Legal

Data processing agreement

How PDFGeny processes personal data on your behalf, and who our sub-processors are.

Last updated 31 August 2026

Scope

This describes how PDFGeny processes personal data on your behalf when you use the API. Where you are subject to the GDPR, you are the controller and PDFGeny is the processor. A signed copy on your paper is available — write to [email protected].

What we process, and why

Content you send. HTML, template data and URLs. Processed solely to render the document you requested. Held in memory during rendering; not retained afterwards.

Generated documents. Stored only when you ask, for seven days, then deleted.

Account data. Email address, authentication tokens, and billing records — processed as controller, not processor, since it is our relationship with you.

Request metadata. Timestamps, sizes, durations and status codes, kept 90 days for support, billing accuracy and abuse prevention.

Sub-processors

OVH (France) — hosting. Cloudflare (EU/US) — DNS, TLS termination, bot protection. Stripe (US/EU) — payments; card data never reaches our systems. Email delivery runs on our own infrastructure.

We notify account holders by email at least 30 days before adding a sub-processor that handles content.

Security measures

TLS in transit; access controls and IP restrictions on administrative interfaces; API keys stored as hashes; isolated rendering contexts; signed, expiring document links; daily encrypted backups with tested restore. Details on the security page.

Your rights and our obligations

We process content only on your documented instructions — in practice, the API requests you send. We assist with data subject requests, notify you without undue delay of a personal data breach affecting your content, and delete or return content on termination.

Transfers outside the EEA rely on the European Commission's standard contractual clauses where applicable.

Need it signed on your paper? Send it over.