Last updated: September 2026
1.1. This is a legally binding End User License Agreement (“Agreement”) between PSPDFKit GmbH d/b/a Nutrient (“Nutrient”, “us”, “we”, “our”, or “Licensor”) and you, which applies to the Nutrient DWS API Software and all related software, application programming interface, data, components, materials, services, updates, and documentation (collectively the “API”) provided by Nutrient. “You”, “your”, or “Licensee” means the person who accesses or uses the API (and, if you represent a legal entity, it also means that entity, and you represent and warrant that you are authorized to enter into this Agreement for that entity). The API provides functionality to modify and convert different file formats, and is provided through application programming interface, web interface, and/or mobile applications. “Enterprise” for the purposes of this Agreement, an “enterprise” is defined as any organization with more than 20 employees or generating more than $1 million USD in annual gross revenue. “Commercial Use” means use of the API in any manner that supports a business function, revenue generation, or service delivery, including internal operations within a business context.
1.2. By accessing or otherwise using the API, you agree and acknowledge that you (1) have read all of the terms and conditions set forth in this Agreement, (2) agree to be bound by the terms and conditions set forth in this Agreement, and (3) agree to review the API Website (https://www.nutrient.io/api/(opens in a new tab)) and documentation regularly for any updates and/or amendments to the terms of this Agreement. You further agree that if you do not acknowledge and agree with all terms set forth in this Agreement, you may not and will not use or access the API. This API is owned, operated, and maintained by PSPDFKit GmbH, an Austrian company with a registered address of Kaiserstrasse 117/17, 1070 Vienna, Austria.
1.3. The API may be offered under different subscription plans, including a free tier. Eligibility for the free tier is limited to personal, non-commercial use and small businesses. Commercial use of the Processing API by enterprises—defined as entities with more than 20 employees or over $1 million USD in annual revenue—requires a paid subscription.
2.1. The term (“Term”) of the license granted under this Agreement shall continue until terminated, as set forth herein. We may terminate this Agreement immediately in the event of non-payment or non-compliance by you with any provision of this Agreement. In the event of termination of this Agreement, all licenses granted to you shall immediately cease, you shall make no further use of the API pursuant to those licenses, and we will cancel your user credentials in the API Customer Portal (https://dashboard.nutrient.io/(opens in a new tab)) and you will no longer be able to access the API.
3.1. In consideration of your payment of the applicable license fees, and acceptance of and compliance with the terms of this Agreement, we hereby grant you a non-exclusive, non-transferable, worldwide, license to access and use the API during the Term.
This license grant under any free or promotional access tier does not extend to commercial use by enterprises. Any commercial use of the API by organizations exceeding 20 employees or $1 million USD in annual revenue constitutes a material breach of this Agreement unless covered by a paid subscription.
4.1. The API is licensed, not sold. You may use the API only as expressly permitted in this Agreement, and we reserve all other rights, including all worldwide technology and intellectual property and proprietary rights therein. You acknowledge that the API contains trade secrets and other proprietary information of Nutrient, and you acknowledge that Nutrient owns all right, title, and interests therein (including but not limited to all copyright rights), and you shall not take any action inconsistent with our ownership. You shall not:
4.2. Free-tier access to the API is restricted to non-commercial or small-scale use. Enterprises exceeding the thresholds defined in Section 1.3 may not use the API under the free tier for any purpose, including development, testing, internal operations, or client services.
5.1. Pursuant to the terms of this Agreement, we will provide you with access to the API over the Internet. All calls to the API must reference the credentials issued by Nutrient to you. You are not permitted to disclose your credentials to any other party. You are solely responsible for ensuring the secrecy and security of your credentials, and you will be responsible for all activities that occur and actions taken using such credentials. You shall not use the API in any manner that exceeds a reasonable volume of requests, or that otherwise constitutes excessive or abusive usage.
