PaperWorksPDF
Privacy

Privacy policy

How PaperWorksPDF handles documents and personal data, written to follow India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, together with the Information Technology Act, 2000 and its rules.

Last updated: 30 July 2026

  • DPDP Act 2023 aligned
  • Files processed in your browser
  • Clear data principal rights
  • Grievance officer in India
1

Who we are and what this notice covers

PaperWorksPDF operates the paperworkspdf.com website and its PDF, document and text tools. For the limited personal data we determine the purpose and means of processing, we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023, and you are the Data Principal.

This notice is provided in clear and plain language as required by Section 5 of the DPDP Act. On request, it can be made available in English and in the languages listed in the Eighth Schedule to the Constitution of India through the language selector on this site.

2

Files you process — no upload by default

PDF editing, conversion, compression, OCR, organisation and security tools run inside your browser using your device's processor and memory. Your document content is not transmitted to us for these tools, and we neither read nor store it.

The only exception is the optional 'send for signature' feature. If you choose it, the document you select is stored in encrypted cloud storage solely to deliver it to the recipient link you generate, and it is deleted after the request expires.

5

Your rights as a data principal

You have the right to obtain a summary of the personal data being processed and the processing activities undertaken, the right to correction, completion, updating and erasure, the right to nominate another individual to exercise your rights in the event of death or incapacity, and the right to readily available grievance redressal.

To exercise any right, email the grievance officer using the address on the contact page with enough detail to identify your request. We acknowledge requests within a reasonable period and ordinarily respond within thirty days. If you are not satisfied, you may approach the Data Protection Board of India.

6

Retention, deletion and security safeguards

Personal data is retained only for as long as the stated purpose requires or as long as an applicable law requires. Signature request documents and metadata are erased after the request expires; support correspondence is retained only as long as needed to resolve and evidence the matter.

We apply reasonable security safeguards, including encryption in transit, encryption at rest for stored signature documents, access controls and least-privilege service credentials, to prevent a personal data breach. In the event of a breach we will notify affected data principals and the Data Protection Board of India as required by the DPDP Rules, and report reportable cyber incidents to CERT-In within six hours as required by the CERT-In Directions dated 28 April 2022.

Work in progress lives in your active browser tab's memory. Download finished files before closing the tab, refreshing, clearing browser data or switching devices — a closed session cannot be recovered.

7

Sharing, processors and cross-border transfer

We do not sell personal data and we do not share it for advertising. Limited processing is carried out by hosting, storage and infrastructure providers engaged under contract as Data Processors, strictly on our instructions.

Personal data may be processed on servers located outside India in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government. Logs required by the CERT-In Directions are maintained for a rolling period of one hundred and eighty days and, where required, within Indian jurisdiction.

8

Grievance redressal

A Grievance Officer is designated under Section 13 of the DPDP Act and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Contact details are published on the contact page.

Complaints are acknowledged within twenty-four hours and resolved within fifteen days of receipt, and information related to unlawful content covered by Rule 3(2)(b) is acted upon within twenty-four hours. Please do not include confidential document contents in a first message.

9

Changes to this policy

Material changes to purposes, retention or your rights will be reflected here before they take effect. Continued use after an update means you have had the opportunity to review it; consent-based processing is not extended to a new purpose without fresh consent.

Need to work on a PDF now?

Open the editor or browse every PDF and text tool from the dashboard — everything runs right in your browser.