Legal / Data Processing Agreement

Data Processing Agreement

Last updated 29 July 2026

The short version

When we handle personal data inside your documents, we act only on your documented instructions, keep it confidential and secured, use sub-processors transparently and remain liable for them, assist you with data-subject requests and breach duties, transfer data abroad only under safeguards, notify you of breaches within 72 hours, and delete or return the data when the service ends.

Scope and Roles

This Data Processing Agreement ("DPA") applies where, in providing the service, PDFglyph processes personal data on your behalf. It forms part of and is incorporated into the Terms of Service, and prevails over them on matters of personal-data processing. You are the controller (or a processor acting for a third-party controller) and PDFglyph is the processor. Terms such as "personal data", "processing", "controller", "processor" and "data subject" have the meanings given in the GDPR.

Details of the Processing

The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. In summary, we process the personal data contained in the data you submit to generate documents, for the duration of your account, solely to render and deliver your documents on your instructions.

Processing on Documented Instructions — Art 28(3)(a)

We process personal data only on your documented instructions, including with regard to international transfers, unless required otherwise by EU or Member State law (in which case we will inform you of that legal requirement before processing, unless the law prohibits it). Your instructions are this DPA, the Terms, and your configuration and use of the service. We will inform you if, in our opinion, an instruction infringes the GDPR or other data-protection law.

Confidentiality — Art 28(3)(b)

We ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the data only as needed to provide the service.

Security — Art 28(3)(c) and Art 32

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. These include encryption in transit, access controls, hashed credentials, server-side SSRF screening of external resources, and time-bounded rendering.

Sub-processors — Art 28(2), (4) and (3)(d)

You give general written authorisation for us to engage sub-processors to provide the service. The current sub-processors are listed in Annex 3. We impose on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA, and we remain fully liable to you for the performance of each sub-processor's obligations. We will give you at least 30 days' notice of any intended addition or replacement, during which you may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service.

Assisting With Data-Subject Rights — Art 28(3)(e)

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to data subjects exercising their rights under Chapter III of the GDPR. If we receive a request directly from a data subject, we will not respond ourselves but will forward it to you without undue delay.

Assisting With Security, Breaches and DPIAs — Art 28(3)(f), Arts 32–36

We will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to us. We will notify you without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting your personal data, and will provide the information you reasonably need to meet your own notification obligations.

Return and Deletion — Art 28(3)(g)

On termination of the service, and at your choice, we will delete or return all personal data processed on your behalf and delete existing copies, unless EU or Member State law requires us to keep it. We do not retain generated documents, and we store request payloads only where you enable per-template input storage.

Information and Audits — Art 28(3)(h)

We will make available to you all information necessary to demonstrate compliance with the obligations in Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy this by providing relevant documentation and, where appropriate, independent third-party reports, subject to reasonable notice, confidentiality, and not compromising the security of other customers.

International Transfers

We will not transfer personal data outside the EEA except on your instructions or as needed to provide the service, and only where an adequacy decision applies or appropriate safeguards are in place, principally the European Commission's Standard Contractual Clauses, which the parties agree to enter into where required.

Liability

Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, to the extent permitted by law.

Annexes

Annex 1 — Details of processing

  • Subject-matter: rendering documents (PDF today) from the templates you create and the data you submit through the dashboard and the /v1 API.
  • Duration: for as long as you use the service, until the data is deleted or returned as described in "Return and Deletion" above.
  • Nature and purpose: automated generation and delivery of your documents on your instructions. We do not use this data for any other purpose — we do not sell it, use it to train models, or profile data subjects.
  • Types of personal data: whatever personal data you choose to include in the data you submit — determined and controlled by you. It may include, for example, names, contact details, postal addresses and transaction or invoice details.
  • Categories of data subjects: the individuals you choose to include in your documents — for example your own customers, clients, employees or contacts.
  • Note: we do not retain the generated document, and we store request payloads only where you enable per-template input storage.

Annex 2 — Technical and organisational measures

  • Encryption in transit (TLS) for all dashboard and API traffic.
  • Passwords stored hashed (bcrypt); API keys stored hashed, shown once, and revocable without deletion.
  • Access controls and least-privilege access to production systems.
  • Server-side screening of external resources referenced in templates (SSRF protection) and time-bounded rendering.
  • Hosting within the EU (Amsterdam) on a managed PostgreSQL database, with encrypted, scheduled daily backups.
  • Generated documents are never stored; request payloads are stored only where you turn on per-template input storage.
  • Structured request logging with secrets (credentials, cookies) redacted, and request bodies never logged.

Annex 3 — Approved sub-processors

  • Railway — cloud hosting and managed PostgreSQL database. Data is hosted in the EU (Amsterdam); the provider is incorporated in the US, with EU Standard Contractual Clauses in place for any provider access.
  • Stripe — payment processing and billing. Processed in the EU (Ireland) and the US under EU Standard Contractual Clauses. We do not store full card numbers.
  • Resend — transactional email delivery (for example password-reset, verification and alert emails). Processed in the US under EU Standard Contractual Clauses.

Each provider's legal entity and processing locations reflect its current setup and may change; we will update this Annex and give notice of any change as described under "Sub-processors" above.