5.2. The plan under which you purchase a subscription to use the API limits the scope of your use of the API (see Section 6 “Plans and Payment” below). You agree not to exceed the usage limits associated with your subscription plan. If your usage of the API exceeds the usage permitted under your subscription plan, the API will return an error message to this effect. You are solely responsible for ensuring that your application(s) properly detect and address any such error messages. We reserve the right to limit the number of calls made by your application(s) to the API or otherwise constrain your use of the API in the event that we determine, in our sole discretion, that such calls are being made to the API for any malicious or harmful purpose or are the result of a technical error.
5.3. During the Term, we will provide reasonable support for bugs and other critical issues (the criticality of which is solely determined by us) of the API via our Support Portal at https://www.nutrient.io/api/support/(opens in a new tab).
5.4. You are solely responsible for acquiring, maintaining, providing, and using all necessary hardware, software, and Internet services which may be required to access and use the API. This includes, but is not limited to, internet connections and related telecommunications services, web browsers, and/or all other related equipment and software which may be required to access and use the API.
5.5. You are responsible for maintaining backup copies of your data which is sent to the API for processing. For plans where data retention is enabled (see Section 5.7), Nutrient retains and uses the content and outputs you submit as described in Section 5.7 and our Privacy Policy. For all other plans, Nutrient does not make or maintain copies of your data beyond the period necessary to process your requests or to provide API features that store data at your direction (for example, Viewer API file storage and Data Extraction API run history), as described in our Privacy Policy and Section 9. We make commercially reasonable efforts to provide an error-free API, but we do not guarantee that your data will not be lost, damaged, and/or deleted. You acknowledge and agree that you will maintain backup copies of all of your data which is sent to the API for processing.
5.6. You expressly acknowledge that from time to time, the API may be unavailable, inaccessible, and/or inoperable for any reason. This includes, but is not limited to, equipment/hardware failure or malfunction, software failure or malfunction, periodic maintenance and/or repairs undertaken by Nutrient or its affiliates or suppliers at any time, and/or any other cause. You expressly acknowledge that Nutrient may, in its sole discretion and at any time, modify or update the content or format of the API. We shall undertake reasonable efforts to communicate reasonable advance notification of such changes; however, from time to time sudden changes may be required and significant advance notice may not be possible. You expressly acknowledge that we may require you to use the latest (or any other) version of the API.
5.7. Data retention and use to improve our services. For plans where data retention is enabled (as indicated for your subscription plan), you grant Nutrient a worldwide, royalty-free license to host, retain, and use the content and outputs you submit to the API to operate, secure, test, develop, and improve our services, including to train and evaluate machine-learning and AI models, and to create de-identified and anonymized derivatives, which Nutrient may retain and use without limitation and which survive termination. For this retention, improvement, and training use, Nutrient acts as an independent controller and processes the data under its Privacy Policy. You represent and warrant that you have the rights and authority, and have provided the notices and obtained the consents, necessary to permit this retention and use, and that you will not submit special-category or sensitive personal data (for example, health, biometric, or government-identification data) for retention or training. You will indemnify and hold harmless Nutrient and its affiliates from any claim arising out of your breach of this Section. Retention periods are described in our Privacy Policy. Where a plan that previously did not retain data is changed to enable retention, this change applies to existing customers as follows. For paid plans (plans for which a fee is charged), we will provide advance notice and obtain your affirmative acceptance before the change applies to your account, and if you do not accept, your account will remain on the non-retention terms without interruption to the API. For free plans (plans provided at no charge), we will provide advance notice of the effective date of the change, and your continued use of the free service on or after that date will constitute your acceptance of these terms, including data retention; if you do not agree, you must discontinue use of the free service before that date. In all cases, you may exercise your data-subject rights, including the right to object and the right to deletion, as described in our Privacy Policy. This Section does not apply to plans where data retention is not enabled. Section 9 does not apply to the retention and use described in this Section 5.7, which Nutrient carries out as an independent controller; Section 9 continues to apply to Nutrient’s processing of the same content to provide the API to you.
