Privacy Notice
for PDF Copilot by PDF Expert

Date: Nov 27, 2025

Key Changes to the Privacy Notice for PDF Copilot by PDF Expert

At Readdle, we care about our users, and, as PDF Copilot by PDF Expert evolves, we have improved this Privacy Notice governing your use of this website.

In a nutshell, we clarified how we handle the feedback and support requests.

We encourage you to carefully review the full text of this Privacy Notice. The changes become effective as of the publication date above.

Intro

Readdle Limited (“Readdle”, “we”, or “us”) welcomes you. We provide you with access to our web application “PDF Copilot by PDF Expert” (“App” or “PDF Copilot”) and related website services (collectively, the “Service”), subject to the terms and conditions of our Terms of Service.

This Privacy Notice describes what personal data the Service collects, how stores, processes, and uses it, and what happens when you use the Service. We understand you care about your privacy, and we appreciate the trust you place in us. To justify that trust, we embed the latest data security standards, improve our awareness of privacy matters, and comply with the General Data Protection Regulation and other privacy laws.

When you use our application for Mac and iOS “PDF Expert”, your personal data is processed in accordance with the Privacy Notice for PDF Expert App.

If you have any questions or comments about this Privacy Notice, please feel free to contact us.

About Us

We are the controller of your personal data processed in connection with the Service. This means that we determine the purposes and means of personal data processing.

Controller
Readdle Limited
Company number
630281
Address
Glandore Business Centres, 26-27 Fitzwilliam Place, Fitzwilliam Hall, Dublin 2, D02T292, Ireland
Data Protection Officer
Privacity GmbH, Neuer Wall 50, 20354 Hamburg, Germany
Email
rdsupport@readdle.com – for general inquiries
dpo@readdle.com – for privacy inquiries

Our support team is happy to assist you in any matter. We kindly ask you to be polite and calm in your communication with us. Otherwise, we may not respond to offensive emails/messages.

About You

When you access or use the Service, you become our user (“User”), and we collect and process some of your personal data.

Please note that we do not knowingly process the personal data of Users under the age of 16. If you are such a User or you are a legal representative of such a User, please contact us.

Personal Data

Sources of Data

We collect data directly from you or automatically when you access or use the Service. We may generate some data in relation to you, for example a user ID. We may also, although we do not necessarily do so, receive data from third parties. It depends on your settings and the features you use.

Lawful Bases for Processing

To process your personal data, we rely on one of the following lawful bases:

  • performance of the contract — for the processing of personal data necessary for the negotiating on, conclusion, and performance of a contract (mainly, Terms of Service) with you;
  • legal obligation — for the processing of data as required by applicable laws (for example, to comply with tax or KYC/AML regulations) or if requested by a law enforcement agency, court, supervisory authority, or another state-authorized public body;
  • legitimate interest — for the processing necessary for the development of our services and security, taking into consideration your interests, rights, and expectations;
  • consent — for additional processing for specific purposes.

Personal Data in PDF Copilot by PDF Expert

We collect your personal data according to this Privacy Notice when you access or use the Service, depending on how you interact with it, what features you use, and what subscription you have.

Technical Data

We collect identifiers, technical information, usage, and diagnostics data about the Users to optimize performance, debug issues, and improve our Service while ensuring security and privacy to improve the overall user experience. Some data may be collected via cookies and similar technologies; for more details please refer to our Cookie Policy.

DataReasons for ProcessingLawful BasisData Storage
  • User ID
  • Device info (device ID, IP address, phone settings, local time, country and city, language, etc.)
  • Files metadata (size, number of pages, etc.)
  • Crash and error logs
Providing you with the ServicePerformance of the contractWe store the data during your use of the Service and for six (6) years after your account deletion. If your account is inactive for thirty six (36) months, we may delete it by ourselves with a prior notice.
  • Analytics ID
  • Device info (device ID, IP address, phone settings, local time, country and city, language, etc.)
  • Interactions with the Service, its screens, and features (e.g., activation of the feature)
  • Files metadata (size, number of pages, etc.)
  • Crash and error logs
Improvement of the ServiceLegitimate interestWe store the data until you object to the processing where we have your email and can identify you

Information about You

We may ask you for some information about yourself to register an account, provide you with the Service and communicate with you.

