Legal
Last updated: 19 August 2026
This Privacy Policy explains how Extract API OÜ ("we", "us", "our") processes personal data when you use Extract API (the "Service") — including our website, REST API, documentation, and billing integration.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national laws. For a technical summary of data flows, caching, and sub-processors, see our Data processing documentation.
For personal data relating to API account holders, billing contacts, and website visitors, we act as the data controller.
Replace with your legal entity:
Extract API OÜ
Registry code:
12345678
VAT:
EE123456789
Address:
Example Street 1, 10111 Tallinn, Estonia
Email:
privacy@extract.example.com
Phone:
+372 5123 4567
Data Protection Officer (DPO): Not appointed — contact privacy@extract.example.com
Extract API is a business-to-business document extraction service. When you upload PDFs containing third-party personal data (names, addresses, payment details in invoices or CMRs), you are the data controller for that information.
For document processing, we act as a data processor on your instructions. You must have a lawful basis to upload such data. Our Data Processing Agreement (DPA) applies when you register for the Service.
Depending on document type and deployment settings, document content may be sent to sub-processors for OCR or structured extraction:
Digital PDFs with an embedded text layer are first processed locally on our servers (Poppler). Cloud AI is used when local text is insufficient or for configured structured/vision stages. See Sub-processors and Data processing docs.
To improve performance and reduce cost, we cache extraction results in Redis for up to 30 days. The cache stores:
Cache entries are scoped to your API account (account ID + file hash + document type). Results are never served from one customer's cache to another customer.
| Purpose | Legal basis |
|---|---|
| Provide API extraction service | Contract (Art. 6(1)(b) GDPR) |
| Billing and credit management | Contract; legal obligation for invoices |
| Security, fraud prevention, rate limiting | Legitimate interest |
| Extraction result cache (per account, identical PDF + type) | Legitimate interest (efficiency, cost reduction) — you may object (see §7) |
| Sub-processor AI/OCR when required for extraction quality | Contract performance; sub-processors bound by DPA Art. 28 |
| Marketing communications | Consent where required |
We use third-party providers for hosting, OCR, structured extraction, and payments. A complete list, purposes, and locations is at /subprocessors (DPA Annex III).
We notify API account holders by email at least 30 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within 14 days as set out in the DPA.
As an account holder (controller for your own registration data), you may request access, rectification, erasure, restriction, portability, or object to processing — including objecting to result caching on legitimate-interest grounds.
For personal data inside documents you uploaded (where you are controller and we are processor), coordinate erasure requests through your DPA contact or ours at dpa@extract.example.com .
You may delete your account at any time from the Dashboard (delete account section). We remove your profile, API credentials, extraction history, and support tickets. Anonymized billing records are kept for the statutory period in §6.
You may download a machine-readable copy of your account data from the Dashboard (Privacy & data section). The export includes account profile, billing, extraction metadata and results returned to you, support messages, and cookie consent records. API secrets are excluded.
Contact: privacy@extract.example.com . You may lodge a complaint with your supervisory authority.
Primary hosting is in the EEA. When sub-processors (e.g. Mistral AI, OpenAI, Stripe) process data outside the EEA, we rely on Standard Contractual Clauses, adequacy decisions, or equivalent safeguards as described in the DPA.
privacy@extract.example.com