Privacy Policy
How this website collects, uses, and stores personal data.
Last updated: 2026-06-28
This Privacy Policy explains how PATEON Network Technology Inc. (“PATEON”, “we”) handles personal data collected through the website getnextpdf.com (the “Site”). It is written to a global standard and follows the EU General Data Protection Regulation (GDPR) where it applies.
The Site is a low-data marketing and lead-capture surface. It is not the NextPDF software, and it is not a multi-tenant service. The heavy contractual documents (the commercial license, the EULA, and any Data Processing Agreement) attach to the product and the purchase, not to browsing this Site.
Who is responsible
The controller is PATEON Network Technology Inc. (registered in Taipei, Taiwan). For any privacy question or to exercise your rights, contact [email protected].
What we collect, why, and on what basis
| Data | When | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|---|
| Name, email, message, and any details you provide | You submit the contact or enterprise-quote form | Respond to your enquiry | Legitimate interest / steps prior to a contract | Until the enquiry is resolved, then a limited follow-up window |
| IP address, user-agent, request metadata | Automatically, when you load the Site | Deliver and secure the Site (CDN, logs) | Legitimate interest (security, delivery) | Short-lived operational logs |
| Aggregate, cookieless usage metrics | Automatically | Understand traffic | Legitimate interest | Per the analytics provider |
We do not sell or share personal data for cross-context behavioural advertising, and we do not run advertising trackers on the Site.
Cookies
See the Cookie Policy. The Site uses privacy-first, cookieless analytics; any strictly-necessary cookies (for example, a security challenge) are described there.
Who we share data with (sub-processors)
We use a small number of service providers. Each acts under contract and only as needed:
| Provider | Role | Region |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, security, cookieless analytics | United States / global edge |
| Resend (when contact forms are live) | Transactional email delivery for your enquiry | United States |
| GitHub, Inc. | Source hosting and CI build of the Site | United States |
Purchases and the Merchant of Record
When you buy a commercial licence, the purchase is sold by our Merchant of Record (MoR) — an authorised reseller that is the seller of record. For the payment transaction the MoR is an independent data controller: it determines how it processes your payment, billing, tax, and fraud-prevention data, it is not PATEON’s processor or sub-processor, and its handling of your data is governed by the MoR’s own privacy notice. PATEON receives from the MoR only the limited order data needed to fulfil and support your licence — typically your name, email, billing country, and order/licence details — and uses it only to deliver the licence and provide support, not for marketing unless you separately opt in. For self-hosted NextPDF software, PATEON does not receive your end-users’ personal data; see the DPA.
International transfers
The Site runs on infrastructure operated by US-based providers, so personal data may be processed outside your country, including in the United States. Where required, transfers rely on the EU Standard Contractual Clauses (2021) and/or the EU–US Data Privacy Framework, supported by a transfer impact assessment. Taiwan is the controller’s home jurisdiction.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or objection, and you may withdraw consent at any time. EU/EEA residents may lodge a complaint with their supervisory authority. California residents have rights to know, delete, correct, and opt out, and we do not sell or share personal information; we honour Global Privacy Control signals. To exercise any right, email [email protected]; we may need to verify your identity.
Security
PATEON operates an information-security management system that is independently ISO/IEC 27001:2022 certified. No method of transmission or storage is perfectly secure, and you use the Site at your own risk to the extent permitted by law.
Children
The Site is a developer and business audience and is not directed to children under 16. We do not knowingly collect personal data from children.
Changes
We may update this policy; the effective date above will change and material changes will be indicated. Continued use of the Site after an update constitutes acknowledgement of the revised policy, to the extent permitted by law.
Governing law
This policy and any dispute relating to the Site are governed by the laws of Taiwan, with the Taipei District Court as the forum, without prejudice to any mandatory rights you have under your local consumer or data-protection law.