Privacy Policy
As of 10 August 2026 · applies to pdftoolkit.ch and the associated web app
The essentials first: There is no tracking, no advertising and no third-party analytics. Your documents are not passed on to third parties, not analysed and not used to train software. No access logs with visitor IP addresses are kept. Emails only arrive when you trigger them — to confirm your address or to reset your password, never as advertising.
1 · Controller
The person named above is responsible for the processing of personal data on pdftoolkit.ch. Swiss data protection law (FADP) applies.
2 · What data is processed
Account
Registration collects:
- Email address — serves as your username for signing in.
- Display name — optional, used only to greet you in the interface.
- Password — never stored in plain text, only as a bcrypt hash (cost factor 12).
- Time the account was created and the storage quota assigned to it.
- Interface language — so that emails arrive in the same language.
- Whether the email address has been confirmed — as a yes/no value only; confirming is voluntary and nothing is blocked without it (section 8).
Two-factor authentication (optional)
If you switch on two-factor authentication, two further items are added:
- A TOTP key, from which your authenticator app derives the six-digit codes. It is stored encrypted (Fernet, with a key derived from the server secret) — not in plain text.
- Ten recovery codes, stored as hash values. They cannot be recomputed from the database; they are shown exactly once during setup.
The sole purpose is to secure your sign-in. When you switch the feature off, the key and the codes are deleted immediately, as they are when you delete your account. If you lose your second device along with the codes, the operator can reset the feature for your account — after that your password is enough again.
To protect against password guessing, failed sign-in attempts are counted temporarily in memory (email address and IP address, 15 minutes). These counters never reach the database and disappear on every restart.
Sign-in (session)
After signing in, a cookie named pdftk_session is set. It is
httpOnly (unreadable to JavaScript), Secure (HTTPS only)
and SameSite=Lax. It is valid for 30 days. The database stores not the
token itself but only its hash value.
This cookie is technically necessary to keep you signed in. No other cookies are set — in particular none for statistics, recognition or advertising. That is also why there is no cookie banner.
Documents and files
- The PDF files you upload, together with the result files created from them (merged, split, compressed, OCR-processed, signed).
- Their metadata: file name, size, page count, origin of the file and time of creation.
The files are held in a library assigned to your account and are processed solely for the step you trigger yourself. No analysis of the content takes place. One technical exception is the smart rename feature: it reads the text of the first page in order to form name suggestions. This happens on the same server, the result is not stored and never leaves the application.
Signing certificates
For digital signatures you can create your own certificate. The private key is stored in your library and can be protected with a password of your choosing. That certificate password is stored nowhere — if you lose it, the certificate can no longer be used.
Log data
The web server in front of the application (Caddy) is configured without access logging. The application logs requests only with the internal address of the reverse proxy, not with visitors' IP addresses. In the event of technical faults, error messages may appear in the server log; these serve troubleshooting only.
3 · Purpose and legal basis
Data is processed in order to provide the service: maintaining your account, enabling sign-in, storing files and carrying out the PDF operations you choose. The basis is the performance of this user relationship, which you enter into by registering. No processing takes place for advertising, profiling or sales purposes.
4 · Where the data is stored
The service runs on a rented server at Hetzner Online GmbH, Industriestrasse 25, 91710 Gunzenhausen, Germany. The data centre used is in Nuremberg, Germany. Hetzner provides the infrastructure and acts as a processor; in normal operation it does not access any content.
Your data is therefore stored in Germany and not in Switzerland. Germany appears on the Federal Council's list of countries with an adequate level of data protection (Annex 1 of the Data Protection Ordinance).
For sending confirmation and password emails, the mail server of united-domains AG in Germany is additionally used (details in section 8).
Beyond operating the service, no data is transmitted to any other third party. No external services are embedded — no fonts, scripts, maps or video embeds from foreign servers. When you open this website, only resources from pdftoolkit.ch are loaded.
5 · Security
- Transmission is exclusively encrypted via HTTPS (TLS), with automatic redirection of unencrypted requests and HSTS enabled.
- Passwords are stored as bcrypt hashes and cannot be reversed.
- Access to files is tied to the respective account.
