Last updated: February 10, 2026
PixelToPdf is operated by an EU-based company registered in Spain. As a European company, GDPR compliance is at the core of how we build and operate our service. This page provides a detailed overview of our data protection practices.
The General Data Protection Regulation (EU 2016/679) establishes a unified framework for the protection of personal data across the European Union. As a company based in Spain, we are subject to both the GDPR and the Spanish Organic Law 3/2018 on the Protection of Personal Data (LOPDGDD).
We are committed to ensuring that your personal data is processed lawfully, fairly, and transparently. Our full data processing practices are described in our Privacy Policy.
The following entity acts as the data controller for personal data processed through the PixelToPdf service:
We process personal data for the following activities:
| Activity | Data processed | Legal basis |
|---|---|---|
| Account management | Name, email, password hash | Contract performance |
| Billing | Billing address, last 4 card digits | Contract performance, legal obligation |
| API usage | IP address, API calls, timestamps | Legitimate interest |
| PDF conversion | User-submitted HTML content | Contract performance |
| Analytics | Aggregated, anonymized usage data | Legitimate interest |
| Marketing emails | Email address | Consent |
We follow the principle of data minimization. We only collect the minimum personal data necessary to provide the service. Regarding file processing:
As a data subject, you have the following rights under Articles 15-22 of the GDPR:
You can request a copy of all personal data we hold about you, along with information about how it is processed.
You can request correction of inaccurate personal data or completion of incomplete data.
You can request deletion of your personal data when it is no longer necessary for the purpose it was collected, or when you withdraw consent.
You can request that we restrict processing of your data while a dispute is resolved or while we verify the accuracy of your data.
You can request your personal data in a structured, commonly used, and machine-readable format (JSON or CSV).
You can object to processing based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling grounds.
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us using the details at the bottom of this page. We will respond within 30 days. If we need to extend this period, we will notify you within the initial 30-day window.
We retain personal data only for as long as necessary:
| Data type | Retention period |
|---|---|
| Conversion files (HTML/PDF) | 1 hour after conversion |
| Account data | Duration of account + 30 days after deletion |
| API usage logs | 12 months |
| Billing records | 5 years (Spanish tax law) |
| Support communications | 2 years after resolution |
We use a limited number of sub-processors to deliver the Service. All sub-processors are bound by Data Processing Agreements (DPAs) that ensure GDPR-compliant data handling.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | USA (EU SCCs) |
| Cloud provider | Infrastructure hosting | EU |
| Email provider | Transactional emails | EU |
For transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent adequacy decisions.
We implement technical and organizational measures to protect personal data in accordance with Article 32 of the GDPR:
In the event of a personal data breach, we will:
If you are using PixelToPdf on behalf of an organization and need a Data Processing Agreement (DPA) for compliance purposes, please contact us using the details below. We provide standard DPAs based on the European Commission's model clauses.
Our lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD). If you believe your data protection rights have been violated, you have the right to lodge a complaint:
Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
Website: www.aepd.es
For GDPR-related inquiries, data subject requests, or to request a DPA: