Data Protection

Privacy engineered into the infrastructure.

PacyNet's data-protection approach is built around purpose limitation, data minimisation, access control, security, accountability and appropriate handling of individual rights.

Framework

A governance layer, not a footer statement.

The corporate website is only one part of the framework. Product-specific controls must be proportionate to the data, users, institutions and legal obligations involved.

Purpose

Collect for a defined reason

Personal information should be collected and used for specified, legitimate purposes and not expanded into unrelated uses without an appropriate basis.

Minimisation

Only what is necessary

Systems should request the minimum information reasonably required for the intended function, transaction, security control or legal obligation.

Accuracy

Maintain reliable records

Where personal information is used operationally, PacyNet aims to provide appropriate processes for correction, validation and controlled updates.

Retention

Do not keep data indefinitely

Retention should follow the processing purpose, contractual requirements and applicable legal obligations, followed by secure deletion, anonymisation or archival controls where appropriate.

Security

Protect confidentiality and integrity

Controls may include encryption in transit, authenticated access, role separation, audit records, input validation, anti-abuse measures, backups and incident-response procedures appropriate to the system.

Accountability

Decisions should be traceable

Data-handling responsibilities, approvals, access boundaries and significant changes should be documented sufficiently to support oversight and investigation.

Roles

Controller and processor responsibilities depend on context.

Corporate website

PacyNet determines the website purpose

For personal information submitted directly through the PacyNet corporate website and corporate portal, PacyNet may act as the data controller where it determines why and how that information is processed. The Privacy Notice explains the current website processing in more detail.

Institutional platforms

The contractual arrangement matters

For future or deployed institutional products, PacyNet's role may differ depending on whether an institution determines the purposes and means of processing or PacyNet independently determines them. Product and customer documentation should define those responsibilities before production use.

Sensitive environments

Higher-risk products require stronger controls.

Education, health, artificial intelligence and public-sector infrastructure can involve information that warrants enhanced governance.

Education

Learner and child safeguards

Systems involving learners or children should incorporate age-appropriate privacy, authorised institutional access, safeguarding, limited visibility and carefully controlled data sharing.

Health

Health information requires restraint

Health-related information should receive heightened access, purpose, disclosure and security controls, with clear separation between PacyNet's infrastructure role and regulated healthcare responsibilities.

AI

Human oversight where consequences matter

AI-supported processing should be designed with appropriate transparency, data-quality controls, access boundaries and human review where outputs could materially affect an individual or institution.

Public institutions

Need-to-know access

Government and public-institution deployments should use strict role separation, authorisation controls, auditability and contractual restrictions appropriate to the sensitivity of the information involved.

Rights

Individuals should have a usable route to exercise their rights.

Access

Understand the processing

Where applicable, individuals may request information about personal data processed about them and the relevant purposes, categories, recipients and retention.

Correction

Fix inaccurate information

Appropriate mechanisms should exist to correct inaccurate personal data and complete information where required.

Control

Deletion, objection or restriction

Requests for erasure, restriction or objection should be assessed against the applicable law, contractual responsibilities, retention duties and rights of other persons.

Third parties

Third-party processing should be purposeful and controlled.

Processors and service providers

Access is limited to a defined operational purpose.

PacyNet may rely on carefully selected third parties where necessary to operate, protect or support its systems and business processes. Selection, contractual safeguards, access scope, transfer considerations and security responsibilities should be assessed according to the information and processing involved.

Requests

Privacy and data-protection contact.

The public route for website privacy questions and data-subject requests is available now.