Back to Home

Privacy Policy

Last updated: January 2026

1. Introduction

So Design and Branding Pty Ltd ("we", "us", "our") operates PDF AA Compliance.com ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For users in the European Union, we also consider the requirements of the General Data Protection Regulation (GDPR).

By using PDF AA Compliance, you consent to the collection and use of information in accordance with this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password (encrypted)
  • Payment Information: Processed securely by Stripe; we do not store credit card numbers
  • Documents: PDF files you upload for remediation
  • Communications: Messages you send through our contact form

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on Service
  • Device Information: Browser type, operating system, device type
  • IP Address: For security, fraud prevention, and analytics
  • Cookies: Session management and preferences (see Section 7)

2.3 Document Processing

When you upload documents for remediation:

  • Documents are temporarily stored for processing
  • AI systems analyze document content to generate accessibility features
  • Images within documents are processed to generate alt text descriptions
  • We do not read or use document content for any purpose other than providing the Service

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Process your documents and generate accessibility features
  • Process payments and manage your account
  • Send transactional emails (receipts, notifications)
  • Respond to your inquiries and support requests
  • Monitor and analyze usage trends and preferences
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

We do NOT:

  • Sell your personal information to third parties
  • Use your documents for training AI models
  • Share your documents with third parties (except as required for processing)
  • Send marketing emails without your consent

4. Data Sharing and Third Parties

We may share your information with:

4.1 Service Providers

  • Cloud Infrastructure: Enterprise-grade hosting, CDN, and security services (USA/Global)
  • Document Processing: Secure cloud-based processing infrastructure (USA)
  • Stripe: Payment processing (USA)
  • Resend: Email delivery (USA)

These providers are contractually bound to protect your data and only use it to provide their services.

4.2 Legal Requirements

We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Data Security

We implement robust security measures to protect your information:

  • Encryption: All data transmitted via HTTPS/TLS 1.3
  • Password Security: Passwords are securely hashed using industry-standard algorithms
  • Access Controls: Strict access controls for employee access
  • Infrastructure: Enterprise-grade cloud security
  • Document Storage: Documents encrypted at rest in secure cloud storage
  • Regular Audits: Security practices regularly reviewed

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your information for the following periods:

Data TypeRetention Period
Account InformationUntil account deletion + 30 days
Uploaded Documents90 days after processing (auto-deleted)
Remediated Documents90 days (available for download)
Transaction Records7 years (legal requirement)
Usage Analytics24 months (anonymized after)
Support Communications2 years

7. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand how users interact with the Service

You can control cookies through your browser settings. Note that disabling essential cookies may impact Service functionality.

8. Your Rights

Under Australian Privacy Law and GDPR (where applicable), you have the right to:

  • Access: Request a copy of personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Portability: Request your data in a machine-readable format
  • Objection: Object to certain processing of your information
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw Consent: Withdraw consent where processing is based on consent

To exercise these rights, contact us at support@pdfaa.ai.

9. Account Deletion

You may request deletion of your account at any time by contacting us. Upon deletion:

  • Your account will be deactivated immediately
  • Personal information will be deleted within 30 days
  • Documents will be permanently deleted
  • Some information may be retained for legal compliance
  • Unused page credits will be forfeited

10. International Data Transfers

Your information may be transferred to and processed in countries outside Australia, including the United States, where our service providers operate.

We ensure appropriate safeguards are in place for international transfers, including:

  • Standard contractual clauses approved by relevant authorities
  • Service provider certifications (e.g., SOC 2 Type II)
  • Data processing agreements with all third parties

11. Children's Privacy

PDF AA Compliance is not intended for children under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes

13. Contact Us

For privacy-related inquiries or to exercise your rights:

Privacy Officer

So Design and Branding Pty Ltd

Email: support@pdfaa.ai

Website: Contact Form

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

By using PDF AA Compliance, you acknowledge that you have read and understood this Privacy Policy.