Legal

Subprocessors

Third-party processors engaged in the delivery of the HTPBE service.

Last Updated: July 20, 2026

This page lists all subprocessors (third-party data processors) engaged by TMI Iurii Rogulia (“HTPBE”, “we”, “us”) in the delivery of the PDF authenticity checking service at htpbe.tech. It is maintained in accordance with GDPR Article 28(3)(d).

Two processing modes — different data flows

Web UI users only (free check)

The user uploads a PDF file in the browser. The file is transferred directly from the browser to Cloudflare R2 via a presigned PUT URL, then the HTPBE server downloads and analyzes it in memory. Web-uploaded files may be retained in R2 and used, without any linkage to your account, to test and improve the detection algorithm; alongside every check, the extracted metadata and the verdict are also stored persistently. Cloudflare R2 is engaged as a sub-processor exclusively in this mode.

API users only (URL-based)

The API client sends an HTTP URL pointing to a PDF already hosted on their infrastructure. HTPBE fetches the file from that URL directly into server memory, performs the analysis, and immediately discards the file. No file content is written to any storage system. Cloudflare R2 is not involved. Only extracted metadata and the analysis verdict are stored.

In both modes, HTPBE never reads, parses, or renders the textual or visual content of the document. Analysis is limited to structural metadata: information dictionary fields, cross-reference tables, object layout, and digital signature structures. In Web-UI mode the uploaded file itself — which contains that content — is stored on Cloudflare R2 as described above; in API mode no file is stored. Beyond that storage, only the extracted structural metadata and the resulting verdict are transmitted to any other subprocessor.

Analytics & advertising — consent categories

Analytics and advertising subprocessors load in your browser on the htpbe.tech marketing site and are governed by our cookie-consent banner, which uses Google Consent Mode v2 (default-denied until you choose):

  • Necessary (always on) — strictly-functional storage (sign-in, your cookie choice) and the cookieless Umami traffic counter, which sets no cookies and stores nothing on your device.
  • Analytics (opt-in) — Google Analytics 4 and Microsoft Clarity.
  • Marketing (opt-in) — Google Ads and the Meta Pixel.

Under “Reject all,” Clarity and the Meta Pixel are never injected, and Google Analytics 4 and Google Ads send only cookieless modelling pings. Sentry and vatnode.dev are operational subprocessors that support error monitoring and billing rather than analytics or advertising.

Active subprocessors

Engaged in service delivery

Cloudflare R2

Temporary PDF file transit storage (Web UI only)

Web UI only

Data processed

PDF file binary (web uploads only). May be retained without any linkage to your account and used to test and improve the detection algorithm. The substantive content of the document is never read or indexed — analysis is limited to structural metadata.

Storage region

European Union

Cloudflare R2 is not engaged for API-mode requests. API clients bear responsibility for their own file storage.

Axiom

Structured logging and observability

All users

Data processed

Request logs: endpoint, HTTP status, response time, API key identifier (truncated), error traces. No PDF file content, no document metadata fields, no user email.

Storage region

United States — EU Standard Contractual Clauses

Axiom is not certified under the EU-US Data Privacy Framework; transfers outside the EEA rely on the 2021 EU Standard Contractual Clauses (Module Two) under its Data Processing Addendum.

Vultr

Cloud infrastructure — virtual servers on which the application and its PostgreSQL database run (orchestrated via Coolify)

All users

Data processed

Application code and in-transit HTTP request/response payloads, plus the self-hosted PostgreSQL database: PDF metadata extracted during analysis (filename, creator, producer, dates, page count, verdict, detection markers), registered user data (email address, name), API key hashes, and billing plan metadata. No PDF file content.

Storage region

European Union

Mollie

Payment processing and subscription management

Paying subscribers

Data processed

Payment card data (tokenized by Mollie, never seen by HTPBE), billing address, subscription status, invoice history, Mollie customer ID. Mollie acts as an independent data controller for payment card data.

Storage region

European Union

Resend

Transactional email delivery (magic-link authentication)

Registered users

Data processed

Recipient email address, email subject and body (authentication link). No PDF content.

Storage region

United States — EU-US Data Privacy Framework

Resend is certified under the EU-US Data Privacy Framework; its Data Processing Addendum additionally incorporates the EU Standard Contractual Clauses (Module Two) as a supplementary safeguard.

