Privacy Policy

Last modified: June 17, 2026.

This Privacy Policy explains how MB Tech256 ("we", "our" or "us") collects, uses, shares and protects personal data when you use html2pdf.app, the dashboard at dash.html2pdf.app, the playground at playground.html2pdf.app, the API, documentation, conversion tools, templates, plugins and related support services (collectively, the "Services").

MB Tech256 is established in Lithuania. For personal data we process as a controller, you can contact us at ppa.fdp2lmth@ofni. This Privacy Policy should be read together with our Terms of Service, Cookie Policy and, where applicable, our Data Processing Agreement.

Our Role

We act as a controller for account, billing, Website, analytics, support, marketing, security and business administration data that we decide how to process.

We act as a processor where a customer submits personal data in HTML, URLs, templates, files, API requests or generated documents for us to process on the customer's behalf. In that case, the customer is responsible for its own privacy notices, legal bases and instructions, and our Data Processing Agreement applies unless a separate agreement has been signed.

Personal Data We Collect

Depending on how you use the Services, we may collect and process the following categories of personal data:

  • Account and contact data, such as name, company name, email address, country, address, VAT number and account preferences.
  • Authentication and service data, such as API keys, dashboard session information, account status, plan, quota, usage limits and security events.
  • Billing and transaction data, such as subscription, order, invoice, payment status, tax and Stripe payment reference information. We do not store full payment card numbers.
  • Customer Content and conversion data, such as templates, files, generation settings, source URLs used for conversion logs, generated PDFs processed only during runtime and related metadata submitted to or produced by the Services. We do not store raw HTML or text content submitted in the html parameter.
  • API and technical data, such as IP address, browser type, device information, operating system, request timestamps, selected request parameters, URL and query parameters, HTML length, response status, error information and logs. For example, if the html parameter contains a URL used as the conversion source, we may store that URL in conversion logs for the customer. If the html parameter contains raw HTML or text, we do not store that raw HTML or text value in conversion logs.
  • Support and communication data, such as support messages, Crisp chat conversations, email correspondence and feedback.
  • Analytics, referral and cookie data, such as Google Analytics identifiers where you consent, cookie preference records and affiliate reference information.
  • Marketing data, such as newsletter preferences and communications about product updates where you subscribe or where we may lawfully contact you.

How We Collect Data

We collect personal data:

  • directly from you when you create an account, subscribe, contact support, use the dashboard, use the API or submit Customer Content;
  • automatically through servers, logs, cookies, local storage, session storage and similar technologies; and
  • from service providers such as Stripe, analytics, support, email and error monitoring providers where needed to operate the Services.

Purposes and Legal Bases

Customer Content

Customer Content may contain personal data controlled by our customers. We process that data to provide the Services, generate files, troubleshoot errors, protect security and comply with customer instructions. Generated PDF documents are stored only temporarily at runtime while document generation is taking place and are deleted immediately after document generation is completed. We do not permanently store generated PDF documents on our servers.

We may store selected conversion parameters and metadata to provide explicit conversion logs to customers. If the html parameter contains a URL value, we may store that URL as the source of the conversion. If the html parameter contains raw HTML or text, we do not store that raw HTML or text value in conversion logs. Customers should avoid submitting special category data, payment card data or other highly sensitive data unless they have a lawful basis and appropriate safeguards.

We do not use Customer Content to sell personal data. We do not intentionally inspect Customer Content except where needed to provide support, debug issues, prevent abuse, comply with law or protect the Services.

Cookies and Similar Technologies

We use necessary browser storage to operate the Services, including storing cookie choices and dashboard session authentication. We use optional Google Analytics and Crisp support technologies where consent is required and has been provided. We also use Cloudflare for traffic security and availability, which may involve necessary cookies or similar technologies, and an affiliate reference cookie when a URL contains an affiliate reference.

More information about cookies, local storage, session storage and third-party cookies is available in our Cookie Policy.

Service Providers and Recipients

We may share personal data with service providers and other recipients where needed to operate the Services, process payments, provide support, send emails, analyze usage, monitor errors, comply with law or protect rights. These providers include:

  • infrastructure, hosting and network security providers, including Cloudflare, Amazon Web Services, Railway, Hetzner and Interneto vizija (iv.lt);
  • Stripe for payment processing, billing support and fraud prevention;
  • Google Analytics for optional analytics on html2pdf.app, dash.html2pdf.app and playground.html2pdf.app;
  • Crisp for optional support chat on html2pdf.app and dash.html2pdf.app;
  • Sentry for error monitoring and debugging;
  • Mailgun for transactional email delivery;
  • MailerLite for marketing emails and related subscription management; and
  • professional advisers, authorities, courts or other parties where required by law or necessary to protect our rights.

Third-party websites and services linked from the Services are governed by their own terms and privacy notices.

International Transfers

We are based in the European Union. At this time, Customer Content, API conversion processing and generated PDF processing are handled on servers located in the European Union. Generated PDF documents are processed only temporarily during runtime and are deleted immediately after document generation is completed.

Some third-party providers used for billing, support, analytics, email, security or other operational purposes may process limited account, usage, payment, support or security data outside the European Economic Area. If we transfer personal data outside the European Economic Area in the future, we will rely on safeguards recognized by applicable data protection law, such as adequacy decisions, Standard Contractual Clauses or other lawful transfer mechanisms where required.

Retention

We keep personal data only for as long as reasonably needed for the purposes described in this Privacy Policy, including to provide the Services, maintain security, comply with tax and accounting obligations, resolve disputes and enforce agreements.

Unless a different period is required by law, agreement or technical configuration, we generally retain server logs and user/service records for up to twelve (12) months. Generated PDF documents are retained only during runtime while document generation happens and are deleted immediately after document generation is completed. Billing, tax and accounting records may be retained for longer where required by law.

Security

We use technical and organizational measures designed to protect personal data, including transport encryption, access controls, credential protection, logging, monitoring, backups and restrictions on access to personnel and contractors who need the information to provide, maintain or improve the Services.

No Internet service can be guaranteed to be completely secure. You are responsible for using strong account credentials, protecting API keys and limiting the personal data you submit to what is necessary for your use of the Services.

Your GDPR Rights

Subject to conditions and exceptions under applicable law, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request data portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a supervisory authority, including the State Data Protection Inspectorate in Lithuania (Valstybine duomenu apsaugos inspekcija) or your local EU/EEA supervisory authority.

To exercise rights for data we control, contact us at ppa.fdp2lmth@ofni. If your request relates to personal data contained in Customer Content, we may direct you to the relevant customer because we process that data on the customer's behalf.

Marketing Choices

You may opt out of marketing emails by using the unsubscribe link in the email or by contacting us. We may still send non-marketing service messages, such as account, security, billing and legal notices.

Children

The Services are not directed to children and should not be used by anyone under the age required to enter into a binding agreement or provide valid consent under applicable law.

No Automated Decisions

We do not use personal data for automated decision-making that produces legal or similarly significant effects about individuals.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised modification date. If changes are material, we may provide notice through the Website, dashboard or account contact information.

Contact

Questions about this Privacy Policy or our privacy practices may be sent to ppa.fdp2lmth@ofni.