Privacy policy
This policy explains how PIM S.A., under the Pacto brand, processes the personal data of company representatives, freelancers, ambassadors, partners, prospects and visitors.
The formal status of the data protection officer (failing which the wording « privacy contact point » is used), the public email address, the list of processors, transfers outside the EEA and the 10-year archiving periods must be validated by Belgian legal counsel.
1. Controller and contact
For the processing whose purposes and means it determines, the controller is:
Chemin de la Fraite 18 1380 Lasne
Company number: 1020.264.212
General email address: pierre@pim.eu.com
Privacy contact: dpo@pacto.global
The wording « privacy contact point » is used as long as the formal appointment of a data protection officer with the Data Protection Authority is not confirmed.
2. Scope
The policy applies to processing carried out in the context of:
- the Pacto.global website;
- forms and meeting requests;
- the accounts of companies, members, ambassadors and partners;
- network membership and the professional listing;
- introductions and the follow-up of applications;
- contractual, administrative and financial management;
- the tools and registers made available inside programmes;
- support, security and service continuity;
- business-to-business prospecting.
The services are aimed at professionals. Business contact details may nevertheless constitute personal data where they make it possible to identify a natural person.
3. Pacto's two roles
3.1 Pacto as controller
PIM S.A. acts as controller in particular for:
- the website and its forms;
- the accounts and contracts entered into with Pacto;
- membership and the listing of members;
- introductions;
- the network of ambassadors and partners;
- the invoicing of its own services;
- the security of the system;
- commercial management and business prospecting.
3.2 Pacto as processor
Where a client company uses the Pacto tools to run its own programme, it determines in principle the purposes of the processing carried out in its register, its messaging and its mission cards. It then acts as controller and Pacto processes the data on its behalf, under the applicable processing agreement.
To exercise a right regarding this internal data, the person may contact the company concerned. If the request is sent to Pacto, Pacto forwards it to the controller and provides the assistance required by the GDPR.
4. Where the data comes from
The data may come:
- directly from the person concerned, through a form, a registration, an exchange or the use of the service;
- from the company the person represents or from colleagues authorised to enter their contact details;
- from an ambassador or partner who registers a business introduction and who must inform the prospect;
- from the use of the website and the tools, in particular through technical logs, timestamps, views and actions performed;
- from the contractual, administrative, accounting and invoicing documents sent to Pacto.
5. Data, purposes, legal bases and periods
5.1 Visitors and contact requests
| Purpose | Data | Legal basis | Expected period |
|---|---|---|---|
| Display and secure the website | IP address, technical logs, browser and device information, security events | Legitimate interest in ensuring operation and security | Technical logs: up to 12 months, except for an incident requiring longer evidential retention |
| Answer a request | Last name, first name, business email address, capacity, company, message | Pre-contractual steps or legitimate interest in replying | 24 months after the last exchange, unless there is a contractual relationship or a longer obligation |
| Count the pages viewed | The path of the page viewed, with no cookie, no identifier, no fingerprint and no retention of the IP address. Details in the cookie policy | Legitimate interest: the measurement is anonymous by design and therefore exempt from consent | No individual data retained: only totals per page and per day |
5.2 Business prospecting
| Purpose | Data | Legal basis | Expected period |
|---|---|---|---|
| Contact relevant business prospects | Identity, role, company, business contact details, history of exchanges | Legitimate interest in developing business-to-business activity, after balancing against the rights of the persons concerned | Up to 36 months after the last contact, then deletion or archiving where proof of an objection must be kept |
| Handle objections | Email address or other minimal identifier and the date of the objection | Obligation to respect the objection and legitimate interest in not contacting the person again | As long as necessary to respect the objection |
Every prospecting message must identify Pacto, explain where the contact details came from where this is required, and offer a simple way to object to future communications.
5.3 Client companies
| Purpose | Data | Legal basis | Expected period |
|---|---|---|---|
| Create the account and perform the contract | Identity and business contact details of the representatives, role, company, contractual data, programme settings | Performance of the contract or pre-contractual steps | For the duration of the contract, then up to 10 years in evidential archive if that period is confirmed by legal counsel |
| Invoice the Pacto services | Identification data, VAT, invoices, payments, accounting references | Legal obligations and performance of the contract | Applicable accounting and tax periods, which may reach 10 years |
| Administer the programme | Users, roles, access, settings, seats, administration events | Performance of the contract and legitimate interest in administering the service | For the duration of the contract, then according to the applicable evidential periods |
5.4 Members and freelancers
| Purpose | Data | Legal basis | Expected period |
|---|---|---|---|
| Manage membership | Company, identity and role of the representative, contact details, payment of the entry fee, any voucher or code | Performance of the contract | For the duration of the membership, then up to 10 years in evidential archive if that period is confirmed |
| Publish the professional profile | Skills, experience, availability, public references, logo, area of activity | Performance of the contract | Visible during the membership and removed from the listing when it ends |
| Handle opportunities and applications | Views, applications, choices, timestamps and exchanges | Performance of the contract | During the membership, then 36 months where they play a part in a refund condition, and thereafter only in the necessary evidential archive |
5.5 Ambassadors, partners and registered prospects
| Purpose | Data | Legal basis | Expected period |
|---|---|---|---|
| Manage the account and the relationship | Identity, contact details, training, referral code, contract, statements and commissions | Performance of the contract and accounting obligations | For the duration of the contract, then the applicable contractual, accounting and tax periods |
| Attribute an introduction | Business contact details of the prospect, author of the introduction, timestamp, status and outcome | Legitimate interest in attributing introductions fairly | For prospects that are not converted, at the latest 12 months after the registration protection expires, unless there is an objection or a different documented justification |
5.6 Programme registers and messaging
In this context the client company is in principle the controller and Pacto acts as processor.
| Processing | Data | Retention instruction currently planned |
|---|---|---|
| Programme register | Services, cards, balances, payments, invoices and evidential events | 10 years, subject to legal validation and to the client's instructions |
| Internal messaging | Messages, attachments and timestamps | 3 years after the programme closes, subject to the applicable evidential obligations |
| Access to the balance | Identity, balance and history of the member | As long as a balance remains open, then the applicable evidential period |
Where several periods are possible, Pacto applies the shortest period compatible with the contract, the law, the defence of legal claims and the valid instructions of the controller.
6. Whether the data is mandatory
Fields marked as mandatory are necessary in order to handle a request, create an account, enter into or perform a contract, ensure security or comply with a legal obligation.
Without this data, Pacto may be unable to reply, to open the account, to perform the service or to issue invoices. Optional data is flagged as such and its absence does not block the journey concerned.
7. Recipients
The data is accessible, on a need-to-know basis, to:
- authorised members of Pacto's staff and contributors bound by a confidentiality obligation;
- the client company and the authorised participants in its programme;
- technical providers in charge of hosting, infrastructure, communications, invoicing, payment of the Pacto services, support and security;
- professional advisers, auditors or insurers where this is necessary and governed by an agreement;
- administrative or judicial authorities where the law requires it;
- an acquirer or legal successor, in compliance with applicable law, in the event of a documented restructuring.
A member's profile may be visible to authorised client companies. The internal data of a programme is accessible only to persons whose role justifies it. The information passed on to an ambassador or partner remains limited to what is necessary to follow up their own introductions.
Pacto neither sells nor rents personal data.
The up-to-date list of the main processors is available on request at dpo@pacto.global.
8. Transfers outside the European Economic Area
Pacto favours hosting and processing inside the European Economic Area.
If a provider involves a transfer or an access from a country outside the European Economic Area, Pacto checks the applicable mechanism, for instance an adequacy decision, the European Commission's standard contractual clauses and, where necessary, additional measures.
Persons may ask for information about the applicable safeguards at dpo@pacto.global.
An external continuity channel may only be used exceptionally. The data passing through it is limited, the useful exchanges are recorded back into the Pacto tool and the practices of the provider concerned are documented.
9. Security
Pacto applies technical and organisational measures appropriate to the risks, in particular:
- access control and role management;
- encryption of communications in transit;
- logging of relevant events;
- backups and continuity procedures;
- logical separation of programmes;
- restriction of permissions;
- incident and vulnerability management;
- awareness training for authorised persons.
No electronic transmission or storage can be presented as absolutely secure. In the event of a data breach, Pacto applies the notification and information obligations laid down by the GDPR according to the level of risk.
10. Your rights
Under the conditions laid down by the GDPR, the person concerned may request:
- access to their data;
- rectification of inaccurate data;
- erasure of data;
- restriction of a processing operation;
- portability of the data provided, where the conditions are met;
- objection to processing based on legitimate interest;
- objection to prospecting, which is respected at any time;
- withdrawal of consent, without calling into question the processing carried out before that withdrawal.
The request may be sent to dpo@pacto.global or by post to PIM S.A., Chemin de la Fraite 18, 1380 Lasne, Belgium, marked « Privacy ».
Pacto may ask for the information strictly necessary to verify identity where this is justified. The reply is provided in principle within one month. That period may be extended by two months for a complex or numerous request, with information given to the person within the first month.
A right is not absolute. Data may in particular be kept where a legal obligation, an ongoing contract, an open balance or the defence of legal claims requires it. Pacto then explains the applicable limitation.
11. Complaints
A person may lodge a complaint with the Data Protection Authority:
They may also contact the supervisory authority of their place of residence or work where the GDPR allows it.
12. Automated decisions
Pacto does not take decisions producing legal effects or significantly affecting a person on the sole basis of automated processing, unless specific information to the contrary is given in a particular journey.
The listing may help present profiles or opportunities. Decisions to apply, to select or to contract remain taken by people.
13. Minors
The Pacto services are intended for professionals and are not designed for minors. Pacto does not knowingly seek to collect their data.
14. Cookies and trackers
Information about cookies, pixels, local storage and other trackers is set out in the cookie policy. Trackers that are not strictly necessary stay switched off until valid consent is obtained.
What this website stores or measures today
- Record of your consent choice
Stored on your device by the website itself, read back by the website only and never sent to a third party. Strictly necessary: without it the question would be asked again on every page. - Count of the pages viewed
No cookie, nothing stored on your device, no identifier, no fingerprint and no retention of the IP address: only the path of the page is sent, and only totals per page and per day are kept. The measurement therefore does not single you out and does not depend on your consent. - Session of the signed-in spaces
At sign-in only, the session items needed to keep you authenticated inside your space. Strictly necessary and limited to the duration of the session.
The technical name, the nature and the exact period of each item are set out in the cookie policy, which is checked at every release.
No third-party audience measurement tool, no advertising pixel, no font and no script loaded from an external domain are used on this website.
15. Changes to the policy
The policy is dated and versioned. In the event of a substantial change, Pacto informs account holders by an appropriate means before it takes effect where this is required.
Earlier versions are archived and may be provided on request.
Version 1.1, updated on 30/08/2026. Contact: dpo@pacto.global.