Data Processing Agreement
The terms under which CastPDF processes personal data on your behalf (GDPR Article 28), with the processing details, security measures and subprocessors.
Last updated
Contents
Parties and scope
This Data Processing Agreement ("DPA") is between the customer who has accepted the Terms of Service ("Customer", the controller) and CONSUL INTERNATIONAL 1991 SH.P.K., Taulantia Str. 1, 2001 Durrës, Albania ("CastPDF", the processor). It forms part of the Terms and applies whenever CastPDF processes personal data on the Customer's behalf. CastPDF applies the standard of the EU General Data Protection Regulation (GDPR) to all Customer Personal Data, wherever the data subjects live, and the article references in this DPA are to the GDPR. "Data Protection Law" means the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and any similar law that applies. As an Albanian company, CastPDF also complies with Albanian Law no. 124/2024 "On personal data protection", which follows the GDPR.
It takes effect when the Customer accepts the Terms; no signature is needed. A countersigned copy is available on request at [email protected]. If this DPA and the Terms conflict on the protection of personal data, this DPA prevails.
Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means the personal data in the templates, data, HTML, metadata, file names and generated documents that the Customer sends to or creates with the Service.
Processing on instructions
- CastPDF processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use of the dashboard and the API (for example a request to generate a document or delete a template) are those instructions.
- CastPDF does not process Customer Personal Data for its own purposes. In particular, it does not sell it, use it for advertising, or combine it with other data.
- If CastPDF believes an instruction infringes Data Protection Law, it tells the Customer, and may suspend that processing until the instruction is confirmed or changed.
- If the law requires CastPDF to process Customer Personal Data otherwise, it tells the Customer first, unless the law forbids that.
CastPDF does not use Customer Personal Data to train AI models, and does not allow its subprocessors to.
The subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects, are in Annex 1.
Confidentiality
CastPDF ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, and that access is limited to those who need it to operate the Service.
Security
CastPDF implements the technical and organisational measures in Annex 2, appropriate to the risk of the processing. It may update them over time, provided the overall level of protection does not decrease.
Subprocessors
- The Customer gives CastPDF general authorisation to engage subprocessors. The current subprocessors are listed in Annex 3 and in the Privacy Policy.
- CastPDF informs the Customer of any intended addition or replacement of a subprocessor by email to the account owner and by updating the list, at least 30 days before the new subprocessor processes Customer Personal Data. This applies to subprocessors listed as planned as well: they process no data until that notice has been given.
- The Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected Service without penalty. Fees already paid are not refunded, as the Refund Policy provides.
- CastPDF imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for its subprocessors' performance of them.
Assistance
- Data subject requests: taking into account the nature of the processing, CastPDF helps the Customer respond to requests from data subjects. The Customer can itself read and download its templates and documents at any time through the dashboard and the API. Templates can be removed from use there. Stored PDFs are deleted automatically when their retention period ends, and everything is erased when the Customer's account is deleted (on request by email). If CastPDF receives a request directly, it forwards it to the Customer and does not answer it itself, unless the Customer asks it to.
- Other obligations: CastPDF provides reasonable help with the Customer's data protection impact assessments and prior consultations with supervisory authorities, as far as they concern the Service, using the information available to it.
Personal data breaches
CastPDF notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice goes to the account owner's email address and describes, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information that is not yet available is provided as soon as it is. CastPDF takes reasonable steps to contain the breach and reduce its effects. A notice is not an admission of fault.
Deletion and return
- During the term, the Customer can retrieve its templates through the API and its stored documents until their retention ends, as described in the Privacy Policy.
- Generated documents, document metadata and other records are deleted automatically on the schedule in Annex 1.
- When the Terms end, or when the Customer asks by email ([email protected]) for its account to be deleted, CastPDF deletes the remaining Customer Personal Data from its live systems within 30 days, unless the law requires it to keep it. Copies in backups are deleted when the backups age out under CastPDF's backup retention (backups are encrypted on our own server (netcup GmbH, Nuremberg, Germany) with a key we keep offline, and kept for at most 30 days; there is no off-site copy yet), and are not restored except to recover the Service from a failure.
Audits and information
CastPDF makes available the information reasonably needed to demonstrate compliance with Article 28 GDPR, primarily by answering the Customer's written questions and providing relevant documentation. If that is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit, or have an independent auditor bound by confidentiality carry it out, at most once a year, with at least 30 days' written notice, during business hours, at the Customer's cost, and without access to other customers' data or to information that would compromise the security of the Service.
International transfers
CastPDF runs the Service with netcup GmbH in Nuremberg, Germany, and some subprocessors are in other countries (Annex 3).
CastPDF is established in Albania. The European Commission has not decided that Albania ensures an adequate level of protection, so Customer Personal Data that CastPDF receives from the Customer under the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection is transferred to a third country, even though the servers are in Nuremberg, Germany.
