Skip to content

Privacy

Privacy Policy

This policy explains how exdata handles personal data across the public site, advertising measurement, accounts, API usage, document extraction, billing, support, security, and service administration.

1. Scope

This Privacy Policy applies to exdata’s public website, advertising measurement, API documentation, account workspace, document extraction API, billing flows, support interactions, and service communications.

exdata is a product and service operated by Outer Platforms Limited (“Company”). For customer-uploaded documents and extracted content, the customer decides what is uploaded, why it is processed, and how long it should be retained. For account administration, billing, security, service administration, support, and legal records, the Company may act as an independent controller where necessary to run and protect the service.

The controller for account, billing, support, website, and service-administration data is the Company, with its address at Centris Business Gateway, Level 4/W, Triq Is-Salib Tal-Imriehel, Zone 3, Central Business District, Birkirkara, CBD 3020, Malta. Privacy requests can be sent to privacy@exdata.app.

2. Data We Process

  • Account data: name, email address, password hash, account membership, role, invitation status, authentication metadata, and workspace settings.
  • API and integration data: API token metadata, token prefix, scopes, request IDs, idempotency keys, requester labels, webhook endpoints, webhook delivery metadata, and API logs.
  • Document data: uploaded files, extracted text, normalized fields, previews, thumbnails, file metadata, processing state, extraction run versions, feedback, and review notes.
  • Billing data: billing contact details, VAT or tax IDs, credit balance, ledger entries, top-up history, invoices, receipts, payment status, and Stripe customer references.
  • Support and service data: support messages, issue context, audit records, abuse-prevention signals, service logs, error traces, and incident communications.
  • Website data: technical request information such as IP address, browser details, bot-detection signals, pages requested, timestamps, and security logs.
  • Advertising measurement data: only after permission, campaign parameters, advertising click references, landing path, referring host, consent record, registration or purchase event, event time, currency and purchase value, and privacy-preserving matched identifiers such as a normalized one-way hash of an email address.

3. Why We Process Data

The Company processes data through the exdata service to provide document extraction, authenticate users and API requests, manage account access, return structured fields, generate previews, deliver webhooks, process credits and billing, provide support, prevent abuse, improve reliability, comply with legal obligations, and protect the service.

Where the Company acts as controller, the legal bases may include performance of a contract for account, service, and billing administration; legitimate interests in security, support, abuse prevention, and service reliability; compliance with legal, tax, accounting, and regulatory obligations; and consent for advertising measurement and wherever another specific communication, setting, or workflow requires it. Where the Company acts as processor, processing is governed by the customer’s documented instructions and the Data Processing Addendum.

4. AI Processing And Third-Party Providers

The Company uses AI-assisted extraction as part of the exdata service. Uploaded document content, extracted text, or document snippets may be sent to AI subprocessors where needed to extract, interpret, and normalize fields. When a customer separately instructs exdata to perform a temporary quality diagnosis, the approved document sample may also be sent to the listed AI subprocessor to classify an extraction problem. Exdata-held document evidence and document-content processing remain limited by the customer’s instruction and the sample’s existing expiry; content-free diagnosis and lifecycle records follow the account’s operational-log retention setting. This workflow does not create a permanent document corpus or model-training dataset. The Subprocessor List identifies the provider, while its handling and retention of data follow the applicable data-processing agreement and provider terms.

Cloudflare Turnstile protects account registration against automated abuse. It processes the visitor’s IP address, TLS fingerprint, user-agent header, Turnstile site key and associated origin, challenge token, and verification metadata to distinguish legitimate registrations from bots. Cloudflare processes those signals on the Company’s behalf for site protection and describes a separate controller role for improving Turnstile’s bot-detection capabilities in its privacy terms.

The Company also uses infrastructure, billing, email, security, monitoring, and support providers to provide the service. These providers receive data only for defined service functions. Relevant provider categories, processing purposes, roles, and location notes are summarized on the Subprocessor List, which distinguishes production subprocessors from selected providers used for account, billing, and service delivery.

The Company does not use document extraction output to make legal, financial, employment, credit, or similarly significant decisions about individuals on its own behalf. Customers remain responsible for reviewing extraction output before using it in downstream workflows.

5. Advertising Measurement And Privacy Choices

exdata may use enabled Google Ads or OpenAI Ads integrations to understand which consented campaigns lead to account registrations and completed credit purchases. These integrations remain inactive unless exdata enables them. No advertising-platform scripts run in the browser. First-party campaign attribution is stored only after a visitor chooses “Allow measurement,” and matching conversion events are shared with enabled advertising providers only while that permission and the related attribution record remain valid.

Advertising events never contain uploaded documents, filenames, extracted text, extracted fields, API request content, or payment-card details. An advertising event may contain a normalized one-way hash of an account email address, an advertising click reference, a random event identifier, the event time, and—for a completed purchase—the amount and currency.

exdata does not use this website choice to build personalized advertising audiences. Visitors can reject measurement or reopen “Privacy choices” at any time. Withdrawing permission blocks future advertising events and revokes and scrubs the active attribution record; it cannot recall events a provider already received before withdrawal.

6. Retention And Deletion

Account owners and admins can configure retention for source files, previews, extracted metadata, and account history in account settings. Retention controls remove configured document data according to those settings. Customers can also delete documents through the API or workspace where supported.

Customers may separately opt in to a limited quality-review sample for PDF extractions. The option is off by default, has a named approver and expiry, and is available only to authorized personnel for investigating extraction quality. A sample remains after ordinary document deletion only while that approval permits it; withdrawal, expiry, or account erasure removes access and triggers deletion. This optional sample is not consent for permanent training use.

Advertising attribution expires after the configured campaign-attribution period, and matching copies are removed after their shorter configured retention period. The remaining pseudonymous consent record and individual conversion and delivery audit records—including event identifiers, event time, purchase value, and provider receipts or diagnostics—are deleted after the configured conversion-audit period. Aggregate campaign snapshots and action history may remain for their longer configured period. Advertising providers apply their own retention periods under their published terms.

Some records may be retained longer where necessary for billing, tax, accounting, fraud prevention, dispute handling, security, audit, legal obligations, or backup integrity. Backup copies are removed according to backup rotation and restore procedures.

7. Security

The Company uses technical and organizational measures to protect personal data processed through exdata, including account-scoped access controls, role-based permissions, hashed API tokens, reveal-once webhook secrets, TLS, file intake validation, audit logs, retention controls, and restricted support access. The current measures are described in the Technical and Organizational Measures.

8. International Transfers

Some subprocessors may process data outside the customer’s country or the European Economic Area. Where a transfer mechanism is required, the Company relies on appropriate safeguards such as adequacy decisions, standard contractual clauses, subprocessor data processing terms, and supplementary measures where applicable.

9. Data Subject Rights

Depending on the applicable law and the processing role, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. For data inside customer-uploaded documents or customer-controlled accounts, the Company may direct the requester to the relevant customer or assist the customer in responding.

Individuals may also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with their local data protection authority. Where the Company receives personal data from a customer rather than directly from the individual, the source is usually the customer account, the customer user who uploaded the document, or the customer’s connected system.

10. Contact

For privacy, deletion, security, or support requests, email privacy@exdata.app. Customers should include the account name, request ID, document ID, or billing reference where relevant so the Company can locate the correct records.