CloudPDF
DocsPricing
Start building

Legal

Privacy Policy

How CloudPDF handles account, billing, product, licensing, and website data across managed, connected, and air-gapped products.

Last updated 4 August 2026

01

Who we are and what this policy covers

CloudPDF LTD (“CloudPDF”, “we”, “us”, or “our”) provides the CloudPDF managed service, CloudPDF self-hosted software, EmbedPDF Pro, related websites, account and commercial portals, APIs, support, evaluations, and licensing services (collectively, the “Services”).

This Privacy Policy explains how we handle personal data when we decide why and how it is processed—for example, account, sales, licensing, website, security, and support data. In those situations, CloudPDF is the controller or business responsible for the personal data.

When a CloudPDF customer uses the managed service to process PDFs or end-user information on its own behalf, that customer normally decides why and how the data is used. CloudPDF acts as its processor or service provider under the applicable agreement. Requests about that Customer Content should first be directed to the relevant customer.

This Policy does not govern third-party websites or separately licensed open-source code that does not send personal data to CloudPDF.

02

Personal data we collect

CategoryExamples
Account and identityName, business email address, password hash, email-verification status, account identifiers, login and password-reset events, and authentication session information.
Organization and commercialCompany or workspace name, organization type, memberships, roles, billing contact, offer recipients, accepted offers, evaluations, support plan, internal customer reference, and communications with sales or support.
Billing and transactionBilling name, company details, country, address, VAT or tax ID, Paddle customer, transaction and subscription identifiers, product, amount, currency, invoice status, and payment or refund status. CloudPDF does not receive or store full payment-card numbers or card security codes.
Technical and securityIP address, browser and device information, requested URLs, timestamps, cookies, session identifiers, API and authentication activity, rate-limit events, error logs, security events, and audit records.
Managed-service content and usagePDFs and related files, document names and metadata, annotations, comments, forms, signatures, viewer and access configuration, API requests, monthly views, monthly uploads, total storage, and other information submitted by the customer or its users.
Self-hosted licensing and usageLicense and organization identifiers, deployment or installation identifiers, activation and validation status, license term and mode, aggregate monthly views and uploads, current storage, threshold status, timestamps, and diagnostics needed to operate and support the license.
CommunicationsEmails, support requests, product feedback, meeting notes, survey responses, and records of transactional or marketing email delivery and engagement where supported and permitted.

Customer Content may contain personal data

We do not require sensitive personal data to create an account. A customer may choose to place personal or sensitive data inside PDFs or other Customer Content. The customer is responsible for deciding whether that is appropriate and lawful, and we process it only to provide the Services and as instructed under the customer agreement.

03

Where the data comes from

  • From you: when you register, verify your email, create or join an organization, request a trial, accept an offer, configure a product, contact us, or use the Services.
  • From your organization: when an owner or administrator invites you, assigns a role, identifies you as a contact, forwards an offer, or manages your access.
  • Automatically: from browsers, applications, APIs, servers, security controls, and connected self-hosted installations when they interact with our systems.
  • From service providers: including Paddle for transaction and subscription status, Resend for email delivery events, and Keygen for connected-license issuance, machine activation, and validation events.
  • From business interactions: such as a colleague, reseller, public business source, conference, or direct sales conversation where permitted by law.

05

Payments through Paddle

Paddle is our authorized reseller and Merchant of Record for purchases made through Paddle checkout. Paddle independently collects and processes payment credentials, billing details, tax information, fraud-prevention data, and transaction data. Its use of that information is governed by Paddle’s Privacy Policy and Buyer Terms.

Paddle sends us the information needed to identify the purchasing organization, record the order, activate entitlements, manage subscription status, provide support, and reconcile commercial records. This may include your name, email address, business and billing details, tax status, Paddle identifiers, purchased items, amount, currency, and transaction or subscription status. We do not receive your full card number or card security code.

06

How product mode affects data collection

CloudPDF managed service

Customer Content is uploaded to and processed in systems operated for CloudPDF. We use it to store, transform, secure, render, and deliver documents and requested collaboration or workflow features. We also process usage and technical data needed to apply plan limits, troubleshoot, protect the service, and support the customer.

Connected self-hosted deployments

Documents remain in the customer-controlled deployment unless the customer deliberately sends them to us for support or another service. The software connects for license issuance, activation, validation, status, and aggregate usage reporting. Connected usage reports are limited to licensing and plan information such as monthly PDF views, monthly document uploads, current total storage, warning thresholds, deployment identifiers, and relevant timestamps or diagnostics. Keygen may also receive license, machine, installation, network, and validation information needed to operate connected licensing.

Air-gapped self-hosted deployments

Air-gapped mode does not automatically send telemetry to CloudPDF or Keygen. To activate, renew, or update an air-gapped license, an authorized person manually exports an offline request and submits it to CloudPDF, then imports the signed response into the deployment. We process the license, deployment, machine-binding, request, validity, and audit information contained in that exchange. We receive no document content or operational usage from an air-gapped environment unless the customer intentionally provides it.

