Legal
Privacy Policy
Last updated:
This policy explains what personal data Compose PDF collects, why, and what you can do about it. The controller is Eedge, Inc., whose registered address is disclosed without delay on request. It covers the website and the Service; it does not cover sites we link to.
Two kinds of information are involved and we treat them differently. Account data is information about you as a customer. Customer Content is what you put into the Service — templates, data and documents. We process Customer Content only to run the Service for you, under the Terms of Service.
1. What we collect
Account data
- Your name and email address, and a hash of your password.
- The organizations you belong to, your role in them, and invitations you send or accept.
- Billing details held by our payment processor — we never see or store card numbers.
Usage data
- A record of each API call: the time, which template and key were used, whether it succeeded, how long it took, and how much of your allowance it consumed.
- Operational logs needed to run and debug the Service, including error details.
Customer Content
- Templates, uploaded assets, datasets, and the documents rendered from them.
Customer Content may contain personal data about your own customers or employees. For that data you are the controller and we are your processor: we act on your instructions, and we do not use it for our own purposes.
2. Data we deliberately do not keep
When you connect an external source such as a spreadsheet or a database, we store the credential — encrypted — and the identifier of the sheet or table you chose. We do not copy the rows. They are read at the moment a document is rendered or previewed and are not retained afterwards. Rendered documents naturally contain whatever was read; that is the document, and it is retained only if you asked us to store it.
3. Why we process it
- To provide the Service and the features you use — performance of our contract with you.
- To bill you and keep the records tax law requires — contract and legal obligation.
- To keep the Service secure, enforce limits and prevent abuse — our legitimate interest in running a working service.
- To send service messages about outages, security or material changes — contract and legitimate interest. Marketing email, if we ever send it, is consent-based and always has an unsubscribe link.
Where the GDPR or a comparable law applies, the legal bases are those named above. We do not sell personal data, and we do not use it to train machine-learning models.
4. Who we share it with
We use a small number of processors, each for a specific job:
- Cloudflare — hosting, database, object storage and the rendering containers. Effectively all data lives here.
- Stripe — payments, subscriptions and invoices. Stripe receives your billing details directly; we receive only identifiers, status and amounts.
- Resend — email. That is the two messages your account needs (confirming your address, resetting your password), for which it receives only that address.
We may also disclose data if the law requires it, or to establish or defend legal claims. If the business is sold or merged, data may transfer with it; we will say so before it takes effect.
5. International transfers
Our processors operate globally, so data may be processed outside your country. Where transfers are subject to the GDPR we rely on the European Commission’s standard contractual clauses or another approved mechanism. Ask us at info@composepdf.com for details.
6. How long we keep it
- Account and organization data — while the account exists. A deleted organization can be restored for 30 days; after that it and its stored documents are erased permanently.
- Temporary rendering artefacts — automatically deleted after 7 days.
- Usage records — retained so you can review your own history and so we can investigate abuse.
- Billing records — retained for the period tax and accounting law requires, even after an account closes.
7. Security
Data is encrypted in transit. Credentials for connected data sources are encrypted before they are stored, and are never returned by the API. API keys are stored as hashes, so we cannot show you a key again after it is issued — only replace it. Access between organizations is enforced at the data layer rather than only in the interface. No system is perfectly secure; if a breach affects your personal data we will notify you and, where required, the relevant authority.
8. Cookies
We set one cookie: the session cookie that keeps you signed in. There are no advertising cookies, no cross-site trackers and no third-party analytics on the Service. Payment pages hosted by Stripe set their own cookies under Stripe’s policy.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable form. You can change your name and password, export your data and delete your organization from within the Service; for anything else, write to info@composepdf.com. We will respond within the time the applicable law allows. You also have the right to complain to your data protection authority.
If your personal data reached us as part of another organization’s Customer Content, that organization is the controller: please contact them, and we will assist them in responding.
10. Children
The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16; if we learn we have, we will delete it.
11. Changes
We may update this policy. Material changes will be announced by email or in the Service before they take effect, and the date at the top always reflects the current version.
12. Contact
Eedge, Inc. Our registered address is disclosed without delay on request. Privacy enquiries: info@composepdf.com.