01
Who we are and what this policy covers
CloudPDF LTD (“CloudPDF”, “we”, “us”, or “our”) provides the CloudPDF managed service, CloudPDF self-hosted software, EmbedPDF Pro, related websites, account and commercial portals, APIs, support, evaluations, and licensing services (collectively, the “Services”).
This Privacy Policy explains how we handle personal data when we decide why and how it is processed—for example, account, sales, licensing, website, security, and support data. In those situations, CloudPDF is the controller or business responsible for the personal data.
This Policy does not govern third-party websites or separately licensed open-source code that does not send personal data to CloudPDF.
02
Personal data we collect
| Category | Examples |
|---|---|
| Account and identity | Name, business email address, password hash, email-verification status, account identifiers, login and password-reset events, and authentication session information. |
| Organization and commercial | Company or workspace name, organization type, memberships, roles, billing contact, offer recipients, accepted offers, evaluations, support plan, internal customer reference, and communications with sales or support. |
| Billing and transaction | Billing name, company details, country, address, VAT or tax ID, Paddle customer, transaction and subscription identifiers, product, amount, currency, invoice status, and payment or refund status. CloudPDF does not receive or store full payment-card numbers or card security codes. |
| Technical and security | IP address, browser and device information, requested URLs, timestamps, cookies, session identifiers, API and authentication activity, rate-limit events, error logs, security events, and audit records. |
| Managed-service content and usage | PDFs and related files, document names and metadata, annotations, comments, forms, signatures, viewer and access configuration, API requests, monthly views, monthly uploads, total storage, and other information submitted by the customer or its users. |
| Self-hosted licensing and usage | License and organization identifiers, deployment or installation identifiers, activation and validation status, license term and mode, aggregate monthly views and uploads, current storage, threshold status, timestamps, and diagnostics needed to operate and support the license. |
| Communications | Emails, support requests, product feedback, meeting notes, survey responses, and records of transactional or marketing email delivery and engagement where supported and permitted. |
Customer Content may contain personal data
We do not require sensitive personal data to create an account. A customer may choose to place personal or sensitive data inside PDFs or other Customer Content. The customer is responsible for deciding whether that is appropriate and lawful, and we process it only to provide the Services and as instructed under the customer agreement.
03
Where the data comes from
- From you: when you register, verify your email, create or join an organization, request a trial, accept an offer, configure a product, contact us, or use the Services.
- From your organization: when an owner or administrator invites you, assigns a role, identifies you as a contact, forwards an offer, or manages your access.
- Automatically: from browsers, applications, APIs, servers, security controls, and connected self-hosted installations when they interact with our systems.
- From service providers: including Paddle for transaction and subscription status, Resend for email delivery events, and Keygen for connected-license issuance, machine activation, and validation events.
- From business interactions: such as a colleague, reseller, public business source, conference, or direct sales conversation where permitted by law.
04
Why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Create and secure accounts; verify email; authenticate users; manage organizations and permissions. | Contract; steps requested before entering a contract; legitimate interests in operating a secure business service. |
| Provide the managed service, software access, downloads, evaluations, APIs, support, licensing, and usage-limit notifications. | Contract; legitimate interests in delivering and improving the Services. |
| Prepare offers; manage orders, subscriptions, entitlements, invoices, tax information, renewals, refunds, and commercial records. | Contract; legal obligations; legitimate interests in administering customer relationships. |
| Detect bots, abuse, account takeover, fraud, licensing misuse, and security incidents; investigate and enforce our terms. | Legitimate interests in protecting customers, CloudPDF, and the Services; legal obligations where applicable. |
| Communicate about service changes, security, billing, offers, support, and account activity. | Contract; legitimate interests in communicating with customers and users. |
| Analyze reliability and product usage, troubleshoot errors, and improve features using data that is aggregated or minimized where practical. | Legitimate interests in maintaining and improving the Services. |
| Send product news or marketing and measure its effectiveness. | Consent where required; otherwise legitimate interests, with an opt-out. |
| Comply with tax, accounting, sanctions, court orders, regulatory duties, and legal claims. | Legal obligations; legitimate interests in establishing, exercising, or defending legal claims. |
Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, we balance those interests against the effect on your rights and expectations. You may contact us for more information about that assessment.
05
Payments through Paddle
Paddle is our authorized reseller and Merchant of Record for purchases made through Paddle checkout. Paddle independently collects and processes payment credentials, billing details, tax information, fraud-prevention data, and transaction data. Its use of that information is governed by Paddle’s Privacy Policy and Buyer Terms.
Paddle sends us the information needed to identify the purchasing organization, record the order, activate entitlements, manage subscription status, provide support, and reconcile commercial records. This may include your name, email address, business and billing details, tax status, Paddle identifiers, purchased items, amount, currency, and transaction or subscription status. We do not receive your full card number or card security code.