07

When we share personal data

We disclose personal data only as reasonably needed to:

  • Your organization: owners, administrators, billing contacts, and other authorized members may see account, membership, offer, billing, usage, and licensing information according to their permissions.
  • Paddle: to operate checkout, reseller transactions, subscriptions, invoicing, tax, refunds, and fraud prevention.
  • Resend: to deliver verification codes, password resets, offer emails, service notifications, and other communications.
  • Keygen: to issue and operate connected licenses, machine activations, validation, and signed licensing artifacts.
  • Infrastructure and operations providers: for hosting, databases, storage, content delivery, backups, security, monitoring, and customer support. They may process data only to provide services to us under appropriate obligations.
  • Professional advisers and authorities: where reasonably necessary for legal, audit, accounting, insurance, security, or compliance purposes, or in response to a valid legal request.
  • Corporate transactions: in connection with a financing, reorganization, merger, acquisition, or sale, subject to appropriate confidentiality and notice where required.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We may publish or share information that has been aggregated or de-identified so that it does not reasonably identify a person or customer.

08

International data transfers

CloudPDF and its service providers may process personal data in countries other than the country where you live. Where law requires safeguards for a transfer—for example, from the United Kingdom or European Economic Area to a country without an adequacy decision—we use an approved transfer mechanism such as Standard Contractual Clauses, a UK addendum or international data transfer agreement, or another lawful safeguard. You may contact us for information about the safeguards relevant to your data.

09

How long we keep data

We retain personal data only for as long as reasonably needed for the purpose for which it was collected, including to provide the Services, maintain security and audit trails, comply with tax and accounting rules, resolve disputes, and enforce agreements. The period depends on the type of data and our relationship with you.

  • Account, organization, entitlement, and license records are generally kept while the account, license, or customer relationship is active and for a reasonable period afterward for security, support, dispute, and legal purposes.
  • Paddle transaction references, accepted offers, invoices, and related commercial records are kept for the period required by tax, accounting, and limitation laws.
  • Managed-service Customer Content is retained according to customer settings and the applicable agreement. Following deletion or termination, residual copies may remain in protected backups until the relevant backup cycle expires.
  • Verification challenges and similar temporary security data expire after a short period. Security, authentication, and audit logs are kept for a period proportionate to detecting abuse and investigating incidents.

When data is no longer needed, we delete, anonymize, or securely isolate it unless law requires continued retention.

10

How we protect data

We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. Depending on the system, these measures include access controls, email verification, least-privilege permissions, encryption in transit, encryption or protected storage for sensitive secrets, audit logging, rate limiting, backups, monitoring, and incident procedures.

No system is completely secure. You are responsible for protecting your credentials, limiting administrator access, securely configuring your applications and self-hosted infrastructure, and notifying us promptly of suspected compromise.

11

Cookies and similar technologies

We use cookies and similar local technologies that are necessary to operate and secure the website and account experience—for example, to maintain a session, complete an authentication handoff, remember a security state, or prevent abuse. Blocking necessary cookies may prevent account or checkout-related features from working.

Paddle uses its own technologies when you interact with Paddle checkout, subject to Paddle’s privacy and cookie notices. If we introduce non-essential analytics, personalization, or advertising technologies, we will update this Policy and request consent where required by law.

12

Email and marketing choices

We send transactional messages needed to operate the Services, such as verification codes, password resets, security alerts, offer and order communications, license and usage notices, billing status, and important service changes. You generally cannot opt out of essential messages while maintaining the relevant account or Service.

You may opt out of marketing emails at any time using the unsubscribe link or by emailing us. Opting out of marketing does not stop transactional or support communications. We may retain a minimal suppression record so that we can respect your choice.

13

Your privacy rights

Depending on your location and subject to legal exceptions, you may have the right to:

  • request access to and a copy of your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion or restriction of processing;
  • receive certain data in a portable, machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent without affecting earlier lawful processing;
  • opt out of direct marketing at any time;
  • appeal a denied request where local law provides that right, and complain to the data protection authority where you live or work.
You have an unconditional right to object to the use of your personal data for direct marketing. You may also object to processing based on our legitimate interests, in which case we will stop unless we have a compelling lawful reason to continue.

To exercise a right, email hello@cloudpdf.com. We may need to verify your identity and authority. If your request concerns Customer Content controlled by one of our customers, we may direct the request to that customer or assist it in responding.

14

Additional U.S. state disclosures

Residents of certain U.S. states may have rights to know, access, correct, delete, or obtain a portable copy of personal information, to opt out of certain sales, sharing, or targeted advertising, and to appeal a denied request. CloudPDF does not sell personal information and does not use it for cross-context behavioural advertising. We do not discriminate against a person for exercising an applicable privacy right.

You may submit a request at hello@cloudpdf.com. An authorized agent may submit a request where permitted, but we may require proof of authority and verification of the relevant individual.

15

Automated decisions and children

We use automated controls to detect abuse, apply rate limits, validate licenses, and protect accounts. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about individuals. You may contact us if you believe an automated security control has incorrectly affected you.

The Services are intended for businesses and are not directed to children under 18. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.

16

Changes and how to contact us

We may update this Privacy Policy as our Services, providers, or legal obligations change. We will post the revised version with a new “last updated” date. If a change materially affects how we use personal data, we will provide additional notice or request consent where required.

Privacy contact and controller:
CloudPDF LTD
Email: hello@cloudpdf.com

You may also complain to the data protection authority in your country. We would appreciate the opportunity to address your concern first, but contacting us is not a prerequisite to filing a complaint.