Value must return to those who create it: collaboration without debt or dilutionLanguageFRENSign in
Data protection

Privacy policy

This policy explains how PIM S.A., under the Pacto brand, processes the personal data of company representatives, freelancers, ambassadors, partners, prospects and visitors.

Version 1.1 Updated: 30/08/2026
Preproduction, to be confirmed before publication

The formal status of the data protection officer (failing which the wording « privacy contact point » is used), the public email address, the list of processors, transfers outside the EEA and the 10-year archiving periods must be validated by Belgian legal counsel.

In short
Who processes the data?PIM S.A., Chemin de la Fraite 18, 1380 Lasne, Belgium, company number 1020.264.212.
Why?To run the website, the requests, the accounts, the memberships, the programmes, the network, the contracts, the invoicing, security and business prospecting.
Does Pacto always have the same role?No. Pacto is the controller for its own activities. Inside the internal spaces of a client programme, the client company is in principle the controller and Pacto acts as processor.
Is the data sold?No. Pacto neither sells nor rents personal data.
What are your rights?Access, rectification, erasure, restriction, portability, objection and withdrawal of consent where it applies.
Who should you contact?dpo@pacto.global, privacy contact point.

1. Controller and contact

For the processing whose purposes and means it determines, the controller is:

PIM S.A.
Chemin de la Fraite 18 1380 Lasne
Company number: 1020.264.212
General email address: pierre@pim.eu.com
Privacy contact: dpo@pacto.global

The wording « privacy contact point » is used as long as the formal appointment of a data protection officer with the Data Protection Authority is not confirmed.

2. Scope

The policy applies to processing carried out in the context of:

The services are aimed at professionals. Business contact details may nevertheless constitute personal data where they make it possible to identify a natural person.

3. Pacto's two roles

3.1 Pacto as controller

PIM S.A. acts as controller in particular for:

3.2 Pacto as processor

Where a client company uses the Pacto tools to run its own programme, it determines in principle the purposes of the processing carried out in its register, its messaging and its mission cards. It then acts as controller and Pacto processes the data on its behalf, under the applicable processing agreement.

To exercise a right regarding this internal data, the person may contact the company concerned. If the request is sent to Pacto, Pacto forwards it to the controller and provides the assistance required by the GDPR.

4. Where the data comes from

The data may come:

5. Data, purposes, legal bases and periods

5.1 Visitors and contact requests

PurposeDataLegal basisExpected period
Display and secure the websiteIP address, technical logs, browser and device information, security eventsLegitimate interest in ensuring operation and securityTechnical logs: up to 12 months, except for an incident requiring longer evidential retention
Answer a requestLast name, first name, business email address, capacity, company, messagePre-contractual steps or legitimate interest in replying24 months after the last exchange, unless there is a contractual relationship or a longer obligation
Count the pages viewedThe path of the page viewed, with no cookie, no identifier, no fingerprint and no retention of the IP address. Details in the cookie policyLegitimate interest: the measurement is anonymous by design and therefore exempt from consentNo individual data retained: only totals per page and per day

5.2 Business prospecting

PurposeDataLegal basisExpected period
Contact relevant business prospectsIdentity, role, company, business contact details, history of exchangesLegitimate interest in developing business-to-business activity, after balancing against the rights of the persons concernedUp to 36 months after the last contact, then deletion or archiving where proof of an objection must be kept
Handle objectionsEmail address or other minimal identifier and the date of the objectionObligation to respect the objection and legitimate interest in not contacting the person againAs long as necessary to respect the objection

Every prospecting message must identify Pacto, explain where the contact details came from where this is required, and offer a simple way to object to future communications.

5.3 Client companies

PurposeDataLegal basisExpected period
Create the account and perform the contractIdentity and business contact details of the representatives, role, company, contractual data, programme settingsPerformance of the contract or pre-contractual stepsFor the duration of the contract, then up to 10 years in evidential archive if that period is confirmed by legal counsel
Invoice the Pacto servicesIdentification data, VAT, invoices, payments, accounting referencesLegal obligations and performance of the contractApplicable accounting and tax periods, which may reach 10 years
Administer the programmeUsers, roles, access, settings, seats, administration eventsPerformance of the contract and legitimate interest in administering the serviceFor the duration of the contract, then according to the applicable evidential periods

5.4 Members and freelancers

PurposeDataLegal basisExpected period
Manage membershipCompany, identity and role of the representative, contact details, payment of the entry fee, any voucher or codePerformance of the contractFor the duration of the membership, then up to 10 years in evidential archive if that period is confirmed
Publish the professional profileSkills, experience, availability, public references, logo, area of activityPerformance of the contractVisible during the membership and removed from the listing when it ends
Handle opportunities and applicationsViews, applications, choices, timestamps and exchangesPerformance of the contractDuring the membership, then 36 months where they play a part in a refund condition, and thereafter only in the necessary evidential archive

