Privacy Policy

Last updated: May 21, 2018

PSPDFKit GmbH ("PSPDFKit" or "we") respects the privacy of its users ("you") and has developed this privacy policy ("Privacy Policy") to demonstrate its commitment to protecting your privacy. During the course of our activities we will collect, store and process data about you. The use and share of your data by us and your choices about such processes are described in this Privacy Policy. Please read this document carefully before you use our website, software, applications, our official social media pages that we control, or other mobile interactive features (each our "Service", together our "Services"). As we are based and processing data in Austria, this Privacy Policy is developed, and your data is processed in accordance with the Austrian Data Protection Act.

If you have any questions or concerns regarding this Privacy Policy, please contact us by email: [email protected]

## Data We May Collect and How We Use It

By agreeing to our Privacy Policy, we may collect, store, retain, parse and process:

  • "Personal Data" meaning information that identifies you as an individual, such as your name, user name, title, postal address (including billing and shipping addresses), telephone number (including home and mobile phone numbers), email address, ip address, company you work for and their address, credit and debit card number, avatar picture, gender, country of residence, signature, and

  • non-personally identifiable data ("Other Data"), meaning any information that does not reveal your specific identity, such as: browser and device information, license ID and type, operating system and uptime, app version and bundle ID, language used, server log file information, the name of your host or the domain name of the website that referred you to ours, app & SDK usage data, site data, demographic information, information collected through cookies, anonymous app usage data and other information provided by you.

PSPDFKit SDKs & App(s)

At activation of the app as a technical requirement to run the service we collect the following Other Data:

  • Model and version of the device used
  • Device ID, name, model
  • License ID and type
  • Operating System version and uptime
  • App version and Bundle ID
  • Language used

Product Development Support

In order to improve our products, we collect non-personal behavioral framework events such as when a user adds a bookmark or prints a PDF. The purpose of such information is for us to gauge the frequency of use so that we can help prioritize development improvements. We use Google Firebase to collect and store the information. As we only use this data for statistical analysis and development improvement, we do not combine it with other data or information.

PSPDFKit & PDF Viewer Website

Traffic Analysis

For traffic analysis purposes, we collect our website's visitors' Other Data of mouse activity coordinates and their IP address. For collecting this information, we may use cookies and similar technology like pixel tags. As we only use this data for statistical analysis, marketing and website improvement, we do not combine it with other data or information.

We also collect website visitors' Other Data via the Google Analytics platform provided by Google, Inc., a US-based company, for purposes of analyzing and interpreting how our visitors interact with our website. We track data such as what pages a visitor has viewed, whether a prospective customer has started one of our contact forms, whether a prospective customer has completed one of our contact forms and segmenting this data out depending on which of our various platforms such prospective customer is interested in. Further, with Google Analytics User-ID, we also track a unique per device random ID assigned through the service to visitors. All of this data is anonymized so that we have no way of determining the exact source of the data. Google may disclose this data to third parties if this is required by law or if third parties process this data on behalf of Google. Google will not associate your IP address with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you decline cookies, you may not be able to use the full functionality of our website. By using our website, you agree to the processing of collected data in the manner and for the reasons described above.

We also collect website visitors' Personal Data and Other Data via Intercom, Inc, a US-based company, interactive customer communication service for purposes of analyzing and interpreting how visitors interact with our website. Some of the data collected are the pages visited by a prospective customer and a prospective customer's email address if a customer communication is initiated by the prospective customer. Intercom also assigns a random unique user ID to every visitor that accesses a page with the service activated on it. For more information about the data collected by the service, please visit www.intercom.com/privacy.

We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices (in particular device's IP address (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar’s privacy policy by clicking on this link.

You can opt-out to the creation of a user profile, Hotjar’s storing of data about your usage of our site and Hotjar’s use of tracking cookies on other websites by following this opt-out link.

Technical Support

For the purpose of providing support for our application and our web service we collect and store your email address as well as any additional information that is included in support requests. As a means to properly deal with incoming support requests, we may need to use the submitted information (email address) to contact you in order to gain further information, if necessary.

We may collect Personal Data and Other Data you provide us with or which we obtain from your device or activities by using our Services, e.g. through our website, subscribing to our mailing lists, contacting our customer service and other sources like social media platforms.

To optimize your experience while you are using our Services, we collect data by using cookies. We use Cookies to automatically collect certain Other Data such as the browser and device you are using, the hostname, the website that has referred you to us, language, settings, etc. Cookies are small text files that are stored on your browser or device. They are used in various ways, e.g. to analyze users' behavior on a website or for personalization reasons based on the user's preferences.

In the section above, we have explained which tools we use exactly and how you can either delete them if they are already placed on your computer or decline their use. However, you might not be able to use some features of our Services properly if you decide to block or delete cookies.

We may place links and plug-ins from plug-in providers such as Facebook, Google, YouTube, Twitter, LinkedIn, Intercom, Google Play Store, Apple Store, or certain media on our website. However, these services may use their own cookies or web beacons to collect information about users who interact with links to their websites.

If you visit our website, your browser connects directly with the servers of plug-in providers and the content of the plug-in may be directly generated and incorporated on our website by your browser. Therefore, plug-in providers may be enabled to track and connect your visit and activities on our website with your profile set on such plug-in provider's website. Any information about interactions such as comments or the use of "like-buttons" may be directly transmitted to the plug-in providers' websites and may be stored by the relevant plug-in provider. If you want to avoid such transmission and storage of your data, you may prevent this by logging out of your relevant profiles with plug-in providers before using the plug-in. For further information about the purpose and extent of data usage and processing by plug-in providers on our website, please find the relevant providers' privacy policies below:

We use all the above obtained data in order to customize and to improve our Services and to evaluate effectiveness of our content, advertising, programming or other activities.

PSPDFKit Web Services

With licensing the PSPDFKit SDK, we store the email address submitted to us. We may use it to send you important notifications regarding the Service and its use. In addition, we connect your email address with the information we collected at activation of the App for support purposes. You agree that with registration to the Service, we may store that email address connected with the information referred to above in our systems in order to serve important notifications regarding the Service and its use and for support purposes. If a document is uploaded to a PSPDFKit service, we additionally store your IP-address for technical reasons. Moreover, the document you upload gets publicly available. Therefore, we are not able to guarantee confidentiality of any information contained in these documents. Hence, please consider carefully what you upload. On the basis of this information, you consent to public availability of the information you upload to PSPDFKit web services. We store your Personal Information with adequate protection. Our servers, on which we store this information, are located within the European Economic Area (EEA). We generally do not store your Personal Information longer as absolutely necessary to provide the Service to you. At termination of the Service towards you we will delete any Personal Information we collected from you without undue delay, unless further storage of such Information is required for a valid purpose. Please be aware that an encrypted storage of your Personal Information in our back-up system might be necessary for technical reasons for a period of 6 months from the termination of the Service.

How We Use Collected Data

We limit the collection of Personal Data and Other Data to the amount required to review, analyze, adapt and improve quality of our Services, products, advertising, customer support, fraud fighting, testing and calibration of our Services, for verification of your eligibility and credit report and to inform you about changes and news to our Services.

All Personal Data collected will only be processed by our employees to the extent needed except otherwise explained in this Privacy Policy. Personal Data will not be disclosed to third parties unless it is necessary for execution of your order, in particular for delivery of products or services by logistic partners, for investigating your credit status and the handling of payments, if you have granted us permission to do so or if the disclosure is permitted by law. By handling of payments, we use and protect your data with respect to and in compliance with the PCI DSS 3.1 standards by the PCI Security Standards Council.

Payments may be processed by our payment service provider Wirecard CEE (Wirecard Central Eastern Europe GmbH with registered office at Primoschgasse 3, 9020 Klagenfurt, Austria, registered with the company register under number FN 195599 x) whereby relevant data like you customer ID may be shared with Wirecard CEE for organizing and handling payments.