Nobody can guarantee absolute security for transmission over the internet. For particularly sensitive documents: judge for yourself whether storing them in an online service is appropriate.
6 · Retention and deletion
- Files can be deleted by you at any time in the app. They are removed from your library in the process.
- Sessions expire after 30 days; signing out invalidates the session immediately.
- Your account can be removed permanently by you in the app, under Account → Delete account. This deletes the account, all files, the signing certificates, pending jobs and every session — both in the database and on disk. The process requires your password and the entry of your email address as confirmation, and it cannot be undone.
- If you get stuck, a message to thomas@conduxa.ch is enough.
Inactive accounts
As long as an account is in use, the associated data remains stored. If an account is not used for twelve months (no sign-in), it is deleted after two warnings:
- After 12 months without a sign-in: first warning by email, stating that the account will be deleted in 44 days.
- 30 days later: second and final warning.
- A further 14 days later: deletion of the account with all files, certificates and shares.
A single sign-in is enough to keep the account — the period then starts again and any warning already issued lapses. Accounts that were never confirmed and contain no files are removed silently after 90 days without a sign-in; a warning email to an address that was never confirmed would be pointless.
The purpose is data minimisation: what nobody needs any more should not be stored indefinitely. For this rule, only the time of the last sign-in and the warning stage reached are stored.
Backups
In case of a server or disk failure, an encrypted daily backup to a Hetzner Storage Box in Germany is planned. The processor would be Hetzner Online GmbH; the backup is encrypted before transfer, so Hetzner cannot read its contents. 7 daily and 4 weekly states would be retained.
This means: deleted files and accounts may persist in backups for up to 35 days and are only gone for good after that. They are removed from live operation immediately.
As of today this backup is not yet active. Once it runs, this section will be updated accordingly. Regardless of that, please keep your own copies of your files — the library is a workspace, not an archive.
7 · Your rights
Under Swiss data protection law you have, in particular, the right
- to request information about which data concerning you is processed,
- to have incorrect data corrected,
- to request the deletion of your data,
- to receive your data in a common format,
- to object to the processing.
Please contact thomas@conduxa.ch. So that no data reaches unauthorised persons, proof of identity may be required in cases of doubt.
You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
8 · Email
The service sends emails for two purposes only:
- Confirming your email address after registration. The link is valid for 48 hours. Confirmation is voluntary — without it the service remains fully usable.
- Resetting your password, when you request it yourself. The link is valid for 60 minutes and can be used once; afterwards all signed-in devices are signed out.
There are no newsletters, no advertising and no product announcements — no mail is sent that you did not trigger by your own action. Unsubscribing is therefore unnecessary; the email address also serves as your sign-in name.
Sending uses the mail server of united-domains AG (Gautinger Strasse 10, 82319 Starnberg, Germany). They act as a processor; what is transmitted is your email address, your display name and the content of the respective message. No further data is passed on for sending — in particular no documents.
Only a hash value of the links is stored, not the link itself. No valid link can therefore be reconstructed from the database. Expired and used entries are invalidated.
Beyond that, contact only arises if you write yourself.
9 · Share links
You can create a share link for a file. Anyone who knows the link can download the file without an account — that is the point of the feature, but it also means the link is the secret. Only pass it on to people you would entrust with the file.
- You set the validity period (1, 7 or 30 days); after that the link expires automatically.
- Optionally you can set a password and limit the number of downloads.
- Links can be revoked at any time, with immediate effect. If the file goes to the trash, all associated links become invalid at once.
- Only a hash value of the link is stored, not the link itself.
- Share pages carry
noindexand are not indexed by search engines. - If a link has expired, been revoked or never existed, the same neutral page always appears — it cannot be used to infer whether a file exists.
Opening a share page creates no visitor profiles; only the number of downloads per link is counted, so that a limit you set can take effect.
10 · Trash
Deleted files first go to a trash and are permanently deleted there automatically after 30 days. Until then they can be restored — and they still count towards your storage quota, because they really are still on the server. You can remove them permanently by hand at any time. If you delete your account, the trash is deleted along with it, leaving nothing behind.
11 · Changes
This policy is adjusted when the service changes. The version published here, with the date given above, is the authoritative one.