Data Processing Addendum (DPA)

This DPA forms part of the agreement between SmartAssPDF (“Processor”) and the customer (“Controller”) and governs our processing of Personal Data on your behalf, in accordance with GDPR Article 28 and applicable privacy laws (including CCPA/CPRA).

Last updated: Sept 9, 2025

GDPR Article 28

We act only on documented instructions and maintain appropriate technical and organizational measures.

CCPA/CPRA

We do not “sell” or “share” personal information and only use it to provide the requested service.

Minimal Retention

Short-lived file handling with automatic deletion after processing completes.

Transfers & SCCs

International transfers are protected by appropriate safeguards (e.g., EU Standard Contractual Clauses).

1. Scope & Roles

This DPA applies where SmartAssPDF processes Personal Data on behalf of the Controller. The Controller determines the purposes and means of processing; the Processor processes Personal Data solely to provide the services.

2. Nature, Purpose & Duration of Processing

3. Types of Personal Data & Data Subjects

4. Controller Instructions

Processor will process Personal Data only on documented instructions from Controller, including with respect to transfers, unless required by law. Controller is responsible for ensuring its instructions comply with applicable law.

5. Confidentiality

Processor ensures persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate privacy/security training.

6. Security Measures

7. Sub-Processors

Processor may engage Sub-Processors for hosting, storage, delivery, or auxiliary functions, subject to data protection obligations no less protective than those in this DPA. Controller authorizes the use of such Sub-Processors. Upon request, Processor will provide an updated list of Sub-Processors.

Category Purpose Examples
Hosting/CDN Serve the app; transient storage Cloud hosting providers / CDN
Analytics Basic product analytics Aggregate usage metrics
Email Support communications Transactional email service

8. International Data Transfers

Where processing involves a transfer of Personal Data to a third country, Processor will ensure appropriate safeguards are in place (e.g., EU Standard Contractual Clauses or other valid transfer mechanisms).

9. Assistance to Controller

10. Deletion & Return

Upon termination of services or upon Controller request, Processor will delete or return Personal Data (unless retention is required by law). Uploaded files are generally removed automatically shortly after processing completes.

11. Breach Notification

Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller data and provide information reasonably required for Controller to meet its obligations.

12. Audits

Upon reasonable written request, Processor will make available information necessary to demonstrate compliance with this DPA and, where required, allow for audits conducted by Controller or an independent auditor (subject to confidentiality, scheduling, and scope limitations).

13. Liability

The parties’ liability under this DPA is subject to the limitations and exclusions set out in the underlying agreement, except to the extent prohibited by applicable law.

14. Order of Precedence

In case of conflict between this DPA and the underlying agreement, this DPA controls with respect to data protection obligations.

15. Contact

Contact SmartAssPDF Team : support@smartasspdf.com

Retention Snapshot

Data Type Typical Retention Deletion Method
Uploaded Files Up to ~1 hour post-processing Automated secure deletion
Temporary Browser Data Session-scoped Local/session clear
Operational Metadata Up to 30 days Scheduled purge

Actual retention may vary for reliability, abuse prevention, or legal compliance.