PRIVACY POLICY

Last Updated: 24 July 2026

These Terms and Conditions of Sale and Use (the “Terms”) govern access to and use of ThePDF.co (the “Platform”) and the digital services made available through it (collectively, the “Services”).

The Platform is operated by:

LINDMA LTD

Promachon Eleftherias 1
1st Floor, Office 18/19
Agios Athanasios, 4103
Limassol, Cyprus

Email: contact@thepdf.co

We process personal data in accordance with applicable data protection legislation, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Cypriot data protection law.

This Privacy Policy should be read together with our Terms and Conditions, Cookie Policy, Subscription Terms and Refund Policy, where applicable.

1. ABOUT THEPDF

ThePDF is an online platform providing digital tools for creating, editing, converting, compressing, merging, organising and otherwise processing PDF documents and compatible file formats.

In order to provide these Services, certain information may need to be processed when you visit the Platform, create an account, purchase a Service, upload a document, contact us or otherwise interact with ThePDF.

We seek to collect and process only personal data that is reasonably necessary for the relevant purpose.

2. PERSONAL DATA WE MAY COLLECT

Depending on how you use ThePDF, we may process the following categories of information.

Account and Contact Information

This may include:

  • name, where provided;
  • email address;
  • account identifier;
  • account preferences;
  • communications with our customer support team.

We do not require information such as date of birth, telephone number, voice or image unless it becomes genuinely necessary for a specific feature or legitimate purpose.

Transaction and Subscription Information

When you purchase a Service or subscribe to ThePDF, we may process:

  • subscription plan or purchased Service;
  • transaction reference;
  • amount and currency;
  • payment status;
  • subscription status;
  • billing and renewal dates;
  • cancellation or refund information;
  • limited information received from our payment service providers.

Technical and Usage Information

When you access the Platform, we may automatically receive certain technical information, including:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • language and regional settings;
  • approximate location derived from technical information;
  • referring source;
  • session information;
  • pages and features used;
  • interactions with the Platform;
  • technical logs and error information.

User Files and Documents

When you upload a document to ThePDF, the file and its contents are technically processed to perform the action requested by you.

A document may itself contain personal data depending entirely on the content uploaded by the User.

ThePDF does not require Users to include personal data in their documents unless necessary for their own intended purpose.

3. HOW WE COLLECT PERSONAL DATA

We may collect information:

  • directly from you when you create an account, purchase a Service, upload a file or contact us;
  • automatically when you interact with the Platform;
  • from payment, security or technical service providers where necessary to operate the Services;
  • through cookies and similar technologies, subject to applicable consent requirements.

Further information regarding cookies and similar technologies is available in our Cookie Policy.

4. HOW WE USE PERSONAL DATA

We may process personal data where reasonably necessary to:

  • provide and operate the Services;
  • create and manage User accounts;
  • process documents and files at the User's request;
  • process payments and subscriptions;
  • manage recurring billing;
  • process cancellations and refunds;
  • authenticate Users and maintain account security;
  • communicate important information concerning the Services;
  • provide customer support;
  • investigate technical issues;
  • prevent and detect fraud, abuse and unauthorised activity;
  • maintain the security and integrity of the Platform;
  • analyse and improve the operation and performance of our Services;
  • comply with legal, regulatory, tax and accounting obligations;
  • establish, exercise or defend legal claims;
  • send marketing communications where permitted by applicable law.

We do not use uploaded documents for unrelated advertising purposes.

5. LEGAL BASES FOR PROCESSING

Under the GDPR, our processing of personal data must rely on an appropriate legal basis.

Depending on the purpose and circumstances, we may rely on:

Performance of a Contract

We process information where necessary to provide Services requested by you, including account management, document processing, subscriptions, payments, cancellations and customer support.

Legitimate Interests

We may process information where necessary for our legitimate interests, provided those interests are not overridden by your fundamental rights and freedoms.

