Privacy Policy
Privacy Policy
Last Updated: February 2026
1. Data Controller
The controller responsible for data processing under the General Data Protection Regulation (GDPR) is:
Felix Ruby
PaperBridge
Scheffelstraße 1
78048 Villingen-Schwenningen
Germany
VAT ID: DE336384698
Email: support@paperbridge.app
2. Overview of Processing
Paperbridge is a cloud-based Software-as-a-Service platform for automating document creation. When you use Paperbridge, we process personal data in connection with: providing the website, registering and managing your user account, processing the templates and data you upload for document generation, electronic signature, payment processing, and support requests.
Where you use Paperbridge to create documents containing personal data of third parties (e.g. your own customers), you are typically the data controller for that data, and Paperbridge acts as a processor on your behalf. A Data Processing Agreement (DPA) is available on request at support@paperbridge.app.
3. Your Rights as a Data Subject
Under the GDPR you have the following rights:
- Access (Art. 15 GDPR) to the data we hold about you
- Rectification (Art. 16 GDPR) of inaccurate data
- Erasure (Art. 17 GDPR), unless a legal retention obligation applies
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR), in particular where processing is based on legitimate interests
- Withdrawal of any consent given, with future effect (Art. 7(3) GDPR)
- Lodging a complaint with a supervisory authority (Art. 77 GDPR), e.g. the data protection authority of Baden-Württemberg, Germany
To exercise these rights, simply contact us at support@paperbridge.app.
4. Provision of the Website and Server Log Files
When you access our website, our hosting provider automatically collects technical access data (including IP address, date and time of access, page requested, browser used, and referrer URL). This data is stored in server log files to ensure reliable operation and IT security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). Log files are deleted after 30 days at the latest, unless needed to investigate a security incident.
5. Registration and User Account
Using Paperbridge requires creating a user account. We process your name, email address, an encrypted password, and, if provided, your company name and language preference. The legal basis is Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures). Login itself is handled via a session cookie, see Section 10.
6. Templates, Form Data, and Generated Documents
When you upload document templates and fill out forms, we process the content to automatically generate documents from it. This may include personal data of third parties (e.g. names, addresses, or contact details of your own customers) that you enter into templates or collect via web forms you create. The legal basis for our processing is Art. 6(1)(b) GDPR, or Art. 28 GDPR under a processing relationship with you as controller. Generated documents remain available for download for up to 30 days after termination of your account and are then deleted, unless a longer retention period is agreed or legally required.
7. Document Generation via Carbone.io
To generate your documents, we transmit your template and the data required to populate it to our service provider Carbone.io. Carbone.io processes this data solely for document generation on our behalf and does not retain it permanently. Where Carbone.io processes data outside the EU/EEA, we ensure an adequate level of data protection through appropriate safeguards, in particular EU Standard Contractual Clauses under Art. 46 GDPR.
8. Electronic Signature via Documenso
If you use the signature feature, we transmit the document to be signed as well as the name and email address of the signer(s) to our service provider Documenso, which sends the signature request and logs the signing process. The legal basis is Art. 6(1)(b) GDPR or Art. 28 GDPR.
9. Payment Processing via Stripe
Paid subscriptions are processed through our payment provider Stripe. Payment and billing data (e.g. name, billing address, payment method) is processed directly by Stripe; card data never passes through our own servers. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). For more information, see Stripe's privacy policy.
10. Cookies and Local Storage
We use a technically necessary session cookie for login and session management (legal basis: Art. 6(1)(f) GDPR). This cookie is required to provide core functionality and cannot be disabled without limiting use of the service. We do not use marketing or tracking cookies (e.g. Google Analytics or similar services).
On publicly shared demo pages (/demo/...), we store a randomly generated, non-personal session identifier in your browser's sessionStorage to count usage events (e.g. page view, document generation). This identifier is not persisted across browsers, is not shared with third parties, and is not used for profiling. The legal basis is our legitimate interest in evaluating usage of our demo feature (Art. 6(1)(f) GDPR).
11. Contact and Support
If you contact us by email or via the contact form, we process the data you provide (name, email address, message content) to handle your request. The legal basis is Art. 6(1)(b) or (f) GDPR.
12. Retention Period
We retain personal data only as long as necessary for the respective purpose or as required by statutory retention periods (e.g. commercial and tax retention obligations of up to 10 years for invoicing data). Account data is deleted after termination of your user account; generated documents and uploads as described in Section 6.
13. Recipients and Processors
We use the following processors, each bound by an Art. 28 GDPR data processing agreement:
- Hosting provider (servers located in Germany, ISO 27001 certified)
- Carbone.io (document generation, see Section 7)
- Documenso (electronic signature, see Section 8)
- Stripe (payment processing, see Section 9)
We do not transfer data to any other third parties unless legally required to do so.
14. International Data Transfers
Where any of the above service providers process data outside the EU/EEA, we ensure an adequate level of data protection through appropriate safeguards, in particular by entering into EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with the respective provider.
15. Data Security
We employ technical and organizational measures to protect your data against loss, misuse, and unauthorized access, including encryption of data in transit (TLS/SSL) and an ISO 27001-certified hosting infrastructure located in Germany.
16. Minors
Our service is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law or to our service. The version published at the time of your visit applies.
18. Contact for Privacy Inquiries
For questions about data protection or to exercise your rights, please contact:
Felix Ruby
PaperBridge
Scheffelstraße 1
78048 Villingen-Schwenningen
Germany
Email: support@paperbridge.app