Privacy Policy
Effective date: 24 September 2026
This Privacy Notice explains how Ignat Savkin, trading as PaperSprocket ("PaperSprocket", "we", "us", or "our"), handles personal data in connection with the PaperSprocket website, API, account, payment, support, and related services.
PaperSprocket is operated as an Irish sole trader.
Business address: 5 Harcourt Road, Dublin, Ireland, D02 FW64 Privacy/support contact: support@papersprocket.com
PaperSprocket is currently offered for business, professional, developer, and organisational use only.
1. Our roles under data-protection law
PaperSprocket can handle personal data in two different roles.
1.1 PaperSprocket as controller
PaperSprocket acts as controller for personal data that we use for our own business purposes, including:
- account and contact information;
- account and API identifiers;
- payment and transaction references received from Paddle;
- usage and billing records;
- request and service metadata;
- IP addresses and security information;
- support communications;
- operational and security logs; and
- information required for legal, accounting, tax, fraud-prevention, and dispute purposes.
This Privacy Notice primarily explains that controller-side processing.
1.2 PaperSprocket as processor
If a customer submits document content containing personal data for rendering, PaperSprocket acts as a processor or subprocessor, as applicable, for that rendering operation. The customer or another organisation in the processing chain determines the purposes and lawful basis for the underlying personal-data processing.
Customer document content is processed transiently to perform the requested render. PaperSprocket does not provide durable storage of submitted document content or generated PDFs.
The data-processing terms governing this processor or subprocessor activity are included in the PaperSprocket Terms of Service.
2. Personal data we collect and use
Depending on how you use PaperSprocket, we may process the following categories of personal data.
2.1 Account and contact data
This may include:
- name;
- business or organisation name;
- email address;
- account identifiers; and
- information you provide when creating or maintaining an account.
2.2 API and service-usage data
This may include:
- account or API-key identifiers, but not raw API keys in ordinary application logs;
- request identifiers;
- timestamps;
- API endpoint used;
- render status;
- successfully rendered page counts;
- processing duration;
- HTTP status;
- error or diagnostic codes;
- renderer or service version information; and
- other technical metadata needed to operate and secure the Service.
2.3 Network and security data
This may include:
- IP address;
- request timing;
- rate-limit and abuse-prevention information;
- security-event information; and
- technical information reasonably necessary to investigate service misuse, attacks, or faults.
2.4 Payment and transaction data
Payments are handled through Paddle, which acts as Merchant of Record for purchases made through Paddle.
PaperSprocket may receive information from Paddle such as:
- Paddle customer, transaction, or payment identifiers;
- transaction amount and status;
- refund or dispute status;
- billing country or other tax-related transaction information where provided;
- purchase timestamps; and
- information needed to provision, reconcile, or refund PaperSprocket usage.
PaperSprocket does not receive or store full payment-card details used in Paddle checkout.
2.5 Usage and accounting ledger
PaperSprocket maintains records needed to determine:
- usage purchased;
- usage consumed;
- remaining usage;
- render/page counts;
- transaction adjustments;
- refunds or reversals; and
- related accounting or audit history.
2.6 Support communications
If you contact us, we may process:
- your name and email address;
- organisation or account details;
- the content of your message;
- attachments you choose to send; and
- information needed to investigate and respond to your request.
Please do not send unnecessary sensitive personal data or confidential document content through support email.
3. Customer document content
PaperSprocket is designed to minimise retention of document content.
When you submit content for rendering:
- the content is processed only as needed to perform the requested render;
- the generated PDF is returned as part of the render response;
- submitted source content and generated output are not retained as durable document storage;
- on normal completion, temporary render artifacts are deleted as part of processing; and
- orphaned temporary artifacts left by failed or interrupted jobs are subject to automated cleanup and are intended to be deleted within one hour.
PaperSprocket's ordinary application logs are not intended to contain:
- document bodies;
- submitted HTML or document text;
- generated PDFs;
- uploaded document files or images;
- raw API keys;
- authorisation headers; or
- other authentication secrets.
Where URLs or similar values could contain query-string personal data or tokens, they should not be logged indiscriminately. Sanitised technical information may be recorded where necessary for operation or security.
