Skip to main content
Dynamic Document API
Product
HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise All features
Use cases
Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API All use cases
Tools Developers Pricing
EnglishEN DeutschDE
Sign in Start free

Product

HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API
Tools Developers Pricing
EN DE
Sign in Start free

Legal

Privacy Policy

Version 1.0 · Last updated 4 October 2026

This policy explains what we do with personal data when you visit this website, write to us, create an account or use the API. A short version: we collect what we need to run the Service and bill for it, we keep customer documents only as long as you set, we do not sell data, and we do not train models on your content.

On this page

  1. Who is responsible
  2. Two different roles
  3. What we process, why, and on what basis
  4. Where data is processed
  5. Who receives data
  6. International transfers
  7. How long we keep things
  8. Your rights
  9. Cookies and storage on your device
  10. Security
  11. Children
  12. United States: state privacy rights
  13. Changes

1. Who is responsible

Controller within the meaning of the GDPR: N.M.M. Noble Minds Media Ltd, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, registration number HE 453611. Full provider details are in the legal notice.

For any question about data protection, and to exercise your rights, write to privacy@dynamicdocumentapi.com.

You can complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus; you may also complain to the authority where you live or work.

2. Two different roles

Keeping these apart matters, because different rules apply.

  • We are the controller for data about you as a visitor, account holder or contact: registration and login, billing contact data, emails and support conversations, usage of the Service, security logs and marketing you asked for. That is what this policy covers.
  • We are a processor for whatever is inside the documents you generate — the payload you send to the API, the templates you build, the files we return. We process that only on your instructions, under the Data Processing Agreement. If you are an employee, customer or recipient of one of our customers and have a question about such data, please contact that customer; they decide what happens to it.

3. What we process, why, and on what basis

DataPurposeLegal basis
Name, email, password hash, company, country Creating and running your account Art. 6(1)(b) — performance of a contract
Name, email and account ID from Google, GitHub or Microsoft Signing you in with that account, if you choose to Art. 6(1)(b)
IP address and browser signals during sign-up and login Telling people from bots (Cloudflare Turnstile) Art. 6(1)(f) — legitimate interest in protecting accounts from automated abuse
Billing contact, billing address, tax ID, subscription status Charging for paid plans and keeping tax records. The seller of paid plans is Link (see section 5); we never see card data Art. 6(1)(b) and (c) — contract and legal obligation
API key metadata; for each request and render: time, endpoint, template, pages, size, status, duration, IP address Delivering renders, counting usage for your plan, diagnosing errors, protecting against abuse Art. 6(1)(b) and (f) — contract and our legitimate interest in a working, secure service
Request logs in your workspace: method, path, headers with secrets removed, IP address, status; request bodies only if you switch them on Letting you trace and debug your own requests Art. 6(1)(b)
Request payloads and generated files Producing the document you asked for Processed for you as processor — see the DPA
Error reports: stack trace and technical context of the failed request Finding and fixing bugs Art. 6(1)(f) — legitimate interest in a working service
Emails you send us, with attachments Answering you and keeping a record of what was agreed Art. 6(1)(b) and (f)
Security and audit logs: actions in your account, IP address, browser, country Detecting attacks, investigating incidents, showing you who did what Art. 6(1)(f) and (c)
Email address for product and marketing mail Service notices; newsletters only if you asked for them Art. 6(1)(b) for service mail, Art. 6(1)(a) — consent — for marketing, withdrawable at any time
Connection data when you visit this website: IP address, browser, page, time Delivering the page and defending against attacks. Cloudflare does this for us; we keep no server logs of the website Art. 6(1)(f)

Where we rely on legitimate interests, we have weighed them against your interests; you can object under section 8.

The PDF tools stay in your browser. Files you open in the free PDF tools on this website are processed on your device and are not uploaded to us or anyone else.

No training on your content. We do not use customer documents, templates or payloads to train machine-learning models, neither our own nor anyone else’s.

No sale of data. We do not sell personal data and we do not share it for cross-context behavioural advertising.

4. Where data is processed

We run the Service in the European Union. Servers and file storage are in data centres in Germany, encrypted backups stay in the EU. That is where your account, request payloads, templates and generated files are stored and rendered. There is no other region yet; if we add one, you will choose it per workspace, and we will update this policy before it opens.

Some service providers process data outside the EU, for example for payments or email. Section 5 and the sub-processor list say who and where; section 6 explains the safeguards.

5. Who receives data

Inside our company, only people who need access for their work get it, under confidentiality obligations. Beyond that, data goes to service providers who process it on our behalf: hosting, delivery and protection of the website and the Service, email, and error monitoring. The current list, with purpose and location, is on the sub-processors page; we announce changes there at least 30 days in advance.

Some recipients act on their own responsibility:

  • Payments. Paid plans are sold through Stripe Managed Payments; the seller (merchant of record) is Sold through Link, LLC, a Stripe company (“Link”). Link collects your payment details at checkout and processes them under its own privacy policy. We receive your billing contact, billing address, tax ID and subscription status.
  • Sign-in with Google, GitHub or Microsoft. If you choose it, that provider confirms your identity to us under its own privacy policy.
  • Stock photos. If you use the image search in the template editor, your browser loads the preview images directly from Unsplash or Pexels, which therefore see your IP address.

Emails to our addresses are forwarded through Cloudflare to our mailboxes with email providers in Switzerland and the United States.

