Home
Tools
Blog
Resources
About
Legal
Donate Get Started — Free
Data Processing (GDPR / DPA)

Your data never leaves
your device

All data is processed locally in your browser. We comply with GDPR, CCPA, and global privacy regulations.

How your data flows

A visual breakdown of what happens when you use a PDFly tool

You select a file

Pick a PDF from your device. The file loads directly into your browser's memory — no upload occurs.

Browser processes it

WebAssembly runs the PDF engine entirely on your CPU. Merge, split, compress — all locally.

You download result

Save the processed file. When you close the tab, all data is wiped from memory — permanently.

Data processing principles

The core principles that govern how PDFly handles your information

Lawfulness & transparency

We process no personal data. There are no accounts, no logins, and no hidden data collection. Everything PDFly does is visible to you in your browser.

Purpose limitation

Your file is processed solely for the action you selected — merging, splitting, compressing. No secondary use, no analytics on file contents, no profiling.

Data minimization

We collect zero personal data. No cookies for tracking, no analytics scripts, no fingerprinting. The only data that exists is the file you load — and it stays in your browser.

Storage limitation

No data is stored on any server. When you close the browser tab, the file and all processed results are cleared from memory. Nothing persists.

Integrity & confidentiality

All processing is sandboxed within your browser's security model. No third party can intercept or access your files because they never leave your device.

Accountability

We document our processing activities in this agreement and our privacy policy. Our architecture is verifiable — open the browser DevTools and confirm no network requests are made.

GDPR compliance overview

How PDFly aligns with the General Data Protection Regulation

Article 6 — Lawful basis

PDFly operates on the basis of legitimate interest — providing free PDF tools without collecting personal data. No consent is needed because no personal data is processed.

No personal data collected

Article 25 — Privacy by design

Our architecture is privacy-by-design: client-side processing means data protection is built into the core technology, not bolted on as a policy.

Built into the architecture

Article 32 — Security

No server-side storage eliminates entire categories of security risk. There are no databases to breach, no APIs to exploit, no credentials to steal.

Zero attack surface

Articles 15–22 — Data subject rights

Since we hold no personal data, all GDPR rights are inherently satisfied. There is nothing to access, rectify, erase, port, or restrict — because we have nothing stored.

Rights auto-satisfied

Your rights under this agreement

Even though we process no personal data, here's how each right applies

01

Right of access

You can access any information about you that we hold. Since we hold none, this right is automatically fulfilled. Open DevTools to verify zero network activity.

02

Right to rectification

You can correct inaccurate personal data. We store no personal data, so there is nothing to rectify. Your files are yours and remain under your sole control.

03

Right to erasure

Also known as the right to be forgotten. Close your browser tab and all data is instantly and permanently erased from memory. No traces, no backups, no residuals.

04

Right to data portability

You can receive your data in a structured format. Since your files never leave your device, they are already portable — you always have the original and processed copies.

05

Right to restrict processing

You can limit how your data is processed. Simply stop using the tool and close the tab. Processing ceases immediately — there is no background activity.

06

Right to object

You can object to processing at any time. Since all processing is local and initiated by you, you object by simply not using the tool. No opt-out forms needed.

Technical Safeguards

How we enforce data protection technically

Privacy policies are only as strong as the technology behind them. PDFly doesn't just promise privacy — the architecture makes data exfiltration technically impossible.

  • No network requests during file processing — verifiable in browser DevTools
  • WebAssembly sandbox isolates all PDF processing from the network layer
  • No cookies or localStorage for personal data — only a theme preference
  • No third-party scripts — no analytics, no ads, no trackers loaded
  • CSP headers restrict all outbound connections to the static asset CDN

Zero data architecture

Verified by design

0 Files uploaded
0 Tracking cookies
0 Third-party scripts
Verifiable in browser DevTools

Sub-processors & third parties

PDFly does not use any sub-processors. We do not share data with any third party because there is no data to share. Our static assets (HTML, CSS, JavaScript, WebAssembly modules) are served from a CDN, but no user data — ever — is transmitted to it.

We do not use analytics tools, advertising networks, error tracking services, or any other third-party service that could collect personal data. This is a deliberate architectural decision, not a configuration choice.

No Google Analytics No Facebook Pixel No Sentry No Hotjar No Cloudflare Analytics

Questions about data processing?

We're transparent about our zero-data architecture. Reach out anytime.