Skip to main content
Dynamic Document API
Product
HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise All features
Use cases
Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API All use cases
Tools Developers Pricing
EnglishEN DeutschDE
Sign in Start free

Product

HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API
Tools Developers Pricing
EN DE
Sign in Start free

Legal

Data Processing Agreement

Version 0.1 (draft) · Last updated 23 September 2026 · Part of the Terms of Service

Draft — not yet in force. This text is a working draft awaiting review by qualified counsel. Passages marked like this depend on facts that are not yet fixed. The technical measures in Annex 2 must match what the platform actually does before this is offered to anyone.

This agreement governs how we process personal data on your behalf when you use the Service. It applies automatically to every customer — you do not have to request or sign anything separately, though we will sign a copy if your procurement process needs one. Write to privacy@dynamicdocumentapi.com.

On this page

  1. Scope and precedence
  2. Definitions
  3. Roles and subject matter
  4. Your instructions
  5. Confidentiality
  6. Security of processing
  7. Sub-processors
  8. Data subject requests
  9. Assistance with your obligations
  10. Personal data breaches
  11. Deletion and return
  12. Audits and evidence
  13. International transfers
  14. Government access requests
  15. United States: service provider terms
  16. Liability, term and law
  17. Annex 1 — Description of the processing
  18. Annex 2 — Technical and organisational measures
  19. Annex 3 — Sub-processors

1. Scope and precedence

This agreement forms part of the Terms of Service between you (the controller) and N.M.M. Noble Minds Media Ltd (the processor). It applies whenever we process personal data on your behalf in providing the Service. On data protection matters it takes precedence over the Terms of Service. Where you are yourself a processor for someone else, this agreement operates as a processor-to-processor arrangement and your own controller’s instructions flow through you to us.

2. Definitions

Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given in the GDPR. Customer Personal Data means personal data contained in Customer Content and Output as defined in the Terms of Service. Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP and any other data protection law that applies to the processing.

3. Roles and subject matter

You decide why and how Customer Personal Data is processed. We process it only to provide, secure and support the Service, as set out in Annex 1. We remain the controller for the account, billing, support and security data described in our Privacy Policy; that data is outside this agreement.

You are responsible for having a legal basis for the processing, for informing data subjects, and for the lawfulness of the content you send us — including whether you may capture a third-party web page.

4. Your instructions

We process Customer Personal Data only on your documented instructions. The Terms of Service, this agreement, the settings you choose in the workspace and each API request you send are your instructions. Additional instructions must be agreed in writing; if they require work beyond the Service as documented, we may charge for it.

We will tell you if, in our view, an instruction breaches Data Protection Law, and may suspend that instruction until it is resolved. We will not process Customer Personal Data for our own purposes, and we will not use it to train machine-learning models.

5. Confidentiality

Everyone we allow to process Customer Personal Data is bound by confidentiality obligations that survive the end of their engagement, and receives access only to the extent their work requires.

6. Security of processing

We implement the technical and organisational measures in Annex 2 and keep them under review. Measures may change as technology moves on, but the overall level of protection will not fall below what Annex 2 describes. You are responsible for the security of your own systems and for how you configure the workspace — in particular retention windows, whether payload logging is enabled, who has access and how API keys are handled.

7. Sub-processors

You give us general authorisation to engage sub-processors. The current list, with purpose and location, is at dynamicdocumentapi.com/subprocessors.

Before a new sub-processor starts processing Customer Personal Data, we announce it there and notify subscribers at least [TO CONFIRM: 30] days in advance. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.

We impose on every sub-processor data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.

8. Data subject requests

The workspace lets you access, export, correct and delete Customer Personal Data yourself, which will answer most requests. Where it does not, we assist you with appropriate technical and organisational measures, as far as is reasonably possible, and at your cost where the effort goes beyond the Service as documented.

If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance. We will forward the request to you without undue delay, and tell the data subject that we did.

9. Assistance with your obligations

Taking into account the nature of the processing and the information available to us, we assist you with your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation.

10. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay and in any event within [TO CONFIRM: 48] hours of becoming aware. The notification describes what happened, which categories and approximate numbers of data subjects and records are affected, the likely consequences, the measures taken and a contact point. Where we cannot provide all of it at once, we provide it in phases without undue further delay.

We will not notify supervisory authorities or data subjects on your behalf unless you instruct us to, and we will not name you publicly without your agreement unless the law requires it.

11. Deletion and return

During the term, deletion follows the retention windows in the Terms of Service and your workspace settings. On termination you may export Customer Personal Data for 30 days. After that we delete it, including from backups as they roll off within [TO CONFIRM: 35] days, unless the law requires us to keep it — in which case we keep it only for that purpose and continue to protect it under this agreement.

We confirm deletion in writing on request.

12. Audits and evidence

We make available the information needed to demonstrate compliance with Article 28 GDPR. In practice, in this order:

  • this agreement, Annex 2 and the security page;
  • our answers to your written security questionnaire, once per year and free of charge;
  • [TO CONFIRM: third-party audit reports once they exist — do not promise SOC 2 or ISO 27001 before it is certified];
  • an on-site audit, where the above genuinely does not suffice: with 30 days’ notice, during business hours, no more than once a year unless a supervisory authority or a breach requires otherwise, by you or an independent auditor who is not our competitor and who signs a confidentiality undertaking, at your cost, and without access to other customers’ data.