5.5 Ambassadors, partners and registered prospects

PurposeDataLegal basisExpected period
Manage the account and the relationshipIdentity, contact details, training, referral code, contract, statements and commissionsPerformance of the contract and accounting obligationsFor the duration of the contract, then the applicable contractual, accounting and tax periods
Attribute an introductionBusiness contact details of the prospect, author of the introduction, timestamp, status and outcomeLegitimate interest in attributing introductions fairlyFor prospects that are not converted, at the latest 12 months after the registration protection expires, unless there is an objection or a different documented justification

5.6 Programme registers and messaging

In this context the client company is in principle the controller and Pacto acts as processor.

ProcessingDataRetention instruction currently planned
Programme registerServices, cards, balances, payments, invoices and evidential events10 years, subject to legal validation and to the client's instructions
Internal messagingMessages, attachments and timestamps3 years after the programme closes, subject to the applicable evidential obligations
Access to the balanceIdentity, balance and history of the memberAs long as a balance remains open, then the applicable evidential period

Where several periods are possible, Pacto applies the shortest period compatible with the contract, the law, the defence of legal claims and the valid instructions of the controller.

6. Whether the data is mandatory

Fields marked as mandatory are necessary in order to handle a request, create an account, enter into or perform a contract, ensure security or comply with a legal obligation.

Without this data, Pacto may be unable to reply, to open the account, to perform the service or to issue invoices. Optional data is flagged as such and its absence does not block the journey concerned.

7. Recipients

The data is accessible, on a need-to-know basis, to:

A member's profile may be visible to authorised client companies. The internal data of a programme is accessible only to persons whose role justifies it. The information passed on to an ambassador or partner remains limited to what is necessary to follow up their own introductions.

Pacto neither sells nor rents personal data.

The up-to-date list of the main processors is available on request at dpo@pacto.global.

8. Transfers outside the European Economic Area

Pacto favours hosting and processing inside the European Economic Area.

If a provider involves a transfer or an access from a country outside the European Economic Area, Pacto checks the applicable mechanism, for instance an adequacy decision, the European Commission's standard contractual clauses and, where necessary, additional measures.

Persons may ask for information about the applicable safeguards at dpo@pacto.global.

An external continuity channel may only be used exceptionally. The data passing through it is limited, the useful exchanges are recorded back into the Pacto tool and the practices of the provider concerned are documented.

9. Security

Pacto applies technical and organisational measures appropriate to the risks, in particular:

No electronic transmission or storage can be presented as absolutely secure. In the event of a data breach, Pacto applies the notification and information obligations laid down by the GDPR according to the level of risk.

10. Your rights

Under the conditions laid down by the GDPR, the person concerned may request:

The request may be sent to dpo@pacto.global or by post to PIM S.A., Chemin de la Fraite 18, 1380 Lasne, Belgium, marked « Privacy ».

Pacto may ask for the information strictly necessary to verify identity where this is justified. The reply is provided in principle within one month. That period may be extended by two months for a complex or numerous request, with information given to the person within the first month.

A right is not absolute. Data may in particular be kept where a legal obligation, an ongoing contract, an open balance or the defence of legal claims requires it. Pacto then explains the applicable limitation.

11. Complaints

A person may lodge a complaint with the Data Protection Authority:

Data Protection Authority
Rue de la Presse 35
1000 Brussels, Belgium
www.autoriteprotectiondonnees.be

They may also contact the supervisory authority of their place of residence or work where the GDPR allows it.

12. Automated decisions

Pacto does not take decisions producing legal effects or significantly affecting a person on the sole basis of automated processing, unless specific information to the contrary is given in a particular journey.

The listing may help present profiles or opportunities. Decisions to apply, to select or to contract remain taken by people.

13. Minors

The Pacto services are intended for professionals and are not designed for minors. Pacto does not knowingly seek to collect their data.

14. Cookies and trackers

Information about cookies, pixels, local storage and other trackers is set out in the cookie policy. Trackers that are not strictly necessary stay switched off until valid consent is obtained.

What this website stores or measures today

The technical name, the nature and the exact period of each item are set out in the cookie policy, which is checked at every release.

No third-party audience measurement tool, no advertising pixel, no font and no script loaded from an external domain are used on this website.

15. Changes to the policy

The policy is dated and versioned. In the event of a substantial change, Pacto informs account holders by an appropriate means before it takes effect where this is required.

Earlier versions are archived and may be provided on request.

Version 1.1, updated on 30/08/2026. Contact: dpo@pacto.global.

Pacto; the program that

pays work at the pace of revenue.

Signing in happens on the member area. This button takes you there.