Privacy notice
This page describes what actually happens to a document you upload to this Public Early Access service, who is responsible, and what the service does and does not promise. It is written from the system's real behaviour; where a fact has not been confirmed yet, it says so instead of guessing.
1. Who runs this service
| Service provider (operator) | Henri Tikkanen |
|---|---|
| Contact for questions and requests | henri.tikkanen@tikkaconsult.fi |
| Hosting provider (processor) | Azure |
| Data location | Sweden Central |
The operator decides how the service processes your documents. The hosting provider supplies the server the service runs on and is a processor on the operator's behalf. The validator (veraPDF) and remediation engine run on the server itself. PDFAccess uses first-party server-side funnel analytics described below. If payment is enabled, Stripe processes the payment on its hosted checkout page and creates the paid invoice. Stripe collects the buyer's email, name, billing address and optional business tax ID for the payment and tax calculation; card details never reach PDFAccess. The signed webhook passes payment and customer details through application memory, but PDFAccess stores only the payment status, amount, Stripe identifiers and the buyer's delivery consent with the job.
2. Your documents
- What is uploaded. The PDF you choose. It is transferred over HTTPS to the server. It does leave your computer.
- What is created. A processed copy, automatic check reports from before and after processing, and a record of your review decisions (image descriptions you typed and checks you confirmed). These are stored together with your uploaded document.
- Who can see it. Only the browser session that uploaded it. Every request checks a signed, HttpOnly session cookie; knowing a job identifier is not enough. The operator can access the server and therefore the files while they exist; the operator does not open customers' documents except to investigate a fault you report.
- How long it is kept. Until you press Delete my files now, and in any case for at most 24 h after upload, when a timer deletes the whole job directory. Finished jobs, ownership and payment state survive ordinary restarts only until the original deadline. Unfinished or malformed saved jobs are removed. Temporary working files are isolated and removed when their processing step ends, including on timeout.
- Backups. The document storage is not backed up by the service. Whether the hosting provider takes server-level snapshots that could include the storage has not yet been confirmed for this deployment; until it is confirmed that no snapshot includes the storage, the deletion promise above applies to the live server only.
3. Service logs, session and analytics
Separately from the documents, the service keeps operational logs: time, request path, HTTP status, job identifiers, page counts and processing stages. Logs never contain file names, document text or alt texts. The reverse proxy logs the method, status and duration of requests, not their bodies or query strings. A random signed browser cookie ties each job to its creator and expires after 24 hours. A separate signed language cookie remembers the EN/FI choice for 24 hours. Funnel analytics record only event names, times and keyed pseudonymous identifiers; they do not record filenames, PDF content, alt text or a full IP address. IP-based abuse limits stay in memory and expire with their short rate-limit windows. Logs are rotated and kept for a few days.
4. What to upload during Early Access
This is Public Early Access. Use your own documents or public test documents. A public document is not automatically free of personal data: minutes, decisions and reports often name people. Before an organisation's documents containing personal data are processed here, the operator and that organisation need a data processing agreement and a documented legal basis; an Early Access label does not replace either. If you are unsure whether a document is suitable, do not upload it.
5. What the result means
PDFAccess applies automatic repairs, checks the PDF before and after, and lists what a person still needs to review. "Automatic checks passed" does not guarantee accessibility. Confirming a review task records that you checked it; it does not change the PDF. The report distinguishes what automation fixed, what needs a person, what can only be fixed in the source document, and what could not be classified. The service never states that a document is accessible.
6. Payments
Stripe processes one-time payments and uses the billing address and optional tax ID to calculate applicable VAT. PDFAccess receives the signed payment result but no card details. Stripe keeps the payment, customer and invoice records under its own retention obligations. See the terms, immediate-delivery consent, refund and failure policy.
7. Your rights and how to exercise them
You can delete your documents yourself at any time from the result page. For anything else — access, correction, objection, a complaint about how your data was handled — contact the operator named above. Adding this page does not by itself make the service compliant with data protection law; the operator's obligations (a record of processing, an agreement with the hosting provider, a legal basis for each use) exist independently of it.
Version 0.5.0-early-access of this notice, generated from the running configuration on each request.