Data protection

Privacy Policy

How pdf-to-fax handles personal data — and why it collects almost none.

Controller

Steven Greenwood
Contact

This site uses Cloudflare Web Analytics, which is cookieless — it doesn't use cookies, local storage, or any other client-side tracking technology, and doesn't build a profile of you across visits or sites. It does not use tracking pixels, third-party advertising, or any other analytics tool.

When you visit this site, your browser automatically transmits certain technical information to our hosting provider (Cloudflare), including your IP address, browser type, and the pages you request. This data is processed by Cloudflare on our behalf, under a data processing agreement, solely for the purpose of delivering, securing, and measuring usage of the website, and is subject to Cloudflare's privacy policy. Because Cloudflare is a US-based provider, this may involve transferring data to servers outside the EU/EEA; Cloudflare commits to appropriate safeguards (including its EU-U.S. Data Privacy Framework certification and the EU Standard Contractual Clauses) for such transfers.

Sending a fax

If you use the fax-sending service, we process the fax number and email address you provide, and the document you upload, in order to perform the contract with you (Art. 6(1)(b) GDPR).

Transmitting the fax necessarily involves passing your document and the destination fax number to our fax provider, Telnyx, who carries out the transmission on our behalf under a data processing agreement. Telnyx is a US-based provider, so this involves transferring that data outside the EU/EEA; the transfer is covered by Telnyx’s certification under the EU-U.S. Data Privacy Framework, and by the EU Standard Contractual Clauses where that certification does not apply. Your document is also, by the nature of the service, delivered to the fax number you specify — we cannot control what the receiving party does with it, so please make sure the number is correct before sending.

Payment is handled entirely by Stripe; we never see or store your card details. For customers in Europe the contracting entity is Stripe Payments Europe, Limited, registered in Ireland, and Stripe operates infrastructure in the EU. Where Stripe transfers personal data outside the EU/EEA within its own group, the transfer is covered by the EU Standard Contractual Clauses and, where applicable, by Stripe’s certification under the EU-U.S. Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR — processing necessary to perform the contract. Stripe’s data protection officer can be reached at dpo@stripe.com. Delivery confirmations are sent by email through our SMTP provider.

Your uploaded document is kept for up to 180 days after the transmission, solely so that we can evidence what was transmitted if a payment is disputed (Art. 6(1)(f) GDPR — establishing and defending legal claims). It is then deleted automatically, whether the fax succeeded or failed. While it is held it is not indexed, shared, or read (see our Security page).

Contacting us

If you use our contact form, we process the name, email address, subject and message you submit in order to answer your enquiry (Art. 6(1)(b) and (f) GDPR). The form is protected against automated abuse by Cloudflare Turnstile, which processes technical information about the request for that purpose only. Messages are sent to our own mailbox and kept only as long as needed to deal with the enquiry and any follow-up.

How long we keep things

  • Uploaded documents — kept for up to 180 days after the transmission as evidence of what was sent, then deleted automatically. The period is set against the card chargeback window, which is the dispute this evidence exists for.
  • The fax as transmitted — we also keep Telnyx's rendering of the fax as it was actually transmitted (monochrome, at fax resolution), for the same 180 days and for the same reason, then deleted automatically. Producing it means Telnyx briefly stores a copy as well.
  • Transaction records (fax number, email address, page count, price, timestamps): retained for 10 years, because they are business and accounting records we are required to keep under § 147 AO and § 257 HGB.
  • Server logs — kept only briefly for security and troubleshooting, then discarded.
  • Contact enquiries — kept only as long as needed to handle the enquiry.

Admin access

This site includes a password-protected admin area used solely by the site operator to manage its content. Logging in sets a session cookie, and requesting a password reset sends a one-time link by email through our SMTP provider. Neither of these involves visitor or customer data — they concern only the operator's own account.

Fonts

This site uses fonts from Google Fonts, loaded via next/font, which downloads them at build time and serves them from our own domain. No requests are made to Google servers when you visit this site.

Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing of your personal data. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us using the email address above.

Changes to this policy

Last updated: 11 August 2026.