6.1. The API is accessed by purchasing a number of API Credits or an access plan within the API Customer Portal (login at https://dashboard.nutrient.io/(opens in a new tab)). The cost of different API operations is described in the API Customer Portal.
6.2. Subscription Plans. All plans are purchased on a Subscription basis, wherein a certain Quota for using the API is provided to your account each month, on the prices, terms, and expiration limits set forth in the API Pricing Page. As used here, “Quota” means (but is not necessarily limited to) usage limits, number of operations, sizes of assets, duration of transactions, and/or number of API Credits. If your Subscription plan includes API Credits, they will be activated on your account in the API Customer Portal as soon as we receive your payment, and the selected amount of API Credits will subsequently be added to your account in the API Customer Portal on the monthly anniversary of your initial payment. You may cancel your Subscription at any time in the API Customer Portal, with such cancellation becoming effective at the end of the then-current billing cycle. You may change your Subscription plan at any time, but the total number of API Credits defined in your subscription that are already in your account in the current billing cycle will expire.
6.3. Purchasing subscriptions. Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all of our orders. Paddle provides all customer service enquiries and handles returns. Your relationship with Paddle is governed by the following Terms and Conditions paddle.com/legal-buyers/ and Privacy Policy paddle.com/privacy-buyers.
Use of the API beyond the free tier thresholds defined in this Agreement requires payment of applicable subscription fees. Nutrient reserves the right to audit usage and enforce compliance, including requiring license upgrades or suspending access for violations.
6.4. Automated Usage Auditing and Compliance Review. Nutrient reserves the right to monitor API usage for the purpose of ensuring compliance with this Agreement, including but not limited to subscription plan limits, eligibility criteria, and restrictions on commercial use. Such monitoring may include automated audits of request volume, frequency, metadata, and other usage patterns. Nutrient may, at its discretion, request from you reasonable information and documentation to verify compliance with the terms of this Agreement, including confirmation of organizational size, revenue, or use case. You agree to promptly provide such information upon request. Failure to cooperate with a compliance review or provision of materially false or incomplete information shall be considered a breach of this Agreement and may result in suspension or termination of access to the API.
7.1. THE API IS PROVIDED TO YOU “AS IS” AND “AS AVAILABLE” AND “WITH ALL FAULTS,” AND WE MAKE NO EXPRESS OR IMPLIED WARRANTIES WHATSOEVER WITH RESPECT TO ITS FUNCTIONALITY, CONDITION, PERFORMANCE, OPERABILITY, OR USE. WITHOUT LIMITING THE FOREGOING, WE DISCLAIM ALL IMPLIED WARRANTIES INCLUDING, WITHOUT LIMITATION, ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR FREEDOM FROM INFRINGEMENT. WE DO NOT WARRANT THAT THE API IS FREE OF ERRORS OR MATERIAL DEFECTS, AND WE DO NOT WARRANT THE ACCURACY, RELIABILITY, TIMELINESS, CORRECTNESS, COMPLETENESS, AND/OR AUTHENTICITY OF THE API.
7.2. We are not aware of any rights of third parties that oppose the utilization purposes of the API. We are not liable, however, for API and the associated know-how being free of rights of third parties.
7.3. You shall indemnify and hold harmless Nutrient and its affiliates, subsidiaries, and suppliers against any and all loss, damage, liability, and/or expenses (including but not limited to attorney’s fees and costs) arising out of any claim asserted by a third party based upon (1) any act or omission by you, any affiliate of you, or any end-user of yours with respect to this Agreement and/or the API, and/or (2) any breach or non-compliance with any term or aspect of this Agreement.
