Legal
Privacy Policy
This policy explains what we do with personal data when you visit this website, write to us, create an account or use the API. A short version: we collect what we need to run the Service and bill for it, we keep customer documents only as long as you set, we do not sell data, and we do not train models on your content.
1. Who is responsible
Controller within the meaning of the GDPR: N.M.M. Noble Minds Media Ltd, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, registration number HE 453611. Full provider details are in the legal notice.
For any question about data protection, and to exercise your rights, write to privacy@dynamicdocumentapi.com.
You can complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus; you may also complain to the authority where you live or work.
2. Two different roles
Keeping these apart matters, because different rules apply.
- We are the controller for data about you as a visitor, account holder or contact: registration and login, billing contact data, emails and support conversations, usage of the Service, security logs and marketing you asked for. That is what this policy covers.
- We are a processor for whatever is inside the documents you generate — the payload you send to the API, the templates you build, the files we return. We process that only on your instructions, under the Data Processing Agreement. If you are an employee, customer or recipient of one of our customers and have a question about such data, please contact that customer; they decide what happens to it.
3. What we process, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, password hash, company, country | Creating and running your account | Art. 6(1)(b) — performance of a contract |
| Name, email and account ID from Google, GitHub or Microsoft | Signing you in with that account, if you choose to | Art. 6(1)(b) |
| IP address and browser signals during sign-up and login | Telling people from bots (Cloudflare Turnstile) | Art. 6(1)(f) — legitimate interest in protecting accounts from automated abuse |
| Billing contact, billing address, tax ID, subscription status | Charging for paid plans and keeping tax records. The seller of paid plans is Link (see section 5); we never see card data | Art. 6(1)(b) and (c) — contract and legal obligation |
| API key metadata; for each request and render: time, endpoint, template, pages, size, status, duration, IP address | Delivering renders, counting usage for your plan, diagnosing errors, protecting against abuse | Art. 6(1)(b) and (f) — contract and our legitimate interest in a working, secure service |
| Request logs in your workspace: method, path, headers with secrets removed, IP address, status; request bodies only if you switch them on | Letting you trace and debug your own requests | Art. 6(1)(b) |
| Request payloads and generated files | Producing the document you asked for | Processed for you as processor — see the DPA |
| Error reports: stack trace and technical context of the failed request | Finding and fixing bugs | Art. 6(1)(f) — legitimate interest in a working service |
| Emails you send us, with attachments | Answering you and keeping a record of what was agreed | Art. 6(1)(b) and (f) |
| Security and audit logs: actions in your account, IP address, browser, country | Detecting attacks, investigating incidents, showing you who did what | Art. 6(1)(f) and (c) |
| Email address for product and marketing mail | Service notices; newsletters only if you asked for them | Art. 6(1)(b) for service mail, Art. 6(1)(a) — consent — for marketing, withdrawable at any time |
| Connection data when you visit this website: IP address, browser, page, time | Delivering the page and defending against attacks. Cloudflare does this for us; we keep no server logs of the website | Art. 6(1)(f) |
Where we rely on legitimate interests, we have weighed them against your interests; you can object under section 8.
The PDF tools stay in your browser. Files you open in the free PDF tools on this website are processed on your device and are not uploaded to us or anyone else.
No training on your content. We do not use customer documents, templates or payloads to train machine-learning models, neither our own nor anyone else’s.
No sale of data. We do not sell personal data and we do not share it for cross-context behavioural advertising.
4. Where data is processed
We run the Service in the European Union. Servers and file storage are in data centres in Germany, encrypted backups stay in the EU. That is where your account, request payloads, templates and generated files are stored and rendered. There is no other region yet; if we add one, you will choose it per workspace, and we will update this policy before it opens.
Some service providers process data outside the EU, for example for payments or email. Section 5 and the sub-processor list say who and where; section 6 explains the safeguards.
5. Who receives data
Inside our company, only people who need access for their work get it, under confidentiality obligations. Beyond that, data goes to service providers who process it on our behalf: hosting, delivery and protection of the website and the Service, email, and error monitoring. The current list, with purpose and location, is on the sub-processors page; we announce changes there at least 30 days in advance.
Some recipients act on their own responsibility:
- Payments. Paid plans are sold through Stripe Managed Payments; the seller (merchant of record) is Sold through Link, LLC, a Stripe company (“Link”). Link collects your payment details at checkout and processes them under its own privacy policy. We receive your billing contact, billing address, tax ID and subscription status.
- Sign-in with Google, GitHub or Microsoft. If you choose it, that provider confirms your identity to us under its own privacy policy.
- Stock photos. If you use the image search in the template editor, your browser loads the preview images directly from Unsplash or Pexels, which therefore see your IP address.
Emails to our addresses are forwarded through Cloudflare to our mailboxes with email providers in Switzerland and the United States.
