MiniFiles.io

Data Processing Agreement

Version 1.0 · Effective March 12, 2026

Available to Business and Enterprise customers · Governed by GDPR Article 28

1. Parties and Scope

This Data Processing Agreement ("DPA") is entered into between the customer organisation subscribing to a MiniFiles.io Business or Enterprise plan ("Controller") and MiniFiles.io ("Processor"), and forms part of the Terms of Service.

This DPA applies to all processing of personal data carried out by MiniFiles.io on behalf of the Controller in connection with the provision of the MiniFiles.io service, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

Important architectural note: MiniFiles.io processes all file compression and PDF protection operations entirely within the end user's browser using WebAssembly. Files containing personal data are never transmitted to or stored on MiniFiles.io servers. The personal data processed by MiniFiles.io as Processor is therefore limited to: account registration data (email address), billing data (processed by Stripe as an independent controller), and anonymised compression statistics (no personal identifiers).

2. Details of Processing

Subject matter:Provision of browser-based file compression and PDF protection services.
Duration:For the term of the subscription, plus any retention period required by applicable law.
Nature:Account management, authentication, and subscription billing. File contents are not processed server-side.
Purpose:To provide the contracted services and manage the customer relationship.
Data categories:Name (if provided), email address, subscription and billing status, IP address (in server logs), usage metadata (anonymised).
Data subjects:Employees, contractors, and authorised users of the Controller's organisation.

3. Obligations of the Processor

MiniFiles.io, as Processor, undertakes to:

  • Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by EU or Member State law.
  • Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
  • Not engage another processor without prior specific or general written authorisation of the Controller.
  • Assist the Controller, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests for exercising data subjects' rights.
  • Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, DPIAs).
  • At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless EU or Member State law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor.

4. Security Measures (Article 32 GDPR)

MiniFiles.io implements the following technical and organisational measures:

  • Local-only file processing: All file operations run in the user's browser. No file contents are transmitted to MiniFiles.io servers at any point.
  • Encryption in transit: All communications between the user's browser and MiniFiles.io infrastructure use TLS 1.2 or higher.
  • Encryption at rest: Account data stored in Supabase is encrypted at rest using AES-256.
  • Access control: Access to production systems is restricted to authorised personnel using multi-factor authentication.
  • Subprocessor security: All subprocessors are contractually required to maintain equivalent security standards.
  • Incident response: MiniFiles.io maintains an incident response procedure and will notify the Controller without undue delay — and in any event within 72 hours — upon becoming aware of a personal data breach.

5. Subprocessors

MiniFiles.io uses the following subprocessors. The Controller grants general authorisation for their use. MiniFiles.io will inform the Controller of any intended changes to this list with reasonable prior notice.

SubprocessorPurposeLocation
Supabase Inc.Authentication, database (account data)EU (Frankfurt) / US
Vercel Inc.Hosting and content deliveryEU / US / Global CDN
Stripe Inc.Payment processing (independent controller for billing data)US / EU

All subprocessors located outside the EEA process data under Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism.

6. International Transfers

Where personal data is transferred to a country outside the European Economic Area that does not benefit from an adequacy decision, MiniFiles.io ensures that appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission under Article 46(2)(c) GDPR.

7. Data Subject Rights

MiniFiles.io will assist the Controller in responding to data subject requests within the timeframes required by GDPR. Controllers should direct their end users to use thecontact form for access, rectification, erasure, portability, restriction, or objection requests. MiniFiles.io will respond within 5 business days.

8. Term and Termination

This DPA remains in effect for the duration of the subscription. Upon termination, MiniFiles.io will, at the Controller's choice and within 30 days of the request, delete or return all personal data held on behalf of the Controller, and certify deletion in writing.

9. Governing Law

This DPA is governed by the laws of the European Union and, where applicable, the national laws of the Member State in which the Controller is established. Any disputes shall be subject to the exclusive jurisdiction of the courts of the Controller's Member State of establishment, unless otherwise agreed in writing.

10. Acceptance

By subscribing to a MiniFiles.io Business or Enterprise plan and accepting this DPA during the checkout process, the Controller confirms that it has read, understood, and agrees to be bound by this DPA. The date and version of acceptance are recorded and available in the Controller's account settings.

For questions regarding this DPA, please use our contact form.

DPA Version 1.0 · Effective March 12, 2026

Privacy Policy · Terms of Service · Security