PrivaPDF Privacy Policy

calendar_today

Last updated: March 2026

"At PrivaPDF, privacy is not an added layer; it is the engine of our existence. This policy explains transparently how we handle the minimal information necessary to offer you our service and how we guarantee that your documents never leave your control."

shield_lock

1. The "Data Sovereignty" Principle

Our technical architecture has been designed under the principle of Privacy by Design.

  • Local Processing: Unlike other PDF tools, PrivaPDF uses WebAssembly (WASM) technology.
  • Zero Uploads: This means that your documents are processed entirely within your browser's memory.
  • No Cloud Footprint: Your files are never uploaded to our servers, or those of third parties, for processing.
database

2. Information We Collect

We only request the information strictly necessary to manage your subscription and platform access.

Access Data

We collect your email and an encrypted password for your account.

Billing Data

Payment processing is handled by Stripe, and invoicing is managed via Holded. We do not store credit card or bank account details on our infrastructure.

Communications: If you decide to subscribe to our newsletter, we manage your contact through our own private Listmonk infrastructure to avoid third-party tracking.

cloud_done

3. Storage and Security (AWS)

Your access credentials are stored using AWS Cognito, the gold standard in identity management from Amazon Web Services.

Bank-Grade Encryption: Your profile data is protected by multiple layers of encryption and firewalls managed within the AWS infrastructure.

Session Isolation: Every time you close the tool's tab, any temporary data from the processed document is automatically deleted from your browser's local memory.

hub

4. Third Parties and Transfers

PrivaPDF is a closed tool that minimizes external connections:

  • Infrastructure: We use AWS to host the application and manage authentication.
  • Payments: We delegate financial management to Stripe, complying with PCI-DSS standards.
  • Billing & Accounting: We use Holded for invoicing and tax compliance purposes, ensuring the secure custody of your tax and financial records.
  • Processing Engines: Engines (Ghostscript or PyMuPDF) are loaded from secure CDNs but operate exclusively within your browser.
gavel

5. Your Rights (GDPR)

As a user, you have full rights over your personal data:

edit

Access and Rectification

You can modify your profile details at any time.

delete_forever

Cancellation and Right to be Forgotten

Unsubscribe and request permanent deletion through the Subscription Portal.

file_download

Portability

Request a report of the billing and tax data stored across our management platforms (Stripe and Holded).

mail

6. Contact

If you have any questions about how we protect your professional secrecy, you can contact us directly at our private mailbox:

privacidad@privapdf.app