Data Processing Agreement

Last modified: June 17, 2026.

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between MB Tech256 ("we", "our" or "us") and the customer using the Services ("Customer", "you" or "your").

This DPA applies where MB Tech256 processes personal data in Customer Content on behalf of Customer as a processor under the GDPR or similar data protection laws. It does not apply to personal data MB Tech256 processes as a controller, which is covered by our Privacy Policy.

Definitions

"Applicable Data Protection Laws" means the GDPR, ePrivacy rules and other privacy or data protection laws that apply to the processing of Customer Personal Data.

"Customer Personal Data" means personal data contained in Customer Content that MB Tech256 processes on behalf of Customer through the Services.

"GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.

"Services" has the meaning given in the Terms of Service and includes html2pdf.app, dash.html2pdf.app, the API, the playground, documentation, conversion tools, templates, plugins and related support services.

Roles and Scope

Customer is the controller or processor, as applicable, of Customer Personal Data. MB Tech256 is a processor or subprocessor of Customer Personal Data. Customer is responsible for ensuring that it has all notices, consents, rights, instructions and legal bases required for MB Tech256 to process Customer Personal Data under this DPA.

The subject matter, duration, nature, purpose, categories of data subjects and categories of personal data are described in Annex 1 below.

Customer Instructions

Customer instructs MB Tech256 to process Customer Personal Data only as necessary to provide, secure, maintain and support the Services, comply with Customer's documented instructions, comply with applicable law and perform the agreement between the parties.

The Terms, this DPA, Customer's use and configuration of the Services, API requests, support requests and written instructions sent to MB Tech256 are Customer's documented instructions. MB Tech256 will notify Customer if it believes an instruction violates Applicable Data Protection Laws, unless prohibited by law.

MB Tech256 Obligations

MB Tech256 will:

  • process Customer Personal Data only on documented instructions from Customer, unless required by law;
  • ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations;
  • implement appropriate technical and organizational measures designed to protect Customer Personal Data;
  • assist Customer, taking into account the nature of the processing and information available to MB Tech256, with data subject requests, security obligations, data protection impact assessments and consultations with supervisory authorities where required by Applicable Data Protection Laws;
  • notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data;
  • at Customer's choice and subject to the Terms, delete or return Customer Personal Data after the Services end, unless retention is required by law; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

Customer Obligations

Customer will:

  • comply with Applicable Data Protection Laws in its use of the Services;
  • provide all required privacy notices and obtain all required consents or other legal bases for processing Customer Personal Data;
  • ensure Customer Personal Data is accurate, lawful and limited to what is necessary for Customer's use of the Services;
  • avoid submitting special category data, payment card data or other highly sensitive data unless lawful, necessary and protected by appropriate safeguards; and
  • maintain the security of its accounts, users, API keys, tokens and integrations.

Security Measures

MB Tech256 maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These measures include the controls described in Annex 2.

Customer acknowledges that security measures may evolve over time as long as the overall level of protection is not materially reduced.

Subprocessors

Customer grants MB Tech256 general authorization to engage subprocessors to process Customer Personal Data for the Services. MB Tech256 will use reasonable diligence when selecting subprocessors and will enter into written terms requiring subprocessors to protect Customer Personal Data in a manner consistent with this DPA.

Current subprocessors and other service providers are listed in Annex 3. MB Tech256 may update that list from time to time. If Customer objects to a new subprocessor on reasonable data protection grounds, Customer may contact MB Tech256 at ppa.fdp2lmth@ofni and the parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may stop using the affected Services.

International Transfers

At this time, Customer Content, API conversion processing and generated PDF processing are handled on servers located in the European Union. Generated PDF documents are processed only temporarily during runtime and are deleted immediately after document generation is completed.

Customer authorizes MB Tech256 and its subprocessors to process Customer Personal Data in other countries if needed to provide the Services in the future, subject to Applicable Data Protection Laws. Where Customer Personal Data is transferred outside the European Economic Area or another jurisdiction with transfer restrictions, MB Tech256 will rely on a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses or another mechanism recognized by Applicable Data Protection Laws.

Data Subject Requests

If MB Tech256 receives a request from a data subject relating to Customer Personal Data, MB Tech256 may direct the requester to Customer unless otherwise required by law. Taking into account the nature of the processing and information available to MB Tech256, MB Tech256 will provide reasonable assistance to Customer in responding to data subject requests.

Personal Data Breaches

MB Tech256 will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to MB Tech256 to help Customer meet its own legal obligations. MB Tech256's notification or response to a breach is not an admission of fault or liability.

Audits and Information

Upon reasonable written request, MB Tech256 will provide information reasonably necessary to demonstrate compliance with this DPA. Any audit must be conducted during normal business hours, with reasonable notice, no more than once in any twelve (12) month period unless required by a supervisory authority or following a confirmed personal data breach, and in a manner that does not compromise security, confidentiality or availability of the Services or other customers' data.

Deletion and Return

On termination of the Services, MB Tech256 will delete or return Customer Personal Data in accordance with the Terms, the Services' functionality and applicable retention periods, unless continued retention is required by law. Generated PDF documents are processed only temporarily during runtime and are deleted immediately after document generation is completed; they are not permanently stored as service deliverables on MB Tech256 servers. Some retained logs, metadata or security records may remain temporarily in backups, logs or security systems until deleted through ordinary retention cycles.

Order of Precedence

If there is a conflict between this DPA and the Terms, this DPA controls for the processing of Customer Personal Data. If the parties sign a separate data processing agreement, that signed agreement controls over this online DPA to the extent of any conflict.

Annex 1: Processing Details

Annex 2: Security Measures

  • Transport encryption for data transmitted to and from the Services.
  • Access controls designed to limit access to authorized personnel and contractors who need access for service operation, support, security or maintenance.
  • Credential and API key controls, including customer responsibility for protecting account credentials and API keys.
  • Logging, monitoring and error tracking to support security, debugging, abuse prevention and service reliability.
  • Network security, traffic filtering, bot management, DDoS protection and service availability controls where infrastructure providers are used for these purposes.
  • Backup, retention and deletion practices designed to support availability and ordinary deletion cycles.
  • Confidentiality obligations for personnel with access to personal data.
  • Use of service providers under contractual terms intended to protect personal data.
  • Incident response practices for investigating and responding to suspected security events.

Annex 3: Subprocessors and Service Providers

Subprocessors for Customer Personal Data

The following providers may process Customer Personal Data depending on how the Services are deployed, routed, monitored or used by Customer.

Other Operational Providers

The following providers are used for account, billing, analytics, support or marketing operations. They may act as processors or independent controllers depending on the activity and their own terms.

Some providers may act as independent controllers for parts of their processing, such as payment processing, fraud prevention, analytics or security. Those activities are also described in the Privacy Policy where relevant.

Contact

Questions about this DPA may be sent to ppa.fdp2lmth@ofni.