LegalPrivacy Policy
Legal Document

Privacy Policy

This Privacy Policy explains how PDFFillr collects, uses, stores, and protects your information. It applies to all individuals who create an account or otherwise use the Application.

Last Updated: 11 February 2026Jersey City, NJ, United StatesEngineersmind Corp

Your Data, Your Control

PDFFillr does not sell your personal information. Your documents are processed solely to provide the Service and are never used to train AI models. Questions? Contact us at Support@pdffillr.ai

01

Introduction & Scope

This Privacy Policy explains how PDFFillr, operated by Engineersmind Corp, collects, uses, stores, and protects information. The Application is operated from Jersey City, United States.

PDFFillr is a browser-based AI solution designed to perform automated document analysis using content provided by users. This Policy applies to all individuals who create an account or otherwise use the Application.

02

Definitions

The following terms are used throughout this Privacy Policy:

2.1 Company

Engineersmind Corp, the legal entity operating and maintaining the Service.

2.2 Service

The web-based application operated by the Company, including its UI, backend services, and supporting infrastructure.

2.3 User

Any individual who creates an account or otherwise accesses or uses the Service.

2.4 Account

The registered profile created by a User to access and use the Service.

2.5 Account Information

Information provided during account registration, such as name, email address, and login credentials.

2.6 User Content / Documents

Any documents, files, data, or information uploaded, submitted, or generated by a User through use of the Service.

2.7 Personal Data

Any information relating to an identified or identifiable User collected or processed in connection with the Service.

2.8 Processing

Any operation performed on Personal Data or User Content, including collection, storage, use, modification, and deletion.

2.9 Third-Party Services

External services or providers integrated into the Service for authentication, hosting, analytics, or security.

2.10 Security Incident

Any confirmed unauthorized access, disclosure, alteration, or destruction of Personal Data or User Content.

2.11 Retention Period

The period for which Personal Data or User Content is retained by the Company.

2.12 Connected Accounts

Third-party accounts voluntarily connected by the User, including Google Drive, Dropbox, and Microsoft OneDrive.

03

Data Controller & Contact

The User (or the organization on whose behalf the User acts) is the Data Controller for any personal data submitted through the Service. The Company acts as a Data Processor and processes personal data solely for the purpose of providing the Services.

04

Categories of Data Collected

4.1 — Account Information

Name, email address, authentication credentials, and login-related metadata.

4.2 — Documents and File Metadata

Uploaded documents, generated PDFs, file names, sizes, timestamps, and processing metadata. Documents may contain sensitive categories of personal data including health information, financial data, and government-issued identification.

4.3 — Usage and Technical Data

Logs, timestamps, error reports, IP addresses, and other technical data. Operational logs are retained for up to 90 days unless a longer period is required for security investigation.

4.4 — Integration and Authorization Data

OAuth tokens, access scopes, and identifiers associated with Connected Accounts.
05

Methods of Data Collection

Information is collected:

  • Directly from Users when they create accounts, upload documents, or provide inputs;
  • From Connected Accounts when Users authorize access to selected files;
  • Automatically through Application operation, logging, and security monitoring.
06

Cloud Storage Integrations

The Service enables Users to import documents from third-party cloud storage providers. Access is initiated exclusively by the User and is limited to the specific document explicitly referenced.

6.1 — Google Drive

Access is limited to user-selected files. No full-drive, contacts, email, or unrelated Google account data is accessed. Authentication is handled directly by Google.

6.2 — Dropbox

Access is limited to specific files explicitly selected or linked by the User. No continuous or unrestricted Dropbox access is requested. Credentials are not stored by the Service.

6.3 — Microsoft OneDrive

Access is limited to user-selected files provided via a OneDrive link. No email, calendar, contacts, or other Microsoft account data is accessed. Authentication is managed by Microsoft.
07

Purpose of Data Use & Legal Basis

The Company processes personal data for the following purposes and on the following legal bases under GDPR Article 6:

PurposeLegal Basis (GDPR Art. 6)
Providing core Service functionality (document analysis, PDF generation)Performance of a contract (Art. 6(1)(b))
Account management and authenticationPerformance of a contract (Art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f))
System performance and operational loggingLegitimate interests (Art. 6(1)(f))
Support and quality assuranceLegitimate interests (Art. 6(1)(f))
Legal compliance obligationsLegal obligation (Art. 6(1)(c))
08

AI Processing & Human Review

The Application uses automated AI systems including large language models to process documents.