4. Why we use personal data and our legal bases
Where GDPR applies, PaperSprocket relies on the following legal bases for controller-side processing.
4.1 Contract and steps connected with a contract
We process data where necessary to:
- create and administer your account;
- authenticate and provide access to the Service;
- provide purchased API usage;
- meter usage;
- provide customer support;
- manage refunds or corrections; and
- otherwise perform our agreement with you.
4.2 Legal obligations
We may process and retain information where necessary to comply with:
- tax and accounting requirements;
- applicable business-record obligations;
- lawful requests from courts, regulators, tax authorities, or other competent authorities; and
- other legal obligations that apply to PaperSprocket.
4.3 Legitimate interests
We may process personal data where necessary for legitimate business interests that are not overridden by your rights and interests, including:
- securing accounts and API access;
- preventing fraud, abuse, credential misuse, and attacks;
- enforcing technical and usage limits;
- diagnosing faults and maintaining service reliability;
- maintaining accurate usage, transaction, and audit records;
- establishing, exercising, or defending legal claims; and
- protecting PaperSprocket, its users, and its infrastructure.
Where we rely on legitimate interests, we aim to use only the personal data reasonably necessary for the relevant purpose.
4.4 Consent
PaperSprocket does not currently rely on consent for advertising or behavioural marketing because those activities are not part of the launch service.
If we introduce optional processing that requires consent in the future, we will request it separately where required.
4.5 Information needed to provide the Service
Some personal data is necessary to enter into or perform our agreement with you, administer your account, provision purchased usage, secure access, reconcile transactions, or respond to support requests.
Where information is necessary for one of those purposes and you do not provide it, we may be unable to create or maintain the relevant account, provide the affected functionality, complete or reconcile a purchase, or respond fully to the request.
Where information is required by law, we may be unable to provide or continue the relevant part of the Service if the required information is not available.
5. Where personal data comes from
We may receive personal data:
- directly from you;
- from activity performed through your PaperSprocket account or API credentials;
- automatically from requests made to our website or API;
- from Paddle in connection with purchases, refunds, disputes, and payment reconciliation; and
- from communications you send to us.
For customer document content, the data is supplied by the customer or by systems acting under the customer's authority.
6. Service providers and recipients
We use a limited number of external providers to operate PaperSprocket.
6.1 Hetzner Online GmbH
PaperSprocket's website, API, and rendering infrastructure are hosted with Hetzner Online GmbH in Falkenstein, Germany.
Hetzner infrastructure may process:
- website and API traffic;
- IP addresses and request metadata;
- account/service data held on the server; and
- customer document content transiently while a render is being performed.
6.2 Paddle
Paddle acts as Merchant of Record for PaperSprocket purchases.
Paddle independently processes payment and transaction data under its own privacy and legal terms. PaperSprocket exchanges only the information reasonably necessary to provision purchases, reconcile transactions, manage refunds or disputes, and support customers.
Customer render/document content is not sent to Paddle as part of the rendering process.
6.3 Proton
PaperSprocket uses Proton for support email.
If you email support@papersprocket.com, your message and related email metadata are processed through Proton's email service.
Customer render content is not routinely sent to Proton. It may be processed there only if you deliberately include it in a support email.
6.4 Hostinger
Hostinger is used for PaperSprocket's domain registration and DNS service.
The public website and API are served directly from PaperSprocket's Hetzner infrastructure rather than through a Hostinger content-delivery or application proxy.
6.5 Legal and regulatory recipients
We may disclose personal data where reasonably necessary to:
- comply with applicable law;
- respond to a lawful request from a competent authority;
- protect legal rights or security;
- investigate fraud or misuse; or
- establish, exercise, or defend legal claims.
We do not sell personal data to advertisers or data brokers.
7. International transfers
The PaperSprocket website, API, and rendering infrastructure are hosted in Germany within the European Economic Area.
Some controller-side service providers, including payment or communications providers, may process data in or make data accessible from countries outside the EEA.
Where PaperSprocket is responsible for such a transfer, we will rely on an appropriate transfer mechanism recognised under GDPR, such as:
- an adequacy decision;
- approved standard contractual clauses; or
- another lawful transfer safeguard.
