Skip to content
Schedule V transparency disclosures

Pacten Public Privacy Policy

This Privacy Policy explains how Pacten collects, uses, stores, shares, and retains personal data before you create an account, submit identity documents, or enter an agreement on the platform.

01

Purpose, scope, and identity of the data controller

Scope and platform role. Pacten operates a digital agreement documentation, identity verification, and dispute evidence management platform in Sri Lanka. Under Section 56 of the Personal Data Protection Act No. 9 of 2022 (PDPA), Pacten acts as the Data Controller responsible for determining the statutory purposes and means of processing personal data on the platform.

Schedule V compliance mandate. This document is your official Schedule V Privacy Notice under the PDPA. It provides operational transparency about our data collection, processing, storage, counterparty sharing, and retention practices.

Target audience and legal age. Pacten services are intended exclusively for people aged 18 years or older who have full legal capacity under Sri Lankan law. Accounts created by minors under 18 are prohibited.

02

Personal data we collect and how we collect it

Basic account profile data. When you register an account, we collect your full legal name, email address, mobile phone number, and encrypted authentication credentials. We process this data to perform our core service contract with you under Schedule I Item (b) of the PDPA.

Voluntary NIC verification and masking guidance. To obtain a Verified badge, you may voluntarily submit photos of your National Identity Card (NIC). In line with Section 7 on data minimisation, our mobile camera interface provides real-time masking overlays that prompt you to cover non-essential information, including your home address and physical signature. We extract only your full name, photograph, and NIC number.

Agreement and evidence records. When you draft, execute, or join agreements on Pacten, we process agreement terms, execution timestamps, counterparty identities, mutual digital signatures, and any dispute evidence photos or documents uploaded by agreement parties.

Statshare standing and trust profiling metrics. We compute internal account-standing metrics from objective platform events: total completed agreements, verified identity status, account age, and the ratio of resolved to open or pending disputes.

03

NIC review, pseudonymisation, and the seven-day purge rule

No plaintext document storage. Pacten does not store plaintext identity-card numbers or unencrypted raw document images in persistent database tables.

Manual zero-retention review dashboard. Uploaded front and back NIC images are held in isolated, encrypted AWS S3 quarantine storage (pacten-quarantine). Vetted Pacten review staff check them through a secure dashboard that renders memory-only Blob URLs with dynamic reviewer watermarks showing reviewer ID, timestamp, and IP address. Screen captures, local downloads, and clipboard copies are disabled.

Strict seven-day S3 hard purge. Uploaded NIC images are permanently hard-deleted from S3 quarantine within seven days after an approved or rejected review decision by an automated background process. Pacten maintains no secondary backups or cold-storage archives of raw identity-card images.

HMAC-SHA256 cryptographic identity key. After manual approval, your canonicalised 12-digit NIC number is converted into a non-reversible, unpadded Base64 cryptographic hash using HMAC-SHA256 with a secret pepper managed in AWS Secrets Manager. Plaintext NIC numbers are immediately removed from our database. This supports a one-person, one-account anti-fraud constraint without storing raw ID numbers.

Personal NIC ownership and fraud penalties. Verification is limited to the account holder's authentic government-issued NIC. You must not submit another person's identity document, including that of a spouse, family member, or associate. A third-party NIC, stolen credentials, or fabricated documents may constitute criminal impersonation. Fraudulent attempts can lead to account termination, device blacklisting, referral to the Sri Lanka Police and Department for Registration of Persons, and secure retention of the submitted photos in encrypted quarantine audit logs as legal evidence.

04

Counterparty sharing and Statshare visibility

Real full-name display in agreements. When you initiate, join, or execute an agreement on Pacten, your verified full name, as displayed on your verified account, is shared with the counterparty so both parties can identify who is executing the agreement.

Minimal Statshare standing preview. To help a counterparty assess trust before entering an agreement, Pacten shares a limited version of your Statshare standing tier, such as a trust badge or tier. This limited preview is intended to help prevent fraud while protecting your detailed account history.

Voluntary full Statshare sharing. You may choose to share your detailed Statshare history with another user upon request. You are never required to share your full Statshare profile publicly or with any party.

