legal document drafts and templates generated through the Service.
- "User" or "you" means any individual or entity that accesses or uses the Service.
1. Introduction and Scope
Nero L.D. Consulting LTD ("Pactlio," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your Personal Data when you use pactlio.com and our AI-powered legal document generation services (the "Service").
This policy applies to all users of our Service, regardless of location. We have designed this policy to comply with applicable privacy laws, including:
- European Union: General Data Protection Regulation (GDPR - Regulation 2016/679)
- United Kingdom: UK GDPR and Data Protection Act 2018
- California: California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Virginia: Virginia Consumer Data Protection Act (VCDPA)
- Colorado: Colorado Privacy Act (CPA)
- Connecticut: Connecticut Data Privacy Act (CTDPA)
- Israel: Protection of Privacy Law, 5741-1981 and Privacy Protection Regulations
- Other applicable data protection laws
Important: Please Read Carefully
By clicking "I Accept" or using our Service, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your Personal Data as described herein, including international data transfers and AI processing. If you do not agree with our data practices, please do not use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Email address, password (securely hashed), and account preferences when you register
- Profile Information: Name, role selection, and optional business information
- Communications: Messages you send to our support team, feedback, and survey responses
2.1.1 Contract and Business Document Data
When you create contracts or business documents, we collect detailed information to generate accurate legal drafts:
Party Information
- Party names (individuals or companies)
- Party type (individual, LLC, corporation, etc.)
- Business addresses
- Jurisdiction/location
- Party role in the agreement (client, provider, discloser, recipient, etc.)
Deal and Financial Terms
- Deal description and scope of work
- Payment type (hourly, fixed fee, milestone-based, retainer)
- Payment amounts and currency
- Payment schedules and milestones
- Deliverables and project timelines
- Effective and termination dates
Legal Terms and Preferences
- Intellectual property ownership preferences
- Confidentiality requirements
- Non-compete and non-solicitation preferences
- Termination notice periods
- Liability limitations
- Governing law and dispute resolution preferences
- Custom terms and special provisions
Founders Agreement Data (Business Formation)
- Founder names, emails, and addresses
- Founder roles (CEO, CTO, COO, etc.)
- Equity percentages and vesting schedules
- Cliff periods and acceleration triggers
- Company information (name, type, state of incorporation)
- Initial capital contributions
Employment/Separation Agreement Data
- Employee name, title, and employment dates
- Severance terms and amounts
- Benefits continuation details
- Release of claims provisions
- Non-disparagement terms
Note: Contract data is used solely to generate your requested documents. This information is processed by our AI providers and stored in our database to allow you to access, edit, and regenerate your documents.
Privacy Policy and DPA Generation Data
When generating privacy policies or data processing agreements for your business, we collect:
- Your business name, type, and contact information
- Description of data you collect from your users/customers
- Third-party services and integrations you use
- Data processing purposes and legal bases
- Data retention periods you implement
- International data transfer mechanisms
- Cookie and tracking technologies you use
This information describes YOUR data practices (not ours) and is used to generate accurate compliance documents for YOUR business.
