Skip to content
Schedule V transparency disclosures

Pacten Public Privacy Policy

This Privacy Policy explains how Pacten handles personal data when you visit our public website, send feedback, create an account, submit identity documents, or enter an agreement on the platform.

01

Purpose, scope, and identity of the data controller

Scope and platform role. Summit Logic (Private) Limited operates Pacten and is the Data Controller responsible for determining the purposes and means of processing personal data through Pacten.

Schedule V compliance mandate. This document is your official Schedule V Privacy Notice under the PDPA. It provides operational transparency about our data collection, processing, storage, counterparty sharing, and retention practices.

Target audience and legal age. Pacten services are intended exclusively for people aged 18 years or older who have full legal capacity under Sri Lankan law. Accounts created by minors under 18 are prohibited.

02

Personal data we collect and how we collect it

Basic account profile data. When you register an account, we collect your full legal name, email address, mobile phone number, and encrypted authentication credentials. We process this data to perform our core service contract with you under Schedule I Item (b) of the PDPA.

Voluntary NIC verification and masking guidance. To obtain a Verified badge, you may voluntarily submit photos of your National Identity Card (NIC). In line with Section 7 on data minimisation, our mobile camera interface provides real-time masking overlays that prompt you to cover non-essential information, including your home address and physical signature. We extract only your full name, photograph, and NIC number.

Agreement and evidence records. When you draft, execute, or join agreements on Pacten, we process agreement terms, execution timestamps, counterparty identities, mutual digital signatures, and any dispute evidence photos or documents uploaded by agreement parties.

Account-standing and trust indicators. We derive a standing tier from relevant account activity and verification information. The tier may be shown to a counterparty as a limited trust indicator and may affect access to agreement-creation features. You may request human review of a restriction.

03

Identity review, pseudonymisation, and document deletion

Raw identity data. Pacten does not retain plain identity-card numbers or unencrypted document images for routine platform use.

Restricted manual review. Identity-document images are encrypted and available only to authorised reviewers for the verification decision. Access is logged and subject to technical and organisational safeguards.

Document deletion. Uploaded identity-document images are deleted within seven days after an approved or rejected review decision, unless limited retention is required to investigate suspected unlawful use or comply with a legal obligation. Any exceptional retention is access-restricted and ends when the relevant purpose or obligation expires.

Pseudonymous identity control. After approval, the identity-card number is transformed using a keyed one-way process so Pacten can enforce a one-person, one-account control without retaining the plain number for routine use.

Personal NIC ownership and fraud response. Verification is limited to the account holder's authentic government-issued NIC. You must not submit another person's identity document or a fabricated, modified, or stolen document. Suspected fraud may lead to verification refusal, account restriction or termination, preservation of evidence where legally required, and referral to the appropriate authorities.

04

Counterparty sharing and Statshare visibility

Real full-name display in agreements. When you initiate, join, or execute an agreement on Pacten, your verified full name, as displayed on your verified account, is shared with the counterparty so both parties can identify who is executing the agreement.

Minimal Statshare standing preview. To help a counterparty assess trust before entering an agreement, Pacten shares a limited version of your Statshare standing tier, such as a trust badge or tier. This limited preview is intended to help prevent fraud while protecting your detailed account history.

Voluntary full Statshare sharing. You may choose to share your detailed Statshare history with another user upon request. You are never required to share your full Statshare profile publicly or with any party.

05

Your responsibility for peer-to-peer identity verification

Platform verification scope. A Pacten verification badge confirms that our manual review team verified the account name against the government identity document presented. Pacten provides a software ledger and does not perform physical, in-person identity checks.

Peer-to-peer verification. Before entering a high-value agreement, you are encouraged to carry out your own identity checks, such as inspecting a physical NIC in person where appropriate. Direct personal verification between individuals falls under the personal and domestic exemption in Section 2(3)(a) of the PDPA.

06

Our neutral platform role

Neutral infrastructure provider. Pacten is a software platform that provides digital agreement documentation, cryptographic audit trails, and platform-level anti-fraud protections.

No legal entity or legal representation role. Pacten is not a law firm, notary public, financial institution, arbitration body, or legal entity that is party to an agreement created on the platform. Pacten assumes no legal, financial, or contractual liability for the performance, breach, enforceability, or dispute outcome of agreements between users.

07

Third-party handling, security, and our commitment not to sell data

Pacten does not sell, rent, monetise, or trade user personal data, profile details, or agreement records to third parties, data brokers, or advertisers.

We use contracted hosting, storage, communications, security, and support providers to process data on our instructions. Appropriate technical and organisational safeguards protect data in storage and transit. Some providers may process data outside Sri Lanka, subject to contractual and legal safeguards required by the PDPA.

08

Data retention schedule and lifecycles

In line with Section 9 of the PDPA, Pacten retains personal data only for as long as needed to fulfil the stated collection purposes.