05

Your responsibility for peer-to-peer identity verification

Platform verification scope. A Pacten verification badge confirms that our manual review team verified the account name against the government identity document presented. Pacten provides a software ledger and does not perform physical, in-person identity checks.

Peer-to-peer verification. Before entering a high-value agreement, you are encouraged to carry out your own identity checks, such as inspecting a physical NIC in person where appropriate. Direct personal verification between individuals falls under the personal and domestic exemption in Section 2(3)(a) of the PDPA.

06

Our neutral platform role

Neutral infrastructure provider. Pacten is a software platform that provides digital agreement documentation, cryptographic audit trails, and platform-level anti-fraud protections.

No legal entity or legal representation role. Pacten is not a law firm, notary public, financial institution, arbitration body, or legal entity that is party to an agreement created on the platform. Pacten assumes no legal, financial, or contractual liability for the performance, breach, enforceability, or dispute outcome of agreements between users.

07

Third-party handling, security, and our commitment not to sell data

Pacten does not sell, rent, monetise, or trade user personal data, profile details, or agreement records to third parties, data brokers, or advertisers.

Personal data is hosted on secure cloud infrastructure in AWS regional data centres in ap-south-1 and ap-southeast-1. We use AES-256 server-side encryption with AWS SSE-KMS at rest and TLS 1.3 in transit. Infrastructure providers operate under binding Data Processing Agreements under Sections 21, 22, and 26 of the PDPA.

08

Data retention schedule and lifecycles

In line with Section 9 of the PDPA, Pacten retains personal data only for as long as needed to fulfil the stated collection purposes.

Data categoryRetention period and purge policy
Raw NIC document imagesPermanently hard-deleted within seven days after an approved or rejected review decision.
Active profile dataRetained while you maintain an active Pacten account.
Agreement and dispute evidence logsRetained for five years after agreement completion or dispute resolution to support statutory limitation periods for legal claims.
HMAC-SHA256 identity keyRetained indefinitely in cryptographic hashed form to enforce one-person, one-account anti-fraud constraints.
09

Your statutory data-subject rights

Right to access. Under Sections 13 and 14, you may request a copy of personal data held by Pacten about your profile and active agreement participation.

Right to rectification. Under Section 15, you may request correction or updating of inaccurate, incomplete, or outdated account profile information.

Right to review automated decisions. Under Section 18, if your agreement-creation privileges are automatically restricted because of Statshare standing calculations, you may request a manual human review.

Right to complain. Under Sections 19 and 35, you may appeal to the Data Protection Authority of Sri Lanka if a data-subject request is refused or handled improperly.

How to exercise your rights. Email privacy@pacten.com with your verified account details. Pacten will acknowledge and fulfil a request free of charge within one month, or 21 working days. Where complex data extraction is needed, we will issue a Section 17 extension notice, which may extend the timeline by up to three months.

Counterparty PII redaction. To protect third-party privacy rights under Section 17(2)(e), generated data-export files automatically sanitise counterparty private email addresses, unshared phone numbers, private dispute-evidence photos, and internal security hashes.

10

Account deletion and account archival

Unencumbered accounts. If your account has no active agreements, completed agreements, or open disputes, we will honour your deletion request and hard-delete personal profile records after a 30-day grace period.

Active ties and multi-party protection. If you are a party to executed agreements, active agreements, or unresolved disputes, immediate hard deletion cannot be granted. Removing records while those agreements or disputes remain active could infringe the legal rights and legal-claim defences of counterparties under Section 17(2)(e) of the PDPA.

Account archival. In these cases, your account moves to archived status. Login access is permanently revoked, credentials are disabled, and the public search profile is hidden. Agreement text and audit trails remain securely preserved in cold storage for the statutory five-year retention period. Full data erasure occurs automatically once active obligations and statutory limitation periods expire.

Impersonation recovery. If someone used your NIC to verify an unauthorised profile, email privacy@pacten.com to begin step-up identity recovery, including a liveness selfie and physical NIC verification. The Data Protection Office will suspend the impersonator account, void unexecuted agreement drafts, blacklist the impersonator device, reassign the verified identity-key hash to you, and refer the matter to police authorities.