Data Processing Agreement (DPA)
Last updated: 2026-08-16
This DPA applies on every plan, including Free. It is not gated behind a paid tier, and you do not need to request it — it forms part of the Terms of Service.
1. Parties and roles
This DPA is between you ("Customer") and FRONTPLUG LLC, a limited liability company organized under the laws of the State of Delaware, United States of America ("Processor", "we").
For personal data contained in the data you send us to render, Customer is the Controller (or a Processor acting for its own controller) and we are the Processor. For our own account data we are the Controller, and the Privacy Policy applies instead.
2. Scope and instructions
We process Customer personal data only on Customer's documented instructions, which consist of the Terms, this DPA, and Customer's use of the Service, and only to generate PDF and image output. We do not process it for any other purpose, and we do not use it to train models.
We will inform Customer if we believe an instruction infringes applicable data protection law.
3. Duration and subject matter
| Item | Detail |
|---|---|
| Subject matter | Generating documents from Customer templates and data |
| Duration | For as long as Customer's account is active |
| Nature and purpose | Storage, rendering, and delivery of generated files |
| Types of personal data | Whatever Customer chooses to place in its data — typically names, addresses, order or invoice details |
| Categories of data subjects | Customer's own end users, employees, or counterparties |
Customer decides what personal data to send. The Terms prohibit sending special-category data such as health records or government identification numbers.
4. Confidentiality
Personnel authorized to process Customer personal data are bound by confidentiality obligations and access it only as needed to provide the Service.
5. Security measures
- TLS for all data in transit
- Passwords hashed with PBKDF2-HMAC-SHA256; API keys stored only as hashes
- Per-account isolation enforced at the database query layer, not by application checks
- Network access blocked inside the rendering environment
- Request payloads deleted immediately after rendering
- Generated output expires automatically (24 hours by default, 30 days maximum)
- Access audit records retained for 2 years
6. Subprocessors
Customer gives general authorization for us to engage the subprocessors listed on the Subprocessors page. We impose data protection obligations on them no less protective than this DPA and remain liable for their performance.
We will give advance notice before adding or replacing a subprocessor. Customer may object on reasonable data protection grounds; if we cannot resolve the objection, Customer may terminate the affected Service.
7. Assisting the Controller
Taking into account the nature of the processing, we will assist Customer with data subject requests, data protection impact assessments, and consultations with supervisory authorities. Because request payloads are not retained and generated output expires automatically, most data subject requests can be satisfied by Customer directly.
8. Personal data breach ★
We will notify Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to us at that time, and will update Customer as we learn more.
9. Government access requests
If we receive a legally binding request from a public authority for Customer personal data, we will notify Customer unless legally prohibited, and will challenge requests that appear unlawful or overbroad.
10. International transfers ★
We are located in the United States and the Service runs on a global network, so processing occurs outside the EEA, the UK, and Switzerland.
- EEA — the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) or Module Three (Processor to Processor) as applicable, are incorporated into this DPA by reference.
- United Kingdom — the ICO International Data Transfer Addendum (Addendum B1.0) applies to those Clauses.
- Switzerland — the Clauses apply with references to the GDPR read as references to the Swiss FADP.
Where the Clauses require a choice, the governing law and forum are those stated in the Terms, to the extent the Clauses permit.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA. Where Customer requires an on-site audit, the parties will agree scope and timing in advance, limited to once in any 12-month period unless a supervisory authority requires otherwise.
12. Return and deletion
Customer can delete its data at any time from the console. On termination we delete Customer personal data from our database and object storage. Audit records subject to a statutory retention obligation are kept with identifiers removed rather than deleted.
13. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms.
14. Governing law and precedence
This DPA is governed by the laws of the State of Delaware, United States of America, without regard to its conflict of laws rules, except where the Standard Contractual Clauses require otherwise. If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer personal data.
15. Language
This DPA is published in English and Korean. The English version is the authoritative version; the Korean version is a convenience translation.
16. Contact
FRONTPLUG LLC — support@brewmypdf.com