1. Who is responsible for your data?
Pandectis S.à r.l.-S., a company established in Luxembourg and registered with the Luxembourg Trade and Companies Register under number B307680, is the controller of the processing operations described as such in this policy.
- Registered office: 15 rue de l’industrie, L-8069 Bertrange, Luxembourg
- VAT number: LU37551827
- Contact: [email protected]
- Website: pandectis.com
2. Scope and allocation of roles
This policy applies to the website pandectis.com, the Pandectis platform and Pandectis’s relationships with its users, clients, prospects and newsletter subscribers. The service is reserved for adult professionals.
2.1 Pandectis as controller
Pandectis determines the purposes and means of the processing necessary for account management, billing, platform security, support, professional prospecting, the newsletter, strictly technical statistics and the exercise of rights.
2.2 Pandectis as processor for the client
For the content of uploaded documents, queries, conversations and responses generated from the client’s content, the client organisation remains the controller. Pandectis processes such data solely on the client’s instructions, in accordance with the data processing agreement entered into with it.
Where a person mentioned in a client document contacts Pandectis directly, Pandectis forwards the request to the relevant client and assists it. Pandectis does not itself decide on the request, except where required by law or pursuant to a documented instruction from the client.
3. Data processed and sources
3.1 Data provided directly
- Account data: first name, last name, professional address, firm or organisation, role, country and authentication data.
- Contractual and billing data: professional identity and contact details, contract references, invoices and information relating to incoming bank transfers. Pandectis does not collect any payment card data.
- Contact and support data: content of requests, exchanges, voluntarily attached documents and follow-up actions.
- Communication preferences: subscription, unsubscription and objection to the newsletter or solicitations.
- Service content: full text of queries and conversations, generated responses, uploaded documents and associated metadata.
3.2 Data collected during use
Pandectis may collect the IP address, connection dates and times, browser type and operating system used, as well as the technical and security events necessary for the operation and protection of the platform.
Pandectis may also process a pseudonymous user identifier, the history of operations performed, the features or models selected and the volume of use. This information is used to ensure security, technical operation, any usage-based billing and the measurement of feature usage.
Technical usage metrics are not intended to contain the text of documents, queries, conversations or generated responses.
Pandectis also uses the data strictly necessary for the operation of cookies and other session, authentication, security and preference-storage trackers.
3.3 Data obtained indirectly
Professional contact details of prospects may come from demo forms, events, referrals, LinkedIn, professional websites or other publicly available sources. A user’s data may also be transmitted by the administrator of their organisation in order to create their account. Pandectis provides the required information no later than at the time of first contact or within the period provided for by Article 14 of the GDPR.
4. Purposes and legal bases
4.1 Creating and administering accounts; providing the platform
Main data: professional identity, organisation, role, country, authentication data.
Legal basis: performance of the contract where the user contracts directly with Pandectis; legitimate interest of Pandectis and of the client in managing their collaborators’ accounts.
Retention period: for the entire duration of the account and of the contract, subject to legal archiving obligations.
4.2 Providing search, chat and document analysis features
Main data: queries, conversations, imported documents, generated responses, pseudonymised identifier.
Legal basis: processing carried out on the instructions of the client controller under the data processing agreement.
Retention period: until the data are deleted by the user or until the account is closed.
4.3 Billing for services and meeting accounting obligations
Main data: billing details, contractual information, invoices and payment data.
Legal basis: performance of the contract and compliance with accounting and tax obligations.
Retention period: ten (10) years in accordance with applicable legal obligations.
4.4 Ensuring platform security
Main data: event logs, IP addresses, technical metadata and security information.
Legal basis: Pandectis’s legitimate interest in ensuring the security of its services, as well as legal obligations where they apply.
Retention period: in principle twelve (12) months, with longer retention where necessary for the management of an incident, an investigation or litigation.
4.5 Responding to support requests
Main data: contact details, content of exchanges with support, technical information necessary for diagnosis and, where the user voluntarily transmits them, extracts or documents necessary to handle the request.
Legal basis: performance of the contract or Pandectis’s legitimate interest in providing support and ensuring the proper operation of its services.