7.4. IN NO EVENT SHALL WE, OUR AFFILIATES, OUR SUBSIDIARIES, AND/OR OUR SUPPLIERS BE LIABLE TO YOU, YOUR AFFILIATES, AND/OR YOUR END-USERS FOR ANY DAMAGES OF ANY TYPE, WHETHER DIRECT OR INDIRECT, CONSEQUENTIAL, INCIDENTAL, OR SPECIAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST REVENUES, LOST PROFITS, LOSSES RESULTING FROM BUSINESS INTERRUPTION, SERVICE INTERRUPTION, DELAY, UNAVAILABILITY, INOPERABILITY, INACCURACY, ERROR, OR LOSS OF DATA, REGARDLESS OF THE FORM OF ACTION OR LEGAL THEORY UNDER WHICH SUCH LIABILITY MAY BE ASSERTED, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OR LIKELIHOOD OF SUCH DAMAGES. WE SHALL HAVE NO LIABILITY WITH RESPECT TO ANY DATA THAT IS READ, ACCESSED, STORED, OR PROCESSED WITH THE API, OR FOR THE COSTS OF RECOVERING ANY SUCH DATA. IN NO EVENT SHALL OUR MAXIMUM AGGREGATE LIABILITY UNDER THIS AGREEMENT EXCEED THE TOTAL FEES PAID OR PAYABLE BY YOU TO LICENSE, ACCESS, OR USE THE API. SOME JURISDICTIONS DO NOT ALLOW THE LIMITATION OR EXCLUSION OF LIABILITY FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES, SO THE ABOVE LIMITATION OR EXCLUSION MAY NOT APPLY TO YOU.
8.1. This Agreement constitutes the complete and exclusive understanding and agreement between the parties regarding its subject matter and supersedes all prior or contemporaneous agreements or understandings, written or oral, relating to its subject matter. You agree that additional or different terms on your purchase order or from any other previous oral or written discussions or negotiations shall not apply. Our failure to enforce any provision of this Agreement shall not constitute a waiver of our future enforcement of that or any other provision.
8.2. We (or any future maintainer of the API) shall be permitted to list and disclose your name and/or company and your products that include the API on our website and related material.
8.3. Both parties agree to the application of the laws of Austria with the exclusion of its conflict of law rules to govern, interpret, and enforce all of the parties’ rights, duties, and obligations arising from or relating in any manner to this Agreement. The United Nations Convention on Contracts for the International Sale of Goods shall not apply. Both parties agree that this Agreement is executed and accepted in Vienna, Austria. For all disputes arising out of or related to this Agreement, the sole place of jurisdiction shall be the relevant court in Vienna, Austria. Both parties hereby submit to the personal jurisdiction of such court and waive any such jurisdictional arguments to the contrary.
8.4. This Agreement is personal to you and may not be assigned or transferred for any reason whatsoever (including, without limitation, by operation of law, merger, reorganization, or as a result of an acquisition or change of control involving you) without our prior written consent, and any action or conduct in violation of the foregoing shall render this Agreement void and without effect. We expressly reserve the right to assign this Agreement and to delegate any of its obligations hereunder.
8.5. The terms of this Agreement incorporate our Privacy Policy (https://www.nutrient.io/legal/privacy/(opens in a new tab)). Section 9 and Schedule 1 set out the terms on which Nutrient processes personal data on your behalf and, together with the rest of this Agreement, are the complete data processing agreement between you and Nutrient for the API. No other data processing terms apply, including terms in a purchase order, vendor questionnaire, or other document you provide, except as set out in this Section 8.5. Section 9 and Schedule 1 do not apply to you if (a) you use the API under a master subscription agreement or other enterprise agreement signed by you and Nutrient that includes a data processing agreement (an “Executed DPA”), or (b) you and Nutrient signed a data processing agreement that references this Agreement before January 1, 2026 (a “Legacy DPA”), for as long as that Legacy DPA remains in effect. In either case, your Executed DPA or Legacy DPA governs Nutrient’s processing of personal data on your behalf instead. In the event of a conflict regarding the processing of personal data, the applicable Executed DPA or Legacy DPA controls, followed by this Agreement (including Section 9 and Schedule 1), and then the Privacy Policy.