We also disclose data where we must: to public authorities on a valid legal basis, and to advisers, auditors or an acquirer in the context of a corporate transaction, in each case under confidentiality. We will tell you about an authority request unless we are legally barred from doing so.

6. International transfers

Where a provider processes personal data outside the EEA, the transfer rests on an adequacy decision of the European Commission — for example for Switzerland, or for US companies certified under the EU–US Data Privacy Framework — or otherwise on the Commission’s Standard Contractual Clauses (Decision 2021/914), together with an assessment of the legal situation in the destination country and additional safeguards where needed — in particular encryption in transit and at rest and a policy of challenging unlawful access requests. For the United Kingdom we add the IDTA addendum, for Switzerland the Swiss amendments. Copies are available on request.

7. How long we keep things

Generated files7 days by default. You can change this per workspace, template or request up to your plan’s maximum (Free 7 days, Starter 90 days, Growth 365 days, Pro and above unlimited), or not store files at all
Request logsPaid plans: 7 days by default, adjustable up to the plan’s maximum (Starter and Growth 7 days, Pro 30, Scale 90, Enterprise 365). The Free plan keeps no request logs
Render and usage records13 months after the generated file is gone; daily usage totals per workspace are kept with the billing records
Webhook and email delivery logs30 days
Access logs of the application14 days
Audit log1 year
Security logs1 year
API keysTime and IP address of last use, until the key is deleted
Account after deletion7 days recoverable, then deleted; audit entries remain without IP address and browser details, billing records as below. Backups roll off within 35 days
Billing records6 years, as Cypriot tax law requires
Emails and support conversations3 years
This websiteWe keep no server logs

8. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict its processing, or hand it to another provider in a portable format. You can object to processing we base on legitimate interests, including profiling; we then stop unless we have compelling grounds. You can withdraw consent at any time, with effect for the future. Marketing email can be stopped with the unsubscribe link in every message.

Write to privacy@dynamicdocumentapi.com. We answer within one month and may ask for information to confirm who you are. Much of it is also self-service in the workspace: export, change or delete your data yourself.

9. Cookies and storage on your device

This website sets no cookies and loads nothing from third-party servers: fonts, styles, scripts and images all come from our own domain. If you switch between light and dark mode in the documentation, your browser remembers that choice in its local storage; nothing else is stored on your device. There is nothing to consent to and therefore no cookie banner.

The web application uses two cookies. Both are strictly necessary and therefore do not require consent under Article 5(3) of the ePrivacy Directive.

CookiePurposeLifetime
dda_sessionKeeps you logged in14 days after your last activity
dda_csrftokenProtects forms against cross-site request forgery1 year

The application also keeps settings such as the editor layout and the colour theme in your browser’s local storage, and unsaved template drafts in its database (IndexedDB) until you save them. The bot check at sign-up and login is loaded from Cloudflare (see section 3).

10. Security

We protect data with encryption in transit and at rest, strict separation between workspaces, least-privilege access with multi-factor authentication for staff, sandboxed rendering, logging and monitoring, and tested backups. The security page describes the measures; Annex 2 of the DPA is the binding version for customer data. If a breach affects your personal data and is likely to result in a high risk to you, we tell you without undue delay.

11. Children

The Service is not directed at children. We do not knowingly process the data of anyone under 18. If you believe a child has given us data, write to us and we will delete it.

12. United States: state privacy rights

Several US states give their residents privacy rights, among them California, Colorado, Connecticut, Texas and Virginia. We extend the following to everyone, regardless of whether a particular state law applies to us:

  • Your rights. You can ask what personal information we hold about you, get a copy, have it corrected or deleted, and appeal a refusal by writing to us again. Send requests to privacy@dynamicdocumentapi.com; we answer as described in section 8.
  • No sale, no sharing, no profiling. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling with legal or similarly significant effects.
  • Do Not Track and Global Privacy Control. We do not track visitors across websites, so these browser signals have nothing to switch off. We still treat them as a valid request to opt out of sale and sharing.
  • No discrimination. Using these rights never affects the price or quality of the Service you get.

Where we process personal information on behalf of a business customer, we act as its service provider or processor: we use that information only to provide the Service and for no other purpose. Section 15 of the DPA contains the service-provider terms.

13. Changes

We update this policy when the Service or the law changes. The version and date are at the top, and the change history below records what moved. If a change materially affects how we handle your data, we tell you by email before it takes effect.

Change history

VersionDateChange
0.123 September 2026First draft, pending legal review
1.04 October 2026Matched to the Service as built: EU only with servers in Germany, retention periods, cookies, recipients (Cloudflare, Link, sign-in providers, stock photos), privacy contact instead of a data protection officer, short US section incl. Do Not Track; no longer a draft
Dynamic Document API

API infrastructure for automated document and image generation.

Product

HTML to PDF API PDF Generation API Image Generation API URL to PDF API PDF Template API Markdown to PDF API Enterprise Pricing

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API

PDF tools

Compress PDF Merge PDF Split PDF PDF to image PNG to PDF HTML to PDF Markdown to PDF All free tools

Developers

Documentation API reference SDKs Webhooks Template gallery Security

Company

About Contact

Legal

Terms Privacy DPA Acceptable use Sub-processors Legal notice

© 2026 Dynamic Document API. All rights reserved.

  • Deutsch
  • Legal notice
  • Privacy
  • Terms