Skip to main content
Dynamic Document API
Product
HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise All features
Use cases
Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API All use cases
Tools Developers Pricing
EnglishEN DeutschDE
Sign in Start free

Product

HTML to PDF API PDF Generation API Image Generation API PDF Template API URL to PDF API Markdown to PDF API Enterprise

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API
Tools Developers Pricing
EN DE
Sign in Start free

Legal

Privacy Policy

Version 0.1 (draft) · Last updated 23 September 2026

Draft — not yet in force. This text is a working draft awaiting review by qualified counsel. Passages marked like this depend on facts that are not yet fixed and must be checked against the running system before publication.

This policy explains what we do with personal data when you visit this website, create an account or use the API. A short version: we collect what we need to run the Service and bill for it, we keep customer documents only as long as the plan says, we do not sell data, and we do not train models on your content.

On this page

  1. Who is responsible
  2. Two different roles
  3. What we process, why, and on what basis
  4. Where data is processed
  5. Who receives data
  6. International transfers
  7. How long we keep things
  8. Your rights
  9. Cookies and reach measurement
  10. Security
  11. Children
  12. United States: state privacy rights
  13. Changes

1. Who is responsible

Controller within the meaning of the GDPR: N.M.M. Noble Minds Media Ltd, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, registration number HE 453611. Contact: privacy@dynamicdocumentapi.com. Full provider details are in the legal notice.

Data protection officer: [TO CONFIRM: appointed? If yes, name and contact. If not, say so and name the internal contact.]

You can complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus; you may also complain to the authority where you live or work.

2. Two different roles

Keeping these apart matters, because different rules apply.

  • We are the controller for data about you as a visitor, account holder or contact: registration and login, billing contact data, support conversations, product usage, security logs and marketing you asked for. That is what this policy covers.
  • We are a processor for whatever is inside the documents you generate — the payload you send to the API, the templates you build, the files we return. We process that only on your instructions, under the Data Processing Agreement. If you are an employee, customer or recipient of one of our customers and have a question about such data, please contact that customer; they decide what happens to it.

3. What we process, why, and on what basis

DataPurposeLegal basis
Name, email, password hash, company, country Creating and running your account Art. 6(1)(b) — performance of a contract
Billing contact, tax status, subscription and invoice data Charging for paid plans, tax records. Payment itself runs through Stripe as merchant of record; we do not see card data Art. 6(1)(b) and (c) — contract and legal obligation
API key metadata, request metadata (time, endpoint, size, status, duration, IP) Delivering renders, metering usage, diagnosing errors, protecting against abuse Art. 6(1)(b) and (f) — contract and our legitimate interest in a working, secure service
Request payloads and generated files Producing the document you asked for Processed for you as processor — see the DPA; logging of payloads is off by default
Support messages and their attachments Answering you and keeping a record of what was agreed Art. 6(1)(b) and (f)
Product usage events (which features are used, errors) Understanding what works and what breaks Art. 6(1)(f) — legitimate interest in improving the Service [TO CONFIRM: pseudonymous and cookieless?]
Security and audit logs, abuse signals Detecting attacks, investigating incidents, meeting our own obligations Art. 6(1)(f) and (c)
Email address for product and marketing mail Service notices; newsletters only if you asked for them Art. 6(1)(b) for service mail, Art. 6(1)(a) — consent — for marketing, withdrawable at any time
Server logs of this website (IP, user agent, referrer, time) Delivering the page, defending against attacks Art. 6(1)(f) [TO CONFIRM: retention, see §7]

Where we rely on legitimate interests, we have weighed them against your interests; you can object under section 8.

No training on your content. We do not use customer documents, templates or payloads to train machine-learning models, neither our own nor anyone else’s.

No sale of data. We do not sell personal data and we do not share it for cross-context behavioural advertising.

4. Where data is processed

You choose a processing region for your workspace: the European Union, or [TO CONFIRM: the United States]. Your choice governs where request payloads and generated files are stored and rendered.

Account and billing data, support conversations and security logs are processed [TO CONFIRM: in the EU], regardless of the workspace region. Section 5 lists where each provider sits.

5. Who receives data

Inside our company, only people who need access for their work get it, under confidentiality obligations. Beyond that, data goes to service providers who process it on our behalf. The current list, with purpose and location, is on the sub-processors page; we announce changes there at least 30 days in advance.