DataReasons for ProcessingLawful BasisData Storage
  • Email
  • Name
Registration and maintaining your accountPerformance of the contractWe store the data during your use of the Service and for six (6) years after your account deletion. If your account is inactive for thirty six (36) months, we may delete it by ourselves with a prior notice.
Confirming your subscription status
Confirming the payment for compliance with the applicable lawLegal obligation
Communication with you about the product (updates, recommendations, tips, news) and our major news and offersLegitimate interestWe process the data during the performance of the contract or until you unsubscribe

Payments Data

We collect some additional data to process your payments. We also keep the history of payments, as this is a legal requirement, and we cannot delete this information until the filing of the annual accounts expires.

DataReasons for ProcessingLawful BasisData Storage
  • Customer ID
  • Email
  • Country
  • Charging platform name
  • Information about the payment (date, time, currency etc.)
  • Subscription start and expiration dates
  • Subscription status
  • Subscription autorenewal
Confirming the payment for compliance with the applicable lawLegal obligationWe store the data during your use of the App and for six (6) years after your account deletion. If your account is inactive for thirty six (36) months, we may delete it by ourselves with a prior notice.
Confirming the payment for providing you with the paid features of the AppPerformance of the contract

User Content and App’s Features

We collect personal data to provide you with the Services depending on your interactions with it.

Files Management

DataReasons for ProcessingLawful BasisData Storage
FilesProviding you with the ServicePerformance of the contractWe store the data during your use of the Serice and fourteen (14) days after deletion of your account. If your account is inactive for thirty six (36) months, we may delete it by ourselves with a prior notice.
If you have not signed in to your account, the files are stored for 1 day.

AI Chat features

You will have access to AI chat features. The request within the AI chat features is processed in two steps.

  • First, we receive your request, and then transmit it to an AI provider for processing.
  • Second, we receive the output and provide the result back to you.

We do not control or edit the data included in your requests as well as we do not change results delivered by an AI provider.

We process your requests within the AI Chat features with the engagement of different third-party AI providers (Open AI by Open AI LLC and Vertex AI by Google). We may switch between the AI providers to provide a more secure and faster service, to run new versions of models, or for other commercially justifiable reasons. The switch between the providers is manual, and we retain full control over it. We will not provide notification about such switches.

Please note that the AI providers commit not to use the User’s data to train their models. They retain the data sent within the request for abuse and misuse monitoring purposes for a maximum of thirty (30) days, after which it is deleted, unless otherwise required by law.

DataReasons for ProcessingLawful BasisData Storage
  • File
  • Type and text of the request
  • Email address
  • User ID
  • Technical data
  • Result of the request
  • Errors
Providing you with the App featuresPerformance of the contractWe store the data until you delete a relevant document or clear the AI Chat history. We do not store this data. After completion of your request, the data is deleted.
The AI providers may store the data up to thirty (30) days, unless otherwise required by law.
  • Type and text of the request
  • Size of the response
  • Technical data
  • Errors
Analytics and improvement of the AppLegitimate interestWe store this data until deletion of your account or object to the processing
You can also delete your communication in the AI Chat by clearing the chat in the App.

Support Requests Data

When you address your request to support in relation to the Service, we collect some information to help you. We may collect your detailed log files to help you with your problem. These log files may contain sensitive personal information and are connected to you.

For resolving your support requests, we may offer the option of using AI-powered assistance from a trusted provider. In this case, you can get quick, automated responses to your inquiries. No data will be used for training. Still, you can always choose to continue without AI, if you prefer so.

We may also collect analytics on request categories to improve our services and responses.

To process and analyse your requests more efficiently, we may engage trusted AI providers. Before proceeding with these providers, we always take necessary technical and organizational precautions, including pseudonymisation, data minimization, conducting data protection impact assessments, and establishing data processing agreements. No data is used for training.

Depending on the source of your request, we may process the following data:

Request Submitted via Email

DataReasons for ProcessingLawful BasisData Storage
  • Email
  • Name
  • Type of device
  • Text of the request
  • Attached files
  • Logs
Assistance with your support requestPerformance of the contractWe store the data during communication and for six (6) years after the last communication on the ticket

Request Submitted through the Support Chat

DataReasons for ProcessingLawful BasisData Storage
  • Messages and commands in the chat
  • Chat User ID and Chat ID (it is not linked to your name or email, unless you share them)
  • Name and email
  • Technical data
To respond to your requestPerformance of the contractIf you submit your request to our support team, the data is stored during communication and for six (6) years after the last communication on the ticket
If you use Support Chat but do not submit your request to our support team, the data is stored during communication and up to one (1) year after closing the conversation.
  • Interaction with the Support Chat
  • Chat User ID and Chat ID (it is not linked to your name or email, unless you share them)
  • Technical data
Improvement of the ServiceLegitimate interestStored during communication and up to one (1) year after closing the conversation.