Retention period: support-related exchanges are retained for three (3) years after the request is closed. Copies of documents, queries, conversations or other client content voluntarily transmitted to support are deleted or made inaccessible as soon as they are no longer necessary for diagnosis, except where longer retention is necessary to handle a security incident, establish evidence of a malfunction or defend rights in legal proceedings.
4.6 Contacting professional prospects
Main data: first name, last name, professional contact details, role, organisation, country, data source and history of exchanges.
Legal basis: depending on the recipient’s country, the nature of the address used and the communication channel, prospecting is based on Pandectis’s legitimate interest or on the prior consent of the individual where required.
In France, prospecting addressed to a professional may in particular be based on legitimate interest where its subject matter is directly related to the professional activity or role of the person contacted. The person is informed of the use of their data and has, from the first message, a simple and free means of objecting to any further solicitation.
In Luxembourg, the sending of an unsolicited commercial email to the personal email address of a natural person is subject to prior consent where required by applicable regulation. An exception may in particular apply where Pandectis obtained the address directly in the context of an existing commercial relationship and offers its own similar services, subject to allowing a simple and free objection at the time of collection and in each communication.
The mere fact that an email address is publicly available does not, in itself, constitute consent to receive commercial communications. Generic organisation addresses and other prospecting channels are used in accordance with the rules applicable to them.
Retention period: three (3) years from collection of the data or from the last contact originating from the prospect. At the end of this period, the data are deleted, with the exception of the minimal information necessary to respect an objection to prospecting.
4.7 Sending the legal newsletter
Main data: email address and communication preferences.
Legal basis: consent of the data subject. Communications strictly necessary for the operation of the service are based on performance of the contract.
Retention period: until consent is withdrawn or after three (3) years of inactivity.
4.8 Handling requests relating to data subject rights and complaints
Main data: identity, request made, any supporting documents required and exchanges.
Legal basis: compliance with legal obligations arising from data protection regulation.
Retention period: three (3) years after the request is closed, except in the event of litigation requiring longer retention.
4.9 Measuring the technical operation and use of the platform
Main data: pseudonymous identifier, features used, technical events, dates and durations of use, device type, browser, operating system and information relating to platform performance.
No document, query text, conversation content or generated response is used for this purpose.
Legal basis: Pandectis’s legitimate interest in measuring the availability, performance and use of its features, detecting malfunctions and improving the technical usability of the platform.
Retention period: technical usage data are retained for as long as necessary for these purposes, up to a maximum of twenty-five (25) months. They are then deleted or aggregated so that they no longer allow a user to be identified.
5. Mandatory data
Fields marked as mandatory when creating an account are necessary to identify the professional user, secure access and provide the service. Their absence may prevent the creation or use of the account. Uploading a document and entering a query are optional, but necessary in order to use the corresponding features.
6. Documents, sensitive data and professional secrecy
Documents, queries and conversations processed through the platform may contain ordinary personal data, special categories of data within the meaning of Article 9 GDPR, data relating to criminal convictions and offences within the meaning of Article 10 GDPR, data concerning minors, financial information or elements protected by a confidentiality obligation or by professional secrecy.
The client organisation remains responsible for the lawfulness of the processing carried out through the platform. It is in particular for the client to ensure that:
- it has an appropriate legal basis and, where necessary, an exception authorising the processing of sensitive or criminal data;
- it complies with its information obligations towards data subjects;
- it limits the data uploaded to what is necessary for its purposes;
- it is authorised to use a cloud provider and the artificial intelligence providers it chooses to enable;
- it complies with the professional and ethical rules applicable to it.
Pandectis processes such content solely in order to provide the service, in accordance with the client’s documented instructions and the data processing agreement entered into with the client. Pandectis does not reuse such content for its own purposes.
The spaces of different clients are separated by means of logical isolation measures. A document is accessible only to users authorised by the client according to the features and settings enabled within its organisation. No public sharing or sharing via an external link is offered, except for a subsequent development expressly enabled by the client and brought to its attention.
Pandectis teams do not access uploaded content in the ordinary course of the service. Exceptional access may nevertheless occur where necessary:
- to respond to a support request in the context of which the user has voluntarily transmitted the relevant content;
- to handle a security incident or a technical malfunction;
- to comply with a legal obligation;
- or pursuant to a documented instruction from the client.
