Privacy Policy
Information under Art. 13 and 14 GDPR. Version: 2026-07-24.
Privacy at a glance
- We do not store your documents. They are deleted right after conversion (zero-retention, section 1).
- Processed in the EU. Conversion runs exclusively in the EU (Scaleway, France); data is transferred to a third country only for payment processing.
- No tracking cookies. We set no tracking or advertising cookies and embed no third-party trackers (section 10).
- Only the data we need. The only durable data is account, usage and billing data (section 4).
- Your rights. Access, erasure and more (section 7); you can delete your account yourself at any time, or email info@hexworld.eu to exercise them.
1. Zero-retention: we do not store your document
We never retain your document. While it is being converted your file exists only as an encrypted blob we cannot read without the per-job key (which we discard) plus the worker’s RAM-backed scratch, and it is destroyed immediately afterward.
Carve-out: inbound e-invoices (ZUGFeRD/XRechnung) you send us are business records and are archived for 8 years under §147 AO. This is the only durable store that holds document-derived content of any kind - and that content is business records you send us, never a converted document; it is kept separate from the conversion plane. Our other durable data (the content-free page-usage record, the signed deletion-audit events, and the record of Terms acceptance) consist only of counters, hashes, and timestamps. Your converted documents themselves are never durably retained.
How we make sure of this (technical properties)
- RAM-only processing: The worker’s scratch is RAM-backed (tmpfs) and is purged after each job; nothing of your document is written to durable disk on the worker.
- No content in logs: No document bytes, OCR text, or original filename ever appear in any log stream (BFF or worker) - only metadata (job id, byte/page counts, timing, status).
- Source purged after processing: The encrypted source is deleted from the inbox after processing; a subsequent fetch returns 404/410 (≈1-hour effective lifetime, with a background-cleanup pass on a ~15-minute cadence as the crash-safe backstop).
- Result delivered at most once: The encrypted result is delivered to your browser at most once - the first fetch deletes it server-side and any later fetch returns 410 (≈15-minute effective lifetime, with the same ~15-minute background-cleanup pass as the crash-safe backstop). Saving the file locally afterwards is a client-side copy and never touches the server.
- Signed deletion audit: A content-free, cryptographically-signed deletion-audit event is recorded for every job (job id + event + timestamp + HMAC signature; never any content).
We continuously verify these properties with automated tests against the production system.
2. Controller
Controller within the meaning of Art. 4 (7) GDPR:
HexWorld Solutions GmbH, Altmarkt 10 B/D, 01067 Dresden, Germany.
Email for privacy matters: info@hexworld.eu
HexWorld Solutions GmbH is the controller for all personal data processed in the course of the service - for the content of converted documents as well as for account, sign-in, usage and billing data, and the limited, content-free abuse-prevention data. Document content is processed exclusively to provide the service and exclusively transiently (zero-retention, section 1). Records of processing activities (Art. 30 GDPR) are maintained.
3. Data protection officer
We have not appointed a data protection officer; we are not legally required to (Art. 37 GDPR, §38 BDSG). For privacy matters, contact us at info@hexworld.eu.
4. Processing activities, purposes and legal bases
The overview below lists the categories of processing with their purpose, legal basis and retention. We maintain a full record of processing activities (Art. 30 GDPR) internally and make it available to the supervisory authority on request.
| Purpose | Legal basis | Retention |
|---|---|---|
| Document conversion (PDF/image → Markdown) | Art. 6 (1) b (contract) | Zero-retention - see section 1 (source ~1 hour, result delivered once; a background-cleanup pass on a ~15-minute cadence removes any remainder as a backstop) |
| Account and sign-in (registration, sessions, account security) | Art. 6 (1) b | For the lifetime of the account; deleted with the account |
| Billing and tax (subscription, page usage, payment processing via Stripe, VAT) | Art. 6 (1) b + c | Usage counters content-free and durable as billing evidence; invoices under the statutory periods (e.g. §147 AO) |
| Security and abuse prevention (bot defense at sign-in, flagging of unusually compute-heavy usage, prevention of repeated free trials) | Art. 6 (1) f (legitimate interest: operational and fraud security) | Short-lived, content-free technical metadata; the one-way hash that prevents repeated free trials for up to 3 months after account deletion |
| Accountability records and logs (deletion audit, record of terms acceptance, operational logs) | Art. 6 (1) f / c | Logs 7 days, metrics 30 days; evidence records content-free and durable (checksums, counters and timestamps only) |
| Inbound e-invoices (ZUGFeRD/XRechnung) as business records | Art. 6 (1) c | 8 years (§147 AO) - separated from conversion |
| Contact by email (support, sales, security, privacy) | Art. 6 (1) b or f | As long as needed to handle the enquiry; business correspondence 6 or 8 years (§257 HGB, §147 AO) |
In short: your documents are never durably stored. The only durable data is a small set of content-free records - billing and evidence data (counters, checksums and timestamps only) and invoices and e-invoices (8 years under §147 AO). Backups likewise cover only this durable account and billing data and never contain document content.