Feedback Data

We may reach out to request your feedback. Your insights are invaluable to us for enhancing the Service and improving user experience.

DataReasons for ProcessingLawful BasisData Storage
EmailTo ask for your feedback or suggest participation in the users’ surveysLegitimate interestWe process data in this way until you unsubscribe

When you submit your feedback about the Service to us directly or via third-party platforms, we process personal data in your feedback, which may include the data listed below.

Feedback Provided to us Directly

DataReasons for ProcessingLawful BasisData Storage
  • Email
  • Name or username
  • Attachments and/or photos
  • Other information about you, such as social handles, occupation etc.
Communication regarding your feedback and consentLegitimate interestWe store the data for six (6) years from the feedback or the last communication on feedback, or until you withdraw the consent
Improvement of the Service
Use in marketing activitiesConsent
  • Feedback, including text feedback, answers to the review forms, or feedback provided orally in the meeting
  • Other information related to your feedback such as rating, the date of the feedback, etc.
Improvement of the ServiceLegitimate interest
Use in marketing activities
  • Meeting records
Improvement of the Service and/or Use in marketing activitiesConsent

Feedback Provided via a Third-party Platform

DataReasons for ProcessingLawful BasisData Storage
  • Name or username
  • Feedback, including text feedback and rating
  • Any other information related to your feedback such as the date of the feedback, etc.
To use your feedback in our product development and/or marketing activitiesLegitimate interestWe store the data for two (2) years from feedback or the last communication on feedback

We may collect analytics on the categories of issues mentioned in the feedback to improve our services. To process and analyse your feedback more efficiently, we may engage trusted AI providers. Before proceeding with these providers, we always take necessary technical and organizational precautions, including pseudonymisation, data minimization, conducting data protection impact assessments, and establishing data processing agreements. No data is used for training.

Feature Request Data

When you submit your feedback through the Website, you might also request a new feature. Your insights are invaluable to us for enhancing the Service and improving user experience. We process personal data regarding a feature request in a way described below:

DataReasons for ProcessingLawful BasisData Storage
  • Feedback, including feature request details
  • Attached files
  • User email or Chat URL
  • Ticket ID
  • Technical data
To process your proposalConsentStored for six (6) years, or unless you withdraw your consent

We may collect analytics on the categories of User requests to improve our services. We may retain AI providers to define the category of your request more efficiently. The requests are pseudonymised before such processing. No data will be used for training.

Data Received from Third Parties

We may receive some personal data from third parties.

The amount of data collected, the purposes, and the lawful bases for processing are determined by the respective privacy documents of these parties.

Third PartyPrivacy Documents
GooglePrivacy Policy
ApplePrivacy Policy
OpenAIPrivacy Policy
Enterprise Privacy
Vertex AIPrivacy Policy

Data Sharing with Third Parties

We may share your personal data with third parties without causing you any harm and in strict compliance with applicable privacy laws. Additionally, we maintain organizational and technical measures to secure your personal data during its transfer to third parties.

To share your data, we rely on the lawful bases such as consent, compliance with the law, and performance of a contract, depending on the specific circumstances.

Third PartyDescription
Analytics toolsWe use analytics tools to understand and promote our business.
ContractorsWe cooperate with contractors to operate, develop, and improve the Service, fulfill your support requests, etc.
We sign data processing agreements with them and impose various security measures to ensure your data is safe.
Services PDF Copilot Web usesWe use third-party services to provide you with the Service.
For example, we use different third-party AI providers (Open AI by Open AI LLC, and Vertex AI by Google) to offer the AI features.
You can find links to the privacy documents of AI providers here.
Services our team usesWe use CRM systems, messengers, and other services in our organization to provide you with our services.
For example, to manage and fulfill privacy requests we use:
  • Spark for processing requests and communication with the user;
  • Jira for internal tracking and timely involvement of responsible ones in scope of request.
State authorities, courts, law enforcement agencies, etcWe may be obliged to transfer some of your data to tax authorities, courts, law enforcement agencies, and other governmental bodies:
  • to comply with a government request, court order, or applicable law;
  • to prevent unlawful use of the Service;
  • to protect against claims of third parties;
  • to help prevent or investigate fraud.

