Legal
Version: 1.1 — 19 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Extract API OÜ ("Processor") and the business entity that registers for Extract API ("Controller", "Customer").
It implements Article 28(3) GDPR. By registering for an API key, you enter into this DPA. Our role as controller for your account data is in the Privacy Policy. Technical data-flow details: Data processing docs.
Extract API OÜ
Registry:
12345678
Address:
Example Street 1, 10111 Tallinn, Estonia
DPA contact:
dpa@extract.example.com
Security:
security@extract.example.com
The Customer identified at registration (company name and email).
Subject matter: Provision of PDF document extraction via REST API, including storage of uploaded files during processing, webhook delivery, and related support.
Duration: From registration until account deletion, plus statutory retention for billing records.
Processing personal data contained in PDF documents uploaded by the Controller for the purpose of extracting structured fields and returning results via API or webhook.
Processing may include:
Controller authorises use of sub-processors listed at /subprocessors, including cloud OCR and structured-extraction providers that may receive document content when the pipeline requires it.
We notify Controller at least 30 days before adding or replacing sub-processors. Controller may object on reasonable data protection grounds within 14 days.
Controller acknowledges that disabling cloud OCR/LLM stages (via Processor deployment configuration) may reduce extraction quality for scanned documents.
Transfers outside the EEA use SCCs (Module 2 or 3 as applicable) or adequacy decisions.
Processor caches extraction results (field values, not PDF files) in Redis for up to 30 days, keyed by file hash, document type, and Controller account ID. Cache entries are not shared between customers. Cached data expires automatically or may be deleted earlier on verified request to dpa@extract.example.com .
Upon termination, Processor deletes uploaded PDFs, cached results, and extraction request data within 30 days , except where retention is required by law or for dispute resolution.
Controller may audit compliance once per year on reasonable notice, or request SOC 2 / ISO reports when available: security@extract.example.com .