Data Processing Agreement
Last updated August 17, 2026
This DPA supplements the Terms of Service when personal data is processed through Pagemint on a customer's behalf — for example, names and addresses merged into an invoice template. Where this document and the Terms disagree on data processing, this document controls.
Roles
For data submitted to the render API, you are the controller and Pagemint is the processor. We process data solely to render the document you requested and for no other purpose.
Subject matter and duration
Processing consists of merging the data you submit into a template and returning the rendered file. It lasts for the duration of that request plus the TTL you set on the resulting file — at TTL zero, nothing is retained past the response.
Nature and purpose of processing
- Receiving template data over the API.
- Rendering it into a PDF (or other configured output format) in an isolated, sandboxed browser instance.
- Storing the result, if a non-zero TTL is set, behind a signed URL until it expires.
- Delivering completion or failure webhooks, if configured.
Categories of data subjects and data
Whoever appears in the documents you render — typically your own customers, employees, or counterparties. The categories of personal data are whatever you choose to include in a template: commonly names, addresses, and transaction details. We don't inspect or classify this data beyond what's needed to complete the render.
Sub-processors
We use a limited set of infrastructure sub-processors for compute, storage, and email delivery, each under a data processing agreement matching or exceeding these terms. We'll give notice of a new sub-processor with material access to render data, and you may object on reasonable data-protection grounds.
Security measures
- Encryption in transit (TLS) for every API request and file download.
- Each render executes in a sandboxed, pinned Chromium instance with no outbound network access beyond what the template explicitly requests.
- Access to production systems is limited, logged, and reviewed on a regular schedule.
- Files are deleted on TTL expiry, not archived.
Assisting with data subject rights
Because we typically can't identify data subjects independent of the documents you submit, we rely on you to route rights requests to us for the underlying render data; we'll assist promptly with access, deletion, or export requests you forward.
International transfers
Renders execute in the region you select at request time. We don't transfer render data to a different region without your request, and where a transfer requires a legal safeguard (such as Standard Contractual Clauses), we put one in place before it occurs.
Audit
On reasonable notice, we'll provide the information necessary to demonstrate compliance with this DPA, including responding to a security questionnaire or making a completed audit report available.
Contact
For a countersigned copy of this DPA or a Standard Contractual Clauses annex:legal@pagemint.app.