2.1.2 Will and Estate Planning Data (Highly Sensitive)
Special Category: Estate Planning Documents
Will creation involves particularly sensitive personal information. By using our will generation service, you acknowledge and consent to the collection and AI processing of the following categories:
- Testator Information: Your full legal name, date of birth, current address, marital status, and citizenship
- Beneficiary Information: Names, dates of birth, relationships, and addresses of all named beneficiaries
- Minor Children Data: Names, dates of birth, and relationships of minor children; guardian designations and preferences
- Executor and Trustee Details: Names, addresses, phone numbers, and email addresses of designated executors, alternate executors, and trustees
- Guardian Designations: Names and contact information for guardians appointed for minor children
- Asset Information: Descriptions of real property, financial accounts, personal property, business interests, and their intended distribution
- Digital Asset Information: Information about digital accounts, cryptocurrencies, online businesses, and digital property (we do NOT collect passwords or access credentials)
- Special Instructions: Burial or cremation preferences, charitable bequests, conditional gifts, and other personal wishes
- Family Structure: Information about spouse, ex-spouses, children from previous relationships, and other family members
This information is necessary to generate legally appropriate estate planning documents. All will-related data is processed by our AI systems and stored in our database. See Section 4 for details on AI processing and Section 8 for data retention.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, and time spent on the Service
- Device Information: Browser type and version, operating system, device type, screen resolution
- Log Data: IP address, access times, referring URLs, error logs
- Performance Data: Page load times, response times, and system errors
2.3 Payment Information
Payment processing is handled by our third-party payment processor, Lemon Squeezy. We do NOT store, collect, or have access to your full payment card details. We receive only:
- Confirmation of successful or failed payments
- Last four digits of payment card (for your reference)
- Billing country and postal code (for tax purposes)
- Transaction IDs and amounts
2.4 Sensitive Personal Information
Under CCPA/CPRA, "Sensitive Personal Information" includes specific categories that require additional protections. We generally do NOT intentionally collect the following sensitive categories:
- Social Security numbers or government-issued identifiers
- Financial account numbers with access credentials
- Precise geolocation data
- Racial or ethnic origin
- Religious or philosophical beliefs
- Union membership
- Genetic or biometric data
- Health information
- Sex life or sexual orientation information
- Contents of mail, email, or text messages (other than communications you send to us)
However: You may voluntarily include such information in documents you create. If you do, such information will be processed as part of your document content. We encourage you to minimize sensitive information in documents where possible.
2.5 Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service. See Section 10 and our Cookie Policy for details.
3. How We Use Your Information
3.1 Primary Purposes
We use your information to:
- Provide the Service: Create your account, generate documents, store your data, and deliver requested features
- Process Transactions: Handle payments, send receipts, and manage subscriptions
- Communicate With You: Send service-related announcements, respond to inquiries, and provide customer support
- Improve the Service: Analyze usage patterns, fix bugs, and develop new features
- Ensure Security: Detect and prevent fraud, abuse, and security threats
- Comply With Law: Meet legal obligations, respond to lawful requests, and enforce our terms
3.2 Legal Basis for Processing (GDPR/UK GDPR)
If you are in the EU, UK, or another jurisdiction that requires a legal basis for processing, we process your data based on:
- Contract Performance (Article 6(1)(b)): Processing necessary to provide the Service you requested
- Legitimate Interests (Article 6(1)(f)): Improving our Service, preventing fraud, and direct marketing (where you have not opted out). We have conducted balancing tests to ensure our interests do not override your fundamental rights.
- Legal Obligation (Article 6(1)(c)): Compliance with applicable laws and regulations
- Consent (Article 6(1)(a)): Where you have given specific, informed, freely given, and unambiguous consent (e.g., for marketing emails, optional AI training contribution, and AI processing of your documents)
3.3 Use of Sensitive Personal Information (CCPA/CPRA)
If we process Sensitive Personal Information that you include in your documents, we use it solely for the purposes of providing the document generation Service. We do NOT use Sensitive Personal Information for purposes that require offering you the right to limit use under CCPA/CPRA.
4. AI Processing and Document Generation
Critical Information About AI Processing
Your document content is processed by AI systems to generate legal documents. AI systems can produce errors, inaccuracies, and "hallucinations" (plausible-sounding but incorrect information). You MUST review all AI-generated content before use. By using the Service, you explicitly consent to this AI processing.
4.1 How AI Processing Works
When you create a document, your input is sent to third-party AI providers. The AI processes your input to generate document drafts. Multiple AI systems review the content to improve quality through our multi-agent consensus system:
- Drafter (Claude by Anthropic): Generates initial document drafts
- Critic (GPT by OpenAI): Reviews for gaps, risks, and ambiguities
- Checker (Gemini by Google): Validates legal accuracy and compliance
- Research (Perplexity): Retrieves relevant legal information
4.2 AI Limitations and Disclaimer
Important AI Limitations
- AI-generated content may contain errors, omissions, or inaccuracies
- AI may produce "hallucinations" (confident but incorrect statements)
- AI may not reflect the most current laws or regulations
- AI cannot understand the full context of your specific situation
- AI output is NOT legal advice and does NOT create an attorney-client relationship
- All AI-generated documents are DRAFTS that require human review
4.3 Consent to AI Processing
By using the Service to generate documents, you explicitly consent to:
- Transmission of your input data to third-party AI providers located in the United States
- Processing of your data by multiple AI systems
- Storage of your document content during generation (typically deleted from AI provider systems within 30 days)
- Use of your data to provide the document generation functionality
You may withdraw consent at any time by discontinuing use of the Service and deleting your account. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
4.4 Automated Decision-Making (GDPR Article 22)
Document generation involves automated processing to create drafts. However, this automated processing:
- Does NOT make decisions that produce legal effects concerning you
- Does NOT deny you services or rights
- Produces DRAFTS only, which you must review and decide to use
- Does NOT automatically execute or enforce any agreement
The ultimate decision to use, modify, or discard any AI-generated document rests entirely with you. If you believe automated processing is affecting your rights, contact our Data Protection Officer at dpo@pactlio.com.
