Legal
Privacy Policy
This policy explains what personal data PACOD collects, why we collect it, and the rights you have over it under the EU General Data Protection Regulation (GDPR).
1. Who we are
Xpacore Ltd (Експакор ЕООД), registered at Sofia, Bulgaria, ЕИК 123456789 ("we", "us"), is the data controller responsible for your personal data in connection with PACOD. For any privacy question, or to exercise your rights, contact us at office@pacod.io.
2. Data we collect
- Account data — your name, email address, and password (stored hashed), or the profile details supplied by Google when you sign in with OAuth.
- Content you provide — the messages, questions, and files you submit to your advisors.
- Usage data — pages visited, features used, approximate token usage, and timestamps, used to operate and improve the service.
- Technical data — IP address, browser type, and device information collected in server logs for security and diagnostics.
- Cookies — see our Cookie Policy for the full list.
3. How and why we use your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing your account and delivering advisor responses | Performance of a contract |
| Keeping the service secure and preventing abuse | Legitimate interests |
| Improving features and quality | Legitimate interests |
| Sending the newsletter you subscribed to | Consent |
| Meeting legal and accounting obligations | Legal obligation |
4. Sharing and processors
We do not sell your personal data. We share it only with service providers ("processors") who help us run PACOD, under contracts that require them to protect it and to act only on our instructions. By category, these are:
- a cloud hosting and infrastructure provider;
- an AI/LLM model provider used to generate responses;
- an email-delivery provider used to send the newsletter.
We do not use third-party analytics or error-monitoring providers.
5. International transfers
Where a processor is located outside the European Economic Area, we ensure an adequate level of protection through mechanisms such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. How long we keep it
We keep personal data only as long as necessary for the purposes above. Account data is retained while your account is active and for 90 days after you close it; server logs are kept for 12 months; newsletter data is kept until you unsubscribe.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request erasure of your data ("right to be forgotten");
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with your supervisory authority — in Bulgaria, the Commission for Personal Data Protection (CPDP / КЗЛД).
To exercise any of these rights, email office@pacod.io. We respond within one month.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, hashed passwords, and access controls. No system is perfectly secure, but we work continuously to reduce risk.
9. Children
PACOD is not intended for children under 16, and we do not knowingly collect their data.
10. Changes to this policy
We may update this policy from time to time. We'll post the new version here and update the "Last updated" date; significant changes will be communicated directly where appropriate.