Skip to main content
Dynamic Document API
Product
HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise All features
Use cases
Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API All use cases
Tools Developers Pricing
EnglishEN DeutschDE
Sign in Start free

Product

HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API
Tools Developers Pricing
EN DE
Sign in Start free

Legal

Data Processing Agreement

Version 1.0 · Last updated 4 October 2026 · In force from 4 October 2026 · Part of the Terms of Service

This agreement governs how we process personal data on your behalf when you use the Service. It applies automatically to every customer — you do not have to request or sign anything separately, though we will sign a copy if your procurement process needs one. Write to privacy@dynamicdocumentapi.com.

On this page

  1. Scope and precedence
  2. Definitions
  3. Roles and subject matter
  4. Your instructions
  5. Confidentiality
  6. Security of processing
  7. Sub-processors
  8. Data subject requests
  9. Assistance with your obligations
  10. Personal data breaches
  11. Deletion and return
  12. Audits and evidence
  13. International transfers
  14. Government access requests
  15. United States: service provider terms
  16. Liability, term and law
  17. Annex 1 — Description of the processing
  18. Annex 2 — Technical and organisational measures
  19. Annex 3 — Sub-processors

1. Scope and precedence

This agreement forms part of the Terms of Service between you (the controller) and N.M.M. Noble Minds Media Ltd (the processor). It applies whenever we process personal data on your behalf in providing the Service. On data protection matters it takes precedence over the Terms of Service. Where you are yourself a processor for someone else, this agreement operates as a processor-to-processor arrangement and your own controller’s instructions flow through you to us.

2. Definitions

Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given in the GDPR. Customer Personal Data means personal data contained in Customer Content and Output as defined in the Terms of Service. Data Protection Law means the GDPR, the UK GDPR, the Swiss FADP and any other data protection law that applies to the processing.

3. Roles and subject matter

You decide why and how Customer Personal Data is processed. We process it only to provide, secure and support the Service, as set out in Annex 1. We remain the controller for the account, billing, support and security data described in our Privacy Policy; that data is outside this agreement.

You are responsible for having a legal basis for the processing, for informing data subjects, and for the lawfulness of the content you send us — including whether you may capture a third-party web page.

4. Your instructions

We process Customer Personal Data only on your documented instructions. The Terms of Service, this agreement, the settings you choose in the workspace and each API request you send are your instructions. Additional instructions must be agreed in writing; if they require work beyond the Service as documented, we may charge for it.

We will tell you if, in our view, an instruction breaches Data Protection Law, and may suspend that instruction until it is resolved. We will not process Customer Personal Data for our own purposes, and we will not use it to train machine-learning models.

5. Confidentiality

Everyone we allow to process Customer Personal Data is bound by confidentiality obligations that survive the end of their engagement, and receives access only to the extent their work requires.

6. Security of processing

We implement the technical and organisational measures in Annex 2 and keep them under review. Measures may change as technology moves on, but the overall level of protection will not fall below what Annex 2 describes. You are responsible for the security of your own systems and for how you configure the workspace — in particular how long files and request logs are kept, who has access and how API keys are handled.

7. Sub-processors

You give us general authorisation to engage sub-processors. The current list, with purpose and location, is at dynamicdocumentapi.com/subprocessors.

Before a new sub-processor starts processing Customer Personal Data, we announce it there and notify subscribers at least 30 days in advance; how to subscribe is explained on that page. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.

We impose on every sub-processor data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.

8. Data subject requests

Through the dashboard and the API you can view, download, change and delete templates and generated files yourself, which will answer most requests. Where it does not, we assist you with appropriate technical and organisational measures, as far as is reasonably possible, and at your cost where the effort goes beyond the Service as documented.

If a data subject contacts us directly about Customer Personal Data, we will not respond on the substance. We will forward the request to you without undue delay, and tell the data subject that we did.

9. Assistance with your obligations

Taking into account the nature of the processing and the information available to us, we assist you with your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation.

10. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay and in any event within 48 hours of becoming aware. The notification describes what happened, which categories and approximate numbers of data subjects and records are affected, the likely consequences, the measures taken and a contact point. Where we cannot provide all of it at once, we provide it in phases without undue further delay.

We will not notify supervisory authorities or data subjects on your behalf unless you instruct us to, and we will not name you publicly without your agreement unless the law requires it.

11. Deletion and return

Customer Personal Data is deleted when its retention window under section 11 of the Terms of Service and your workspace settings ends, or earlier when you delete it. Ending a paid subscription does not delete it; the workspace continues on the free plan. When you delete a workspace or your account, its Customer Personal Data can be restored for 7 days and is then deleted; backups roll off within a further 35 days. Before deleting, you can download your files and templates through the dashboard or the API; that is how data is returned. Where the law requires us to keep data, we keep it only for that purpose and continue to protect it under this agreement.

We confirm deletion in writing on request.

12. Audits and evidence

We make available the information needed to demonstrate compliance with Article 28 GDPR. In practice, in this order:

  • this agreement, Annex 2 and the security page;
  • our answers to your written security questionnaire, once per year and free of charge;
  • an on-site audit, where the above genuinely does not suffice: with 30 days’ notice, during business hours, no more than once a year unless a supervisory authority or a breach requires otherwise, by you or an independent auditor who is not our competitor and who signs a confidentiality undertaking, at your cost, and without access to other customers’ data.