06
How product mode affects data collection
CloudPDF managed service
Customer Content is uploaded to and processed in systems operated for CloudPDF. We use it to store, transform, secure, render, and deliver documents and requested collaboration or workflow features. We also process usage and technical data needed to apply plan limits, troubleshoot, protect the service, and support the customer.
Connected self-hosted deployments
Documents remain in the customer-controlled deployment unless the customer deliberately sends them to us for support or another service. The software connects for license issuance, activation, validation, status, and aggregate usage reporting. Connected usage reports are limited to licensing and plan information such as monthly PDF views, monthly document uploads, current total storage, warning thresholds, deployment identifiers, and relevant timestamps or diagnostics. Keygen may also receive license, machine, installation, network, and validation information needed to operate connected licensing.
Air-gapped self-hosted deployments
Air-gapped mode does not automatically send telemetry to CloudPDF or Keygen. To activate, renew, or update an air-gapped license, an authorized person manually exports an offline request and submits it to CloudPDF, then imports the signed response into the deployment. We process the license, deployment, machine-binding, request, validity, and audit information contained in that exchange. We receive no document content or operational usage from an air-gapped environment unless the customer intentionally provides it.
08
International data transfers
CloudPDF and its service providers may process personal data in countries other than the country where you live. Where law requires safeguards for a transfer—for example, from the United Kingdom or European Economic Area to a country without an adequacy decision—we use an approved transfer mechanism such as Standard Contractual Clauses, a UK addendum or international data transfer agreement, or another lawful safeguard. You may contact us for information about the safeguards relevant to your data.
09
How long we keep data
We retain personal data only for as long as reasonably needed for the purpose for which it was collected, including to provide the Services, maintain security and audit trails, comply with tax and accounting rules, resolve disputes, and enforce agreements. The period depends on the type of data and our relationship with you.
- Account, organization, entitlement, and license records are generally kept while the account, license, or customer relationship is active and for a reasonable period afterward for security, support, dispute, and legal purposes.
- Paddle transaction references, accepted offers, invoices, and related commercial records are kept for the period required by tax, accounting, and limitation laws.
- Managed-service Customer Content is retained according to customer settings and the applicable agreement. Following deletion or termination, residual copies may remain in protected backups until the relevant backup cycle expires.
- Verification challenges and similar temporary security data expire after a short period. Security, authentication, and audit logs are kept for a period proportionate to detecting abuse and investigating incidents.
When data is no longer needed, we delete, anonymize, or securely isolate it unless law requires continued retention.
10
How we protect data
We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. Depending on the system, these measures include access controls, email verification, least-privilege permissions, encryption in transit, encryption or protected storage for sensitive secrets, audit logging, rate limiting, backups, monitoring, and incident procedures.
No system is completely secure. You are responsible for protecting your credentials, limiting administrator access, securely configuring your applications and self-hosted infrastructure, and notifying us promptly of suspected compromise.
12
Email and marketing choices
We send transactional messages needed to operate the Services, such as verification codes, password resets, security alerts, offer and order communications, license and usage notices, billing status, and important service changes. You generally cannot opt out of essential messages while maintaining the relevant account or Service.
You may opt out of marketing emails at any time using the unsubscribe link or by emailing us. Opting out of marketing does not stop transactional or support communications. We may retain a minimal suppression record so that we can respect your choice.
13
Your privacy rights
Depending on your location and subject to legal exceptions, you may have the right to:
- request access to and a copy of your personal data;
- correct inaccurate or incomplete personal data;
- request deletion or restriction of processing;
- receive certain data in a portable, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent without affecting earlier lawful processing;
- opt out of direct marketing at any time;
- appeal a denied request where local law provides that right, and complain to the data protection authority where you live or work.
To exercise a right, email hello@cloudpdf.com. We may need to verify your identity and authority. If your request concerns Customer Content controlled by one of our customers, we may direct the request to that customer or assist it in responding.
14
Additional U.S. state disclosures
Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a portable copy of personal information, to opt out of certain sales, sharing, or targeted advertising, and to appeal a denied request. CloudPDF does not sell personal information and does not use it for cross-context behavioural advertising. We do not discriminate against a person for exercising an applicable privacy right.
You may submit a request at hello@cloudpdf.com. An authorized agent may submit a request where permitted, but we may require proof of authority and verification of the relevant individual.
15
Automated decisions and children
We use automated controls to detect abuse, apply rate limits, validate licenses, and protect accounts. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals. You may contact us if you believe an automated security control has incorrectly affected you.
The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.
16
Changes and how to contact us
We may update this Privacy Policy as our Services, providers, or legal obligations change. We will post the revised version with a new “last updated” date. If a change materially affects how we use personal data, we will provide additional notice or request consent where required.
You may also complain to the data protection authority in your country. We would appreciate the opportunity to address your concern first, but contacting us is not a prerequisite to filing a complaint.