+
Privacy Policy
+
Last updated: February 16, 2026
+
+
+ This privacy policy is GDPR compliant and explains how we collect, use, and protect your personal data.
+
+
+
1. Data Controller
+
Cloonar Technologies GmbH
+ Address: Vienna, Austria
+ Email: legal@docfast.dev
+ Data Protection Contact: privacy@docfast.dev
+
+
2. Data We Collect
+
+
2.1 Account Information
+
+ - Email address - Required for account creation and API key delivery
+ - API key - Automatically generated unique identifier
+
+
+
2.2 API Usage Data
+
+ - Request logs - API endpoint accessed, timestamp, response status
+ - Usage metrics - Number of API calls, data volume processed
+ - IP address - For rate limiting and abuse prevention
+
+
+
2.3 Payment Information
+
+ - Stripe Customer ID - For Pro subscription billing
+ - Payment metadata - Subscription status, billing period
+
+
+
+ No PDF content stored: We process your HTML/Markdown input to generate PDFs, but do not store the content or resulting PDFs on our servers.
+
+
+
3. Legal Basis for Processing
+
+ - Contract fulfillment (Art. 6(1)(b) GDPR) - Account creation, API service provision
+ - Legitimate interest (Art. 6(1)(f) GDPR) - Service monitoring, abuse prevention, performance optimization
+ - Legal obligation (Art. 6(1)(c) GDPR) - Tax records, payment processing compliance
+
+
+
4. Data Retention
+
+ - Account data: Retained while account is active + 30 days after deletion request
+ - API usage logs: 90 days for operational monitoring
+ - Payment records: 7 years for tax compliance (Austrian law)
+ - PDF processing data: Not stored (processed in memory only)
+
+
+
5. Third-Party Processors
+
+
5.1 Stripe (Payment Processing)
+
Purpose: Payment processing for Pro subscriptions
+ Data: Email, payment information
+ Location: EU (GDPR compliant)
+ Privacy Policy: https://stripe.com/privacy
+
+
5.2 Hetzner (Hosting)
+
Purpose: Server hosting and infrastructure
+ Data: All data processed by DocFast
+ Location: Germany (Nuremberg)
+ Privacy Policy: https://www.hetzner.com/legal/privacy-policy
+
+
+ EU Data Residency: All your data is processed and stored exclusively within the European Union.
+
+
+
6. Your Rights Under GDPR
+
+ - Right of access - Request information about your personal data
+ - Right to rectification - Correct inaccurate data (e.g., email changes)
+ - Right to erasure - Delete your account and associated data
+ - Right to data portability - Receive your data in machine-readable format
+ - Right to object - Object to processing based on legitimate interest
+ - Right to lodge a complaint - Contact your data protection authority
+
+
+
To exercise your rights: Email privacy@docfast.dev
+
+
7. Cookies and Tracking
+
DocFast uses minimal technical cookies:
+
+ - Session cookies - For login state (if applicable)
+ - No tracking cookies - We do not use analytics, advertising, or third-party tracking
+
+
+
8. Data Security
+
+ - Encryption: All data transmission via HTTPS/TLS
+ - Access control: Limited employee access with logging
+ - Infrastructure: EU-based servers with enterprise security
+ - API keys: Securely hashed and stored
+
+
+
9. International Transfers
+
Your personal data does not leave the European Union. Our infrastructure is hosted exclusively by Hetzner in Germany.
+
+
10. Contact for Data Protection
+
For questions about data processing or to exercise your rights:
+
Email: privacy@docfast.dev
+ Subject: Include "GDPR" in the subject line for priority handling
+
+
11. Changes to This Policy
+
We will notify users of material changes via email. Continued use of the service constitutes acceptance of updated terms.
+
+