Data Processing Agreement. GDPR Article 28.
When you send documents to the SelectPdf Online API, you are the controller and SelectPdf is your processor. This agreement sets out what we do with that content, how long we keep it, who else touches it, and what we owe you under Article 28 of the GDPR. It applies to every Online API account — no signature required — and we countersign a copy for your records on request.
- You are the controller; SelectPdf is the processor. Your content stays yours.
- Content is processed only to produce the document you asked for — never for analytics, profiling, resale or model training.
- Conversion inputs and outputs are deleted as soon as the result reaches you.
- All rendering happens on servers in the United Kingdom.
- One infrastructure sub-processor. No advertising, analytics or AI vendor is in the request path.
- This DPA applies automatically to every Online API account — email support for a countersigned copy.
Parties and Scope
This Data Processing Agreement (the “DPA”) is entered into between Outside Software SRL, a Romanian company registered with number RO16266620, having its registered office at Bd. Dimitrie Cantemir, Nr. 5, Bl. 6, Sc. A, Et. 6, Ap. 24, Sector 4, Bucharest, 040232, Romania (“SelectPdf”, “we”, “us”), and the customer that holds a SelectPdf Online API account (the “Customer”, “you”).
It forms part of, and is governed by, the Terms and Conditions (the “Agreement”). It applies whenever you submit content to the SelectPdf Online API that contains personal data. In that processing you act as the controller and SelectPdf acts as your processor within the meaning of Article 4 of the GDPR.
This DPA does not apply to the SelectPdf Library for .NET. That product runs entirely on your own infrastructure; no content reaches us, and no processor relationship arises.
It also does not cover the account, billing and support data of your own staff — contact name, email address, company details and payment records. For that data SelectPdf is an independent controller, and our handling of it is described in the Privacy Policy.
Where this DPA conflicts with the Agreement, this DPA prevails in respect of the processing of Customer Personal Data.
Definitions
“GDPR” means Regulation (EU) 2016/679 and, where
applicable, the UK GDPR as incorporated by the Data Protection Act 2018.
“Customer Personal Data” means personal data contained in
content the Customer submits to the Online API, together with the request metadata
described in Annex 1.
“Online API” means the SelectPdf REST endpoints under
/api2/, including HTML-to-PDF conversion, PDF merge, PDF-to-text
extraction and the associated job-polling endpoints.
“Sub-processor” means a third party engaged by SelectPdf
to process Customer Personal Data.
“controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” carry the meanings given to them in Article 4 of the GDPR.
Subject Matter, Duration and Purpose
The subject matter of the processing is the provision of the Online API. Its nature is automated document rendering and conversion; its purpose is to return to the Customer the document the Customer requested, and to meter and support that service. The types of personal data and the categories of data subjects are determined by the Customer and are described in Annex 1.
The processing lasts for as long as the Customer's Online API subscription is active, and ends on termination of the Agreement, subject to § 10.
Processing on Documented Instructions
SelectPdf processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country. The Agreement, this DPA and each API request the Customer makes together constitute those instructions: every request is an instruction to render the submitted content with the parameters supplied and to return the result.
SelectPdf does not read, inspect, index, analyse, enrich, aggregate or disclose the content of submitted documents for any purpose other than producing the requested output and diagnosing failures of that output. In particular, submitted content is not used for advertising or profiling, not sold or shared with third parties, and not used to train machine-learning or artificial-intelligence models, by us or by anyone else.
If SelectPdf is required by Union or Member State law to process Customer Personal Data beyond the Customer's instructions, we will inform the Customer of that requirement before processing, unless the law prohibits such notification on important grounds of public interest. SelectPdf will inform the Customer if, in its opinion, an instruction infringes the GDPR.
The Customer warrants that it has a lawful basis for the processing it instructs, that it has given any notice and obtained any consent required from its data subjects, and that its instructions comply with applicable data-protection law.
Confidentiality
SelectPdf ensures that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether by contract of employment or by a separate confidentiality undertaking, and that the obligation survives the end of their engagement. Access is granted only to personnel who need it in order to operate or support the service.
Security of Processing
SelectPdf implements appropriate technical and organisational measures under Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risk to data subjects. The measures in force are listed in Annex 3.
Chief among those measures is that we retain as little as possible: the deletion of conversion content described in § 10 is itself a security control.
SelectPdf may update the measures in Annex 3 over time, provided the level of security is not reduced.