4.5 AI Training Policy
Default Setting: We do NOT use the specific content of your documents to train AI models. Your documents remain private and are used only to provide the Service to you.
Anonymized Data: We may use anonymized, aggregated data derived from usage patterns (such as which features are used, error rates, and general document structures) to improve our AI models. This data cannot be used to identify you or reconstruct your documents.
Opt-In Training: If you explicitly consent through your account settings, we may use your documents (with identifying information removed) to improve our models. This consent is:
- Entirely optional and not required to use the Service
- Revocable at any time through your account settings
- Not retroactive (documents processed before opt-in remain private)
4.6 Third-Party AI Providers
We use the following AI providers. Your document content is transmitted to these providers for processing:
| Provider | Purpose | Data Retention | Location |
|---|---|---|---|
| Anthropic (Claude) | Document drafting | 30 days max | US |
| OpenAI (GPT) | Document review | 30 days max | US |
| Google (Gemini) | Document verification | 30 days max | US |
| Perplexity | Legal research and fact-checking | 7 days (cached locally) | US |
4.6.1 Legal Research via Perplexity
To improve the accuracy and jurisdiction-appropriateness of generated documents, we use Perplexity AI to perform legal research. This involves:
- Web Searches: Perplexity performs real-time web searches to retrieve current legal information, regulatory updates, and jurisdiction-specific requirements
- Research Queries: Jurisdiction research queries include document type, jurisdiction, and relevant legal topics — NOT your personal data or document content
- Fact-Checking (Wills): To verify legal accuracy, a redacted copy of your generated will may be sent to Perplexity. Before sending, we replace names, addresses, and dates of birth collected during the interview with placeholders (e.g. [TESTATOR], [BENEFICIARY-1]). General descriptions of gifts or assets you typed may remain in the redacted text
- Local Caching: Research results are cached in our database for 7 days to improve performance and reduce API costs
Each provider processes data under their own privacy policies. We maintain Data Processing Agreements (DPAs) with these providers requiring appropriate data protection measures. Privacy policies:
5. Information Sharing and Disclosure
We do NOT sell your Personal Data to third parties.
We do NOT share your Personal Data for cross-context behavioral advertising purposes.
5.1 Service Providers (Subprocessors)
We share information with third parties that help us operate the Service:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| AWS Cognito | Authentication | Email, password hash, tokens | US (AWS) |
| MongoDB Atlas | Database | Account data, documents | US/EU (configurable) |
| Lemon Squeezy | Payments | Email, payment details | US |
| Resend | Email delivery | Email address, message content | US |
| PostHog | Analytics | Usage data (cookieless) | EU |
| Google Analytics | Analytics (consent required) | Usage data, IP address (anonymized) | US |
| Render | Hosting | All application data | US |
| Anthropic | AI Processing | Document content | US |
| OpenAI | AI Processing | Document content | US |
| AI Processing | Document content | US | |
| Perplexity | AI Research | Legal queries | US |
All service providers are bound by Data Processing Agreements requiring them to process data only as instructed and implement appropriate security measures.
5.2 Other Disclosures
We may also share your information:
- Legal Requirements: When required by law, subpoena, court order, or government request
- Safety and Rights: To protect the safety, rights, or property of Pactlio, our users, or the public
- Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets (you will be notified of any change in ownership or uses of your Personal Data)
- With Your Consent: When you explicitly authorize sharing
6. International Data Transfers
We are based in Israel, which has been recognized by the European Commission as providing adequate data protection under GDPR Article 45. However, some of our service providers, including AI providers, are located in the United States and other countries.