Data categoryRetention period and purge policy
Raw NIC document imagesPermanently hard-deleted within seven days after an approved or rejected review decision.
Active profile dataRetained while you maintain an active Pacten account.
Agreement and dispute evidence logsRetained for five years after agreement completion or dispute resolution to support statutory limitation periods for legal claims.
Pseudonymous identity identifierRetained in pseudonymous form while needed to enforce the one-person, one-account anti-fraud control.
09

Your statutory data-subject rights

Right to access. Under Sections 13 and 14, you may request a copy of personal data held by Pacten about your profile and active agreement participation.

Right to rectification. Under Section 15, you may request correction or updating of inaccurate, incomplete, or outdated account profile information.

Right to review automated decisions. Under Section 18, if your agreement-creation privileges are automatically restricted because of Statshare standing calculations, you may request a manual human review.

Right to complain. Under Sections 19 and 35, you may appeal to the Data Protection Authority of Sri Lanka if a data-subject request is refused or handled improperly.

How to exercise your rights. Email contact@pacten.lk with your verified account details. Pacten will acknowledge and fulfil a request free of charge within one month, or 21 working days. Where complex data extraction is needed, we will issue a Section 17 extension notice, which may extend the timeline by up to three months.

Protection of other people. A data-access response may omit or redact information where disclosure would adversely affect another person’s rights or reveal security-sensitive information, as permitted by law.

10

Account deletion and account archival

Unencumbered accounts. If your account has no active agreements, completed agreements, or open disputes, we will honour your deletion request and hard-delete personal profile records after a 30-day grace period.

Active ties and multi-party protection. If you are a party to executed agreements, active agreements, or unresolved disputes, immediate hard deletion cannot be granted. Removing records while those agreements or disputes remain active could infringe the legal rights and legal-claim defences of counterparties under Section 17(2)(e) of the PDPA.

Account archival. In these cases, your account moves to archived status. Login access is permanently revoked, credentials are disabled, and the public search profile is hidden. Agreement text and audit trails remain securely preserved for the stated retention period. Full data erasure occurs once active obligations and applicable retention periods expire.

Impersonation recovery. If someone used your NIC to verify an unauthorised profile, email contact@pacten.lk. We will verify the request, secure affected accounts, correct or restrict relevant records, preserve evidence where legally required, and cooperate with the appropriate authorities when necessary.

11

Public website visits, enquiries, and feedback

Website scope. These website-specific disclosures apply to the public Pacten marketing website. You do not need an account to read its pages. Account authentication, identity verification, agreement records, and dispute evidence belong to the separate Pacten application and are covered by the platform sections above.

Feedback you choose to send. When feedback collection is available and you submit the website form, we collect your selected use-case category, any message you provide, your email address if supplied, the page language, whether you submitted from the homepage or contact page, and the submission time. We use this information to understand potential uses, assess feature requests, improve Pacten, and respond where appropriate. Supplying an email is optional and does not subscribe you to advertising emails.

Sensitive information. Please do not submit identity documents, passwords, payment details, private agreement evidence, or another person's personal information through the public feedback form. For privacy requests, use contact@pacten.lk. You do not need a verified account to ask about information collected through this website.

Feedback retention. Where the website feedback service is enabled, submitted records are retained for up to 365 days. This period applies to the feedback record and not necessarily to separate email correspondence or security logs. You can email contact@pacten.lk about access, correction, or deletion of your feedback.

12

Website service providers and technical information

Hosting and delivery. Contracted website-hosting and security providers process technical request information such as IP address, requested URL, request time, browser information, and security signals to deliver and protect the website. This is separate from information you deliberately enter in the feedback form.

Feedback processing. When the website feedback service is enabled, a contracted provider processes and stores the submission on our instructions. The feedback record itself does not separately store a visitor IP-address or browser user-agent field, although infrastructure providers may process technical request data for delivery and security.

Processing location. Website providers may operate international networks, so website-related processing may take place outside Sri Lanka. We use the contractual and legal safeguards required for such processing and do not represent that all website data remains in Sri Lanka.

Fonts and external links. Website fonts and illustrations are served as site assets; displaying them does not require a request to Google Fonts. Links to the Pacten app and other websites take you to services with their own data-handling arrangements. Following a link is different from embedding a tracking service in this website.

13

Website cookies, browser storage, and tracking

Current website functionality. The marketing website's own code does not set cookies or store visitor preferences in localStorage or sessionStorage. Language selection is handled by language-specific page URLs. The site does not include advertising pixels, session-recording tools, or analytics tags in its application code.

Infrastructure security. Our hosting and security providers may use essential security cookies when a protection feature or challenge requires them. These are distinct from advertising or analytics cookies. The Cookie Policy explains this distinction; a statement about our own site code is not a guarantee that the hosting layer never sets a cookie.

Future changes and choices. If we introduce optional analytics or advertising technologies, we will update the relevant disclosures and provide any choice or prior consent required by applicable law before using them. The current website does not offer an optional tracking preference panel because no such trackers are included in its code. You can also manage stored site data through your browser settings.