GDPR Compliance Statement
Last Updated: June 05, 2025
At FileType:PDF, we are committed to ensuring the privacy and protection of your personal data in compliance with the General Data Protection Regulation (GDPR). This page explains how we adhere to GDPR requirements and outlines your rights as a data subject under this regulation.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It enhances privacy rights for individuals within the European Union (EU) and European Economic Area (EEA) and places obligations on organizations that process their personal data, regardless of where those organizations are based.
Our Data Processing Principles
We process personal data in accordance with these core principles:
- Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and in a transparent manner.
- Purpose Limitation: We collect data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
- Data Minimization: We ensure that personal data is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
- Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
- Storage Limitation: We retain personal data only for as long as necessary for the purposes for which it is processed.
- Integrity and Confidentiality: We process personal data securely, protecting against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- Accountability: We are responsible for and can demonstrate compliance with all of these principles.
Legal Bases for Processing
We process personal data only when we have a legal basis to do so. Depending on the specific processing activity, we rely on one or more of the following legal bases:
- Contractual Necessity: Processing necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Processing necessary for compliance with a legal obligation to which we are subject.
- Legitimate Interests: Processing necessary for our legitimate interests or those of a third party, except where such interests are overridden by your interests or fundamental rights and freedoms.
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent.
Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You have the right to access the personal data we hold about you and obtain information about how we process it.
- Right to Rectification: You have the right to have inaccurate personal data rectified and to have incomplete personal data completed.
- Right to Erasure (Right to be Forgotten): You have the right to have your personal data erased in certain circumstances.
- Right to Restriction of Processing: You have the right to obtain restriction of processing in certain circumstances.
- Right to Data Portability: You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format and to transmit this data to another controller without hindrance from us.
- Right to Object: You have the right to object to certain types of processing, including processing based on legitimate interests and processing for direct marketing purposes.
- Rights Related to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
How to Exercise Your Rights
You can exercise your rights by contacting our Data Protection Officer at [email protected]. We will respond to your request without undue delay and at the latest within one month of receipt of the request. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
Data Protection Measures for Files
When you upload files to our service for conversion or editing, we implement specific measures to protect your data:
- Temporary Processing: For non-registered users, we retain your files only for the time necessary to process your request (typically less than 24 hours), after which they are permanently deleted from our servers.
- Encryption: Files are encrypted during transmission using TLS protocols and at rest using AES-256 encryption.
- Access Controls: We have strict access controls that limit employee access to user files. Our staff does not access the content of your files except in rare cases where you explicitly request technical support that requires file inspection.
- Data Minimization: We only collect the data necessary to provide our services.
- Secure Infrastructure: Our systems are hosted in secure data centers that comply with industry standards for security.
International Data Transfers
If we transfer your personal data to recipients in countries outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to provide an adequate level of data protection. These safeguards may include:
- Transfers to countries that the European Commission has decided provide an adequate level of protection;
- Transfers subject to standard contractual clauses approved by the European Commission;
- Transfers based on binding corporate rules; or
- Transfers based on derogations for specific situations, such as your explicit consent.
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will inform you and the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and implementation to ensure compliance with GDPR requirements. You can contact our DPO at:
Email: [email protected]
Postal Address: Data Protection Officer, FileType:PDF
Supervisory Authority
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority responsible for data protection. You may do so in the EU member state of your habitual residence, your place of work, or the place of the alleged infringement.
Changes to This Statement
We may update this GDPR Compliance Statement from time to time. When we make changes, we will update the "Last Updated" date at the top of this statement and notify you through appropriate channels if the changes are significant.