User data is not used to train AI models. AI processing occurs solely to deliver the Service in response to explicit User actions.

Human Review: Documents may also be reviewed by authorized Company personnel for support, quality assurance, or security purposes. Such personnel are bound by confidentiality obligations. Human review is conducted only on an exceptional basis — for example, to investigate a support request or security incident — and is not a routine process. Users may contact Support@pdffillr.ai to request further information.

09

Data Sharing & Third-Party Processors

We do not sell personal information.

Information may be shared with third-party processors solely as necessary to operate the Service, including:

  • Cloud infrastructure providers (e.g., AWS)
  • AI service providers (e.g., AWS Bedrock)
  • Authentication service providers

A full sub-processor list is available upon request at Support@pdffillr.ai.

10

Data Storage, Retention & Deletion

User data is stored on secure cloud infrastructure. Documents and generated outputs explicitly saved by the User are retained for the duration of the active account. Upon deletion:

  • Data is removed from active systems within 30 days;
  • Data may persist in encrypted backups for up to 90 days, after which it is overwritten in the ordinary course of backup rotation.

Operational logs are retained for up to 90 days for security and troubleshooting purposes.

11

Security Measures

The Company implements appropriate administrative, technical, and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest;
  • Role-based access controls limiting data access to authorized personnel only;
  • Internal data minimization practices to limit the scope of data collected and processed.
12

User Rights & Choices

In accordance with applicable law, Users may exercise the following rights. All requests will be responded to within 30 days and may be submitted through the Application or by emailing Support@pdffillr.ai.

RightDescriptionHow to Request
AccessObtain a copy of your personal dataSupport@pdffillr.ai
CorrectionCorrect inaccurate personal dataIn-app or Support@pdffillr.ai
DeletionDelete your personal data and accountIn-app or Support@pdffillr.ai
Portability (GDPR)Receive your data in a structured, machine-readable formatSupport@pdffillr.ai
Restriction (GDPR)Restrict processing in certain circumstancesSupport@pdffillr.ai
Objection (GDPR)Object to processing based on legitimate interestsSupport@pdffillr.ai
Opt-out of sale (CCPA)We do not sell personal dataN/A
13

International Data Transfers

The Company is based in the United States. Where personal data of EU or UK individuals is transferred outside the EEA, the Company relies on Standard Contractual Clauses (SCCs) as the legal transfer mechanism in accordance with GDPR Chapter V. For further information or to obtain a copy of applicable SCCs, contact Support@pdffillr.ai.

14

Cookies & Tracking

The Application uses the following categories of cookies:

CategoryPurposeConsent Required
Strictly NecessaryAuthentication, session management, securityNo
FunctionalSaving user preferencesNo
AnalyticsService performance and usage statisticsYes (GDPR)

Users may manage cookie preferences through their browser settings or the in-app cookie consent banner.

15

Data Breach Notification

In the event of a Security Incident, the Company will:

  • Notify relevant supervisory authorities within 72 hours of becoming aware of the incident, where required by GDPR;
  • Notify affected Users without undue delay where the incident is likely to result in a high risk to their rights and freedoms;
  • Provide information on the nature of the incident, data affected, likely consequences, and measures taken.

Notifications will be sent to the email address associated with your account. Ensure your account email is kept current.

16

Children's Privacy

The Application is not intended for use by children under 18. The Company does not knowingly collect personal data from minors.

17

Updates to This Policy

The Company may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification with at least 30 days' advance notice before changes take effect.

Last Updated11 Feb 2026
Privacy ContactSupport@pdffillr.ai
Data ProcessorEngineersmind Corp
PDFFILLR.AI logo

PDFFILLR.AI

The intelligent layer for modern fund
administration. Automating high-stakes
documentation with precision and speed.

Powered byEngineersMind