Where Customer Personal Data subject to the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection is transferred to a country without an adequacy decision, including to CastPDF itself, the parties rely on the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, which are incorporated into this DPA by reference (Module 2 for transfers from the Customer to CastPDF, Module 3 for onward transfers to subprocessors), together with the UK International Data Transfer Addendum where the UK GDPR applies and the Swiss amendments below where the Swiss Federal Act on Data Protection applies. Annex 1, Annex 2 and Annex 3 of this DPA complete Annexes I.B, II and III of those clauses. CastPDF ensures that its subprocessors transfer data only under an equivalent safeguard.
SCC elections
For the Standard Contractual Clauses incorporated above:
- Clause 7 (the docking clause) applies.
- Clause 9(a): Option 2 (general written authorisation) applies, with at least 30 days' notice, as described under "Subprocessors" above.
- Clause 11(a): the optional wording does not apply.
- Clause 13: the supervisory authority competent for the Customer as data exporter.
- Clause 17: Option 1 applies, and the Standard Contractual Clauses are governed by the law of Ireland.
- Clause 18(b): disputes are resolved by the courts of Ireland.
- Annex I.A: the parties are as in this DPA: the Customer is the data exporter and CastPDF the data importer. Their contact details are those of the Customer's account and those in "Parties and scope" above. Accepting the Terms counts as signing the clauses.
- Annex I.C: the competent supervisory authority is the one under Clause 13.
- Swiss Federal Act on Data Protection: for transfers subject to it, the Swiss Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority, references to the GDPR are read as references to that Act, and "Member State" in the clauses includes Switzerland, so data subjects in Switzerland can enforce their rights where they habitually reside.
Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow them. This DPA lasts as long as CastPDF processes Customer Personal Data under the Terms.
Annex 1: Details of the processing
- Subject matter: providing the CastPDF Service: storing HTML templates and generating PDF documents from them and from the data the Customer sends.
- Duration: the term of the Terms, plus the deletion periods below.
- Nature of the processing: receiving, storing, rendering (turning HTML and data into PDF), transmitting and deleting data, on servers operated for CastPDF.
- Purpose: to provide, maintain and secure the Service for the Customer.
- Categories of data subjects: people whose data the Customer puts into its templates and data, typically the Customer's own customers, suppliers and employees (for example the recipients of invoices); and the people who use the Customer's account.
- Categories of personal data: whatever the Customer includes in its templates, sample data, request data, metadata, file names and generated documents, typically names, contact details, addresses and transaction details; for account users, the account data described in the Privacy Policy.
- Special categories of data: not intended. The Customer should not send special categories of personal data unless it has a lawful basis and has assessed that the measures in Annex 2 are appropriate for them.
- Retention:
| Data | What exactly | Kept for |
|---|---|---|
| Account | Email address, name (optional), password as an argon2id hash, when the email was verified, the last sign-in time, and your workspace (its name and plan). | Until the account is deleted. |
| Sign-in sessions | A SHA-256 hash of the session token, the IP address and browser user agent at sign-in, created and last-seen times. | 30 days after the last use (each use extends it), or until you sign out or reset your password. |
| Email verification and password-reset links | A SHA-256 hash of the token, its purpose and expiry. | Verification links expire after 24 hours, reset links after 1 hour; the record is deleted once expired, or 24 hours after use. |
| API keys | A SHA-256 hash of the key, its first 14 characters (shown to identify it), name, mode and dates. | Until the account is deleted (a revoked key is kept, disabled, so the log can still name it). |
| Templates | Name, HTML, CSS, sample data and settings of each version. | The latest 50 versions of each template, plus the pinned one; older versions are deleted on save. A deleted template is removed from the dashboard and the API at once; it and its stored versions are erased 30 days after you delete the template, or when the account is deleted, whichever comes first. |
| Generated PDFs | The PDF file, when it is stored: always for live keys and the dashboard’s Generate PDF button, and for test keys only with "response": "url" or an Idempotency-Key. Previews and other test renders are never stored. | Your plan’s file retention (table below), then the file is deleted. |
| Document log | Per document: status, page count, size, mode, template and version, file name, error code, request id, time, and the metadata you sent. | Metadata: 30 days. The rest of the record: 120 days (and never before its PDF is deleted). |
| Request data | The data, html and css you send to render a document. | Not stored: used in memory to render the PDF, which is stored as described above. |
| Idempotency keys | The key you sent and a SHA-256 hash of the request. | At least 24 hours, then deleted by the next cleanup run. |
| Billing | Paddle customer and subscription ids, plan, billing interval and status, monthly usage counts, overage charges and their Paddle transaction ids. | Until the account is deleted; invoices and payment records are kept by Paddle as Merchant of Record. |
| Paddle event payloads | The subscription and transaction events Paddle sends us, which include your billing contact details. | 90 days after receipt. |
| Outgoing email queue | The email address and the message of the billing and usage emails we send you, kept so a failed send can be retried. | Deleted 30 days after sending. |
| Server logs | Per request: method, URL path, host, IP address, status and timing, error details, and the browser's user agent and the referring page, where your browser sends them. Never request bodies, API keys, passwords, session tokens or the signatures of download links. | 14 days |
| Backups | Encrypted copies of the database (everything above except PDFs, which are not backed up), with a key we keep offline. | On our own server (netcup GmbH, Nuremberg, Germany) only: the last 14 daily and 4 weekly copies, so none is older than 30 days. There is no off-site copy yet. |
| Plan | Stored PDFs are deleted after |
|---|---|
| Free | 1 day |
| Starter | 7 days |
| Growth | 30 days |
| Pro | 90 days |
| Scale | 90 days |
| Test-key documents (any plan) | 1 day |
Annex 2: Technical and organisational measures
Encryption and credentials
- All connections to the website, the dashboard and the API use TLS, with HSTS on the website and the dashboard.
