GDPR & Data Processing
Information for individuals and organizations in the EU, UK, and other jurisdictions with GDPR-style data protection laws. US residents: see our US Privacy Notice.
Not Another Software Company is the data controller for personal data processed through the Vault PDF SaaS application (account, billing, team metadata, and operational logs).
Registered address: 150, Greenfields Soc., Palodia, Gandhinagar, India 382115
Vault PDF is offered to business teams in the United States, the EU/UK, and other international markets. We do not currently market or tailor the service to customers in India.
For a broader overview, see our Privacy Policy. US customers should also read our US Privacy Notice. Contact details are in the Contact section below.
Vault PDF acts as a data controller for account and workspace data. When your agency uses Vault PDF to process client documents locally in the browser, your agency typically remains the controller for client data, Vault PDF does not receive PDF contents for core tools.
Compliance customers may request a Data Processing Agreement (DPA) covering Not Another Software Company's processing of team member and account data. See our DPA page or email divya@vault-pdf.com with your organization name and billing contact.
Teams can also generate a client-facing privacy document from Settings → Compliance to explain browser-only processing to their own customers.
- Identity data: email address, display name
- Account data: organization name, role, team membership
- Billing data: subscription status, payment provider customer ID (card details handled by Dodo Payments)
- Usage metadata: tool ID, file count, timestamps, compression mode (no filenames or PDF content)
- Audit data: administrative actions, hashed IP for security events
- Integration data: optional Slack OAuth tokens (encrypted) when connected by an admin
Core PDF tools run entirely in the end user's browser. We do not receive, store, or process PDF file contents, filenames, or decryption passwords for those tools.
| Processing activity | Legal basis | Retention |
|---|---|---|
| Client PDF Risk Check campaign measurement | Legitimate interests: understanding whether this educational campaign helps firms reach product activation (Art. 6(1)(f)) | 90 days (automated purge); no IP address, IP hash, user agent, referrer, email, or query string is persisted |
| Account creation and authentication | Contract (Art. 6(1)(b)) | While account is active, plus up to 90 days after deletion for security and billing reconciliation |
| Team and subscription management | Contract (Art. 6(1)(b)) | While subscription is active, plus up to 7 years for billing and tax records where required by law |
| Usage and activity metadata | Legitimate interests: service operation, team visibility, and compliance receipts (Art. 6(1)(f)) | 90 days for activity and audit logs (automated purge); receipt, certificate, and review-manifest proof metadata retained for seven calendar years from processing, unless an authorized deletion request removes it earlier |
| Audit and security logging | Legitimate interests: security, fraud prevention, and accountability (Art. 6(1)(f)) | 90 days (automated purge); export available to org admins before expiry |
| Transactional email | Contract (Art. 6(1)(b)) | Per email provider logs; typically up to 30 days operational retention |
| Optional Slack integration | Consent / contract, enabled only when an admin connects Slack (Art. 6(1)(a)/(b)) | While integration is connected; tokens removed on disconnect |
| Optional Google sign-in | Contract (Art. 6(1)(b)) | While account is active; Google may set cookies during the OAuth redirect |
You may object to processing based on legitimate interests by contacting us. We will assess your request and stop processing unless we demonstrate compelling legitimate grounds that override your interests.
We engage the following sub-processors to deliver the service. A current list is maintained in our Privacy Policy:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, row-level security | EU / US |
| Dodo Payments | Subscription billing and payment processing | Varies by processor region |
| Resend | Transactional email (invites, receipts, onboarding) | US |
| Hetzner Cloud | Application hosting, CDN, and operational logs | EU (region-dependent) |
| Grafana Cloud | Operational log and container metrics (scrubbed before export) | EU / US (region-dependent) |
| Optional Google OAuth sign-in (when you choose that method) | US / global | |
| Slack | Optional job notifications when an admin connects a workspace | US / global |
Personal data may be transferred to sub-processors outside the EEA, including the United States. We implement appropriate safeguards, including EU Standard Contractual Clauses (SCCs) with processors and contractual obligations to protect data to an equivalent standard.
Contact divya@vault-pdf.com to request details of transfer mechanisms relevant to your organization.
We apply technical and organizational measures including encryption in transit (TLS), row-level security in our database, encrypted storage of integration tokens, hashed IP logging for audit events, and browser-only PDF processing for core tools so file bytes are not stored on our servers.
Right of access (Art. 15)
Request a copy of personal data we hold about you.
Right to rectification (Art. 16)
Correct inaccurate account or profile information.
Right to erasure (Art. 17)
Request deletion of your account and associated personal data, subject to legal retention obligations.
Right to restrict processing (Art. 18)
Ask us to limit how we use your data in certain circumstances.
Right to data portability (Art. 20)
Receive account data you provided in a structured, machine-readable format.
Right to object (Art. 21)
Object to processing based on legitimate interests, including security logging where applicable.
Right related to automated decision-making (Art. 22)
Vault PDF does not make solely automated decisions with legal or similarly significant effects.
Right to withdraw consent (Art. 7(3))
Where processing relies on consent (e.g. optional integrations), you may withdraw consent at any time.
To exercise any of these rights, use Privacy & data in your account to export or delete your data, or email divya@vault-pdf.com from the address associated with your account. We may need to verify your identity before fulfilling a request.
If you are in the EU or UK and believe we have not handled your personal data appropriately, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first at divya@vault-pdf.com so we can try to resolve your concern.
EU authorities are listed at edpb.europa.eu. UK residents may contact the ICO at ico.org.uk.
Not Another Software Company
For privacy, legal, DPA, billing, and general support inquiries, email divya@vault-pdf.com.
Document version 2026-07. Added cookie-free, first-party measurement for the Client PDF Risk Check campaign and its 90-day retention period.
This information is provided for transparency and is not legal advice. Consult qualified counsel for jurisdiction-specific requirements.