Privacy Policy
Last updated: September 21, 2026 • Effective immediately
PDFGridly is architected not to persist uploaded document content to durable storage. Uploaded files are processed transiently in volatile memory during your active extraction session and are not retained after processing is complete.
1. Data Controller Identification
The entity responsible for the operation of the PDFGridly service and the processing of personal data is:
2. Document Processing & Lifecycle
When you upload an invoice, financial document, or PDF table to PDFGridly:
- Transient In-Memory Processing: Files are read directly into volatile runtime memory (RAM) solely for the mechanical purpose of parsing coordinates, layout geometry, metadata, and tabular rows.
- No Durable Persistence: We do not write uploaded files to relational databases, disk file systems, object storage, or document backup archives.
- Session Completion: Memory pointers are unreferenced upon transmission of the extraction payload to your browser.
- No AI Model Training: Your financial data, numbers, client names, and invoice totals are never utilized to train, fine-tune, or calibrate any machine learning or AI models.
3. Technical Logs & Metadata Collected
Like virtually all web applications, our web servers automatically record standard network metadata generated during HTTP/HTTPS requests. This may include:
- Internet Protocol (IP) address (classified as personal data under GDPR Art. 4(1))
- Date, timestamp, and duration of the request
- HTTP request method and requested endpoint (e.g.
POST /api/convert) - HTTP response status code (e.g. 200, 400, 422)
- Browser User-Agent string and operating system metadata
- Upload payload size in bytes (used for rate-limiting enforcement)
Legal Basis (GDPR Art. 6(1)(f)): Processing this metadata is necessary for our legitimate interests in safeguarding server infrastructure, preventing automated denial-of-service (DDoS) abuse, ensuring rate-limit boundaries, and monitoring system availability.
4. Hosting Infrastructure & Data Residency
PDFGridly is hosted on virtual server infrastructure provided by Netcup GmbH (Daimlerstraße 25, D-76185 Karlsruhe, Germany). All physical servers are situated within the European Union (Germany) and operate under European data protection standards. Netcup acts strictly as our hosting infrastructure provider.
5. Data Retention Schedule
| Category | Retention Period | Storage Location |
|---|---|---|
| Uploaded PDF content | Transient session (Unpersisted memory) | Volatile RAM only; auto-purged |
| Extracted spreadsheet tables | Active session only | Held in client browser session |
| Web server access/security logs | 14 calendar days | Access-restricted server logs, automatically rotated |
6. Cookies & Tracking Technologies
At present, PDFGridly utilizes zero non-essential cookies. We do not place marketing, behavioral profiling, or cross-site tracking cookies on your device.
In the event that third-party advertising partners (such as Google AdSense) or privacy-preserving analytics are integrated in future releases, a certified Consent Management Platform (CMP) conforming to the IAB Europe Transparency and Consent Framework (TCF v2.2) will be implemented to obtain prior, explicit user consent before any non-essential cookies are loaded.
7. Your Data Protection Rights
Under the General Data Protection Regulation (GDPR) and applicable data protection legislation, you have the following statutory rights regarding personal data (specifically within security logs):
- Right of Access (Art. 15 GDPR): Inquire whether we process log data relating to your IP address.
- Right to Erasure (Art. 17 GDPR): Request the deletion of security log entries containing your IP address.
- Right to Restrict Processing (Art. 18 GDPR): Request limits on how we process your log data.
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a formal complaint with a competent European Data Protection Supervisory Authority (such as the BfDI in Germany, CNIL in France, or ICO in the United Kingdom).
To exercise any of these statutory rights, please contact our designated privacy contact at privacy@pdfgridly.com. We respond to verified inquiries within 30 calendar days.