13. International transfers

You choose the processing region for your workspace. If Customer Personal Data is transferred out of the EEA, the transfer is based on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this agreement by reference:

  • Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor;
  • Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) with the notice period in section 7; Clause 11 without the independent dispute resolution option; Clause 17 option 1 with the law of Cyprus; Clause 18(b) the courts of [TO CONFIRM: Cyprus];
  • Annexes I, II and III of the Clauses are Annexes 1, 2 and 3 of this agreement;
  • for the United Kingdom, the ICO International Data Transfer Addendum applies; for Switzerland, the Clauses are read with the amendments required by the FADP.

We have assessed the law of the destination countries and apply supplementary measures, in particular encryption in transit and at rest, access control and the commitment in section 14. We provide our transfer impact assessment on request.

14. Government access requests

If an authority requests access to Customer Personal Data, we notify you before disclosing anything, unless we are legally barred from doing so — in which case we challenge the prohibition and disclose only the minimum legally required. We do not give any authority direct or unrestricted access to Customer Personal Data, and we do not hold decryption keys for any authority. We publish the number of such requests [TO CONFIRM: transparency report planned? Only promise it if it will exist.]

15. United States: service provider terms

Where the California Consumer Privacy Act or a comparable US state law applies, we act as a service provider or processor. We process personal information only to perform the Service, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and do not combine it with personal information from other sources except as permitted. We will notify you if we can no longer meet these obligations.

16. Liability, term and law

The liability provisions of the Terms of Service apply to this agreement, subject to any mandatory rule of Data Protection Law and to the Standard Contractual Clauses, which prevail in the event of conflict. This agreement lasts as long as we process Customer Personal Data. It is governed by the law stated in the Terms of Service, save that the Clauses are governed by the law named in section 13.

Annex 1 — Description of the processing

A. Parties

Data exporter: you, as identified in your workspace. Data importer: N.M.M. Noble Minds Media Ltd, registration number HE 453611, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, contact privacy@dynamicdocumentapi.com.

B. Description

Categories of data subjectsWhoever you put into your documents: your customers, employees, suppliers, members, recipients of invoices, certificates or messages.
Categories of personal dataWhatever your templates and payloads contain — typically names, addresses, contact details, customer and order numbers, amounts, dates, usage data, and images. Also the metadata of your API requests.
Special categoriesNot permitted without a separate written agreement (Terms of Service, section 9). We do not knowingly process them.
FrequencyContinuous, for as long as you use the Service.
Nature and purposeReceiving, rendering, storing and delivering documents and images; operating, securing and supporting the platform.
RetentionAs set out in the Terms of Service, section 11, and your workspace settings.
Sub-processorsSee Annex 3.

C. Competent supervisory authority

For Module Two and Three transfers: the supervisory authority of the member state where you are established, or where you have designated an Article 27 representative. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

Annex 2 — Technical and organisational measures

[TO CONFIRM: every line against the running platform. A measure listed here that is not implemented is a misrepresentation with contractual effect.]

EncryptionTLS 1.2 or higher in transit; encryption at rest for stored files, databases and backups; signed, expiring URLs for file delivery
Access controlLeast privilege, multi-factor authentication for staff, individual accounts, access reviews, logged administrative access
Tenant separationLogical separation of workspaces enforced in the data layer, with automated tests
Rendering isolationEach render runs in a sandbox without access to other customers’ data, with restricted outbound network access
Key managementAPI keys stored as hashes; secrets in a managed key store; rotation supported
Logging and monitoringSecurity-relevant events logged and monitored; alerting on anomalies; audit log available to customers
Backups and restoreRegular encrypted backups, restore tested [TO CONFIRM: how often]
Secure developmentCode review, dependency and secret scanning in CI, separate environments, no production data in development
Incident responseDocumented process with defined roles and the notification duty in section 10
DeletionAutomatic deletion at the end of the retention window; purge after workspace deletion; backups roll off
StaffConfidentiality undertakings, security training, offboarding checklist
Sub-processor managementDue diligence before engagement, contractual obligations, published list

Annex 3 — Sub-processors

The current list, including purpose, data categories and location, is published at dynamicdocumentapi.com/subprocessors and forms part of this agreement. Changes follow section 7.

Change history

VersionDateChange
0.123 September 2026First draft, pending legal review
Dynamic Document API

API infrastructure for automated document and image generation.

Product

HTML to PDF API PDF Generation API Image Generation API URL to PDF API PDF Template API Markdown to PDF API Enterprise Pricing

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API

PDF tools

Compress PDF Merge PDF Split PDF PDF to image PNG to PDF HTML to PDF Markdown to PDF All free tools

Developers

Documentation API reference SDKs Webhooks Template gallery Security

Company

About Contact

Legal

Terms Privacy DPA Acceptable use Sub-processors Legal notice

© 2026 Dynamic Document API. All rights reserved.

  • Deutsch
  • Legal notice
  • Privacy
  • Terms