BeyondPDF turns Excel rows into PDF documents. To do that we have to receive your file, and that file often holds other people's data — your trainees, your staff, your customers. This page explains what we do with it, how long we keep it, and what you can ask of us.
1. Who is responsible
The data controller for your account is the operator of BeyondPDF. For the contents of the files you upload, you are the controller and we process them on your instructions: we never use the contents of your documents for our own purposes.
2. What we collect
| Type | Contents | Why |
|---|---|---|
| Account | Name, email address, password (stored as a hash and not readable back), time zone | Running your account and counting your daily quota |
| Files you upload | Excel/CSV files and everything in them | Producing the PDFs you asked for |
| Output documents | The PDFs generated from your file | So you can download them |
| Transactions | Invoice number, amount, method, status, proof of transfer | Billing, verifying payments, and meeting financial record-keeping duties |
| Technical | IP address, browser type, timestamps of significant actions | Security, tracing abuse, and the audit trail |
We run no advertising, sell data to nobody, and install no third-party trackers.
3. How long we keep it
- Uploaded files and output documents are deleted automatically according to your plan: 1 day (Free), 7 days (Pro), 30 days (Pro Plus), counted from when the batch was created. After that the files are genuinely removed from storage; what remains is summary numbers only (how many rows succeeded, how many failed).
- Preview files are deleted within 1 hour.
- Proof of transfer is kept for 12 months after the invoice is settled, then the file is deleted.
- Audit trail is kept for 24 months.
- Payment and subscription records are kept longer — see section 6.
4. Who can see your data
- You. Your files are reachable only by your own account, through short-lived signed links. No file can be reached through a guessable URL.
- Our administrators can see your proof of transfer when verifying a payment, and every such access is logged. Administrators do not open the contents of the documents you generate in normal operation.
- The payment provider (Xendit) receives your name, email, amount and invoice number if you choose online payment. They receive no document contents.
- Hosting and email providers process data only as far as running the service requires.
5. Your rights
Under Indonesian Law No. 27 of 2022 on Personal Data Protection, you may:
- Access and download your data — available directly on the Profile page, the “Download my data” button, as JSON.
- Correct your name and email from the Profile page.
- Close your account — also from the Profile page. See section 6 for what happens next.
- Withdraw consent and object to processing, by contacting us.
6. What happens when you close your account
We do not simply delete the row, and we want to be honest about that. What is permanently deleted:
- Your name and email address, replaced with an anonymous marker
- Every file of yours in storage: uploads, output, previews, proof of transfer
- Every dataset, template and batch, along with their row contents
- All of your login sessions
What is kept, in a form that can no longer be linked to you:
- Payment and subscription records — invoice number, amount, date. The basis is the legal duty to keep records of financial transactions; these records cannot be deleted on request, and that is true of every paid service provider.
- The audit trail of significant actions, with the actor's identity detached.
7. Security
- All traffic goes over HTTPS.
- Passwords are stored as hashes, never in their original form.
- Files are stored outside the public directory and reachable only through short-lived signed links.
- Location metadata (GPS) in proof-of-transfer images is stripped automatically on upload.
- Every administrator access to proof of transfer is logged.
No system is completely immune. If personal data is breached, we will notify you and the relevant authority within 3×24 hours of becoming aware, as the Personal Data Protection Law requires.
8. Children
This service is not intended for anyone under 18 and we do not knowingly collect their data.
9. Changes to this policy
If this policy changes meaningfully, we notify you by email at your account address before the change takes effect.