Data Processing Addendum
Last updated: September 2026
This Addendum forms part of the Terms of Service and applies where FileAlloy processes personal data on your behalf under the EU General Data Protection Regulation (GDPR).
1. Roles
For any personal data contained in the files or content you submit to the API, you are the data controller and FileAlloy is the data processor. You are responsible for having a lawful basis for the processing you ask us to perform.
2. Subject matter, duration, nature and purpose
We process the content you send to the API solely to perform the operation you request (for example: compress, convert, merge, split, secure, or OCR a document) and to return the result. Processing lasts only for the duration of each request. We do this for as long as you use the service.
3. Types of data and data subjects
The personal data processed is whatever you choose to include in the files or content you submit, and the data subjects are the individuals to whom that content relates. You determine both; we do not select or control the content of your files.
4. Our obligations as processor
- We process personal data only on your documented instructions, which are the API requests you make (and these terms), unless required by law.
- We keep the data confidential and ensure that anyone authorised to process it is bound by confidentiality.
- We implement appropriate technical and organisational security measures (Article 32). Files are processed in an isolated, temporary workspace and are not written to permanent storage; they are destroyed as soon as the response is returned.
- We assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your security, breach notification, and impact assessment obligations.
- On termination we delete or return personal data; because we do not retain the files you process, there is nothing to return or delete beyond your account data (see the Privacy Policy).
- We make available the information reasonably necessary to demonstrate compliance with this Addendum.
5. Sub-processors
You authorise us to engage sub-processors to provide the service. Current sub-processors are: Supabase (account authentication and database, hosted in the EU), Railway (API hosting, EU region), Cloudflare (content delivery, DNS, and DDoS protection), Stripe (payment processing for paid plans), and Resend (transactional and sign in email). We will give reasonable notice of any new sub-processor so you can object.
6. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.
7. International transfers
Where personal data is transferred outside the EEA (for example to Stripe), the transfer is covered by an adequacy decision or Standard Contractual Clauses.
8. General
This Addendum does not replace any statutory data protection rights. In case of conflict between this Addendum and the Terms of Service on data protection matters, this Addendum prevails.
9. Contact
Data protection questions or requests: support@filealloy.com.