To get a detailed list of the third-party recipients of your personal data, contact us.

Data Sharing Outside the European Economic Area

The personal data we collect is stored on the US servers, which participate in the Data Privacy Framework and European Economic Area (“EEA”) servers, which fall under the General Data Protection Regulation.

We may share personal data with the recipients in the USA and other countries, including non-EEA ones, ensuring that your data is protected and processed in accordance with the General Data Protection Regulation.

To share the data outside the EEA, we rely on the adequacy decision by the European Commission or the Data Privacy Framework participation of the recipient. If the recipient does not participate in the Data Privacy Framework and its country is not deemed to provide an adequate level of protection for your personal data, we adopt Standard Contractual Clauses based on legislation assessments for data protection during transfer and storage.

You can read more detailed measures to protect your personal data here.

Security Measures

We routinely conduct Data Protection Impact Assessments to guarantee the implementation of adequate technical and organizational measures. These measures aim to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.

To enhance the protection of your personal data, we employ HTTPS and encryption, establish segmented group and individual access (as necessary), utilize an alarm system, implement a corporate VPN, and adhere to formally approved internal policies, including those for password management and physical access.

Furthermore, we consistently monitor the state of the art of our technologies and diligently maintain backups. Additionally, all our contractors are bound by contractual obligations that comply with the GDPR and other privacy legislation requirements.

You can contact us in case of any questions regarding security issues.

Here you can find information about the steps we mentioned above:

Physical Measures

  • Limited Access to Premises

Organizational Measures

  • Policies and Instructions
  • Password policy
  • Monitoring and physical access policy
  • Contractual obligations and corporate VPN
  • Internal security policy
  • Access control policy

Transfer Protection

  • Data Transfer Agreements
  • Standard Contractual Clauses
  • Data Privacy Framework

Contractor and Staff Training

  • Agreements
  • Non-disclosure Agreements
  • Data Processing Agreements

Regular Access and Policy Review

Privacy Protection

  • Privacy by design and by default
  • Internal procedures for GDPR compliance

Code Review

Technical Measures

  • Encryption Technologies
  • Encryption in transit
  • Backup encryption
  • State-of-the-art methods of cryptographic keys

Backup

  • Regular backup of the entire system
  • Redundant operation of the critical services in multiple data centers controlled by a high-availability system

Two-factor Authentication

Stress-tests

Static Analysis

Quality Assurance

Regular Patch Management

Dependency and Supply Chain Vulnerability Check

Data Subjects Rights

As a data subject, you have the right to access, manage, and control your data either directly or by submitting a request to us. This section outlines these rights and explains how you can exercise them based on your place of residence.

European Economic Area and United Kingdom Residents

RightDescription
Right to accessYou can request an explanation of the processing of your personal data.
Right to rectificationYou can change the data if it is inaccurate or incomplete.
Right to erasureYou can send us a request to delete your personal data from our systems. We will remove them unless otherwise provided by law.
Right to restrict the processingYou may partially or completely prohibit us from processing your personal data.
Right to data portabilityYou can request all the data you provided to us and request to transfer data to another controller.
Right to objectYou may object to the processing of your personal data.
Right to withdraw consentYou can withdraw your consent at any time.
Right to file a complaintIf your request was not satisfied, you could file a complaint to the regulatory body.

To exercise your rights, contact us.

For EEA residents: we will answer your request within one (1) month. If your request is not satisfied, you can submit a complaint to your local Data Protection Authority. You may find it here.

For UK residents: we will answer your request within one (1) month. If your request is not satisfied, you can submit a complaint at the Information Commissioner’s Office via number 0303-123-1113 or go online at www.ico.org.uk/concerns.

United States Residents

Your rights may vary depending on the state of your residency, as indicated below.