Sub-processors
The Customer grants SelectPdf general written authorisation to engage sub-processors for the performance of the Online API. Those engaged as at the date of this DPA are listed in Annex 2. There is currently one: our infrastructure provider, Fasthosts Internet Ltd., which supplies the United Kingdom servers on which conversions run.
SelectPdf imposes on each sub-processor, by written contract, data-protection obligations no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of that sub-processor's obligations.
SelectPdf will give the Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor, by email to the account contact address and by updating Annex 2. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Online API subscription and receive a pro-rata refund of any prepaid, unused fees.
Assistance to the Customer
Data-subject requests
Taking into account the nature of the processing, SelectPdf assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data-subject rights under Chapter III of the GDPR. Because conversion content is not retained (§ 10), SelectPdf ordinarily holds no copy of a data subject's document and there is nothing to access, rectify, export or erase on our side.
If a data subject contacts SelectPdf directly about content submitted through a Customer's account, SelectPdf will not respond to the substance of the request and will refer the data subject to the Customer, notifying the Customer promptly.
Compliance, DPIAs and prior consultation
SelectPdf assists the Customer in ensuring compliance with Articles 32 to 36 of the GDPR — security of processing, breach notification, data-protection impact assessments and prior consultation with a supervisory authority — taking into account the nature of the processing and the information available to us.
Personal Data Breaches
SelectPdf notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification is sent to the account contact address and includes, to the extent then known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it; and a contact point for further information.
Where the information cannot be provided at once, it may be supplied in phases without further undue delay. SelectPdf documents every such breach and cooperates with the Customer in any notification the Customer must make to a supervisory authority or to data subjects.
Deletion and Return of Data
Conversion content
SelectPdf does not retain the content the Customer submits to the Online API. Input documents and the output generated from them are held only for as long as is necessary to carry out the conversion and deliver the result to the Customer, and are deleted once that has been done. Document content is not archived, and it is not copied to any other system.
Where a request cannot be completed — a conversion that fails, or a result the Customer never collects — any content still held so that the failure can be diagnosed is deleted within 7 days. That deletion is automatic: it is carried out by a scheduled process and depends neither on a request from the Customer nor on any manual step by SelectPdf.
Service records
SelectPdf keeps records of API usage for metering, billing, security and support purposes. Those records describe the requests made — not the content of the documents converted — and are handled in accordance with the Privacy Policy.
On termination
At the Customer's choice, SelectPdf deletes or returns all Customer Personal Data after the end of the provision of services relating to processing, and deletes existing copies, unless Union or Member State law requires storage. A written request may be sent to support@selectpdf.com; SelectPdf confirms completion in writing.
Audits and Information
SelectPdf makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.
In practice, SelectPdf will first respond to a written information request — including a completed security questionnaire — within 30 days. Where that is not sufficient, an on-site or remote audit may be carried out no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality undertakings. Additional audits may be carried out where required by a supervisory authority or following a personal data breach affecting the Customer. Audits are at the Customer's expense, except where the audit reveals a material breach of this DPA.
International Transfers
SelectPdf is established in Romania (European Union) and the servers that run the Online API are located in the United Kingdom. Transfers of personal data from the EEA to the United Kingdom are covered by the European Commission's adequacy decision for the United Kingdom (Commission Implementing Decision (EU) 2021/1772 of 28 June 2021).
SelectPdf will not transfer Customer Personal Data to any other third country without an adequacy decision or an appropriate safeguard under Chapter V of the GDPR — in practice, the Standard Contractual Clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies. Where the Customer requires the Standard Contractual Clauses to be executed, module two (controller to processor) applies, this DPA supplies the content of their Annexes I to III, and § 14 explains how to have them signed.
Liability, Term and Governing Law
Each party's liability under this DPA is subject to the exclusions and limitations of liability set out in the Terms and Conditions. Nothing in this DPA limits any liability that cannot be limited under applicable data-protection law, including liability to data subjects under Article 82 of the GDPR.
This DPA takes effect when the Customer first submits content to the Online API and continues until the Agreement ends and all Customer Personal Data has been deleted or returned in accordance with § 10.
SelectPdf may update this DPA to reflect changes in the service, in the sub-processors engaged, or in applicable law. Material changes are notified to the account contact address at least 30 days before they take effect, and the date at the top of this page is updated.