13. International transfers

Customer Personal Data is stored and rendered in the European Union. If it is nevertheless transferred out of the EEA, the transfer is based on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this agreement by reference:

  • Module Two (controller to processor) where you are a controller, and Module Three (processor to processor) where you are a processor;
  • Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation) with the notice period in section 7; Clause 11 without the independent dispute resolution option; Clause 17 option 1 with the law of Cyprus; Clause 18(b) the courts of Cyprus;
  • Annexes I, II and III of the Clauses are Annexes 1, 2 and 3 of this agreement;
  • for the United Kingdom, the ICO International Data Transfer Addendum applies; for Switzerland, the Clauses are read with the amendments required by the FADP.

Before such a transfer we assess the law of the destination country and apply supplementary measures where needed, in particular encryption in transit, access control and the commitment in section 14. We make that assessment available to you on request.

14. Government access requests

If an authority requests access to Customer Personal Data, we notify you before disclosing anything, unless we are legally barred from doing so — in which case we use the legal remedies available to challenge the prohibition where there are grounds to do so, and disclose only the minimum legally required. We do not give any authority direct or unrestricted access to Customer Personal Data, and we do not hold decryption keys for any authority.

15. United States: service provider terms

Where the California Consumer Privacy Act or a comparable US state law applies, we act as a service provider or processor. We process personal information only to perform the Service, do not sell or share it, do not retain, use or disclose it outside the direct business relationship, and do not combine it with personal information from other sources except as permitted. We will notify you if we can no longer meet these obligations.

16. Liability, term and law

The liability provisions of the Terms of Service apply to this agreement, subject to any mandatory rule of Data Protection Law and to the Standard Contractual Clauses, which prevail in the event of conflict. This agreement lasts as long as we process Customer Personal Data. It is governed by the law stated in the Terms of Service, save that the Clauses are governed by the law named in section 13.

Annex 1 — Description of the processing

A. Parties

Data exporter: you, as identified in your workspace. Data importer: N.M.M. Noble Minds Media Ltd, registration number HE 453611, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, contact privacy@dynamicdocumentapi.com.

B. Description

Categories of data subjectsWhoever you put into your documents: your customers, employees, suppliers, members, recipients of invoices, certificates or messages.
Categories of personal dataWhatever your templates and payloads contain — typically names, addresses, contact details, customer and order numbers, amounts, dates, usage data, and images. Also the metadata of your API requests.
Special categoriesNot permitted without a separate written agreement (Terms of Service, section 9). We do not knowingly process them.
FrequencyContinuous, for as long as you use the Service.
Nature and purposeReceiving, rendering, storing and delivering documents and images; operating, securing and supporting the platform.
RetentionAs set out in the Terms of Service, section 11, and your workspace settings.
Sub-processorsSee Annex 3.

C. Competent supervisory authority

For Module Two and Three transfers: the supervisory authority of the member state where you are established, or where you have designated an Article 27 representative. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

Annex 2 — Technical and organisational measures

The measures below apply to the production platform. We may replace a measure with one that protects at least as well (section 6).

Physical securityServers in the data centres of our hosting providers in the EU, as listed on the sub-processor page
EncryptionTLS 1.2 or higher between you and the Service, with HSTS; database volumes encrypted with AES-256; backups encrypted before they leave the server; generated files delivered through signed URLs that expire after 1 hour by default and at most 7 days
Staff accessIndividual accounts, multi-factor authentication, access only as far as the task requires, administrative access logged
Customer accounts and API keysPasswords hashed with Argon2 and checked against known breaches; multi-factor authentication and passkeys; API keys stored only as hashes, with scopes, template and IP allowlists, expiry and rotation
Tenant separationEvery query is scoped to its workspace in the data layer, backed by row-level security in the database and covered by automated tests
Rendering isolationRenderers run without root rights on a read-only file system, with a seccomp profile and the browser’s own sandbox, and keep no browser profile between renders; outbound requests go only through an egress proxy that blocks private, loopback, link-local and other internal addresses; renderers hold no storage credentials
LoggingSecurity-relevant events and administrative actions are logged; workspaces on Growth and above see their own audit log
Backups and restoreDatabases: continuous archiving with about one minute’s delay plus a nightly full backup, encrypted, kept for 35 days; restore tested at least quarterly
Secure developmentCode review; dependency and secret scanning in continuous integration; development and staging separated from production; no production data used for development
Incident handlingSecurity incidents are assessed, contained and documented; the notification duty in section 10 applies
DeletionAutomatic deletion at the end of the retention window; deleted workspaces and accounts purged after 7 days; backups roll off within 35 days
ConfidentialityEveryone with access is bound to confidentiality; access is removed when someone leaves
Sub-processor managementChecked before engagement, bound by a data processing agreement, listed publicly

Annex 3 — Sub-processors

The current list, including purpose, data categories and location, is published at dynamicdocumentapi.com/subprocessors and forms part of this agreement. Changes follow section 7.

Change history

VersionDateChange
0.123 September 2026First draft, pending legal review
1.04 October 2026In force. Section 7: 30 days’ notice of new sub-processors. Section 10: breach notice within 48 hours. Section 11: deletion and return as the platform handles them. Section 12: no third-party audit reports. Section 13: Customer Personal Data stays in the EU; courts of Cyprus. Annex 2: measures as implemented
Dynamic Document API

API infrastructure for automated document and image generation.

Product

HTML to PDF API PDF Generation API Image Generation API URL to PDF API PDF Template API Markdown to PDF API Enterprise Pricing

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API

PDF tools

Compress PDF Merge PDF Split PDF PDF to image PNG to PDF HTML to PDF Markdown to PDF All free tools

Developers

Documentation API reference SDKs Webhooks Template gallery Security

Company

About Contact

Legal

Terms Privacy DPA Acceptable use Sub-processors Legal notice

© 2026 Dynamic Document API. All rights reserved.

  • Deutsch
  • Legal notice
  • Privacy
  • Terms