Last updated: July 20, 2026
Data Processing Agreement
This page summarises the standard Data Processing Agreement (DPA) that Be My PDF offers to business customers whose use of the service involves processing personal data on their behalf. A signed copy is available on request from connect.cosmodex@gmail.com.
1. Roles
The customer is the data controller of any personal data it submits to the service. Be My PDF acts as the data processor and processes that personal data only on documented instructions from the customer, principally by delivering the tools described in the Terms of Service.
2. Subject-matter and duration
The processing lasts for the term of the customer's subscription and covers the categories of personal data typically contained in the customer's documents (names, contact details, transactional information, or whatever the customer chooses to include). Because the browser-side tools run on the customer's device, we rarely ever handle those documents directly.
3. Security measures
- TLS 1.3 with HSTS on every connection.
- Row Level Security enforced on every user-facing database table with a security definer role check.
- Encryption at rest for backups and account records.
- Least-privilege access controls with hardware second-factor authentication for administrators.
- Automated dependency vulnerability scanning on every commit.
4. Sub-processors
The current list of sub-processors is published on the GDPR page. We give reasonable prior notice before adding a new sub-processor and give business customers the opportunity to object.
5. Personnel
Every person authorised to access personal data on our side is bound by a written confidentiality obligation and receives regular training on data protection responsibilities.
6. Assistance to the controller
We help the customer respond to data subject requests, conduct data protection impact assessments, and consult with supervisory authorities where required by GDPR.
7. Breach notification
If we become aware of a personal data breach affecting customer data, we notify the customer without undue delay and in any case within 72 hours. The notification includes the nature of the breach, likely consequences, and the measures we are taking to address it.
8. Deletion and return
At the end of the subscription, the customer can export any personal data held in account records; anything not exported is deleted within 30 days unless retention is required by law.
9. International transfers
When personal data is transferred outside the EEA, we rely on the 2021 Standard Contractual Clauses (module 2 or module 3 as applicable) with our sub-processors, with supplementary technical measures where recommended.
10. How to sign
Email connect.cosmodex@gmail.com with your legal entity name, address, and the name and role of the signatory. We will return a countersigned PDF within five business days.