EU Data Protection

GDPR Compliant Document Conversion

Convert documents to Markdown while maintaining full GDPR compliance. Zero data retention, no consent fatigue, and privacy by design.

What GDPR Means for Document Conversion

The General Data Protection Regulation (GDPR) sets strict requirements for how organizations handle personal data of EU residents. When you convert a document containing names, addresses, financial information, or any other personal data, the service processing that file becomes a data processor under GDPR.

Most free online converters fail GDPR requirements because they:

  • Retain files for days or weeks ("storage limitation" violation)
  • Use data for AI training without consent ("purpose limitation" violation)
  • Transfer data to third-party services ("accountability" issues)
  • Have vague privacy policies ("transparency" violation)

Our approach is different. We've built our service from the ground up with GDPR principles at the core—not as an afterthought.

How We Meet GDPR Requirements

Point-by-point compliance with GDPR's data processing principles.

Lawfulness, fairness, and transparency

Processing must be lawful, fair, and transparent to the data subject.

We process files only for the conversion you request. Our privacy policy is clear and straightforward.

Purpose limitation

Data collected for specified, explicit purposes only.

Files are processed solely for conversion. No secondary uses, no analytics on content, no training.

Data minimization

Only collect data that is necessary for the purpose.

We receive only the file you upload. No account required, no personal data collection for basic use.

Accuracy

Personal data must be accurate and kept up to date.

We don't store personal data. Conversion output is faithful to your original document.

Storage limitation

Data kept only as long as necessary.

Files are deleted immediately after conversion. No retention period—data exists only during processing.

Integrity and confidentiality

Appropriate security measures must protect data.

TLS encryption in transit, isolated processing, and automated systems with no human access.

Privacy Features for GDPR Compliance

Technical and organizational measures that ensure compliance.

Zero Data Retention

Files are deleted immediately after conversion completes. No copies, backups, or logs of document content.

Encrypted Processing

All file transfers use TLS 1.3 encryption. Your documents are protected from upload to download.

No Tracking

No cookies tracking your document activity. We don't build profiles or track what you convert.

No Account Required

Convert files without providing personal information. No email, no name, no identity linking.

Transparent Policies

Clear, readable privacy policy that explains exactly what we do with your data (nothing).

Data Subject Rights

Your rights under GDPR are respected. Since we don't retain data, there's nothing to request or delete.

Warning: Most Free Converters Aren't GDPR Compliant

Before using any online converter for documents containing personal data, check:

  • Data retention: How long do they keep your files?
  • Sub-processors: Who else processes your data?
  • Data transfers: Is data sent outside the EU?
  • Purpose: Do they use files for AI training?
  • Privacy policy: Is it clear and specific?

If a converter is "free" but has vague privacy policies, your data is likely the product.

Who Needs GDPR-Compliant Conversion?

EU-Based Organizations

Any organization in the EU processing documents with personal data must use GDPR-compliant tools.

  • Customer records and contracts
  • Employee documents and HR files
  • Partner and vendor agreements

Global Companies with EU Data

GDPR applies to any organization processing data of EU residents, regardless of location.

  • US companies with EU customers
  • Remote teams with EU members
  • SaaS serving EU markets

Regulated Industries

Healthcare, finance, legal, and other regulated sectors face additional scrutiny.

  • Healthcare providers (GDPR + local health laws)
  • Financial services (GDPR + PSD2)
  • Law firms (GDPR + professional privilege)

Privacy-Conscious Individuals

Anyone who values their data rights and wants tools that respect privacy.

  • Personal documents and records
  • Financial statements and tax documents
  • Medical records and health data

GDPR Compliance FAQ

Do you require a DPA (Data Processing Agreement)?

For basic use, our zero-retention architecture means minimal data processing. For enterprise customers requiring formal DPAs, contact us to discuss your specific needs.

Where are your servers located?

Our processing infrastructure is designed with data minimization in mind. Since files exist only during the brief conversion window, data residency concerns are minimized.

How can I exercise my data subject rights?

Since we don't retain your files or personal data, there's typically nothing to access, rectify, or delete. Your data rights are protected through our design, not through processes you need to invoke.

Can I use this for documents containing sensitive personal data?

Yes. Our zero-retention architecture means sensitive data (health, financial, etc.) is processed only briefly and deleted immediately. However, always ensure you have proper legal basis for processing such data in the first place.

Do you use sub-processors?

Our core conversion processing uses our own infrastructure. We don't send your files to third-party conversion APIs. Standard cloud infrastructure may be used, but your document content is never retained or accessible.

Ready for GDPR-Compliant Conversion?

Convert documents with confidence. No account required, no data retained.