Data Processing Addendum
If you send us documents containing other people’s personal data, this is the Article 28 contract that covers it. It is already in force — it forms part of the Terms of Service and applies automatically from the moment you use the API. You do not need to sign it, request it, or negotiate it.
Effective 1 September 2026
1. Who is what
You are the controller. You decide what documents to send and what personal data they contain. Gaurav Singh, trading as PDFCraft, is the processor, acting only on your instructions — and your instruction is the API request itself.
Separately, PDFCraft is a controller for your own account data (your email, your keys, your usage). That is governed by the Privacy Policy, not by this addendum.
2. Particulars of the processing
| Article 28(3) item | For this service |
|---|---|
| Subject matter | Converting documents you submit into PDF files and returning them to you. |
| Duration | For each document, the length of the render plus the retention windows in section 5. Overall, for as long as you have an account. |
| Nature and purpose | Automated rendering. A browser loads your HTML or fetches your URL, produces a PDF, and is destroyed. No human reads the content and no profiling or decision-making occurs. |
| Type of personal data | Whatever you choose to put in a document. We do not inspect it, so we cannot enumerate it. In practice, customers render invoices, statements, contracts, reports, tickets and certificates, which commonly contain names, addresses, email addresses, order and account references, and amounts. |
| Categories of data subject | Determined by you — typically your own customers, users, employees or suppliers. |
| Special category data | Not prohibited by the architecture, but you should know that this service carries no additional safeguards for it and no health-, biometric- or criminal-data specific controls. If you intend to render special category data at volume, email us first. |
3. What we commit to
- Process only on your instructions, and only to provide the service. Never for our own purposes. Explicitly: no training of models, no analytics on your content, no sampling for quality review, no sale or sharing.
- Tell you if an instruction looks unlawful rather than quietly carrying it out.
- Confidentiality. Only the operator has access, under an obligation of confidence that survives the end of this agreement.
- Security appropriate to the risk (Article 32) — the measures in section 7, which we will not weaken without telling you.
- Help you answer a data subject. If someone asks you for access, correction or erasure of data inside a document you rendered, we will help you locate and delete it, at no charge. In most cases the answer is that it is already gone — see section 5.
- Help you with a DPIA or a regulator, to the extent the information is ours to give.
- Notify you of a personal data breach without undue delay, and in any event within 48 hours of becoming aware, with what we know and what we are doing. You remain responsible for notifying your own regulator and data subjects.
- Delete on termination. When your account closes, content is deleted per the retention windows. We keep no archive. Confirmation in writing on request.
- Allow audit. We do not hold ISO 27001 or SOC 2 — an honest statement of a one-person operation’s position — so instead: ask any question about our infrastructure, configuration or processes and we will answer it specifically and in writing, once a year or after a breach.
4. Sub-processors
You authorise these, and only these:
| Sub-processor | Processing | Location |
|---|---|---|
| Hetzner Online GmbH | Servers that run the API and the render engine | Germany (EU) |
| Cloudflare, Inc. | Object storage for rendered PDFs (R2), DNS | EU-hosted bucket; company registered in the United States |
| Resend, Inc. | Sign-in links and account email | United States |
| Dodo Payments | Payment processing and merchant of record | Per their own terms |
We will update this page at least 30 days before adding or replacing one. If you reasonably object on data protection grounds, tell us within those 30 days and we will either find an alternative or let you terminate the affected part of the service and refund the unused period. Each sub-processor is bound by terms no weaker than these.
5. Retention — the short version
This is where a rendering API differs from most processors, and it is in your favour: we are not a store.
- Synchronous renders: your document exists in server memory only, for the duration of the render. Nothing is written to disk.
- Asynchronous renders: the job — including your document and any request headers or cookies you supplied — is held in our queue so it can survive a restart. Removed within an hour of success; retained longer after a failure so it can be retried. If a particular document should never touch our queue, use the synchronous endpoint.
- Output PDFs requested as a URL are deleted 24 hours after creation, by default and by a scheduled job, not on request.
- Render records keep metadata only — id, size, page count, duration, error code. Never content.
6. International transfers
Storage and processing happen on servers in Germany. For a controller in the EEA or UK, that means the personal data inside your documents does not leave the EEA in order for the service to work.
Two transfers do occur and you should know about both. The operator administers the infrastructure remotely from India, and account email is sent via a United States provider. Neither has an EU adequacy decision, so for those we rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, 2021/914) and the UK Addendum where relevant, together with the measures in section 7. We will send you the executed clauses on request, and this addendum incorporates them by reference.
7. Technical and organisational measures
| Area | Measure |
|---|---|
| In transit | TLS 1.2+ on every endpoint; plain HTTP redirected; HSTS enabled. |
| At rest | Full-disk encryption on the host. Output objects reachable only through signed, time-limited links. |
| Isolation | Every render runs in a fresh browser context destroyed immediately afterwards. One customer’s document cannot observe another’s. |
| Credentials | API keys stored as one-way hashes only. No plaintext key exists anywhere after issue, including in our own database and backups. |
| Network | Database and cache bound to localhost, unreachable from the internet. Firewall allows only 22, 80 and 443. |
| Administrative access | Key-based SSH only, no password login. Application runs as an unprivileged system user with no shell and no sudo. |
| Egress control | URL rendering rejects private, loopback and link-local destinations to prevent the renderer being used to reach internal systems. |
| Availability | Encrypted daily database backups, retained 14 days, restore-tested. |
| Logging | Web-server access logs retained 30 days. Document content is never logged, at any log level. |
8. Liability and precedence
The liability limit in section 9 of the Terms of Service applies to this addendum as well. Where this addendum conflicts with the Terms on the processing of personal data, this addendum wins. Where it conflicts with the Standard Contractual Clauses, the Clauses win.
9. Data protection contact
support@pdfcraft.dev reaches the operator directly. We are below the threshold that requires a Data Protection Officer and have not appointed one; nor have we appointed an EU or UK representative under Article 27, which you should factor into your own assessment. Our postal address:
Raj Nagar Extension
India