Google Analytics 4 & Google Ads (Google Ireland / Google LLC)

Website usage analytics (GA4) and advertising measurement / conversion tracking (Google Ads)

Web UI only

Data processed

Loaded in the browser via gtag.js on htpbe.tech marketing pages. Sets analytics and advertising cookies (_ga, _ga_*, _gcl_*) that record a client/session identifier, page URL, page title, referrer, and advertising click identifiers. In addition, a server-side Measurement Protocol call sends a cookieless purchase-conversion event (transaction id, gross value, currency, Google click id) after a payment. No PDF file content or document metadata is sent.

Storage region

United States (Google LLC) — EU-US Data Privacy Framework

Consent Mode v2 starts default-denied: GA4 and Google Ads load on every page but only read or write cookies and personalise once you grant consent (GA4 under the Analytics category, Google Ads under Marketing). Before consent they send cookieless modelling pings. The server-side purchase event is cookieless and independent of the banner. Google Ireland Limited is the EEA contracting entity; the data is processed and stored by Google LLC in the United States under the European Commission’s EU-US Data Privacy Framework adequacy decision of 10 July 2023, for which Google LLC is certified.

Microsoft Clarity (Microsoft Corporation)

Product analytics — session replay and heatmaps to see how pages are used

Web UI only

Data processed

Loaded in the browser only after Analytics consent is granted. Records masked page interactions (clicks, scrolls, navigation), device and browser attributes, and sets Clarity cookies (_clck, _clsk). No PDF file content or document metadata.

Storage region

United States — EU-US Data Privacy Framework

Injected only after the Analytics consent category is accepted; never loaded under Reject-all.

Meta Pixel (Meta Platforms Ireland / Meta Platforms, Inc.)

Advertising measurement — attribute site visits and conversions to Meta (Facebook / Instagram) ad campaigns

Web UI only

Data processed

Loaded in the browser only after Marketing consent is granted. Sends a PageView event and sets the Meta advertising cookie (_fbp); Meta may match the visit to a Meta account for ad attribution. No PDF file content or document metadata.

Storage region

United States (Meta Platforms, Inc.) — EU-US Data Privacy Framework

Injected only after the Marketing consent category is accepted; never loaded under Reject-all. Meta Platforms Ireland Limited is the EEA contracting entity; the data is processed and stored by Meta Platforms, Inc. in the United States under the European Commission’s EU-US Data Privacy Framework adequacy decision of 10 July 2023, for which Meta Platforms, Inc. is certified.

Umami (self-hosted)

Privacy-friendly, cookieless traffic analytics

Web UI only

Data processed

Aggregate page views, referrer, and campaign (UTM) parameters. No cookies are set and no cross-site identifier is stored on your device. No PDF file content or document metadata.

Storage region

Self-hosted on operator-controlled infrastructure in the EU (u.rogulia.fi)

Cookieless and does not store data on your device, so it runs under the Necessary category without a consent prompt.

Sentry (Functional Software, Inc.)

Application error monitoring and diagnostics

All users

Data processed

Error and exception reports with stack traces (server-side stack frames include local variable values) and request context. The client SDK attaches default personal context (including IP address and, for signed-in users, an account identifier). No PDF file content or document metadata is sent to Sentry.

Storage region

European Union (Germany)

Runs in the browser and on the server for error monitoring only — session replay is disabled. Error diagnostics are processed under our legitimate interest in keeping the service secure and reliable.

vatnode.dev

EU VAT-ID validation to determine reverse-charge eligibility at billing

Paying subscribers

Data processed

The EU VAT identification number entered on a billing profile is sent for validation (VIES wrapper with national-registry fallback). No PDF file content or document metadata.

Storage region

European Union

Notification policy

Changes to this list

We will update this page at least 10 days before engaging a new subprocessor. If you are an API customer with a Data Processing Agreement in place, we will notify you by email to the address associated with your account. You have the right to object to a new subprocessor within 10 days of notification; if you do not object within that period, the change is deemed accepted. To object or request a list of subprocessor changes, contact [email protected].

For API customers

Data Processing Agreement

If you are an API customer processing personal data on behalf of your own clients, a Data Processing Agreement is available at htpbe.tech/legal/dpa. For Enterprise customers requiring a custom or countersigned DPA, contact [email protected].