This policy explains how PDF Accessibility Check ("we", "us") handles personal data when you use pdfchecks.com. It is written to reflect what the service actually does. It is general information about our practices, not legal advice.
Who we are
The data controller for this website is [YOUR REGISTERED NAME / TRADING NAME], [YOUR TRADING ADDRESS], United Kingdom. You can contact us about privacy at lukeramsdale01@gmail.com. [If registered with the ICO: our registration number is [ICO NUMBER].]
The short version
- The instant pre-check runs entirely in your browser — those files are never uploaded to us.
- If you choose the full audit, your file is uploaded, analysed, and deleted as soon as analysis completes. We keep only the results, a fingerprint (hash), and the file name.
- We do not use cookies and store nothing in your browser.
- We do not sell your data, do not use it to train AI models, and do not build advertising profiles.
- Our servers are in the European Union (Frankfurt, Germany).
What we process, and why
Documents you upload for a full audit
When you run a full audit, your PDF is uploaded over an encrypted connection to our EU servers, checked against the PDF/UA standard, and then deleted immediately once analysis finishes. We retain only: the accessibility results (scores and issues), a SHA-256 hash of the file (so a report can be tied to the exact document analysed), and the file name you provided.
Your uploaded documents may contain personal data — potentially including special category data (for example health or financial information). In respect of the content of those documents, you are the data controller and we act as your processor, processing them only to provide the checking service you requested. Please do not upload documents containing sensitive personal data unless it is necessary for the check. Our lawful basis for processing your file is the performance of the service you asked for.
Technical and usage data
Like any website, we and our infrastructure providers process limited technical data — such as your IP address and basic request information — to deliver the service, keep it secure, and prevent abuse (for example rate-limiting). Our lawful basis is our legitimate interest in operating a secure, functioning service.
Analytics
We use Cloudflare Web Analytics, which is privacy-first and cookieless. It measures aggregate traffic and performance without cookies, without cross-site tracking, and without building a profile of you.
Payments
If you buy a report, payment is handled by Stripe. You are redirected to Stripe's secure checkout; we never receive or store your full card details. Stripe processes your payment data as a controller under its own privacy policy.
Contacting us
If you email us, we process your email address and message to respond to you.
How long we keep data
- Uploaded files: deleted as soon as analysis completes.
- Analysis results, hash and file name: retained only for as long as needed to provide the service, and deleted on request.
- Server and security logs: retained for a limited period by our infrastructure providers for security and diagnostics.
Where your data is processed
Our application and database run in the European Union (Frankfurt). We use the following processors, each of which provides appropriate safeguards for any data processing, including standard contractual clauses and/or the EU–US Data Privacy Framework where a provider is US-owned:
- Google Cloud (Cloud Run) — application hosting, EU region.
- Neon — database, EU (Frankfurt) region.
- Cloudflare — content delivery, security and cookieless analytics.
- Stripe — payment processing.
Your rights
Under UK GDPR / EU GDPR you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. To exercise any of these, email lukeramsdale01@gmail.com. Because we delete uploaded files on completion and retain very little, there is usually little personal data for us to hold. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national data protection authority.
Changes
We may update this policy; the effective date above shows the current version.