Legal
Data Processing Agreement
GoodPDF is a desktop application. The documents you open, edit and save never reach our servers — that is the single most important fact for anyone doing a vendor review, and everything below follows from it. This page is written to be read by that person, so it names our sub-processors and says what actually happens rather than what sounds reassuring.
01Your documents do not come to us
GoodPDF opens, renders and edits PDF files entirely on your own computer. The rendering and editing engine ships inside the application; there is no upload step, no conversion service, and no copy of your file on our infrastructure.
That means for the work the software actually does, there is no processing relationship to govern. We are not your processor for your documents, because we never receive them.
02The one case where we do process your content
There is a single exception, and it is deliberate: when you send a problem report from inside the application, the report includes the document you had open at the time, along with a screenshot of the window.
That is what makes a bug reproducible — most rendering and editing faults cannot be diagnosed from a stack trace alone. But it means the report may contain personal data, and you should treat sending one as a disclosure decision.
Reports go to Sentry, our error-tracking sub-processor. If the document is confidential, do not send the report; write to us from the contact page and describe the problem instead.
03What we hold as controller
- Your email address, received from our payment processor when you buy a licence.
- Your licence key, and for each activation an installation identifier, the platform (mac or win) and, if your operating system supplies one, the device name.
- Records of purchases, renewals and refunds held by our payment processor.
- Correspondence you send us through the contact form or by email.
- Aggregate, cookie-free web analytics for goodpdf.io — page counts and referrers, with no cross-site identifiers and no profile of you.
04What we do not hold
- No account. The software does not ask you to register; a licence key unlocks it.
- No document contents, filenames or file paths, except inside a problem report you chose to send.
- No payment card details. Those go directly to our payment processor and never touch our systems.
- No advertising identifiers, and no data sold or shared with data brokers.
05Sub-processors
These are the services that may handle personal data on our behalf. We will update this list before adding another.
- Stripe — payment processing, invoicing and the billing portal.
- Cloudflare — website hosting, the download endpoint, and the database holding licence keys and activations.
- Sentry — crash reports and the problem reports you choose to send, which may include a document and a screenshot.
- Resend — transactional email such as delivering a licence key or a recovery link.
- FormEmailAPI — delivery of messages sent through the contact form.
- Our web analytics is self-hosted and is not a third-party sub-processor.
06Where the data sits, and international transfers
Our sub-processors operate globally and data may be processed outside your country, including in the United States. For personal data originating in the EEA, the UK or Switzerland, that is an international transfer.
We rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where applicable, as incorporated into our agreements with each sub-processor above.
We do not offer EU-only data residency. If your own assessment requires processing to stay inside the EEA, that is worth raising before you deploy the software widely rather than afterwards.
07Security
- Traffic to goodpdf.io and to our licence endpoints is encrypted in transit.
- Licence records are stored in a managed database with access restricted to the people who operate the service.
- Application updates are signed with an ed25519 key and verified by the updater before installation, so a tampered update will not install.
- Downloads are served over HTTPS from immutable, version-stamped filenames, so a published build cannot be silently replaced.
08Retention and deletion
Licence and activation records are kept while the licence is live and for as long afterwards as we need them for tax and accounting purposes.
Problem reports are kept for a limited retention window in Sentry and then removed automatically. If you sent one and want it deleted sooner, write to us with the approximate time and we will remove it.
Correspondence is kept while it is useful for support and then deleted.
09Personal data breaches
If a breach affects your personal data, we will notify you without undue delay and, where the law requires it, within 72 hours of becoming aware. The notice will say what happened, what data was involved, and what we did about it.
10Your rights and how to exercise them
Write to us from the contact page. You can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. Deleting a licence record ends the licence, so we will confirm before doing that.
We do not charge for these requests and we aim to answer well inside the statutory month.
11Changes to this agreement
If we add a sub-processor or otherwise change how personal data is handled, this page changes with it. Material changes are dated at the top of the page.