Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use between MakeitPDF ("Processor") and the customer ("Controller") and applies where the Controller uploads documents that contain personal data. It reflects Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR provisions.

1. Roles and scope

The Controller determines the purposes and means of processing. MakeitPDF acts solely as Processor and processes personal data only on the Controller's documented instructions — in practice, the act of submitting a file to a tool is that instruction. MakeitPDF does not read, analyse, mine or sell the contents of uploaded documents, and does not use them to train any model.

2. Nature of the processing

Subject matter: conversion, editing, optimisation and analysis of documents submitted by the Controller. Duration: for the length of the retention window described in section 5. Categories of data subject and personal data: determined entirely by the Controller, since MakeitPDF has no control over what a submitted document contains.

3. Sub-processors

MakeitPDF engages the following sub-processors. Each is bound by data protection terms no less protective than this DPA. The Controller is notified of additions through this page.

Sub-processorPurposeLocation
DigitalOceanServer hosting and file storageEuropean Union
StripePayment processing and invoicingUnited States (SCCs)
Google (Gemini API)AI summarise, chat and translate — only for documents submitted to those toolsUnited States (SCCs)
Zoho MailTransactional email deliveryEuropean Union
SentryError monitoring (no document contents)European Union
PostHogProduct analytics, only with consent (no document contents)European Union

Document contents are shared with the Gemini API only when the Controller uses an AI tool. All other tools process files entirely on MakeitPDF's own servers.

4. Security measures

All traffic is encrypted in transit with TLS. Uploaded files are stored on access-restricted servers, are never listed publicly, and are reachable only through unguessable URLs for the duration of the retention window. Access to production systems is limited to key-based administrator authentication. Passwords are stored using salted one-way hashing, and payment card details never reach MakeitPDF's servers.

5. Retention and deletion

Uploaded files and processed results are deleted automatically after the retention window for the Controller's plan: 1 hour on Free, 24 hours on Pro and 72 hours on Business. Deletion is automatic and requires no request. The Controller may also delete results immediately from the tool page. On termination of the account, remaining files are deleted within the retention window and account records are erased on request.

6. Data subject rights

Taking into account the nature of the processing, MakeitPDF assists the Controller in responding to requests to exercise data subject rights. Because files are deleted automatically within hours, most such requests require no action. Account data is erased on request, and a copy of the account information held can be supplied on request.

7. Personal data breaches

MakeitPDF notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information reasonably available to it so that the Controller can meet its own notification obligations. The Controller remains responsible for notifying its supervisory authority and, where required, affected data subjects.

8. International transfers

Where a sub-processor is located outside the EEA or UK, transfers are made under the European Commission's Standard Contractual Clauses or an equivalent approved transfer mechanism.

9. Audits

On reasonable written request, and no more than once in any twelve-month period, MakeitPDF makes available the information necessary to demonstrate compliance with this DPA. Audit obligations are ordinarily satisfied by providing written responses to a security questionnaire and the documentation described above. On-site inspection is available only where a supervisory authority specifically requires it, on 30 days' written notice, during business hours, without disrupting the service, and at the Controller's cost.

10. Accepting this DPA

This DPA applies automatically to every account and needs no signature — using the service accepts it. If your organisation requires a countersigned copy for its records, write to us and we will review the request.

Questions about this agreement: support@makeitpdf.com