- Passwords are stored only as argon2id hashes. API keys, session tokens, and email verification and password-reset tokens are stored only as SHA-256 hashes; an API key is shown once, at creation.
- The dashboard's session cookie is
HttpOnly,Secure,SameSite=Laxand uses the__Host-prefix. Sessions end after 30 days without use and are revoked when the password is reset. Failed sign-ins are limited per IP address and per account; a browser that has signed in to the account before carries a signed (HMAC-SHA256) device cookie and gets its own limit, so failed attempts from elsewhere cannot lock the account holder out. - Download links for stored documents are signed with HMAC-SHA256 and expire with the document.
- Payment card data never reaches CastPDF's systems: Paddle collects it.
Isolation of the rendering
- Documents are rendered by a separate service, running as its own unprivileged system user.
- Each render uses a fresh browser context, which is closed when the render ends, so no cookies, storage or pages are shared between documents.
- The renderer's network access is restricted: only http and https to public addresses on ports 80 and 443. Private, loopback and link-local addresses and the server itself are refused, and every address is checked again after DNS resolution and on each redirect. The number of requests, the bytes downloaded and the time per document are limited, and WebSockets and WebRTC are blocked.
- Liquid templates run in isolated worker processes without file system, network or environment access, with time and memory limits.
Access control and least privilege
- The API and the renderer run as separate unprivileged system users under systemd restrictions (no new privileges, read-only system directories, private temporary files).
- The API and the renderer listen only on unix sockets with restricted permissions, not on public network ports; the public reaches them only through the web server. The database accepts connections from the server itself.
- Every request is authenticated, and every query is limited to the Customer's own workspace; test keys can see only test documents.
- Administrative access to the servers is limited to the people who operate the Service.
Logging
- Logs record requests (method, path, status, timing, IP address) and errors, never request bodies, database query parameters, API keys, passwords or session tokens. The signed query strings of download links are removed from application logs, and the web server does not log download requests at all.
Availability and backups
- The database and the code are backed up nightly. Each backup is encrypted with public-key encryption (age, X25519) as it is written, so no unencrypted copy is stored; the private key is kept offline, never on the server. The server keeps the last 14 daily and 4 weekly backups, readable only by the administrator account, so none is older than 30 days. There is no off-site copy yet: the backups stay on the same server.
- Generated PDFs are short-lived and are not backed up.
- Rate limits per workspace and per IP address protect the Service from overload.
Data minimisation and deletion
- Request data is used in memory to render the document and is not stored. Previews and test renders that are not stored are returned to the caller and never saved.
- A cleanup job runs every 10 minutes and deletes expired documents, metadata, idempotency keys, sessions and tokens on the schedule in Annex 1.
Annex 3: Subprocessors
These subprocessors process Customer Personal Data (the content of templates, request data and documents):
| Subprocessor | Purpose | Personal data it receives | Location | Status |
|---|---|---|---|---|
| netcup GmbH | Server hosting: runs the API, the renderer, the database, stored PDFs and the encrypted database backups | All data the Service stores and processes, including template and document content | Nuremberg, Germany | In use |
| Cloudflare | Content delivery network, TLS termination and DDoS protection in front of the website, the dashboard and the API, and routing of email sent to our contact addresses | All requests and responses in transit, including IP addresses, template and request content and generated documents, and the email you send to our contact addresses; it caches only the public website | Global edge network (company based in the United States) | In use |
| Google Cloud EMEA Limited (Google Workspace) | Receives and stores the email you send to our contact addresses | The email you send to our contact addresses and our replies, including anything you put in them | Ireland (contracting company); the mail may be stored and processed in other countries where Google operates, including the United States | In use |
| Google (Gemini API) | AI template generation (not in use yet; only once the feature ships) | None today; once in use, the prompts and template content sent for generation | United States | Planned: not in use yet, no data is sent |
The following are not subprocessors of Customer Personal Data: SMTP2GO sends CastPDF's transactional emails and receives only the email addresses of account users, as CastPDF's processor for account data; Paddle.com is the Merchant of Record and processes buyer and payment details as an independent controller. Neither receives template or document content.
The full list is also published in the Privacy Policy. A subprocessor marked as planned processes no Customer Personal Data until the notice described under "Subprocessors" above has been given.