6.1 Transfer Mechanisms (EU/EEA)
For transfers from the EU/EEA to countries without adequacy decisions (including the United States), we rely on:
- Standard Contractual Clauses (SCCs): EU Commission-approved contractual terms (Decision 2021/914) incorporated into our agreements with processors
- Data Processing Agreements: Binding agreements requiring appropriate security measures and limiting data use
- Transfer Impact Assessments (TIAs): We have conducted assessments of transfers to the United States considering the Schrems II judgment and applicable supplementary measures
- Supplementary Measures: Additional technical and organizational safeguards including encryption in transit (TLS 1.3) and at rest (AES-256), pseudonymization where feasible, and access controls
6.2 Transfer Mechanisms (UK)
For transfers from the United Kingdom to countries without adequacy decisions, we rely on:
- International Data Transfer Agreement (IDTA): The UK's approved transfer mechanism
- UK Addendum to EU SCCs: Where we use EU SCCs supplemented by the UK Addendum
- Transfer Risk Assessments: Assessments conducted per ICO guidance
6.3 Transfer Impact Assessment Summary
In accordance with the Schrems II judgment and EDPB recommendations, we have assessed transfers to the United States. Our assessment considers:
- The specific categories of data transferred (primarily document content and account information)
- The purposes of transfer (AI processing for document generation)
- The legal framework in the destination country (including US surveillance laws)
- Supplementary measures implemented (technical, organizational, and contractual)
- The practical effectiveness of these measures
We have concluded that, with the supplementary measures in place, the transfers provide an essentially equivalent level of protection. A summary of our Transfer Impact Assessment is available upon request to dpo@pactlio.com.
6.4 Your Acknowledgment
By using the Service, you explicitly acknowledge and consent to:
- The transfer of your Personal Data to Israel, the United States, and other countries
- Processing by AI providers located in the United States
- That these countries may not provide the same level of data protection as your home country
- The protective measures described in this section
7. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption: TLS 1.3 encryption for data in transit; AES-256 encryption for data at rest
- Authentication: Secure password hashing (bcrypt), session management via AWS Cognito
- Access Controls: Role-based access, principle of least privilege, multi-factor authentication for administrative access
- Monitoring: Security logging, anomaly detection, regular security audits
- Infrastructure: Secure cloud hosting with SOC 2 certified providers
- Development Practices: Secure coding standards, code review, vulnerability testing
Security Disclaimer: While we implement industry-standard security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the security of your account credentials.
7.1 Data Breach Response
In the event of a Personal Data breach that poses a risk to your rights and freedoms, we will:
- Investigate immediately: Our Data Protection Officer will lead the investigation
- Notify supervisory authorities: Within 72 hours of discovery (GDPR requirement) where required
- Notify affected users: Without undue delay where the breach is likely to result in a high risk to your rights and freedoms
- Document the breach: Maintain records of all breaches including facts, effects, and remedial actions
- Implement remediation: Take steps to contain the breach and prevent recurrence
8. Data Retention
8.1 Retention Periods
- Account Data: Retained while your account is active, plus 30 days after deletion request
- Document Content (Contracts): Retained while your account is active, deleted within 30 days of account deletion
- Document Content (Wills): Retained while your account is active. Will drafts and associated sensitive data (beneficiaries, executors, assets) are deleted within 30 days of account deletion
- Legal Research Cache: Research results from Perplexity are cached for 7 days, then automatically deleted
- AI Generation Analytics: Token usage, costs, and generation metadata are retained indefinitely for service improvement (does not include document content)
- Usage Logs: Retained for 12 months for security and analytics purposes
- Payment Records: Retained for 7 years as required for tax and accounting purposes
- Support Communications: Retained for 3 years after resolution
- Terms/Privacy Acceptance Records: Retained for duration of account plus 7 years
- Cookie Consent Records: Retained for 1 year from the date of consent
Note on Will Data Retention
Will documents contain particularly sensitive information about your family, assets, and wishes. While your account is active, this data is stored to allow you to access and update your documents. Upon account deletion, all will-related data including beneficiary information, executor details, and asset descriptions is permanently deleted from our primary database within 30 days. Backup copies may persist for up to 90 days.
