Legal
Privacy Policy
Marked gaps require a real value and the whole document requires review by a qualified lawyer before it is relied on.
Last updated August 7, 2026
Draft. This document has not been reviewed by a lawyer. The data flows it describes are accurate to how the product works today, which is what counsel will need — but it is not legal advice and should not be published as final until reviewed.
1. Who is responsible
PDF Generator Pro is operated by[LEGAL ENTITY NAME], registered in[JURISDICTION] at[REGISTERED ADDRESS].
For the personal data inside the documents you generate, you are the controller and we are the processor: that data comes from your CRM, is chosen by you, and is processed on your instructions. For your own account and billing data we act as controller.
Data protection contact: [PRIVACY CONTACT EMAIL].[APPOINT A DPO / EU REPRESENTATIVE IF REQUIRED]
2. What we handle
Installation and authentication data
When you install from the app marketplace we receive and store your CRM location and company identifiers, the workspace name, and OAuth access and refresh tokens. Tokens are required to keep the integration working and are stored so the app can act on your behalf.
Merge data
To generate a document we process the data you send with the request. That is whatever your template needs — commonly contact names, email addresses, postal addresses, opportunity values and dates. We do not choose these fields; your template does.
Do not send special-category data (health, biometric, religious or similar) unless you have established a lawful basis for it and have agreed the arrangement with us in writing.
Generated documents
The PDFs themselves, which contain whatever the merge data placed in them.
Operational records
For each generation we record a request id, the workspace, the template, the status, the file size, how long the render took, the link expiry, any error message, and the amount charged. These support troubleshooting and billing.
Usage and billing data
A count of executions per workspace per period, and the resulting charge. Payment card details are handled by the app marketplace and never reach us.
3. Why we process it
| Purpose | Data | Basis |
|---|---|---|
| Providing the Service | Merge data, templates, generated documents | Performance of a contract; processing on your instructions |
| Keeping the integration connected | OAuth tokens, account identifiers | Performance of a contract |
| Billing | Execution counts, workspace identifiers | Performance of a contract; legal obligation |
| Security and abuse prevention | Operational records, request metadata | Legitimate interests |
| Support | Operational records you reference | Legitimate interests |
4. What we do not do
- We do not sell personal data.
- We do not use your content or merge data to train machine learning models.
- We do not use your data to advertise to your contacts.
- We do not run advertising or analytics trackers on this marketing site. Fonts are requested from Google Fonts, which means Google receives the requesting IP address.[SELF-HOST FONTS TO REMOVE THIS, OR DISCLOSE IN A COOKIE NOTICE]
5. Where documents are stored
Where you configure your own Amazon S3 bucket, generated documents are written to infrastructure you control. Location, retention and deletion are governed by your configuration, and we do not delete files from your bucket.
Where you use the Service's default storage, documents are held on our application infrastructure for[RETENTION PERIOD]. Download links are signed and expire according to the validity set per request.
6. Sub-processors
| Provider | Role | Location |
|---|---|---|
| [CRM PLATFORM LEGAL NAME] | CRM platform, app distribution and billing | [REGION] |
| Amazon Web Services | Application hosting; document storage where S3 is configured | [REGION] |
| Google Fonts | Web font delivery on this marketing site | Global |
[CONFIRM THIS LIST IS COMPLETE — ADD EMAIL, ERROR TRACKING OR ANALYTICS PROVIDERS IF USED]
7. International transfers
Where personal data is transferred outside its country of origin, we rely on[TRANSFER MECHANISM, e.g. Standard Contractual Clauses].
8. How long we keep things
| Data | Kept for |
|---|---|
| Templates and workspace settings | Until you delete them or the workspace is removed |
| Generated documents (your bucket) | Your lifecycle policy |
| Generated documents (default storage) | [RETENTION PERIOD] |
| Generation records | [RETENTION PERIOD] |
| Billing records | [STATUTORY PERIOD] |
| OAuth tokens | Until uninstall, then deleted |
9. Security
- Data is transmitted over TLS.
- Documents uploaded to S3 are written with AES256 server-side encryption.
- Download URLs are signed and time-limited rather than public.
- API secrets are stored only as hashes and cannot be read back.
- Incoming webhooks are signature-verified before being acted on.
- Access is scoped per workspace, so a credential reaches one workspace.
No system is perfectly secure. If we become aware of a breach affecting your data we will notify you without undue delay and as required by law.
10. Your rights
Depending on where you are, you may have rights of access, rectification, erasure, restriction, portability and objection.
Where the personal data is inside documents or merge data, you are the controller — a request from one of your contacts should go to you, and we will assist you in answering it. For your own account data, contact [PRIVACY CONTACT EMAIL].
You may also complain to your local supervisory authority.
11. Children
The Service is intended for business use and is not directed at children.
12. Changes
We may update this policy. The date at the top of this page reflects the most recent change, and material changes will be notified with[NOTICE PERIOD] notice.
13. Contact
Privacy enquiries: [PRIVACY CONTACT EMAIL].