Privacy Policy
What we collect, who it is shared with, and how long it is kept. Written against what the software actually does.
Last updated 26 July 2026 · GAICOMTEL SRL
1. Controller
GAICOMTEL SRL is the data controller for personal data processed through PDFSummaryReport. Contact: info@mail.thepdfreport.com.
Where you upload a document containing other people’s personal data, you are the controller of that data and we process it as your processor, on your instructions, under the Terms of Service.
2. What we collect
Account data
- Your name and email address.
- A hash of your password — never the password itself.
- Your workspace name, brand colours, uploaded logo and default template.
- Session records (so you stay signed in) and email-verification / password-reset tokens.
Content you upload
- The document files themselves (PDF, DOCX, PPTX), stored on disk on our server.
- Their filename, size, page count and file type.
- The figures and text extracted from them, and the reports and PDFs rendered from those.
Billing data
We do not receive or store your card number. Paddle handles the payment and returns to us only the identifiers and status we need to grant access: a customer id, a subscription id, the price purchased, the subscription status, the current period end, and the email address associated with the purchase. We also keep an append-only credit ledger recording how many credits were granted or spent and why.
Usage and technical data
- Server logs of requests (including IP address), kept for operational and security purposes.
- Product analytics events (see section 4) — which pages were viewed, which buttons were clicked, and, if you consent, a session recording.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service — accounts, uploads, report generation | Account data, content you upload | Performance of a contract (b) |
| Taking payment, preventing repeat-trial abuse, tax records | Billing data | Contract (b) and legal obligation (c) |
| Transactional email — confirm address, reset password, welcome | Name, email | Contract (b) |
| Keeping the Service up, debugging, rate limiting, abuse prevention | Server logs, error reports | Legitimate interests (f) |
| Product analytics, autocapture and session replay | Usage data | Consent (a) — see section 4 |
4. Analytics, autocapture and session replay
We use PostHog (EU hosting) for product analytics. Analytics requests are sent to /api/ingest on this domain and forwarded to PostHog by our server; nothing on the page contacts posthog.com directly.
Two features deserve to be called out by name, because they are broader than plain page-view counting:
- Autocapture records the clicks and form interactions on a page automatically, including the text of the element clicked.
- Session replay records a reconstruction of your session — mouse movement, scrolling, and the DOM as it changed — so we can watch back how a flow was used.
Neither runs unless you accept analytics cookies. On your first visit you are asked; if you decline, or ignore the banner, PostHog is never loaded and no analytics request is made. You can change your mind at any time from the “Cookies” link in the footer. Declining does not limit the Service in any way.
Even with consent, report surfaces are excluded: everything that renders your document content carries a no-capture marker, so it is not recorded by autocapture and is masked in replay, and all form inputs are masked. We do not send your name or email address to PostHog — a person is identified there by an opaque account id and their plan.
5. How your documents are processed
To turn a document into a report we send its contents to Google Gemini (Google Ireland Limited / Google LLC) through the paid Gemini API. The file is uploaded to Google’s Files API and referenced on subsequent generations so the same document is not re-sent unnecessarily.
Google states that content submitted through the paid Gemini API is not used to train its models, and is retained only transiently for abuse detection. We do not use your content to train any model, and we do not read your documents except where you ask us to investigate a specific problem with your account.
DOCX and PPTX files are converted to PDF locally, on our own server, before extraction. No third party is involved in that step.
6. Sub-processors
| Provider | Purpose | Data |
|---|---|---|
| Google (Gemini API) | Extracting figures and text from your documents | Document contents |
| Paddle.com Market Ltd (Paddle) | Merchant of record — checkout, payment, tax, invoices | Email, billing and card data (collected by Paddle directly) |
| Resend | Transactional email only — address confirmation, password reset, welcome | Name, email address |
| PostHog (EU) | Product analytics, autocapture, session replay — only with consent | Usage events, opaque account id, plan |
| Hetzner Online GmbH (Germany) | Hosting — the server, the database and the file storage | All of the above at rest |
We do not sell personal data, and we do not share it for advertising. Transfers outside the EEA (principally to Google) are made under the European Commission’s Standard Contractual Clauses.
7. Retention
- Documents and reports — kept until you delete them or close your account. Deleting a document or a report removes the stored file as well as the row.
- Account data — kept for the life of the account, then deleted within 30 days of closure.
- Billing records and the credit ledger — retained for as long as tax and accounting law requires, which is longer than the account itself.
- Server logs — up to 30 days.
- Analytics and session recordings — retained by PostHog under its own retention policy; recordings are kept no longer than 12 months.
8. Your rights
If you are in the EEA or the UK you have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable form. Where processing rests on consent, you may withdraw that consent at any time — for analytics, from the “Cookies” link in the footer.
Email info@mail.thepdfreport.com to exercise any of these. We respond within 30 days. You also have the right to complain to your local supervisory authority; in Romania that is the ANSPDCP.
9. Cookies
- Strictly necessary — a session cookie so you stay signed in, and a small record of your cookie choice itself. These are set without consent because the Service cannot work without them.
- Analytics — set by PostHog only after you accept. They identify a browser across visits so a funnel can be measured.
Paddle sets its own cookies inside its checkout, under its own policy, when you open one.
10. Security
Traffic is served over TLS. Passwords are stored hashed. Every request is scoped to the workspace of the signed-in account, and there is no path through the API that reaches another workspace’s data. Uploaded files are stored outside the web root and served only to the workspace that owns them. No system is perfectly secure; if a breach affects your data we will notify you and the supervisory authority as the GDPR requires.
11. Children
The Service is not for people under 18, and we do not knowingly collect their data.
12. Changes
We will post any update here and change the date at the top. For material changes we will also notify you by email.
Questions about this page? Email info@mail.thepdfreport.com.