8.2 Account Deletion
You can delete your account at any time through your account settings or by contacting support@pactlio.com. Upon deletion:
- Your account will be deactivated immediately
- Your Personal Data and documents will be deleted within 30 days
- Backup copies may persist for up to 90 days before automatic deletion
- Some data may be retained as required by law or for legitimate business purposes (e.g., fraud prevention, legal claims)
- Anonymized, aggregated data that cannot identify you may be retained indefinitely
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your Personal Data:
9.1 Rights for All Users
- Access: Request a copy of your Personal Data
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your data
- Data Portability: Receive your data in a machine-readable format (JSON or CSV)
- Withdraw Consent: Withdraw previously given consent at any time
9.2 How to Exercise Your Rights
You can exercise most rights through your account settings. For additional requests, contact us at:
- Email: privacy@pactlio.com
- Response Time: Within 30 days (may be extended for complex requests)
We may need to verify your identity before processing certain requests. We will not discriminate against you for exercising your privacy rights.
9.3 Global Privacy Control (GPC)
We honor Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we will treat it as a valid opt-out request for:
- Sale of Personal Information (California CCPA/CPRA)
- Sharing for cross-context behavioral advertising (California CCPA/CPRA)
- Targeted advertising (where applicable under state laws)
Learn more about GPC at globalprivacycontrol.org.
10. Cookies and Tracking Technologies
10.1 Cookies We Use
| Cookie Type | Purpose | Duration | Required? |
|---|---|---|---|
| Authentication | Login session (accessToken, refreshToken, idToken) | 1 hour - 30 days | Yes |
| Consent | Record of cookie/terms acceptance | 1 year | Yes |
| Preferences | Theme, UI settings | 1 year | No |
| Analytics (PostHog) | PostHog (cookieless/memory mode) | Session only | No |
| Analytics (Google) | Google Analytics (_ga, _gid) - only with consent | _ga: 2 years, _gid: 24 hours | No |
| Cookie Consent | Your cookie preferences (pactlio_cookie_consent) | 1 year | Yes |
10.1.1 Google Analytics (Consent Required)
Google Analytics cookies are only set if you give explicit consent through our cookie banner. These cookies help us understand how visitors use our Service:
- _ga: Distinguishes unique users (2-year duration)
- _gid: Distinguishes unique users within 24 hours
If you decline analytics cookies, Google Analytics will not be loaded and no tracking cookies will be set. You can change your preference at any time via our Cookie Settings.
10.2 Cookie Consent
When you first visit our Service, you will see a cookie consent banner that allows you to:
- Accept all cookies
- Accept only essential cookies
- Customize your preferences
Essential cookies are required for the Service to function and cannot be disabled. You can change your cookie preferences at any time through your account settings or by clearing your browser cookies.
10.3 Your Cookie Choices
You can manage cookies through your browser settings. Note that disabling certain cookies may affect functionality. For more details, see our Cookie Policy.
11. Additional Information for EU/UK Users (GDPR)
11.1 Additional Rights
If you are in the EU or UK, you also have the right to:
- Restrict Processing: Request limitation of processing in certain circumstances
- Object to Processing: Object to processing based on legitimate interests, including profiling
- Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce legal effects concerning you (see Section 4.4)
- Lodge a Complaint: File a complaint with your local data protection authority
11.2 Data Protection Authorities
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local supervisory authority:
- EU: Find your authority at EDPB Members
- UK: Information Commissioner's Office (ICO)
11.3 Data Protection Officer
Our Data Protection Officer can be contacted at: dpo@pactlio.com
The DPO is responsible for overseeing our data protection strategy, ensuring GDPR/UK GDPR compliance, serving as the point of contact for supervisory authorities, and coordinating our breach response procedures.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
12.1 Your California Rights
- Right to Know: Request disclosure of the categories and specific pieces of Personal Information collected, sold, or disclosed
- Right to Delete: Request deletion of Personal Information we hold (subject to exceptions)
- Right to Correct: Request correction of inaccurate Personal Information
- Right to Opt-Out of Sale/Sharing: We do NOT sell or share your Personal Information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: Request limitation of use of Sensitive Personal Information to purposes necessary to provide the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
12.2 Categories of Personal Information Collected
In the past 12 months, we have collected the following categories of Personal Information:
| Category | Examples | Business Purpose |
|---|---|---|
| Identifiers | Email address, account name, IP address | Account creation, security |
| Commercial information | Purchase history, subscription status | Billing, service delivery |
| Internet activity | Usage logs, browsing on our Service | Improve Service, security |
| Professional information | Business role, company name | Personalization |
| Inferences | Preferences, feature usage patterns | Improve Service |
| Sensitive PI (if provided in documents) | As described in Section 2.4 | Document generation only |
12.3 Sale and Sharing Disclosure
We do NOT sell your Personal Information. We do NOT share your Personal Information for cross-context behavioral advertising purposes. We have not sold or shared Personal Information in the past 12 months.