This DPA is governed by the laws of Romania, and disputes are submitted to the competent court in Bucharest, Romania, in line with the Agreement — without prejudice to a data subject's rights of action and to the jurisdiction rules that apply to any Standard Contractual Clauses executed between the parties.
How to Execute this DPA
This DPA applies to every Online API account on its own terms. No signature is needed for it to bind us, and referencing this page in your records is sufficient for most Article 28 purposes.
If your compliance programme requires a signed instrument, email support@selectpdf.com with:
- the full legal name and registered address of the controller entity;
- the name and role of the signatory;
- the email address or API account the agreement should be attached to;
- whether you also need the Standard Contractual Clauses executed.
We return a countersigned PDF, normally within five business days. We are equally willing to review and sign your own Article 28 template — send it in the same email and we will come back with comments rather than insisting on our own wording.
Annex 1 — Details of the Processing
Categories of data subjects
Determined by the Customer. Typically the Customer's own customers, users, employees, suppliers or other individuals whose details appear in the documents the Customer generates.
Types of personal data
- Document content — any personal data the Customer chooses to include in the HTML, URL or PDF submitted for conversion. SelectPdf neither selects nor inspects it; in practice it tends to be names, postal and email addresses, order, invoice and account references, and free-text fields.
- Request metadata — technical information about each API call, such as the account used, the IP address of the calling system, timestamps and the parameters of the conversion requested.
Special categories of data
The Online API is not designed for special categories of personal data within the meaning of Article 9 of the GDPR, or for personal data relating to criminal convictions and offences under Article 10. The Customer should not submit such data without first agreeing additional safeguards with us in writing.
Nature and purpose of the processing
Automated rendering of submitted content into a PDF document, merging of submitted PDF documents, and extraction of text from submitted PDF documents; transmission of the result to the Customer; and the metering, billing, abuse-prevention and support activities that accompany it.
Frequency and duration
Continuous, on each API request made by the Customer, for the duration of the Online API subscription. Retention periods are set out in § 10.
Controller and processor contact
The Customer's contact is the account holder recorded on the Online API account. The contact point at SelectPdf for all data-protection matters is support@selectpdf.com. As explained in the Privacy Policy, SelectPdf has not appointed a Data Protection Officer, its processing activities not meeting the thresholds in Article 37 of the GDPR.
Annex 2 — Approved Sub-processors
The following sub-processors are engaged in the provision of the Online API as at 2026-05-22:
- Fasthosts Internet Ltd. — United Kingdom — infrastructure and hosting. Supplies the servers on which conversions execute and on which the account and metering database is held. This is the only sub-processor with access to Customer Personal Data.
No content-delivery network, analytics provider, advertising network, artificial-intelligence service or offshore support vendor sits in the Online API request path.
Vendors outside this DPA
The vendors below process the Customer's own account and billing data, for which SelectPdf is an independent controller under the Privacy Policy. They are listed for transparency: they are not sub-processors under this DPA and they receive no content submitted to the Online API.
- Payment processing — Stripe, Inc. and BlueSnap, Inc.
- Transactional and support email delivery.
- Website analytics, advertising measurement and cookie consent on selectpdf.com — Google, Microsoft and Cookie-Script, active only where the visitor has consented.
Annex 3 — Technical and Organisational Measures
Data minimisation and retention
- Content submitted for conversion is deleted once the result has been delivered (§ 10).
- Anything not collected in the normal course — the payload of a failed request, an uncollected result — is removed by an automated purge within 7 days, with no manual step.
- Service records describe the requests made, not the content of the documents converted.
Encryption and transmission
- All API endpoints are served over HTTPS/TLS; content is encrypted in transit between the Customer's system and SelectPdf.
- Where a conversion fetches a URL supplied by the Customer, the security of that connection is determined by the target site.
Access control
- API access is authenticated by a per-account key, which the account holder can rotate or revoke.
- Administrative access to servers and to the database is limited to named personnel, is authenticated, and is granted on a need-to-operate basis.
- Personnel are bound by confidentiality obligations (§ 5).
Isolation and resilience
- Conversions are executed in isolated, short-lived processes; no rendering state is shared between requests or between accounts.
- Per-account concurrency limits and request throttling protect the service against overload and abuse.
- Service availability is monitored continuously, and conversion failures are logged and alerted on.
Physical security
- Servers are located in data centres in the United Kingdom operated by the sub-processor named in Annex 2, under that provider's physical access controls.