Controller
The controller is the publisher of PDF Anonymizer, identified by SIRET 98171884400013. For any privacy request, you can write to contact@pdf-anonymizer.com.
Data processed
When you use the service, the following categories of data may be processed.
- Uploaded PDF, extracted text and personal data contained in the source document, solely to perform the requested anonymization.
- Anonymized PDF, HTML preview, generated identifier, page count, removed categories, review report and technical processing ID.
- Delivery email address entered by the user, used to send the processing status and, on success, the anonymized PDF as an attachment.
- User account: first name, last name, postal address, login email address, hashed password, essential session, role, active or disabled status, last anonymization date, free plan or subscription status, selected plan and data required to enforce usage limits.
- Anonymization audit trail: execution ID, associated user account, plan, timestamps, status, duration, page count, engine, PDF renderer, fallback use and error message. The PDF and its content are not stored in this audit trail.
- Technical information needed to operate the website, such as IP address, timestamp, server logs and application errors.
- Billing information: individual or business, recipient or legal business name, full address, billing email, registration number and VAT number when provided. These details are stored in the account and sent to Stripe for billing. PDF Anonymizer does not store card details.
- Execution report sent by email to the service publisher when SMTP is configured. This internal report does not include the PDF as an attachment.
Purposes
- Check that the file is a usable PDF.
- Remove detected personal data and generate an anonymized PDF.
- Add a short identifier on the first page when requested.
- Allow temporary download of the result.
- Send the user the anonymization status and the anonymized PDF when processing succeeds.
- Authenticate users, limit free usage, manage monthly plans and secure the service.
- Monitor technical failures, PDF generation fallbacks and processing quality.
- Provide administrators with an audit trail that attributes each execution to an account and records its status.
Legal bases
Processing required for anonymization and download is based on performance of the service requested by the user. Security, abuse prevention, technical monitoring and service improvement are based on the publisher's legitimate interest. Billing-related processing is based on contractual performance and applicable legal obligations.
Retention periods
- The source PDF is held in memory only while anonymization is running. It is not written to job storage and is not retained as an original file by the application.
- The anonymized PDF, HTML preview and technical report are stored together in a temporary directory so the result can be viewed and downloaded for 60 minutes.
- An automated process checks for expired jobs every 60 seconds and whenever the application starts. Once the 60-minute period has elapsed, it deletes the entire job directory, including the anonymized PDF, HTML preview and technical report.
- The delivery email address is not stored in the technical processing report. It is used during execution of the request and may appear in the email provider's logs according to that provider's own retention rules.
- The user account and usage state may be kept while the account remains active, then for as long as required to manage legal obligations, security and potential disputes.
- Audit trail metadata may be retained with the account while it is active and then for as long as needed for security, support and potential dispute management. It contains neither the PDF nor its text content.
- Hosting provider technical logs may be retained according to Render's settings and policies.
- Billing data may be retained for the legally required periods when a subscription is enabled.
Recipients and processors
Data may be processed by the providers required to operate the service.
- Render, for application hosting, temporary storage and technical logs.
- Anthropic, when Claude is used to strengthen identification of PDF elements to remove.
- Stripe, when payment or subscription is enabled.
- The configured SMTP provider, to send internal reports without PDF attachments and user emails containing the anonymized PDF when processing succeeds.
Support and anonymization feedback
Support forms and feedback collect your reply email, message, optional satisfaction rating and only the attachments you select. Feedback is linked to your account and the execution's technical metadata. No anonymization document is automatically attached to a support message.
This information is used to handle your request and monitor service quality. Administrators can access it and it is forwarded to contact@pdf-anonymizer.com through the configured SMTP provider. A technical fingerprint helps limit abuse of the forms.
Requests and their metadata are kept in the application for up to 90 days. Attachments are deleted after email transmission; if delivery fails, they remain queued for up to 7 days before automatic cleanup deletes them. These periods are separate from anonymization file retention, including when you choose to attach a PDF to support.
Copies forwarded to the support mailbox are not deleted by application cleanup. Their retention depends on request handling and mailbox policies. You can request deletion at contact@pdf-anonymizer.com.
Transfers outside the European Union
Some technical providers may be established outside the European Union, including in the United States. Where applicable, transfers are governed by the contractual safeguards and security measures offered by these providers.
Cookies
The website only uses cookies that are essential to the service: storing the selected language, maintaining the account session and protecting support forms against fraudulent submissions (a 24-hour cookie). No advertising cookie or non-essential analytics tool is currently used.
Your rights
You may request access, rectification, deletion, restriction or objection to the processing of your personal data where these rights apply. You can exercise these rights by writing to contact@pdf-anonymizer.com.
You also have the right to lodge a complaint with the French data protection authority, the CNIL.
Security
PDF Anonymizer uses HTTPS, does not attach PDFs to internal monitoring emails and limits retention of generated results. The anonymized PDF may be sent to the email address provided by the user. Users should nevertheless avoid uploading documents they are not authorized to process.