RightDescriptionArea
Right to accessYou can request an explanation of the processing of your personal data.California; Colorado; Connecticut; Indiana; Iowa; Montana; Tennessee; Texas; Utah; Virginia.
Right to correctYou can change the data if it is inaccurate or incomplete.California; Colorado; Connecticut; Indiana; Montana; Tennessee; Texas; Virginia.
Right to deleteYou can send us a request to delete your personal data from our systems.California; Colorado; Connecticut; Indiana; Iowa; Montana; Tennessee; Texas; Utah; Virginia.
Right to portabilityYou can request all the data you provided to us and request a data transfer to another controller.California; Colorado; Connecticut; Indiana; Iowa; Montana; Tennessee; Texas; Utah; Virginia.
Right to opt out of salesThe right to opt out of the sale of personal data to third parties.California; Colorado; Connecticut; Indiana; Iowa; Montana; Tennessee; Texas; Utah; Virginia.
Right to opt out of certain purposesThe right to opt out of processing for profiling/targeted advertising purposes.Colorado; Connecticut; Indiana; Montana; Tennessee; Texas; Utah; Virginia.
Right to opt out of the processing of sensitive dataThe right to opt out of the processing of sensitive data.California.
Right to opt in for sensitive data processingThe right to opt in before the processing of sensitive data.Colorado; Connecticut; Indiana; Montana; Tennessee; Texas; Virginia.
Right against automated decision-makingA prohibition against a business making decisions about a consumer based solely on an automated process without human input.California; Colorado; Connecticut; Indiana; Iowa; Montana; Tennessee; Texas; Virginia.
Private right of actionThe right to seek civil damages from a controller for violations of a statute.California.

To exercise your rights, contact us.

We will answer your request within thirty (30) to sixty (60) days, depending on the state and legislative requirements. If your complaint is not satisfied, you can submit a complaint with the Federal Trade Commission.

Please note! Some states do not have privacy laws. The rights of residents of such states are governed by U.S. federal law. If your state is not on the list, please contact us.

Do Not Sell My Personal Information

Under the California Consumer Privacy Act (CCPA), California residents possess the right to opt out of the “sale” of their personal information by entities governed by the CCPA.

We do not sell your personal information to anyone, nor do we use your data as a business model. Ensuring your privacy is our top priority, and we are fully committed to safeguarding it.

We adhere to the CCPA by providing California residents the option to opt out of any potential future sale of their personal information. If you wish to register your preference that we do not sell your data in the future, please contact us at dpo@readdle.com.

Do-Not-Track Requests

California residents using our Service have the option to request that we do not automatically collect and track information related to their online Browse activities across the Internet.

These requests can usually be made via web browser settings that manage signals or other mechanisms, enabling consumers to express their preferences concerning the collection of personal data about their online activities over time and across third-party websites or online services.

We currently do not have the ability to honor these requests. However, we may update this Privacy Notice as our capabilities evolve.

Canada Residents

RightDescription
Right to be informedWith the help of this Notice and Terms of Service, we enable your right to be informed of the purposes of the processing, including automated processing, the categories of personal data processed, the recipients or categories of recipients of such data, and the storage periods.
Right to accessYou can request an explanation of how your personal data is processed.
Right to correction/rectificationYou can change the data if it is inaccurate or incomplete.
Right to delete (Quebec residents only)You can send us a request to delete your personal data from our systems. We will remove all data except what we are obliged to store in compliance with the law requirements.
Right to data portability (Quebec residents only)You can request all the data you provided to us and request a data transfer to another controller.
Right to withdraw consentYou can withdraw your consent at any time.
Right not to be subject to automated decision-makingYou have the right to know if there are consequences for you due to automated processing. You can object to being subject to such processing.
Right to lodge a complaintIf your request is not satisfied, you can file a complaint to the regulatory body.

To exercise your rights, contact us.

We will answer your request within thirty (30) days. If your complaint is not satisfied, you can submit a complaint to the Office of the Privacy Commissioner of Canada.

Privacy Notice Updates

The Privacy Notice and the relationships falling under its effect are regulated by the General Data Protection Regulation. Please note that laws and requirements for processing personal data can evolve. In the event of changes, we will release an updated version of the Privacy Notice to reflect these modifications.

If we make substantial changes to the Privacy Notice or the Service that affect your data privacy rights, we will notify you by email or display information on the website and ask you to read it. You will be notified in advance, and if you continue to use the Service after these changes take effect, it will be considered that you have consented to and accepted the revised Privacy Notice.