Source of the data (Art. 14 (2) f GDPR)
Where we do not collect personal data directly from the data subject, we state its source: data about suppliers/business partners comes from the inbound invoices or business records themselves; billing/payment data may come from our payment provider (Stripe). Document content is processed exclusively to provide the service and exclusively transiently (zero-retention, section 1).
5. Recipients and service providers; third-country transfers
We engage the following service providers (full list and roles: /en/subprocessors):
- Scaleway SAS - EU cloud infrastructure - hosting, compute, and transient encrypted document blobs on local disk (no object storage) - plus delivery of transactional email (sign-in one-time codes/OTP, security and account notifications, billing receipts; no marketing). All document processing and platform operations run on this infrastructure. (France (Paris))
- Stripe Payments Europe, Ltd. - Subscription billing, payment processing (cards + SEPA Direct Debit), and VAT (Stripe Tax). Stripe receives account, billing, and payment data only - never document content. (Ireland)
- Lexware Office (Haufe Service Center GmbH) - Accounting and statutory bookkeeping - recording and audit-proof archiving of inbound supplier invoices, plus posting of outgoing invoices and revenue (commercial and tax books, §147 AO / §257 HGB). Processes invoice and contact data of business partners and customers - never the content of converted documents. (Germany (Freiburg; data centres in the Frankfurt am Main area))
- mailbox.org (Heinlein Hosting GmbH) - Business email mailboxes - receiving and answering messages sent to our published contact addresses (privacy, support, security, and sales enquiries). (Germany (Berlin))
Document processing takes place entirely in the EU/EEA (Scaleway, France); our email mailboxes are also located in the EU (mailbox.org, Berlin). Data is transferred to a third country only as part of payment processing (Stripe, Inc., USA), and only with documented safeguards (EU Standard Contractual Clauses + EU-US Data Privacy Framework - see the service-provider list). You can obtain a copy of these safeguards (in particular the EU Standard Contractual Clauses) from us on request at info@hexworld.eu (Art. 13 (1) f GDPR).
6. Contacting us by email
When you contact us by email (e.g. support, sales, security or privacy enquiries), we process your sender address, the subject line and the content of your message in order to handle the enquiry. The legal basis is Art. 6 (1) b GDPR (initiating or performing a contract) or Art. 6 (1) f GDPR (legitimate interest in answering enquiries). Our mailboxes are operated by a German provider (mailbox.org, Berlin - see the service-provider list); processing takes place in the EU. We keep correspondence for as long as needed to handle it; business correspondence is subject to statutory retention periods (6 or 8 years, §257 HGB / §147 AO).
7. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). We do not store document content (section 1) - requests therefore concern account, sign-in, usage, billing, log and correspondence data. You can delete your account yourself at any time in your account settings (Account → Delete account), or request deletion informally by email to info@hexworld.eu; we respond within one month (Art. 12 (3) GDPR). After account deletion, only content-free, pseudonymized evidence and counter records remain (billing counters, deletion audit, terms acceptance - checksums only), plus a one-way hash of your email address to prevent repeated free-trial sign-ups (abuse prevention) and invoice data within statutory retention periods (§147 AO). You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR): Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden (www.datenschutz.sachsen.de).
Right to object (Art. 21 GDPR): Where we process data based on Art. 6 (1) f GDPR (e.g. abuse prevention, operational logs), you have the right to object at any time, on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defense of legal claims. Contact: info@hexworld.eu.
8. Automated decision-making (Art. 22 GDPR)
We make no solely automated decisions that produce legal effects concerning you or similarly significantly affect you. For abuse prevention, our system automatically flags unusually compute-heavy usage for an internal review - this flag is purely internal and has no effect whatsoever on your account. Any restriction or suspension of an account is decided exclusively by a human, and every such decision is traceably documented.
9. Obligation to provide data (Art. 13 (2) e GDPR)
Using HexRead requires an account, for which an email address is needed. Paid subscriptions additionally require payment details, which are collected directly by our payment provider. Without this information we cannot enter into or perform the respective contract. Beyond that, there is no statutory or contractual obligation to provide us with data.
10. Cookies and local storage
HexRead sets no tracking or advertising cookies and embeds no third-party trackers. The only items used are:
- a strictly necessary, first-party
__Host-session cookie that keeps you signed in for up to 24 hours after sign-in (a fixed lifetime that activity does not extend; afterwards you sign in again), plus a short-lived__Host-sign-in cookie (10 minutes) during the sign-in flow (§ 25 (2) no. 2 of the German TDDDG); - an optional theme cookie
hx-theme(lifetime up to 1 year), set only when you explicitly choose the light or dark design - it carries your choice over to the sign-in page and is removed as soon as you follow the system setting; the same preference is kept as a "theme" entry in your browser's localStorage (never leaves your device); - a cookieless abuse protection we operate ourselves at the sign-in and sign-up boundaries (no transmission to third parties).
Since only strictly necessary or explicitly requested first-party storage is used (§ 25 (2) TDDDG), no consent banner is required; this notice suffices.
11. Technology used
Document conversion runs exclusively on EU infrastructure using open-source AI models. The available models are listed on the pricing page.
12. Changes to this policy
We update this privacy policy when the service or the legal situation changes. The version published here applies; the date of the last revision is shown at the top of the page. We will inform signed-in users of material changes in an appropriate manner.