Privacy Policy
EasyPDF AI Kit Privacy Policy
Aura Digital B.V. operates EasyPDF AI Kit and is the controller of the personal data described in this policy. Effective date: 6 August 2026.
1. Introduction
Aura Digital B.V. operates EasyPDF AI Kit and is the controller of the personal data described in this policy. We process personal data in accordance with applicable data-protection law, including the EU General Data Protection Regulation and Dutch implementing legislation.
2. Personal Data We Collect
We collect personal data reasonably necessary to provide, secure, support, and administer the service.
2.1 Information You Provide
- Full name and email address.
- Billing address, country of residence, and tax-related information where required.
- Account preferences, subscription plan, support communications, and cancellation or refund requests.
- Uploaded documents, document text, prompts, selections, and other content you choose to process.
- Order, transaction, subscription, consent, and confirmation records.
2.2 Payment Information
Payments are handled by PCI-DSS compliant payment providers. We do not store full card numbers, CVV/CVC codes, or equivalent wallet credentials. We may receive transaction identifiers, card brand, last four digits, expiry information where permitted, authorization status, wallet type, billing country, risk signals, and chargeback or refund information needed to administer payments and disputes.
2.3 Automatically Collected Information
- IP address and approximate location derived from it.
- Browser, device, operating system, language, and technical identifiers.
- Pages and features used, timestamps, session duration, referral source, and diagnostic logs.
- Security, fraud, authentication, and payment-consent records.
3. How We Use Personal Data
- Create and manage accounts and subscriptions.
- Process trials, recurring payments, renewals, cancellations, refunds, billing corrections, and disputes.
- Deliver document-processing and AI-assisted functionality.
- Provide customer support and respond to rights requests.
- Authenticate users and prevent fraud, abuse, and unauthorized access.
- Monitor reliability, diagnose technical problems, and improve service performance.
- Comply with tax, accounting, consumer-protection, payment-network, and other legal obligations.
- Send transactional communications, including purchase confirmations, trial-conversion reminders, renewal or cancellation confirmations, security notices, and material policy changes.
We do not sell personal data.
3.1 Marketing Communications
We send marketing or promotional communications only where permitted by a valid legal basis, such as consent. You may opt out at any time using the unsubscribe link or by contacting us. Opting out of marketing does not stop essential service, security, billing, or subscription communications.
4. AI and Document Processing
Uploaded document content is processed to perform the action you request, such as editing, converting, compressing, extracting, or summarizing. Depending on the feature, processing may involve third-party infrastructure or AI service providers acting under contractual data-protection and confidentiality obligations.
Unless you separately opt in, we do not use uploaded document content to train or improve general-purpose underlying AI models. We may use de-identified operational information, error signals, or aggregated statistics to improve service reliability, provided they do not identify you or reconstruct your content.
You should avoid uploading sensitive or special-category personal data unless necessary and lawful. Where uploaded files contain personal data relating to other people, you are responsible for having an appropriate basis to process and submit that information.
5. Legal Bases
- Contractual necessity: to provide the service, manage accounts, and administer subscriptions.
- Legal obligation: to comply with tax, accounting, consumer-protection, law-enforcement, and regulatory requirements.
- Legitimate interests: to secure the service, prevent fraud, resolve disputes, improve reliability, and protect legal rights, balanced against your interests and rights.
- Consent: for optional marketing, non-essential storage technologies, model-improvement participation, or other processing where consent is required.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including:
- Account and subscription data for the active relationship and a limited period afterward to handle reactivation, support, security, and legal claims.
- Payment, invoice, and tax records for periods required by applicable accounting and tax law, commonly up to seven years in the Netherlands.
- Recurring-payment consent, confirmation, cancellation, refund, and dispute evidence for as long as reasonably necessary to manage a claim, chargeback, or regulatory inquiry.
- Uploaded files and generated outputs for the period stated in the product interface or reasonably necessary to complete the requested operation, provide retrieval where offered, secure the service, and resolve support issues. Files should be deleted or anonymized when no longer needed.
- Security and diagnostic logs for a limited period proportionate to fraud-prevention, reliability, and legal needs.
When retention is no longer required, we delete, aggregate, or anonymize the data.
8. Security
- TLS encryption in transit.
- Access controls and least-privilege practices.
- PCI-DSS compliant payment processing.
- Secure hosting, logging, monitoring, and vulnerability-management practices.
- Organizational controls and contractual protections for service providers.
No system is completely secure. If a personal-data breach creates a risk to individuals, we will take the notification and remediation steps required by applicable law.
10. International Transfers
Where personal data is transferred outside the EU/EEA, we use a lawful transfer mechanism and appropriate safeguards, such as an adequacy decision, the European Commission's Standard Contractual Clauses, and supplementary measures where appropriate. You may request information about applicable safeguards by contacting us.
11. Your Rights
- Access personal data held about you.
- Correct inaccurate or incomplete data.
- Request deletion where applicable.
- Restrict or object to certain processing.
- Receive portable data where the right applies.
- Withdraw consent at any time for future processing based on consent.
- Lodge a complaint with a competent supervisory authority.
To exercise a right, email help@easypdfaikit.com from the address associated with your account or provide information reasonably needed to verify your identity. We normally respond within one month, subject to lawful extensions for complex or multiple requests.
In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens. You may also contact the authority in your EU/EEA country of residence or work.
12. Automated Decision-Making
We do not use personal data to make solely automated decisions producing legal or similarly significant effects about you. Automated fraud and security signals may be used to flag transactions or accounts for review. Where applicable law provides a right to human review, you may contact support.
13. Children
The service is not directed to anyone under 18, and we do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data.
14. Changes to This Policy
We may update this Privacy Policy for legal, security, technical, or operational reasons. The revised version will display an updated effective date. Where a change is material, we will take reasonable steps to notify affected users and obtain consent where required.
15. Contact
Company: Aura Digital B.V.
Registration Number: 53180712
Registered Address: De Entree 201, 1101 HG Amsterdam, The Netherlands
Email: help@easypdfaikit.com
Phone: +31 970 1020 6459
Website: https://easypdfaikit.com