These interests may include:

  • securing the Platform;
  • preventing fraud and abuse;
  • maintaining and improving our Services;
  • troubleshooting technical issues;
  • protecting our legal rights;
  • understanding the general performance and use of our Services.

Consent

Where required, we rely on your consent for specific processing activities, particularly certain cookies, tracking technologies or marketing activities.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Consent under the GDPR must represent a genuine and informed choice and cannot simply be presumed.

Legal Obligations

We may process information where necessary to comply with applicable legal, regulatory, tax, accounting or other binding obligations.

6. DOCUMENT PROCESSING AND FILE CONFIDENTIALITY

Documents uploaded to ThePDF are processed for the purpose of performing the functionality requested by the User.

Uploading a document does not transfer ownership of that document to LINDMA LTD.

We process uploaded files only to the extent reasonably necessary to provide, secure and support the requested Service.

Unless a file is intentionally stored by the User through a feature specifically designed for continued storage, uploaded and generated files are intended to be automatically deleted within a maximum of 24 hours following processing.

Limited temporary copies may remain for a longer period where reasonably necessary for technical security, backup integrity, fraud prevention, compliance with legal obligations or resolution of a technical incident.

Any such retention is limited to what is reasonably necessary for the relevant purpose.

Users should avoid uploading information that is unnecessary for the document-processing operation they wish to perform.

7. PAYMENTS

Payments are processed through secure third-party payment service providers.

ThePDF does not need to receive or store complete payment card credentials where those credentials are processed directly by the relevant payment provider.

We may receive limited transaction information necessary to manage a purchase or subscription, including:

  • transaction reference;
  • payment status;
  • amount and currency;
  • date of payment;
  • limited payment method information;
  • information necessary for refunds, disputes or fraud prevention.

Payment providers process payment information in accordance with their own applicable legal and security obligations.

For security and commercial reasons, this Privacy Policy does not needlessly disclose the identity of every payment or infrastructure provider used by ThePDF.

8. COOKIES AND SIMILAR TECHNOLOGIES

ThePDF may use cookies and similar technologies for purposes including:

  • essential Platform functionality;
  • maintaining sessions;
  • security and fraud prevention;
  • remembering preferences;
  • measuring Platform performance;
  • analytics;
  • advertising measurement, where applicable.

Where legally required, non-essential cookies or similar tracking technologies are activated only in accordance with the User's consent choices.

Users must be able to make a genuine choice regarding consent-based processing and withdraw their consent where applicable.

Further information is provided in our Cookie Policy.

9. MARKETING COMMUNICATIONS

Where permitted by applicable law, we may send Users information concerning ThePDF, new features, relevant offers or related Services.

Where consent is legally required, marketing communications will only be sent on the basis of the appropriate consent.

Users may unsubscribe from marketing communications at any time by using the unsubscribe mechanism included in the relevant message or by contacting:

contact@thepdf.co

Opting out of marketing communications does not prevent us from sending transactional or service-related communications that are necessary for an account, subscription, payment, security matter or other requested Service.

10. SHARING OF PERSONAL DATA

We do not sell personal data.

Where reasonably necessary to operate ThePDF, we may disclose or make personal data available to categories of recipients including:

  • cloud hosting and infrastructure providers;
  • document-processing and technical service providers;
  • payment service providers;
  • security and fraud-prevention providers;
  • analytics providers;
  • customer support and communications providers;
  • professional advisers, including legal and accounting advisers;
  • competent courts, regulators, law-enforcement bodies or public authorities where required or permitted by law.

Service providers acting on our behalf are permitted to process personal data only as appropriate for the relevant services and subject to applicable contractual and data protection requirements.

The GDPR expressly requires privacy information to identify the recipients or categories of recipients, rather than necessarily publishing every supplier by commercial name.

11. INTERNATIONAL DATA TRANSFERS

Certain service providers or technical infrastructure used by ThePDF may be located outside Cyprus or the European Economic Area ("EEA").

