Last modified: June 17, 2026.
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between MB Tech256 ("we", "our" or "us") and the customer using the Services ("Customer", "you" or "your").
This DPA applies where MB Tech256 processes personal data in Customer Content on behalf of Customer as a processor under the GDPR or similar data protection laws. It does not apply to personal data MB Tech256 processes as a controller, which is covered by our Privacy Policy.
"Applicable Data Protection Laws" means the GDPR, ePrivacy rules and other privacy or data protection laws that apply to the processing of Customer Personal Data.
"Customer Personal Data" means personal data contained in Customer Content that MB Tech256 processes on behalf of Customer through the Services.
"GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.
"Services" has the meaning given in the Terms of Service and includes html2pdf.app, dash.html2pdf.app, the API, the playground, documentation, conversion tools, templates, plugins and related support services.
Customer is the controller or processor, as applicable, of Customer Personal Data. MB Tech256 is a processor or subprocessor of Customer Personal Data. Customer is responsible for ensuring that it has all notices, consents, rights, instructions and legal bases required for MB Tech256 to process Customer Personal Data under this DPA.
The subject matter, duration, nature, purpose, categories of data subjects and categories of personal data are described in Annex 1 below.
Customer instructs MB Tech256 to process Customer Personal Data only as necessary to provide, secure, maintain and support the Services, comply with Customer's documented instructions, comply with applicable law and perform the agreement between the parties.
The Terms, this DPA, Customer's use and configuration of the Services, API requests, support requests and written instructions sent to MB Tech256 are Customer's documented instructions. MB Tech256 will notify Customer if it believes an instruction violates Applicable Data Protection Laws, unless prohibited by law.
MB Tech256 will:
Customer will:
MB Tech256 maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include the controls described in Annex 2.
Customer acknowledges that security measures may evolve over time as long as the overall level of protection is not materially reduced.
Customer grants MB Tech256 general authorization to engage subprocessors to process Customer Personal Data for the Services. MB Tech256 will use reasonable diligence when selecting subprocessors and will enter into written terms requiring subprocessors to protect Customer Personal Data in a manner consistent with this DPA.
Current subprocessors and other service providers are listed in Annex 3. MB Tech256 may update that list from time to time. If Customer objects to a new subprocessor on reasonable data protection grounds, Customer may contact MB Tech256 at ppa.fdp2lmth@ofni and the parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may stop using the affected Services.
At this time, Customer Content, API conversion processing and generated PDF processing are handled on servers located in the European Union. Generated PDF documents are processed only temporarily during runtime and are deleted immediately after document generation is completed.
Customer authorizes MB Tech256 and its subprocessors to process Customer Personal Data in other countries if needed to provide the Services in the future, subject to Applicable Data Protection Laws. Where Customer Personal Data is transferred outside the European Economic Area or another jurisdiction with transfer restrictions, MB Tech256 will rely on a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses or another mechanism recognized by Applicable Data Protection Laws.
If MB Tech256 receives a request from a data subject relating to Customer Personal Data, MB Tech256 may direct the requester to Customer unless otherwise required by law. Taking into account the nature of the processing and information available to MB Tech256, MB Tech256 will provide reasonable assistance to Customer in responding to data subject requests.
MB Tech256 will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to MB Tech256 to help Customer meet its own legal obligations. MB Tech256's notification or response to a breach is not an admission of fault or liability.
Upon reasonable written request, MB Tech256 will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must be conducted during normal business hours, with reasonable notice, no more than once in any twelve (12) month period unless required by a supervisory authority or following a confirmed personal data breach, and in a manner that does not compromise security, confidentiality or availability of the Services or other customers' data.
On termination of the Services, MB Tech256 will delete or return Customer Personal Data in accordance with the Terms, the Services' functionality and applicable retention periods, unless continued retention is required by law. Generated PDF documents are processed only temporarily during runtime and are deleted immediately after document generation is completed; they are not permanently stored as service deliverables on MB Tech256 servers. Some retained logs, metadata or security records may remain temporarily in backups, logs or security systems until deleted through ordinary retention cycles.
