Legal
Privacy Policy
Draft — not yet in force. This text is a working draft awaiting review by qualified counsel. Passages marked like this depend on facts that are not yet fixed and must be checked against the running system before publication.
This policy explains what we do with personal data when you visit this website, create an account or use the API. A short version: we collect what we need to run the Service and bill for it, we keep customer documents only as long as the plan says, we do not sell data, and we do not train models on your content.
1. Who is responsible
Controller within the meaning of the GDPR: N.M.M. Noble Minds Media Ltd, Grigori Afxentiou 7, 6023 Larnaca, Cyprus, registration number HE 453611. Contact: privacy@dynamicdocumentapi.com. Full provider details are in the legal notice.
Data protection officer: [TO CONFIRM: appointed? If yes, name and contact. If not, say so and name the internal contact.]
You can complain to a supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus; you may also complain to the authority where you live or work.
2. Two different roles
Keeping these apart matters, because different rules apply.
- We are the controller for data about you as a visitor, account holder or contact: registration and login, billing contact data, support conversations, product usage, security logs and marketing you asked for. That is what this policy covers.
- We are a processor for whatever is inside the documents you generate — the payload you send to the API, the templates you build, the files we return. We process that only on your instructions, under the Data Processing Agreement. If you are an employee, customer or recipient of one of our customers and have a question about such data, please contact that customer; they decide what happens to it.
3. What we process, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, password hash, company, country | Creating and running your account | Art. 6(1)(b) — performance of a contract |
| Billing contact, tax status, subscription and invoice data | Charging for paid plans, tax records. Payment itself runs through Stripe as merchant of record; we do not see card data | Art. 6(1)(b) and (c) — contract and legal obligation |
| API key metadata, request metadata (time, endpoint, size, status, duration, IP) | Delivering renders, metering usage, diagnosing errors, protecting against abuse | Art. 6(1)(b) and (f) — contract and our legitimate interest in a working, secure service |
| Request payloads and generated files | Producing the document you asked for | Processed for you as processor — see the DPA; logging of payloads is off by default |
| Support messages and their attachments | Answering you and keeping a record of what was agreed | Art. 6(1)(b) and (f) |
| Product usage events (which features are used, errors) | Understanding what works and what breaks | Art. 6(1)(f) — legitimate interest in improving the Service [TO CONFIRM: pseudonymous and cookieless?] |
| Security and audit logs, abuse signals | Detecting attacks, investigating incidents, meeting our own obligations | Art. 6(1)(f) and (c) |
| Email address for product and marketing mail | Service notices; newsletters only if you asked for them | Art. 6(1)(b) for service mail, Art. 6(1)(a) — consent — for marketing, withdrawable at any time |
| Server logs of this website (IP, user agent, referrer, time) | Delivering the page, defending against attacks | Art. 6(1)(f) [TO CONFIRM: retention, see §7] |
Where we rely on legitimate interests, we have weighed them against your interests; you can object under section 8.
No training on your content. We do not use customer documents, templates or payloads to train machine-learning models, neither our own nor anyone else’s.
No sale of data. We do not sell personal data and we do not share it for cross-context behavioural advertising.
4. Where data is processed
You choose a processing region for your workspace: the European Union, or [TO CONFIRM: the United States]. Your choice governs where request payloads and generated files are stored and rendered.
Account and billing data, support conversations and security logs are processed [TO CONFIRM: in the EU], regardless of the workspace region. Section 5 lists where each provider sits.
5. Who receives data
Inside our company, only people who need access for their work get it, under confidentiality obligations. Beyond that, data goes to service providers who process it on our behalf. The current list, with purpose and location, is on the sub-processors page; we announce changes there at least 30 days in advance.
We also disclose data where we must: to public authorities on a valid legal basis, and to advisers, auditors or an acquirer in the context of a corporate transaction, in each case under confidentiality. We will tell you about an authority request unless we are legally barred from doing so.
6. International transfers
If you choose a processing region outside the EEA, or if a provider processes data outside the EEA, the transfer is based on the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with an assessment of the legal situation in the destination country and additional safeguards where needed — in particular encryption in transit and at rest and a policy of challenging unlawful access requests. For the United Kingdom we add the IDTA addendum, for Switzerland the Swiss amendments. Copies are available on request. [TO CONFIRM: any provider relying on the EU–US Data Privacy Framework instead?]
7. How long we keep things
| Generated files | Free plan 7 days, paid plans 30 days by default, configurable per workspace |
|---|---|
| Request payloads in logs | Off by default; if you switch it on, 7, 30 or 90 days depending on plan |
| Render metadata without payload | 13 months, then aggregated |
| Webhook delivery logs | 30 days |
| Audit log | 1 year |
| Security logs | 1 year live, 3 years archived |
| Account after deletion | 7 days recoverable, then purged; backups roll off within 35 days |
| Invoices and tax records | As required by tax law [TO CONFIRM: Cypriot retention period] |
| Support conversations | 3 years |
| Website server logs | [TO CONFIRM] |
[TO CONFIRM: every row against the running system. Retention that is written down but not implemented is worse than none.]
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict its processing, or hand it to another provider in a portable format. You can object to processing we base on legitimate interests, including profiling; we then stop unless we have compelling grounds. You can withdraw consent at any time, with effect for the future. Marketing email can be stopped with the unsubscribe link in every message.
Write to privacy@dynamicdocumentapi.com. We answer within one month and may ask for information to confirm who you are. Much of it is also self-service in the workspace: export, change or delete your data yourself.
9. Cookies and reach measurement
This website sets no cookies and loads nothing from third-party servers: fonts, styles and images all come from our own domain. There is nothing to consent to and therefore no cookie banner. [TO CONFIRM: stays true — adding any pixel, embedded video or hosted font would change this.]
The web application sets cookies that are strictly necessary to log you in and keep your session secure. These do not require consent under Article 5(3) of the ePrivacy Directive. [TO CONFIRM: names and lifetimes of the cookies, and whether product analytics uses any storage on the device.]
10. Security
We protect data with encryption in transit and at rest, strict separation between workspaces, least-privilege access with multi-factor authentication for staff, sandboxed rendering, logging and monitoring, and tested backups. The security page describes the measures; Annex 2 of the DPA is the binding version for customer data. If a breach affects your personal data and is likely to result in a high risk to you, we tell you without undue delay.
11. Children
The Service is not directed at children. We do not knowingly process the data of anyone under 18. If you believe a child has given us data, write to us and we will delete it.
12. United States: state privacy rights
If you live in California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you may have the right to know what we collect, to obtain a copy, to correct or delete it, and to appeal a refusal. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it for profiling with legal effects.
Where we process personal information on behalf of a business customer, we act as a service provider or processor: we use that information only to provide the Service and for no other purpose. Send requests to privacy@dynamicdocumentapi.com; we do not discriminate against anyone who exercises these rights. [TO CONFIRM with counsel which US laws actually apply — most have revenue or volume thresholds.]
13. Changes
We update this policy when the Service or the law changes. The version and date are at the top, and the change history below records what moved. If a change materially affects how we handle your data, we tell you by email before it takes effect.
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft, pending legal review |