Where personal data is transferred outside the EEA to a jurisdiction that has not been recognised as providing an adequate level of protection, we use an appropriate transfer mechanism where required by applicable law.

Depending on the circumstances, this may include:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses approved by the European Commission;
  • another legally recognised transfer mechanism;
  • or a specific statutory derogation where legally applicable.

Where required, additional safeguards may be implemented taking into account the nature of the transfer and applicable data protection requirements.

12. DATA RETENTION

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.

Account information: retained while the account remains active and thereafter for the period reasonably necessary to deal with legal, security or contractual matters.

Transaction and billing records: may be retained for the period required by applicable tax, accounting, fraud-prevention and legal obligations.

Customer support communications: retained for a reasonable period according to the nature of the request and any resulting legal or operational requirements.

Technical and security information: retained only for a period reasonably necessary for security, troubleshooting, fraud prevention and Platform integrity.

The GDPR requires controllers to disclose either the applicable retention period or the criteria used to determine it.

13. DATA SECURITY

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or misuse.

Access to personal data is restricted according to legitimate operational requirements.

We also require relevant service providers processing personal data on our behalf to maintain appropriate safeguards.

However, no Internet-based system or electronic storage method can guarantee absolute security.

For security reasons, we do not publicly disclose detailed information concerning our internal security architecture, fraud-prevention mechanisms or technical infrastructure.

14. YOUR DATA PROTECTION RIGHTS

Subject to the conditions and limitations provided by applicable law, Users may have the right to:

  • access personal data held about them;
  • correct inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to certain processing;
  • withdraw consent where processing is based on consent;
  • request data portability where applicable;
  • object to certain forms of direct marketing;
  • lodge a complaint with a competent data protection supervisory authority.

Requests may be submitted to:

contact@thepdf.co

We may request information reasonably necessary to verify the identity of the person making a request before acting upon it.

Certain rights are subject to statutory exceptions. For example, we may need to retain information despite an erasure request where retention remains necessary to comply with a legal obligation or establish, exercise or defend legal claims.

The Cypriot supervisory authority has recently specifically required an online service to revise its privacy policy where information concerning the exercise of data-subject rights was insufficient.

15. RIGHT TO LODGE A COMPLAINT

Users have the right to lodge a complaint with a competent data protection supervisory authority if they believe their personal data has been processed in violation of applicable data protection law.

As LINDMA LTD is established in Cyprus, the relevant Cypriot supervisory authority is the:

Office of the Commissioner for Personal Data Protection of Cyprus

Users residing or working elsewhere in the European Union may also have the right to contact the supervisory authority competent in their Member State.

The Cyprus Commissioner confirms that data subjects may lodge a complaint where they consider processing of their personal data to infringe the GDPR.

16. CHILDREN'S PRIVACY

ThePDF is not intended to knowingly collect personal data from children in circumstances where they cannot lawfully use the Services or provide the necessary consent.

We do not knowingly seek to collect personal data from children for advertising or profiling purposes.

If we become aware that personal data relating to a child has been processed in circumstances inconsistent with applicable law, we may take appropriate steps to delete or otherwise lawfully address that information.

17. AUTOMATED DECISION-MAKING

ThePDF may use automated systems for technical, security and fraud-prevention purposes.

We do not currently intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects on Users unless appropriate safeguards and disclosures required by applicable law are implemented.

18. BUSINESS TRANSFERS

If LINDMA LTD undergoes a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, personal data may be disclosed or transferred where reasonably necessary in connection with that transaction.

Any such processing remains subject to applicable data protection requirements and the rights of affected individuals.

19. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, business practices or applicable legal requirements.

The latest version will be made available on ThePDF.co and identified by its "Last Updated" date.

Where a change materially affects the processing of personal data, we will provide additional notice or obtain consent where required by applicable law.

Continued use of the Platform will not be treated as consent to a new processing activity where applicable law requires specific consent.