On this page
1. Who we are and what this policy covers
This policy describes how Legal Pact, Inc. (“Legal Pact”, “we”) handles personal data when you use legal-pact.com and our document builder (the “Service”). For data protection law — including the EU General Data Protection Regulation (GDPR) — Legal Pact is the data controller of the data described here.
Contact for anything privacy-related: support@legal-pact.com.
2. What we collect
Account data. Your email address, and your name and profile picture if you sign in with Google. Sign-in is passwordless, so we never hold a password for you.
Document answers. What you enter into a questionnaire and the documents generated from it. Answers can include personal data — names, addresses, dates, financial figures — about you and about other people you choose to include (for example, the other party to a contract).
Purchase data. Which documents you bought, when, for how much, and the receipt we email you. We never see or store your card number — payment details go directly to our payment processors; we receive only a confirmation of payment and a payment reference.
Support conversations. Messages you send us by email or through the live chat, so we can help you and keep context.
Technical data. Standard server logs (IP address, browser type, pages requested, timestamps) used for security and to keep the Service running.
3. Why we use it (and the legal bases)
GDPR requires a legal basis for each use of personal data. Ours are:
- To provide the Service — generating your documents, live preview, saving them to your account, sign-in links, receipts, customer support. Basis: performance of our contract with you.
- To process payments and keep required records — transactions, invoices, tax and accounting. Basis: contract and legal obligation.
- To keep the Service secure — server logs, abuse and fraud prevention, protecting sign-in (magic-link tokens expire after 15 minutes). Basis: legitimate interest in running a safe service.
- To send product news — only if you opted in. Every email has an unsubscribe link, and marketing preferences are off by default. Basis: consent, withdrawable at any time.
We do not use your data for advertising, we do not profile you, and we make no automated decisions with legal or similarly significant effects.
You are never obliged to give us data — but some of it is what the Service runs on: without an email address we cannot sign you in or deliver files, and without your answers there is nothing to build a document from.
4. Cookies
We use only cookies the Service cannot work without — which is why you do not see a cookie-consent banner:
- Session cookie — keeps you signed in.
- Security (CSRF) cookie — protects forms against cross-site request forgery.
- Country cookie — remembers which country edition of the site you chose.
- Live-chat cookies — set by the chat widget so a conversation survives a page reload; they appear only if you open the chat.
There are no advertising, tracking or third-party analytics cookies.
5. Who we share data with
We never sell personal data and never share it for advertising. Data leaves our systems only to the service providers (processors) we need to run Legal Pact, each bound by a data-processing agreement:
- Hosting and infrastructure — running the Service and storing your account and documents.
- Email delivery (Resend) — sending sign-in links, receipts and (if opted in) product news to your address.
- Payment processors — handling card and express-checkout payments (they process your payment data as independent controllers under their own policies).
- Sign-in with Google (Google LLC) — only if you choose it; Google tells us your email, name and profile picture, nothing more.
- Live chat (Chatwoot) — powering the support chat if you use it.
Beyond processors, we disclose data only if the law genuinely requires it (for example, a binding court order), or as part of a merger or acquisition — in which case this policy continues to apply to your data and we will notify you.
6. International transfers
Legal Pact serves users in the United States, the European Union and other countries, so data may be processed outside the country you live in — including in the United States.
Where data of EU/EEA, UK or Swiss users is transferred to a country without an adequacy decision, we rely on recognised safeguards — the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework certifications of our providers.
7. How long we keep data
- Account and documents — for as long as your account exists. Your saved documents stay re-downloadable indefinitely; that is a feature, not an accident.
- Unfinished drafts — kept so you can resume where you left off; deleted with your account.
- Purchase records — kept as long as tax and accounting law requires (typically up to 10 years), even after account deletion.
- Support conversations — kept while relevant to helping you, then deleted.
- Server logs — short-lived and rotated automatically.
When you delete your account (or ask us to), we erase your data except the minimum that mandatory law requires us to keep, and anything kept is locked to that purpose only.
8. Your rights
You control your data. Wherever you live, you can ask us at any time to:
- access the data we hold about you and get a copy in a portable format;
- correct anything inaccurate;
- delete your account and data (“right to be forgotten”);
- restrict or object to processing based on legitimate interests;
- withdraw consent — for example, unsubscribe from product news — without affecting anything else.
Write to support@legal-pact.com from the email address on your account and we will action it — no forms, no fee, normally within a few days and always within the legal deadline. If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data-protection authority.
California residents (CCPA/CPRA): you have the rights to know, correct and delete as described above, and the right not to be discriminated against for using them. We do not sell or “share” personal information as defined by the CCPA, so there is nothing for an opt-out (or the Global Privacy Control signal) to switch off. You can exercise any right by email or through the live chat on our site.
9. Data about other people in your documents
Documents often mention people other than you — a tenant, an employee, a business partner. For that data, you decide what goes into the document, and we process it only as your service provider: to assemble, preview, export and store the document for you. We never use it for anything else and never contact those people.
Please only include other people’s data that you are entitled to use for your document.
10. How we protect your data
- All traffic is encrypted in transit (TLS), and data is encrypted at rest.
- Passwordless sign-in: there is no password to steal or reuse. Sign-in links are single-use and expire after 15 minutes.
- Card details never touch our servers — they go straight to PCI-DSS-certified payment processors.
- Access to production data is restricted to the few people who operate the Service and is logged.
No system is perfectly secure, but if a breach ever affects your data we will notify you and the competent authority as the law requires.
11. Children
The Service is for adults entering into legal documents and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has used the Service, contact us and we will delete the data.
12. Changes to this policy
If we change this policy in a way that matters — new data, new purpose, new recipient — we will notify you (by email or a notice in the Service) before the change takes effect. The “Effective date” above always shows the current version. We never weaken your rights retroactively.
13. Contact
Privacy questions, requests, complaints: support@legal-pact.com — Legal Pact, Inc. We answer every message, usually within one business day.
Questions about this policy?
We answer every message — usually within one business day. Write to support@legal-pact.com.