Any exceptional access is limited to specially authorised persons, to the data strictly necessary and to the duration strictly required. It is subject to appropriate security and traceability measures.
7. Artificial intelligence
7.1 Choice of model
Pandectis may offer one or more models operated within an infrastructure located in the European Economic Area as well as, where authorised by the client, models provided by external providers.
Where a model is operated within infrastructure controlled by Pandectis, the content is not transmitted to an external artificial intelligence provider.
The up-to-date list of external providers that may process client content, their role, the relevant processing locations and the applicable safeguards is available in Pandectis’s list of processors or in the contractual documentation provided to the client.
Before an external provider is used, Pandectis makes available to the user information relating to the selected provider, the applicable retention conditions and, where applicable, the existence of a transfer of data outside the European Economic Area.
Only the data necessary to perform the requested feature are transmitted to the selected model.
7.2 Sensitive content
Content that may include special categories of data, criminal data or other information subject to enhanced confidentiality obligations is transmitted only to models and providers whose contractual terms and protective measures are compatible with the processing concerned.
Where an external provider does not offer the necessary safeguards, its use is disabled for the content concerned. Such content must then be processed using a compatible model or a solution operated within infrastructure controlled by Pandectis.
The client remains responsible for classifying the data it processes and for choosing the features or providers it authorises for its organisation.
7.3 No training and no reuse of content
Pandectis does not use documents, queries, conversations or generated responses to train artificial intelligence models or to build datasets intended for training.
Pandectis does not reuse content entrusted by its clients in order to develop products unrelated to the requested service, to carry out commercial profiling or to improve models for its own account.
No human review of content is carried out by default.
Where a user voluntarily transmits an extract, a query, a response or a document to support in order to report a malfunction, such content may be reviewed solely by authorised persons, only to the extent necessary to handle the request and for the duration strictly required.
Pandectis selects professional offerings or application programming interfaces that allow the use of content for training purposes to be excluded where such exclusion is necessary. Where such a guarantee cannot be obtained for a provider or a feature, it is not offered for the processing of the client content concerned.
7.4 Retention by providers
The conditions under which an external provider retains data may vary depending on the provider, the contractual offering, the model, the feature and the configuration actually used.
Some providers may apply temporary retention of inputs and outputs for security, abuse prevention or compliance with legal obligations. The applicable duration is brought to the attention of the client or the user via the interface, the list of processors or the contractual documentation.
Pandectis announces an absence of retention or so-called “zero” retention only where such configuration is actually enabled, contractually guaranteed and applicable to the model and feature concerned.
7.5 Scope of results
The results, summaries and responses provided by Pandectis are informative. They do not constitute legal advice, nor an automated decision concerning a person. They must be verified by a qualified professional. The ranking of results is not personalised on the basis of the individual user’s behaviour.
8. Recipients and providers
Within the limits of their roles and authorisations, data may be accessible to:
- authorised staff members and collaborators of Pandectis;
- providers involved in the hosting, security, availability and maintenance of the platform;
- providers of technical monitoring and measurement of the service’s operation;
- providers of commercial management, billing and support;
- artificial intelligence providers enabled by the client or the user;
- Pandectis’s legal advisers, auditors, insurers, banking institutions and accounting providers;
- administrative, judicial or supervisory authorities where required by law.
Each recipient accesses only the data necessary to perform their role.
Pandectis does not sell the personal data of its users or clients and does not disclose them to third parties so that those third parties can carry out their own commercial prospecting.
8.1 List of processors
The up-to-date list of processors that may process personal data on behalf of Pandectis or its clients is available in the contractual documentation, in the client area or on a dedicated page of the Pandectis website.
This list specifies in particular, as applicable:
- the identity of the provider;
- the nature of the service provided;
- the categories of data that may be processed;
- the main place of processing;
- any transfer outside the European Economic Area;
- the main applicable legal safeguards.
Where a provider processes content entrusted by clients, Pandectis informs the client of any addition or replacement in accordance with the arrangements set out in the data processing agreement, so that the client may exercise the contractual rights available to it.