If there is a conflict between this DPA and the Terms, this DPA controls for the processing of Customer Personal Data. If the parties sign a separate data processing agreement, that signed agreement controls over this online DPA to the extent of any conflict.
| Subject matter | Processing Customer Personal Data submitted to or generated by the Services for HTML-to-PDF conversion and related service functionality. |
|---|---|
| Duration | For the term of Customer's use of the Services and for applicable deletion, backup, log, legal and dispute retention periods. Generated PDF documents are processed only during runtime and deleted immediately after document generation is completed. Selected conversion logs and metadata may be retained as described in the Privacy Policy. |
| Nature and purpose | Receiving, hosting, transmitting, converting, generating PDF documents temporarily during runtime, deleting generated PDF documents immediately after generation, logging selected conversion parameters and metadata, securing, troubleshooting and supporting Customer Content and service operation. |
| Processing frequency | Continuous or occasional, depending on Customer's use of the Services. |
| Categories of data subjects | Customer's users, employees, contractors, clients, end users, document recipients and other individuals whose personal data Customer includes in Customer Content. |
| Categories of personal data | Personal data included in HTML, URLs, templates, files, API requests, generated PDFs during runtime, metadata, logs and support requests. If the html parameter contains a URL value, that URL may be stored in conversion logs. If the html parameter contains raw HTML or text, MB Tech256 does not store that raw HTML or text value in conversion logs. The exact categories depend on Customer's use of the Services. |
| Sensitive data | The Services are not designed for special category data, payment card data or other highly sensitive data. Customer is responsible for ensuring that any such data is submitted only where lawful, necessary and protected by appropriate safeguards. |
The following providers may process Customer Personal Data depending on how the Services are deployed, routed, monitored or used by Customer.
| Provider | Purpose | Data categories |
|---|---|---|
| Cloudflare | DNS, CDN, traffic proxying, WAF, bot management, DDoS protection and service availability. | IP addresses, request headers, traffic metadata, security logs and request or response data where traffic passes through Cloudflare. |
| Amazon Web Services | Cloud infrastructure, storage, hosting or supporting cloud services used to provide the Services. | Customer Content, temporary generated PDF documents during runtime, account and service data, technical logs and metadata where AWS services are used. |
| Railway | Hosting, deployment and runtime infrastructure for client-facing service components. | Customer Content, API requests, generated file metadata, technical logs and service metadata, depending on the component hosted by Railway. |
| Hetzner and Interneto vizija (iv.lt) | Server hosting, infrastructure, backups and service operation. | Customer Content, account and service data, technical data, backups and logs. |
| Sentry | Error monitoring and debugging. | Technical logs, error data, device data and limited request metadata. Customer Content may be processed if included in an error report or support context. |
| Mailgun | Transactional email delivery. | Email addresses, email content, delivery metadata and related account or service information. |
The following providers are used for account, billing, analytics, support or marketing operations. They may act as processors or independent controllers depending on the activity and their own terms.
| Provider | Purpose | Data categories |
|---|---|---|
| Stripe | Payment processing, billing and fraud prevention. | Account, billing, payment reference and transaction data. |
| Google Analytics | Optional analytics where consent is provided. | Usage, device, browser, cookie and analytics data. |
| Crisp | Optional support chat on html2pdf.app and dash.html2pdf.app. | Contact details, support messages, chat metadata and device data. |
| MailerLite | Marketing emails and related subscription management. | Contact details, subscription status and email engagement data. |
Some providers may act as independent controllers for parts of their processing, such as payment processing, fraud prevention, analytics or security. Those activities are also described in the Privacy Policy where relevant.
Questions about this DPA may be sent to ppa.fdp2lmth@ofni.