You may contact support@papersprocket.com for information about the safeguards applicable to a particular transfer.
Customer render content is processed on the EU-hosted Hetzner infrastructure in Germany and is not intentionally transferred outside the EEA by PaperSprocket unless necessary to provide the Service under an appropriate GDPR transfer mechanism or required by applicable law.
8. Retention
We keep different categories of information for different periods.
8.1 Customer render content
PaperSprocket does not provide durable storage of submitted document content or generated PDFs.
Source content and generated output are deleted as part of normal processing. Orphaned temporary artifacts are intended to be removed by automated cleanup within one hour.
8.2 Operational and security logs
Operational and security logs are generally retained for up to 30 days, unless a particular record needs to be retained longer to investigate an identified security incident, abuse event, technical fault, dispute, or legal claim.
8.3 Transaction, usage, accounting, and legal records
Transaction, usage-ledger, accounting, refund, tax, and related audit records may be retained for longer periods where reasonably necessary to comply with applicable legal, tax, accounting, fraud-prevention, or dispute requirements.
8.4 Account and support records
Account and support information is retained for as long as reasonably necessary to operate the account, provide support, resolve disputes, enforce agreements, protect security, and meet applicable legal obligations.
Where there is no continuing need or legal reason to retain personal data, we will delete or anonymise it where reasonably practicable.
9. Cookies, analytics, and tracking
At launch, PaperSprocket does not use advertising cookies, behavioural tracking, or external analytics services.
PaperSprocket may use strictly necessary technical mechanisms required to provide account, authentication, security, or session functionality. These are not used for advertising or behavioural profiling.
If we later introduce non-essential analytics, advertising, or similar tracking technologies, we will update this notice and implement any consent mechanism required by applicable law before using them.
10. Automated decision-making
PaperSprocket does not currently use personal data to make solely automated decisions about individuals that produce legal effects or similarly significant effects within the meaning of GDPR.
Automated technical controls may be used for ordinary security, rate limiting, abuse prevention, or service operation.
11. Security
PaperSprocket uses technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss, or misuse.
The current service architecture includes data minimisation, transient document-content processing, service logging designed to exclude document content and authentication secrets, and EU-hosted rendering infrastructure. Additional safeguards are applied as appropriate to the nature and risk of the processing.
No internet-connected service can guarantee absolute security. We review and adjust safeguards according to the nature and risk of the processing.
12. Your data-protection rights
Where GDPR applies to you, you may have rights including:
- access to your personal data;
- correction of inaccurate personal data;
- erasure of personal data in appropriate circumstances;
- restriction of processing;
- objection to processing based on legitimate interests;
- data portability where applicable;
- withdrawal of consent where processing is based on consent; and
- the right not to be subject to certain solely automated decisions.
These rights are subject to the conditions and exceptions provided by applicable law.
To exercise a right, contact support@papersprocket.com.
We may need to verify your identity before acting on a request.
If the information concerned is customer document content that PaperSprocket processed only as processor or subprocessor, the relevant controller in that processing chain is normally responsible for handling the data-subject request. Because PaperSprocket does not retain rendered document content after processing, the content may no longer be held when a request is received.
13. Complaints
If you have a concern about how PaperSprocket handles your personal data, you can contact us at:
support@papersprocket.com
You also have the right to lodge a complaint with the Data Protection Commission (Ireland) or, where applicable, another competent supervisory authority.
14. Business customers and their users
If your employer, client, or another organisation provides you with access to PaperSprocket, that organisation may separately process information about your use of the Service.
PaperSprocket is not responsible for that organisation's independent privacy practices.
15. Changes to this Privacy Notice
We may update this Privacy Notice when the Service, providers, legal requirements, or processing activities change.
Where a change is material, we will take reasonable steps to make the updated notice available before or when the change takes effect, as appropriate.
The effective date at the top of this notice identifies the current version.
16. Contact and operator details
PaperSprocket Operated by Ignat Savkin, trading as PaperSprocket Business address: 5 Harcourt Road, Dublin, Ireland, D02 FW64 Email: support@papersprocket.com
For customer-content processing carried out on your behalf, please also see the data-processing terms contained in the PaperSprocket Terms of Service.