In case we buy or sell any business or asset, we may disclose Personal Data to the prospective seller or buyer of such business or assets. Further we may disclose Personal Data to third parties, if we or substantially all of our assets are acquired by a third party and Personal Data will be one of the transferred assets.

We may process and disclose Personal Data in order to comply with any legal obligation, to enforce or apply any contract with you, to protect our legitimate business rights, property, or safety of our employees, customers, or others.

We may combine Personal Data and Other Data we collect with additional data from other sources. We may share Personal Data and Other Data to advisors, advertisers and investors, for the purpose of conducting general business analysis or other business purposes.

If you subscribe to one of our mailing lists, we will use your email address, name, title and certain Other Data, for providing you with news about our Services. We use this data to keep you up to date about our product development, about the launch of new products, about what we writing about on our blog as well as conferences we attend to, etc. You may unsubscribe from our mailing lists by clicking the unsubscribe button in each of our emails or in your profile settings.

We will only use your data legally. If you believe that we are not using your data in a legal way or wish to inquire about your rights regarding your data you may do so by sending us an email at [email protected].

Third Party Subprocessors

PSPDFKit Email

emails delivered to our email-addresses are stored on servers of Google, Inc., a US-based company. Google, Inc. has bound itself to comply with the Safe Harbor Principles and, therefore, has obliged itself to comply with data protection principles similar to those governing within the EEA. However, according to its own policies, Google, Inc. may store Personal Information on serves of companies or in countries, which do not guarantee for an adequate level of data protection. Based on this information, when sending a message to the e- mail address named above you consent to the disclosure of the Personal Information contained therein to Google, Inc.

PSPDFKit Support

For providing proper support of PSPDFKit users we have commissioned Zendesk, Inc. as helpdesk provider, to whom we disclose the information contained in support request including your email address. This Service Partner is located in the United States and has bound itself to comply with the Safe Harbor Principles and, therefore, has obliged itself to comply with data protection principles similar to those governing within the EEA. Based on this information, when sending a message to our support desk you consent to the disclosure of the Personal Information contained therein to Zendesk, Inc.

List of Third Party Subprocessors

We engage certain subprocessors that assist PSPDFKit in providing our Services as describe here in our Privacy Policy, as well as in our Terms of Service.

A list of all of our third party subprocessors, may be found here at - pspdfkit.com/legal/third-party-subprocessors.

Data Retention

We will store your data as long as it is required for our business purposes respectively as it is required by law e.g. for tax and accounting reasons.

Right to Information

PSPDFKit GmbH is an Austrian limited liability company with registered office at Kaiserstrasse 117/17 1070, Vienna, Austria, registered with the company register of the Vienna Commercial Court under number FN 400890 w. You may request information about your data which is processed by us. Furthermore, you have the right to have your stored data corrected or deleted, if data is incorrect or has been processed contrary to the provisions of the Data Protection Act. Kindly note that we require proof of your identity before we may answer your request. Please send your request by email [email protected] or by postal mail to PSPDFKit GmbH, Kaiserstrasse 117/17, 1070 Vienna, Austria.

Data Protection

In accordance with the Austrian Data Protection Act we will take appropriate security measures to ensure that your Personal Data will not be processed illegally, changed or deleted, duplicated, used by unauthorized third parties and will be prevented from accidental loss or damage. We will implement processes that guarantee the safety of your personal data from the time it is collected until the time it is deleted.

Use of Our Website by Minors

If you are 14 years old or even younger, we will need your parents/ legal guardian's consent before you submit data via our Services. It is not allowed to submit data without such consent. If we receive any such data, we will stop processing this data as soon as we are informed.

Changes to This Privacy Policy

We may change this Privacy Policy at any time. All changes will be published on this site. Any changes to this Privacy Policy will become effective when we publish the revised Privacy Policy on our website. Your use of our website following these changes means that you accept the revised Privacy Policy. Therefore, we ask you to review our Privacy Policy from time to time.

Data Subject Request

You may inquire as to your data subject rights, revoke your consent to this Privacy Policy as well as other rights such as the processing of your Personal Data in the future at any time by sending an email to [email protected].