9. Location and international transfers
Pandectis’s main infrastructure and the content entrusted by clients are hosted within the European Economic Area, principally in France.
Certain providers involved in particular in network security, technical monitoring, support or the provision of artificial intelligence models may nevertheless process data from a country located outside the European Economic Area.
Where an international transfer is carried out, Pandectis ensures that it relies on a mechanism recognised by applicable regulation, in particular:
- an adequacy decision adopted by the European Commission;
- the European Commission’s standard contractual clauses;
- or any other legally recognised transfer mechanism.
Where necessary, these safeguards are supplemented by an assessment of the transfer conditions and by additional technical, organisational or contractual measures.
The choice of a provider by the client or the user constitutes a processing instruction, but does not replace the legal safeguards required for the transfer.
A copy or description of the applicable safeguards may be requested at [email protected], subject to the protection of confidential information, trade secrets and the security measures of Pandectis or its providers.
10. Retention periods
10.1 Account and profile
Retention period: for the entire duration of use of the account and of the contractual relationship.
At expiry: the data are deleted or anonymised, except for those whose retention is necessary to meet legal obligations or to establish evidence of a right.
10.2 Documents, queries and conversations
Retention period: until deleted by the user, deleted by the authorised administrator of their organisation, or until the relevant account is closed.
At expiry: the data are deleted or made permanently inaccessible in active systems within the best technical timeframes and without undue delay.
This deletion also covers technical elements directly derived from the content where they are no longer necessary for the operation of the service.
Any residual copies present in backups are isolated from active systems and deleted according to the normal backup cycle, no later than within thirty (30) days. During this period, they are not restored except where necessary for the continuity or security of the service, in which case the deleted data are erased again as soon as technically possible.
10.3 Data transmitted to an artificial intelligence provider
Retention period: depending on the provider, the contractual offering, the model, the feature and the configuration actually used.
The applicable retention period or criteria are indicated to the client or the user in the interface, in the list of processors or in the contractual documentation before or upon activation of the relevant provider.
An absence of retention or so-called “zero” retention is indicated only where it is actually enabled and applicable to the processing concerned.
At expiry: the data are deleted in accordance with the contractual commitments and retention rules of the selected provider, subject to legally applicable exceptions relating to security, abuse prevention or legal obligations.
10.4 Technical and security logs
Retention period: twelve (12) months in principle.
At expiry: deletion of the logs, except where targeted retention is necessary in connection with a security incident, fraud, litigation or a legal obligation.
10.5 Support-related data
Retention period: exchanges and administrative information relating to a support request are retained for three (3) years after it is closed.
Copies of documents, queries, conversations, generated responses or other client content voluntarily communicated to support are retained only for as long as necessary to handle the request.
At expiry: the data are deleted or anonymised. Client content transmitted for diagnostic purposes is deleted as soon as it is no longer necessary, except where targeted retention is justified by a security incident, litigation, a legal obligation or the need to establish evidence that the request was handled.
10.6 Prospect-related data
Retention period: three (3) years from collection of the data or from the last contact originating from the prospect.
At expiry: the data are deleted, with the exception of the minimal information necessary to retain evidence of an objection to prospecting and to avoid any further solicitation contrary to the person’s choice.
10.7 Newsletter-related data
Retention period: until consent is withdrawn or after three (3) years of inactivity.
At expiry: the data subject is unsubscribed; information relating to the objection may be retained for three (3) years in order to respect that choice.
10.8 Contracts, invoices and accounting records
Retention period: ten (10) years, in accordance with applicable Luxembourg legal obligations.
At expiry: deletion or archiving where required by law.
10.9 Requests relating to the exercise of GDPR rights
Retention period: three (3) years after the request is closed, or longer where litigation so justifies.
At expiry: deletion or archiving limited to the needs of the relevant procedure.
10.10 Cookie preferences
Retention period: six (6) months before the user’s choice is solicited again, unless the user changes their preferences earlier.
At expiry: renewal of the collection of consent or deletion of the recorded preferences.
11. Deletion and end of contract
The user may delete documents, queries and conversations from their space, within the limits of the rights assigned to them by their organisation.