We also disclose data where we must: to public authorities on a valid legal basis, and to advisers, auditors or an acquirer in the context of a corporate transaction, in each case under confidentiality. We will tell you about an authority request unless we are legally barred from doing so.

6. International transfers

If you choose a processing region outside the EEA, or if a provider processes data outside the EEA, the transfer is based on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with an assessment of the legal situation in the destination country and additional safeguards where needed — in particular encryption in transit and at rest and a policy of challenging unlawful access requests. For the United Kingdom we add the IDTA addendum, for Switzerland the Swiss amendments. Copies are available on request. [TO CONFIRM: any provider relying on the EU–US Data Privacy Framework instead?]

7. How long we keep things

Generated filesFree plan 7 days, paid plans 30 days by default, configurable per workspace
Request payloads in logsOff by default; if you switch it on, 7, 30 or 90 days depending on plan
Render metadata without payload13 months, then aggregated
Webhook delivery logs30 days
Audit log1 year
Security logs1 year live, 3 years archived
Account after deletion7 days recoverable, then purged; backups roll off within 35 days
Invoices and tax recordsAs required by tax law [TO CONFIRM: Cypriot retention period]
Support conversations3 years
Website server logs[TO CONFIRM]

[TO CONFIRM: every row against the running system. Retention that is written down but not implemented is worse than none.]

8. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict its processing, or hand it to another provider in a portable format. You can object to processing we base on legitimate interests, including profiling; we then stop unless we have compelling grounds. You can withdraw consent at any time, with effect for the future. Marketing email can be stopped with the unsubscribe link in every message.

Write to privacy@dynamicdocumentapi.com. We answer within one month and may ask for information to confirm who you are. Much of it is also self-service in the workspace: export, change or delete your data yourself.

9. Cookies and reach measurement

This website sets no cookies and loads nothing from third-party servers: fonts, styles and images all come from our own domain. There is nothing to consent to and therefore no cookie banner. [TO CONFIRM: stays true — adding any pixel, embedded video or hosted font would change this.]

The web application sets cookies that are strictly necessary to log you in and keep your session secure. These do not require consent under Article 5(3) of the ePrivacy Directive. [TO CONFIRM: names and lifetimes of the cookies, and whether product analytics uses any storage on the device.]

10. Security

We protect data with encryption in transit and at rest, strict separation between workspaces, least-privilege access with multi-factor authentication for staff, sandboxed rendering, logging and monitoring, and tested backups. The security page describes the measures; Annex 2 of the DPA is the binding version for customer data. If a breach affects your personal data and is likely to result in a high risk to you, we tell you without undue delay.

11. Children

The Service is not directed at children. We do not knowingly process the data of anyone under 18. If you believe a child has given us data, write to us and we will delete it.

12. United States: state privacy rights

If you live in California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you may have the right to know what we collect, to obtain a copy, to correct or delete it, and to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling with legal effects.

Where we process personal information on behalf of a business customer, we act as a service provider or processor: we use that information only to provide the Service and for no other purpose. Send requests to privacy@dynamicdocumentapi.com; we do not discriminate against anyone who exercises these rights. [TO CONFIRM with counsel which US laws actually apply — most have revenue or volume thresholds.]

13. Changes

We update this policy when the Service or the law changes. The version and date are at the top, and the change history below records what moved. If a change materially affects how we handle your data, we tell you by email before it takes effect.

Change history

VersionDateChange
0.123 September 2026First draft, pending legal review
Dynamic Document API

API infrastructure for automated document and image generation.

Product

HTML to PDF API PDF Generation API Image Generation API URL to PDF API PDF Template API Markdown to PDF API Enterprise Pricing

Use cases

Invoice PDF API Receipt Generation API Report Generation API Certificate Generation API Document Generation API

PDF tools

Compress PDF Merge PDF Split PDF PDF to image PNG to PDF HTML to PDF Markdown to PDF All free tools

Developers

Documentation API reference SDKs Webhooks Template gallery Security

Company

About Contact

Legal

Terms Privacy DPA Acceptable use Sub-processors Legal notice

© 2026 Dynamic Document API. All rights reserved.

  • Deutsch
  • Legal notice
  • Privacy
  • Terms