Data Processing Addendum

Version 1.0 — last updated 2026-07-16.

This page is print-friendly. Print to PDF for your records, or grab the plain-text copy directly.

Download dpa.txt

1. Definitions

"Customer" means the organization or individual using the txtfetch API under an accepted plan. "txtfetch," "we," or "us" means the operator of the txtfetch service. "Data Processing Agreement" or "DPA" means this document. "Document Content" means the file bytes or URL-fetched content Customer submits to the API for text extraction. "Personal Data" has the meaning given under applicable data protection law (e.g. GDPR Art. 4(1)) to the extent it appears within Document Content.

2. Roles

With respect to Document Content, Customer is the data controller and txtfetch is the data processor, acting only on Customer's documented instructions as expressed through API calls. With respect to Customer's own account and billing information, and to contact-form submissions, txtfetch is the controller — see the privacy policy.

3. Scope and nature of processing

txtfetch processes Document Content solely to perform text extraction (via Apache Tika, with Tesseract OCR for image-based documents) and to return the extracted text to Customer. Document Content is held in memory for the duration of the request and is not persisted to any datastore. Processing occurs in AWS us-west-2 unless otherwise agreed in writing.

4. Sub-processors

txtfetch uses a defined set of infrastructure sub-processors to deliver the service — see the current list, with purpose, data handled, and region, at /subprocessors. txtfetch will update that list before adding a new sub-processor that touches Document Content.

5. Security measures

txtfetch's technical and organizational measures — what's enforced today and what's on the roadmap — are described in full at /security, including TLS in transit, AWS-managed encryption at rest, in-memory-only processing of Document Content, and planned hardening (SSRF guards, abuse controls, automated patch scanning, SOC 2 Type II).

6. Assistance with data-subject requests

Because Document Content is not retained, txtfetch generally has no stored Document Content to search, export, or delete in response to a data-subject request. Where Customer needs assistance responding to a request that implicates txtfetch's processing, contact us via /contact and we will assist as reasonably required.

7. Breach notification

If txtfetch becomes aware of a security incident affecting Customer's Document Content, we will notify Customer without undue delay after becoming aware, using the contact details on file or via /contact, and provide the information reasonably available at the time.

8. Deletion and return

Because Document Content is not retained beyond the lifetime of a single request, there is no stored copy to return or delete at the end of a processing engagement. Any operational logs are handled per the patch and retention posture described at /security.

9. International transfers

Document Content is processed in AWS us-west-2 (United States). Where Customer is located outside the United States, Customer instructs txtfetch to process Document Content in the United States for the purpose of this DPA. Site analytics data is processed by Plausible in the EU, on an aggregate, cookieless basis.

10. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the agreement governing Customer's use of txtfetch. Nothing in this DPA expands either party's liability beyond that agreement.

11. Contact

Questions about this DPA, or requests to execute a signed copy, should go through /contact.