GDPR Compliance

Last updated: February 10, 2026

PixelToPdf is operated by an EU-based company registered in Spain. As a European company, GDPR compliance is at the core of how we build and operate our service. This page provides a detailed overview of our data protection practices.

1. Our commitment to GDPR

The General Data Protection Regulation (EU 2016/679) establishes a unified framework for the protection of personal data across the European Union. As a company based in Spain, we are subject to both the GDPR and the Spanish Organic Law 3/2018 on the Protection of Personal Data (LOPDGDD).

We are committed to ensuring that your personal data is processed lawfully, fairly, and transparently. Our full data processing practices are described in our Privacy Policy.

2. Data controller

The following entity acts as the data controller for personal data processed through the PixelToPdf service:

3. Data processing activities

We process personal data for the following activities:

ActivityData processedLegal basis
Account managementName, email, password hashContract performance
BillingBilling address, last 4 card digitsContract performance, legal obligation
API usageIP address, API calls, timestampsLegitimate interest
PDF conversionUser-submitted HTML contentContract performance
AnalyticsAggregated, anonymized usage dataLegitimate interest
Marketing emailsEmail addressConsent

4. Data minimization and file handling

We follow the principle of data minimization. We only collect the minimum personal data necessary to provide the service. Regarding file processing:

  • HTML content submitted for conversion is processed in memory and on temporary storage.
  • All conversion files are automatically deleted within 1 hour after processing.
  • We do not retain, index, or analyze the content of your conversions.
  • Generated PDFs are made available for download via time-limited, signed URLs.

5. Your rights under GDPR

As a data subject, you have the following rights under Articles 15-22 of the GDPR:

Right of access (Art. 15)

You can request a copy of all personal data we hold about you, along with information about how it is processed.

Right to rectification (Art. 16)

You can request correction of inaccurate personal data or completion of incomplete data.

Right to erasure (Art. 17)

You can request deletion of your personal data when it is no longer necessary for the purpose it was collected, or when you withdraw consent.

Right to restriction (Art. 18)

You can request that we restrict processing of your data while a dispute is resolved or while we verify the accuracy of your data.

Right to data portability (Art. 20)

You can request your personal data in a structured, commonly used, and machine-readable format (JSON or CSV).

Right to object (Art. 21)

You can object to processing based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling grounds.

Right to withdraw consent (Art. 7)

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us using the details at the bottom of this page. We will respond within 30 days. If we need to extend this period, we will notify you within the initial 30-day window.

6. Data retention

We retain personal data only for as long as necessary:

Data typeRetention period
Conversion files (HTML/PDF)1 hour after conversion
Account dataDuration of account + 30 days after deletion
API usage logs12 months
Billing records5 years (Spanish tax law)
Support communications2 years after resolution

7. Sub-processors

We use a limited number of sub-processors to deliver the Service. All sub-processors are bound by Data Processing Agreements (DPAs) that ensure GDPR-compliant data handling.

Sub-processorPurposeLocation
StripePayment processingUSA (EU SCCs)
Cloud providerInfrastructure hostingEU
Email providerTransactional emailsEU

For transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent adequacy decisions.

8. Security measures

We implement technical and organizational measures to protect personal data in accordance with Article 32 of the GDPR:

  • Encryption in transit: all communications use TLS 1.2 or higher.
  • Encryption at rest: data stored in databases and backups is encrypted.
  • Access controls: role-based access with the principle of least privilege.
  • Monitoring: real-time logging and alerting for suspicious activity.
  • Regular reviews: periodic security assessments and dependency audits.
  • Incident response: documented procedures for data breach identification and notification.

9. Data breach notification

In the event of a personal data breach, we will:

  • Notify the Spanish Data Protection Agency (AEPD) within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR.
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34).
  • Document the breach, its effects, and the remedial actions taken.

10. Data Processing Agreements

If you are using PixelToPdf on behalf of an organization and need a Data Processing Agreement (DPA) for compliance purposes, please contact us using the details below. We provide standard DPAs based on the European Commission's model clauses.

11. Supervisory authority

Our lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD). If you believe your data protection rights have been violated, you have the right to lodge a complaint:

Agencia Española de Protección de Datos (AEPD)

C/ Jorge Juan, 6, 28001 Madrid, Spain

Website: www.aepd.es

12. Contact us

For GDPR-related inquiries, data subject requests, or to request a DPA: