Skip to content

Data processing addendum

Effective 18 August 2026 · version 1.0

This addendum forms part of the terms of service and applies whenever you send us documents or account data containing personal data as the GDPR, the UK GDPR or the Swiss FADP define it.

For that data you are the controller and we are the processor. Where the two documents conflict on the processing of personal data, this one wins.

You do not need to sign anything for it to apply. If your procurement process needs a countersigned copy, write to [email protected] and we will sign one.

This section is Annex I of the standard contractual clauses and the description Article 28(3) requires.

Data exporterYou, the account holder, at the details on your account. You are the controller
Data importerKaho LLC, a Delaware limited liability company, 19 Beechtree Lane, Bronxville, NY 10708, United States. Contact: [email protected]. We are the processor
Subject matterConversion of PDF documents to Markdown; extraction of tables of contents and document structure
DurationFor each document, the length of the request. For account data, the life of your account plus the retention periods in §9
Nature and purposeAutomated conversion and the metering, billing and fraud prevention that support it. No human reads your documents
Categories of personal dataWhatever your documents contain — we do not classify, inspect or index it — plus your account email address, request metadata including source IP address, and payment records
Special category dataNot requested and not required. You may send documents containing it; we apply the same measures to all content and do not treat it differently, so do not send special category data if that treatment is not enough for you
Categories of data subjectWhoever appears in the documents you send, and the individuals who hold or use your account
FrequencyContinuous, on your API calls
Competent supervisory authorityDetermined by your own establishment or your Article 27 representative

We will:

  1. Process only on your documented instructions, including for transfers. Your API calls and your configuration are those instructions. If we are required by law to process otherwise, we will tell you first unless that law forbids it.
  2. Tell you if an instruction infringes the GDPR or other data protection law, in our opinion.
  3. Keep it confidential. Access to production systems is limited to the operator of the service, under a duty of confidence. There is presently one such person.
  4. Apply the security measures in §5, as Article 32 requires.
  5. Respect the sub-processor conditions in §6.
  6. Help you answer data subject requests — see §7.
  7. Help you with Articles 32 to 36: security, breach notification, data protection impact assessments and prior consultation, taking into account what we know and what is available to us.
  8. Delete or return the data at the end, per §9.
  9. Give you the information needed to demonstrate compliance, and allow audits per §10.

You warrant that you have a lawful basis for the personal data you send us, that you have given the notices and obtained any consents your own processing requires, and that your instructions to us are lawful.

Do not send us personal data you do not need to send. The service converts a document; it does not require the document to identify anyone.

This section is Annex II of the standard contractual clauses. The measures are technical and organisational, and each is a fact about the system rather than an aspiration:

  • Documents are not retained after the request. Today there is no upload endpoint, so input bytes exist in memory for the life of the request only.
  • Conversion is isolated. It runs in its own service, on its own machines, reachable only by our API. The container runs as an unprivileged user from a distroless base with no shell and no package manager, makes no outbound network connection, and the PDF engine is compiled without a JavaScript engine, without XFA and without image decoding on the default path.
  • Encryption in transit throughout, TLS 1.2 or better. Encryption at rest by the underlying platforms.
  • Authentication. API keys are stored only as peppered hashes and cannot be recovered, only replaced. Console sign-in is Google OAuth; we never hold a password. Revocation takes effect on the next request.
  • Segregation. The result cache is keyed to your account and project. The worker that holds payment credentials is a separate deployment from the one that parses documents.
  • Retention limits are enforced by scheduled jobs and storage lifecycle rules, not by intention: cached output is deleted after 24 hours, request metadata after 540 days.
  • Logging. The API worker writes no application log of its own beyond a retention-job line. Document bytes and converted output are never written to a log, and no document content appears in a URL — the document travels in the request body and is never named in a path or a query string.
  • Availability. State lives in managed, replicated stores. We do not operate our own database servers.

We may change these measures, but not in a way that materially reduces the overall level of security.

You give general written authorisation for us to engage sub-processors. The current list, with what each does and where, is on the privacy page and forms part of this addendum.

We will give 30 days’ notice before adding or replacing one. If you object on reasonable data protection grounds within that period and we cannot resolve it, you may terminate and we will refund the unspent balance on your account.

Each sub-processor is bound by data protection obligations no less protective than these, and we remain fully liable to you for their performance.

If a data subject contacts us directly about data we process for you, we will tell them to contact you and will not respond substantively, except to confirm that we are a processor.

We will help you respond to access, rectification, erasure, restriction, portability and objection requests, taking into account the nature of the processing. In practice: the data we hold for you is your account data and request metadata, both reachable from the console and the API, and your documents are not held at all, which makes most such requests short.

Where our help requires more than trivial effort, we may charge our reasonable costs, and we will tell you before we do.

We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting personal data we process for you. We will not wait until the picture is complete to tell you it happened.

The notice will describe the nature of the breach, the categories and approximate number of data subjects and records involved so far as known, the likely consequences, the measures taken or proposed, and a contact point.

Documents are not retained after the request they were sent for.

On termination of your account, and at your choice, we delete or return the personal data we process for you, and delete existing copies, within 30 days.

Ledger and purchase records are retained for 7 years and are not deleted on request: they are financial records we are legally required to keep, they identify an account rather than a person, and they contain no document content. This is the exception Article 28(3)(g) permits where Union or Member State law requires storage.

We will make available the information needed to demonstrate compliance with this addendum, and will answer reasonable security questionnaires.

You may audit us, or appoint an independent auditor, once in any 12 months on 30 days’ notice, at your cost, during business hours, without unreasonable disruption, and subject to confidentiality. More often if a supervisory authority requires it or after a breach affecting your data.

We hold no SOC 2 or ISO 27001 certification and will not imply that we do. There is no site to visit; what we offer instead is honest documentation and direct access to the person who built the system.

We process personal data in the United States.

For transfers from the EEA, the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, module two (controller to processor), are incorporated into this addendum by reference and form part of it, with:

  • Clause 7 (docking): included.
  • Clause 9 (sub-processors): Option 2, general written authorisation, with the 30 days’ notice period in §6.
  • Clause 11 (redress): the optional independent dispute resolution paragraph is not included.
  • Clause 17 (governing law): the law of Ireland.
  • Clause 18 (forum): the courts of Ireland.
  • Annex I: §2 above, with you as data exporter and us as data importer, and the sub-processor list on the privacy page.
  • Annex II: §5 above.

For transfers from the United Kingdom, the above applies as amended by the UK International Data Transfer Addendum (version B1.0), which is likewise incorporated by reference; Tables 1 to 3 are populated by the sections named above, and in Table 4 the party that may end the addendum is the importer.

For transfers from Switzerland, references to the GDPR are read as references to the FADP, the competent authority is the FDPIC, and “member state” includes Switzerland for the purpose of data subject rights.

Where a lawful transfer mechanism replaces or supplements the above, it applies automatically from the date it takes effect.

Liability under this addendum is subject to the limits in §13 of the terms of service, except where data protection law does not permit that — in particular, nothing here limits a data subject’s rights under the standard contractual clauses.

[email protected].