Data Processing Agreement (DPA)
Last updated: June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between PDFik.net (“Processor”) and you (“Controller”).
1. Scope and Applicability
This DPA applies to the processing of personal data by PDFik.net on behalf of the Controller during the provision of the PDF Generation API services.
2. Roles
- Controller: The customer utilizing the PDFik.net API. The Controller determines the purpose and means of processing personal data.
- Processor: PDFik.net. The Processor acts only on the documented instructions of the Controller.
3. Data Processing Activities
- Categories of Data: Any personal data contained within URLs or HTML payloads submitted to the API by the Controller.
- Purpose: Rendering URLs and HTML payloads into PDF documents.
- Duration: Personal data is processed ephemerally during rendering. Resulting PDFs are stored in secure S3 buckets and are available for download for 24 hours; physically deleted within 48 hours. Data is also deleted upon request; the request marks the account for deletion and is processed manually within 30 days.
4. Subprocessors
PDFik.net engages the following subprocessors to deliver the service:
- Amazon Web Services (AWS): Hosting, Compute, and S3 Storage (Location:
us-east-1). - Stripe: Payment and billing processing.
- Google Firebase: User authentication and identity management.
- Cloudflare, Inc.: Web Application Firewall (WAF), DDoS protection, CDN, and DNS resolution (Location:
USA / Global Edge). - wFirma (iMakro sp. z o.o.): Accounting, EU VAT invoice generation, KSeF submission, and PDF invoice delivery (Location:
Poland, EU).
The Processor shall provide the Controller with at least 30 days' notice before authorizing any new subprocessor.
5. Security Measures
The Processor implements robust technical and organizational measures to ensure the security of processing:
- Encryption in Transit: All API traffic is encrypted using TLS 1.2 or higher.
- Encryption at Rest: All databases and S3 buckets use AES-256 encryption.
- Isolation: Document rendering is performed in isolated sandbox environments.
- Access Control: Strict IAM least-privilege principles are enforced for all infrastructure access.
6. Personal Data Breaches
In the event of a confirmed personal data breach affecting the Controller's data, PDFik.net will notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of the breach.
7. Audit Rights
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR. Audits shall be conducted at the Controller's expense.