Before the end of the contract or the closure of their account, it is for the client to export the content it wishes to retain using the features made available to it.
Unless otherwise provided contractually, Pandectis does not provide a recovery period after the account closure or termination takes effect. Content is deleted or made permanently inaccessible in active systems without undue delay.
Any residual technical copies contained in backups are isolated and purged according to the backup cycle, no later than within thirty (30) days.
Data that have been transmitted to an external artificial intelligence provider remain subject to the retention conditions indicated for that provider in accordance with Articles 7.4 and 10.3.
Certain data relating to the contract, billing, security or evidence of the parties’ rights and obligations may be retained separately for the periods required or authorised by law.
12. Security
Pandectis implements technical and organisational measures designed to ensure a level of security appropriate to the risks presented by the processing.
These measures include in particular, according to needs and the state of the art:
- encryption of data during transmission and, where appropriate, during storage;
- logical separation of environments and client spaces;
- access control mechanisms based on authorisations and the principle of least privilege;
- strengthened authentication for sensitive access;
- logging and monitoring of technical and security events;
- vulnerability management and patch deployment procedures;
- backup, continuity and restoration arrangements;
- procedures for managing, analysing and notifying personal data breaches;
- confidentiality commitments applicable to persons authorised to process the data.
Detailed security measures and information that could reveal Pandectis’s internal architecture are described in the contractual documentation or the security annex provided to the relevant clients. They are not published where such publication would be likely to compromise the security of the platform or to disclose confidential information.
13. Cookies
Pandectis uses only cookies and other trackers that are strictly necessary for authentication, security, provision of the platform and storage of the user’s technical preferences.
These trackers are not used for advertising, cross-site tracking or the building of an individual commercial profile. Insofar as they are strictly necessary for the operation of the service, their use does not require the user’s consent.
Technically blocking some of these trackers through browser settings may prevent authentication or the normal operation of the platform.
If Pandectis were subsequently to use cookies or trackers that are not strictly necessary, they would be blocked until the user’s consent has been obtained. The user would then have a means of refusing or withdrawing consent as easily as of giving it. This policy and, where applicable, a dedicated cookie policy would be updated accordingly.
14. Your rights
Where Pandectis acts as controller, you may, under the conditions provided for by applicable regulation, request access to the data concerning you, their rectification, erasure, restriction of processing or portability.
You may also object to processing based on Pandectis’s legitimate interest and withdraw your consent at any time where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
You also have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you. Pandectis does not implement such decisions for its own account.
Requests may be sent to [email protected]. Pandectis responds in principle within one month of receipt. This period may be extended under the conditions provided for by regulation where the request is complex or where several requests have been submitted.
Proof of identity limited to the information strictly necessary may be requested where Pandectis has reasonable doubts as to the identity of the person making the request. Any copy of an identity document provided for this purpose is deleted as soon as verification is completed, except where temporary retention is necessary to establish evidence of the response given or in the context of litigation.
Where the request relates to a document or file uploaded by a client organisation for which Pandectis acts as a processor, Pandectis forwards the request to that organisation and provides it with the necessary technical assistance. The client organisation remains responsible for the decision and for the response sent to the data subject.
For persons to whom French law applies, Article 85 of the French Data Protection Act (loi Informatique et Libertés) allows directives to be defined regarding the retention, erasure and communication of their data after their death.
15. Complaints
You may lodge a complaint with the Commission nationale pour la protection des données (CNPD), the Luxembourg supervisory authority competent for Pandectis’s main establishment. You may also contact the authority of your habitual residence or place of work; in France, the Commission nationale de l’informatique et des libertés (CNIL).
16. Changes to the policy
Pandectis may amend this policy in order to reflect changes to its services, processing operations, providers or applicable regulation.
The date of the last update and, where applicable, the effective date of the new version appear at the top of the document.
Where changes are substantial, Pandectis informs users or clients by an appropriate means before they take effect where regulation or the nature of the change so requires.
An amendment to this policy does not allow Pandectis to use data retrospectively for a purpose incompatible with that for which they were initially collected. Where new processing requires consent or additional information, Pandectis completes the necessary formalities before implementing it.