Legal

Data Processing Addendum

This Data Processing Addendum (“DPA”) is between the customer using RelayPDF (“Controller”) and Strategic Products LLC, d/b/a RelayPDF (“Processor,” “RelayPDF”). It forms part of the Terms of Service (the “Agreement”) and applies when RelayPDF processes Customer Personal Data on the Controller’s behalf to provide the Service. By using the Service to process personal data, the Controller agrees to this DPA.

Last updated: August 21, 2026

1. Definitions

Capitalized terms not defined here have the meaning in the Agreement or in applicable Data Protection Laws.

  • Customer Personal Data: Personal Data that RelayPDF processes as a processor on the Controller’s instructions when providing the Service (content in HTML, Markdown, URLs, uploads, templates, template data, generated files, and related job parameters)
  • Data Protection Laws: GDPR, UK GDPR, CCPA/CPRA, and other privacy laws that apply to the processing
  • Personal Data Breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data
  • Subprocessor: a third party engaged by RelayPDF to process Customer Personal Data
  • Services: the RelayPDF document API and dashboard features described in the Agreement, including generate, convert, merge, protect, preview, barcodes, zip, templates, optional AI template generation, async jobs, webhooks, and 24-hour file delivery

2. Scope and roles

For Customer Personal Data, the Controller is the controller (or a processor instructing RelayPDF as a subprocessor) and RelayPDF is the processor. RelayPDF acts as an independent controller for account registration, authentication, wallet and Stripe billing, website logs, and support mail, as described in the Privacy Policy.

This DPA prevails over the Agreement if they conflict on Customer Personal Data. It does not apply to data RelayPDF processes as a controller except where the Controller submits that data to support in connection with a job.

3. Details of processing

Subject matter and duration follow the Agreement and last for the term of the account plus residual retention described below.

3.1 Nature and purpose

RelayPDF processes Customer Personal Data to generate and deliver documents and related files, store outputs for up to 24 hours when a download URL or async job is requested, run conversions and PDF tools, store templates the Controller saves, optionally generate or edit templates with AI when requested, send webhooks the Controller configures, prevent abuse, and provide support when the Controller shares job context.

3.2 Data subjects

Any individuals whose data the Controller includes in payloads or templates: the Controller’s users, customers, employees, counterparties, or others.

3.3 Types of data

Whatever the Controller submits. RelayPDF does not decide those types. The Controller must not submit special-category or similarly sensitive data unless it is necessary, lawful, and appropriate for a general-purpose document API.

4. Controller obligations

The Controller warrants that it has a lawful basis, has provided required notices, and has obtained consents or authorizations needed for RelayPDF to process Customer Personal Data. Documented instructions are the Agreement, this DPA, and the Controller’s API calls and dashboard configuration.

The Controller will not instruct RelayPDF to process data unlawfully. The Controller is responsible for the accuracy of Customer Personal Data and for not sending more personal data than needed.

5. Processor obligations

RelayPDF will:

  • Process Customer Personal Data only on documented instructions, unless law requires otherwise (in which case we will notify the Controller if legally permitted)
  • Ensure persons who process the data are bound by confidentiality
  • Implement appropriate technical and organizational measures given the nature of a multi-tenant document API: TLS; hashed API keys; access control; input validation; SSRF protections on URL fetch; no logging of HTML or file bodies; 24-hour deletion of stored outputs; provider-managed encryption at rest where supported; monitoring and incident response
  • Assist the Controller, taking into account the nature of processing, with data-subject requests, DPIAs, and consultations with authorities
  • Notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and where feasible within 72 hours, with information reasonably available to help the Controller meet its own notice duties
  • Delete stored generated files after 24 hours and delete or return remaining Customer Personal Data on account closure, except data we must keep by law or that remains in rotating backups until expiry

6. Location and transfers

Processing occurs in the United States and on Cloudflare’s global network. Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to the United States or another third country, RelayPDF uses Standard Contractual Clauses (and UK/Swiss addenda as required) with Subprocessors, or another lawful transfer mechanism. Module Two (controller to processor) or Module Three (processor to processor) applies according to the Controller’s role.

The 2021 EU Commission SCCs are incorporated by reference. Annex I and II details are this DPA and the Privacy Policy. For UK transfers, the ICO’s International Data Transfer Addendum is incorporated.

7. Subprocessors

The Controller authorizes RelayPDF to engage the Subprocessors below for Customer Personal Data. RelayPDF will impose written data-protection terms and remains responsible to the Controller for Subprocessor performance as required by Article 28 GDPR.

Stripe processes wallet payments as RelayPDF’s payment processor (controller-to-controller or independent controller for payment data), not as a document-content Subprocessor.

RelayPDF will update this list when Subprocessors change. The Controller may object on reasonable data-protection grounds by emailing support@relaypdf.com within 15 days of a posted change. If the objection cannot be resolved, the Controller may stop using the affected feature or close the account. Security or continuity changes may be made sooner with notice as soon as practicable.

SubprocessorRoleLocation / notes
Cloudflare, Inc.Public API (Workers), Chromium PDF and screenshots, LibreOffice/wkhtml containers, R2 object storage (24-hour TTL)Global network; U.S. contracting entity
Vercel, Inc.Website and dashboard hosting; optional AI Gateway when AI templates are usedUnited States
Supabase, Inc.Postgres for accounts, templates, usage, and hashed keys (not full document bodies)United States (us-east-1)
Clerk, Inc.Authentication. Primarily account data; may see session context if the Controller uses the dashboard with customer contentUnited States
xAIOptional AI template generate/edit only when the Controller uses that featureUnited States, via Vercel AI Gateway
ResendOutbound transactional email if a message includes Customer Personal DataUnited States
AgentMailInbound support@ and security@ if the Controller includes Customer Personal Data in a ticketUnited States

8. Audits

RelayPDF will make available information reasonably necessary to demonstrate Article 28 compliance. Audits are on reasonable written notice, during business hours, under confidentiality, and without disrupting other customers or revealing third-party data. We may satisfy an audit with documentation, architecture summaries, and written answers where that is appropriate.

9. California

Where the CCPA/CPRA applies to Customer Personal Data, RelayPDF is a “service provider” / “contractor.” We will not sell or share that information, retain, use, or disclose it outside the business purpose of providing, securing, and supporting the Services, or combine it with personal information from other sources except as permitted by law. We will comply with applicable restrictions on retaining and reusing Customer Personal Information.

10. Term

This DPA starts when the Controller first uses the Service and continues until the Agreement ends and deletion/return obligations are completed. Confidentiality, deletion, audit, and liability terms survive as needed.

11. General

RelayPDF may update this DPA to reflect law or the Service if the update does not materially reduce protection of Customer Personal Data. Florida law and venue in the Agreement apply. Notices: support@relaypdf.com; security incidents: security@relaypdf.com.

Strategic Products LLC, d/b/a RelayPDF

1583 Hansen Street, Sarasota, FL 34231, United States