12.4 Financial Incentive Programs
We do not offer financial incentives (e.g., price differences, discounts) in exchange for the retention, sale, or sharing of Personal Information.
12.5 Authorized Agent
You may authorize an agent to submit requests on your behalf. We require written authorization signed by you and verification of both your identity and the agent's authority.
12.6 "Do Not Sell or Share" Link
Because we do not sell or share Personal Information, we do not display a "Do Not Sell or Share My Personal Information" link. However, we honor GPC signals as described in Section 9.3.
13. Other US State Privacy Laws
13.1 Virginia Consumer Data Protection Act (VCDPA)
If you are a Virginia resident, you have the right to:
- Access your Personal Data
- Correct inaccuracies
- Delete your Personal Data
- Obtain a copy in a portable format
- Opt out of targeted advertising, sale of Personal Data, and profiling
To exercise your rights, contact privacy@pactlio.com. If we decline your request, you may appeal by emailing dpo@pactlio.com. If unsatisfied with the appeal response, you may contact the Virginia Attorney General.
13.2 Colorado Privacy Act (CPA)
If you are a Colorado resident, you have similar rights to Virginia residents, plus:
- Right to opt out of processing for purposes of targeted advertising
- Right to opt out of sale of Personal Data
- Right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects
We honor universal opt-out mechanisms including Global Privacy Control. Appeals may be directed to dpo@pactlio.com, with further recourse to the Colorado Attorney General.
13.3 Connecticut Data Privacy Act (CTDPA)
If you are a Connecticut resident, you have similar rights to Virginia residents. Appeals may be directed to dpo@pactlio.com, with further recourse to the Connecticut Attorney General.
14. Israeli Privacy Law Compliance
As an Israeli company, we comply with Israel's Protection of Privacy Law, 5741-1981 and related regulations:
- Database Registration: Our user database is registered with the Israeli Privacy Protection Authority as required
- Data Subject Rights: Israeli residents have rights similar to GDPR rights including access, correction, and deletion
- Security Requirements: We implement security measures in accordance with the Privacy Protection (Information Security) Regulations
- Cross-Border Transfers: Israel has an adequacy decision from the EU, allowing transfers from the EU without additional safeguards
Israeli residents may contact the Privacy Protection Authority at www.gov.il/en/departments/privacy_protection_authority with complaints.
15. Children's Privacy
Our Service is not intended for users under 18 years of age. We do not knowingly collect Personal Data from children under 18. If we become aware that we have collected Personal Data from a child under 18, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us at privacy@pactlio.com.
16. Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
- Material Changes: We will notify you by email and/or prominent notice on the Service at least 30 days before material changes take effect. For material changes affecting how we process your Personal Data or your rights, we may require you to re-accept the updated policy.
- Minor Changes: Will be reflected by updating the "Last Updated" date
- Continued Use: Your continued use of the Service after changes constitutes acceptance of the updated policy, except where re-acceptance is required
We encourage you to review this policy periodically. The current version will always be available at pactlio.com/privacy.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Nero L.D. Consulting LTD
Mero 4, Alfe Menashe, Israel 44851
Privacy Inquiries: privacy@pactlio.com
Data Protection Officer: dpo@pactlio.com
General Support: support@pactlio.com
Website: https://pactlio.com
We aim to respond to all privacy inquiries within 30 days. For GDPR/UK GDPR requests, we will respond within one month (extendable by two months for complex requests). For urgent matters, please indicate so in your subject line.
By clicking "I Accept" on our Terms of Use or using Pactlio, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your Personal Data as described herein.
Effective Date: February 1, 2026