Privacy Policy
Last updated: August 3, 2026
1. Introduction
This Privacy Policy explains how Function Labs ("we", "us") collects, uses, and protects your personal data when you use PDF Suite ("the Service"). We are committed to protecting your privacy and complying with the UK GDPR and the EU General Data Protection Regulation (GDPR).
2. Data Controller
Function Labs is the data controller for your personal data. For data protection inquiries, contact us at support@functionlabs.co.uk.
3. Information We Collect
- Account data: Email address, name, and authentication tokens.
- Document data: PDF files you upload, including their content, metadata, and extracted text.
- Usage data: Activity logs, feature usage, and interaction data.
- Technical data: IP address (stored as an irreversible hash), browser type, device information, and a browser fingerprint generated locally for usage-limit tracking and entitlement management.
4. How We Use Your Information
- Providing and maintaining the Service.
- Processing your documents (conversion, editing, AI analysis).
- Communicating with you about your account and support requests.
- Improving and developing our features.
- Ensuring security and preventing abuse.
5. Legal Basis for Processing
Under GDPR, we process your data based on:
- Contract (Article 6(1)(b)): To provide the Service you requested.
- Legitimate interests (Article 6(1)(f)): To improve security and service quality.
- Consent (Article 6(1)(a)): For optional features like marketing communications.
- Legal obligation (Article 6(1)(c)): To comply with applicable laws.
6. Document Processing
- Your PDF files are uploaded to our infrastructure for processing.
- Processing includes format conversion, editing, merging, splitting, OCR, translation, comparison and AI analysis.
- AI features (summarise, ask, OCR, translate, compare) send your document content or extracted text to third-party AI providers — including Google, Anthropic and OpenAI — to generate results. These providers process your content subject to their own terms and retention practices.
- We do not knowingly use your document content to train our own models. Whether a third-party provider uses content for training is governed by that provider's policies, which we do not control.
- You can delete your saved files at any time from the Files section.
7. Data Retention
- Saved files (registered users): Files you save to your library are retained until you delete them or delete your account.
- Guest files: Files uploaded without an account, and any generated outputs, are scheduled for automatic removal within one hour of upload. Guest file records are not visible to other users.
- Temporary processing artefacts: Files uploaded only for processing and not saved are treated as temporary and are removed on the same schedule as guest files.
- Extracted text & AI summaries: Extracted text is stored with the file record and removed when the file is deleted. AI chat and summaries viewed in the Reader are stored in your browser's local storage, scoped to each file, and are removed when you clear browser data.
- Account data is retained while your account is active.
- Activity logs are retained for up to 12 months for security and analytics.
- Usage & entitlement records: Hashed IP address, browser fingerprint, task type, and entitlement status are stored to enforce free-tier limits and manage paid access. For authenticated users, these records are linked to your account. For guests, they are linked to your device hash and expire with the corresponding entitlement.
- Storage limitation: The underlying file-storage objects are managed by our platform provider. When you delete a file, we remove the database record, extracted text and share links immediately. The platform storage object may persist briefly on the provider side before it is purged, and is not reachable through the application after deletion.
- You can request deletion of your data at any time.
8. Sharing Your Documents
- You can share a saved file by creating a secure share link or by sending it to another registered PDF Suite user by email.
- Share links use a randomly generated token, expire automatically (default 7 days), and can be revoked by you at any time.
- Only a hashed version of the share token is stored. A link stops working if the source file is deleted.
- The permanent raw storage address is not included in share emails; only the application share link is sent.
- Share access is app-controlled. The underlying file is stored on platform-managed infrastructure, as described in the retention section.
9. Your Rights (GDPR)
You have the following rights:
- Right of access (Article 15): Request a copy of your personal data.
- Right to rectification (Article 16): Correct inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your data ("right to be forgotten").
- Right to restrict processing (Article 18): Limit how we process your data.
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests.
- Right to withdraw consent (Article 7): Withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at support@functionlabs.co.uk.
10. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies for advertising.
11. Third-Party Processors
We use the following categories of third-party services to process your data:
- Cloud infrastructure & storage: For hosting, file storage, and database services.
- Payment processing: Stripe processes all payments. Stripe receives your card details, billing address, and payment authentication data directly — we never see or store your card information. We receive your email, payment status, and subscription metadata from Stripe to manage your access.
- AI providers: Google (Gemini), Anthropic (Claude) and OpenAI (GPT) for document analysis, OCR, translation, comparison and language processing. Document content or extracted text is sent to these providers when you use the relevant feature.
- Email services: Gmail is used to send share links and support communications to registered users.
Each processor is bound by data processing agreements and GDPR-compliant terms.
12. International Transfers
Your data may be processed outside the UK/EEA. We ensure appropriate safeguards, including Standard Contractual Clauses (SCCs), are in place for such transfers.
13. Children's Privacy
The Service is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe we have collected data from a child, please contact us.
14. Data Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and regular security reviews.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the Service or by email.
16. Contact
For privacy inquiries or to exercise your rights, contact us at support@functionlabs.co.uk or visit our Support Centre.