We also disclose data where we must: to public authorities on a valid legal basis, and to advisers, auditors or an acquirer in the context of a corporate transaction, in each case under confidentiality. We will tell you about an authority request unless we are legally barred from doing so.
6. International transfers
Where a provider processes personal data outside the EEA, the transfer rests on an adequacy decision of the European Commission — for example for Switzerland, or for US companies certified under the EU–US Data Privacy Framework — or otherwise on the Commission’s Standard Contractual Clauses (Decision 2021/914), together with an assessment of the legal situation in the destination country and additional safeguards where needed — in particular encryption in transit and at rest and a policy of challenging unlawful access requests. For the United Kingdom we add the IDTA addendum, for Switzerland the Swiss amendments. Copies are available on request.
7. How long we keep things
| Generated files | 7 days by default. You can change this per workspace, template or request up to your plan’s maximum (Free 7 days, Starter 90 days, Growth 365 days, Pro and above unlimited), or not store files at all |
|---|---|
| Request logs | Paid plans: 7 days by default, adjustable up to the plan’s maximum (Starter and Growth 7 days, Pro 30, Scale 90, Enterprise 365). The Free plan keeps no request logs |
| Render and usage records | 13 months after the generated file is gone; daily usage totals per workspace are kept with the billing records |
| Webhook and email delivery logs | 30 days |
| Access logs of the application | 14 days |
| Audit log | 1 year |
| Security logs | 1 year |
| API keys | Time and IP address of last use, until the key is deleted |
| Account after deletion | 7 days recoverable, then deleted; audit entries remain without IP address and browser details, billing records as below. Backups roll off within 35 days |
| Billing records | 6 years, as Cypriot tax law requires |
| Emails and support conversations | 3 years |
| This website | We keep no server logs |
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict its processing, or hand it to another provider in a portable format. You can object to processing we base on legitimate interests, including profiling; we then stop unless we have compelling grounds. You can withdraw consent at any time, with effect for the future. Marketing email can be stopped with the unsubscribe link in every message.
Write to privacy@dynamicdocumentapi.com. We answer within one month and may ask for information to confirm who you are. Much of it is also self-service in the workspace: export, change or delete your data yourself.
9. Cookies and storage on your device
This website sets no cookies and loads nothing from third-party servers: fonts, styles, scripts and images all come from our own domain. If you switch between light and dark mode in the documentation, your browser remembers that choice in its local storage; nothing else is stored on your device. There is nothing to consent to and therefore no cookie banner.
The web application uses two cookies. Both are strictly necessary and therefore do not require consent under Article 5(3) of the ePrivacy Directive.
| Cookie | Purpose | Lifetime |
|---|---|---|
dda_session | Keeps you logged in | 14 days after your last activity |
dda_csrftoken | Protects forms against cross-site request forgery | 1 year |
The application also keeps settings such as the editor layout and the colour theme in your browser’s local storage, and unsaved template drafts in its database (IndexedDB) until you save them. The bot check at sign-up and login is loaded from Cloudflare (see section 3).
10. Security
We protect data with encryption in transit and at rest, strict separation between workspaces, least-privilege access with multi-factor authentication for staff, sandboxed rendering, logging and monitoring, and tested backups. The security page describes the measures; Annex 2 of the DPA is the binding version for customer data. If a breach affects your personal data and is likely to result in a high risk to you, we tell you without undue delay.
11. Children
The Service is not directed at children. We do not knowingly process the data of anyone under 18. If you believe a child has given us data, write to us and we will delete it.
12. United States: state privacy rights
Several US states give their residents privacy rights, among them California, Colorado, Connecticut, Texas and Virginia. We extend the following to everyone, regardless of whether a particular state law applies to us:
- Your rights. You can ask what personal information we hold about you, get a copy, have it corrected or deleted, and appeal a refusal by writing to us again. Send requests to privacy@dynamicdocumentapi.com; we answer as described in section 8.
- No sale, no sharing, no profiling. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling with legal or similarly significant effects.
- Do Not Track and Global Privacy Control. We do not track visitors across websites, so these browser signals have nothing to switch off. We still treat them as a valid request to opt out of sale and sharing.
- No discrimination. Using these rights never affects the price or quality of the Service you get.
Where we process personal information on behalf of a business customer, we act as its service provider or processor: we use that information only to provide the Service and for no other purpose. Section 15 of the DPA contains the service-provider terms.
13. Changes
We update this policy when the Service or the law changes. The version and date are at the top, and the change history below records what moved. If a change materially affects how we handle your data, we tell you by email before it takes effect.
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft, pending legal review |
| 1.0 | 4 October 2026 | Matched to the Service as built: EU only with servers in Germany, retention periods, cookies, recipients (Cloudflare, Link, sign-in providers, stock photos), privacy contact instead of a data protection officer, short US section incl. Do Not Track; no longer a draft |