8.6. Should any provision of this Agreement be invalid or become invalid or should this Agreement contain an omission, then the legal effect of the other provisions shall not be affected hereby. Instead of an invalid provision, a valid provision is deemed to have been agreed upon which comes closest to what the parties intended commercially. The same applies in the case of an omission.
8.7. Should you have any questions regarding this Agreement or the API, please contact us at support@nutrient.io.
9.1. Scope and roles. This Section 9 and Schedule 1 apply when Nutrient processes personal data on your behalf that is contained in the files, content, and other data submitted to the API by you or on your behalf, including files you provide to Nutrient support to resolve an issue with the API (“Customer Personal Data”), to the extent that processing is subject to Regulation (EU) 2016/679 (the “GDPR”) or, where applicable, the UK GDPR or the Swiss Federal Act on Data Protection (together, “Data Protection Law”). This Section 9 and Schedule 1 are the data processing agreement between you and Nutrient for that processing. They are part of this Agreement, and no separate signature is required. For that processing, you are the controller, or a processor acting on behalf of another controller, and Nutrient is your processor or subprocessor. If you act as a processor, you represent that the relevant controller has authorized your instructions, Nutrient’s appointment, and Nutrient’s engagement of subprocessors under this Section 9. This Section 9 does not apply to personal data that Nutrient processes as a controller, including account, billing, marketing, and security data and the retention and use described in Section 5.7, all of which are described in our Privacy Policy. “Required Law” means the law of the European Union or of an EU Member State and, for processing subject to the UK GDPR or Swiss law, the law of the United Kingdom or Switzerland, in each case to which Nutrient is subject. Terms used in this Section 9 that are defined in Data Protection Law, such as “controller,” “processor,” “personal data,” “personal data breach,” “processing,” “data subject,” and “supervisory authority,” have the meanings given in Data Protection Law.
9.2. Details of processing. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Schedule 1. Nutrient does not control what personal data you submit to the API.
9.3. Instructions. Nutrient will process Customer Personal Data only on your documented instructions, including with regard to transfers of Customer Personal Data to a third country, unless Required Law requires otherwise. In that case, Nutrient will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. This Agreement (including this Section 9 and Schedule 1), the API documentation, your use and configuration of the API, and the support requests you submit are your complete documented instructions. Any additional or different instructions must be consistent with this Agreement, technically feasible, and agreed by Nutrient in writing, and may be subject to additional fees. If, in Nutrient’s opinion, an instruction infringes Data Protection Law, Nutrient will inform you and may suspend the affected processing until the issue is resolved. Nutrient is not obligated to monitor or legally review your instructions.
9.4. Your responsibilities. You are responsible for the lawfulness, accuracy, and minimization of Customer Personal Data and of your instructions, including having a legal basis for the processing, providing any required notices to data subjects, obtaining any required consents and authorizations, and ensuring that you are permitted to submit Customer Personal Data to the API. You will not instruct Nutrient to process Customer Personal Data in violation of applicable law. Subject to Section 5.7 (which prohibits submitting special-category or sensitive personal data for retention or training), if you submit special categories of personal data or personal data relating to criminal convictions and offenses, you are solely responsible for determining that the security measures described in Section 9.6 and Schedule 1 are appropriate for that data, and by submitting it you confirm that they are.
9.5. Confidentiality. Nutrient will ensure that persons it authorizes to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access Customer Personal Data only as necessary to provide, secure, support, or maintain the API.
9.6. Security. Nutrient will take the measures required of a processor by Article 32 of the GDPR, which are summarized in Schedule 1. Nutrient may update its measures from time to time, provided the updates do not materially decrease the overall security of the API. You are responsible for the security of your credentials (Section 5.1), your own systems and applications, and your backups (Section 5.5).
9.7. Subprocessors. (a) You grant Nutrient general written authorization to engage subprocessors, including Nutrient affiliates, to process Customer Personal Data. Nutrient’s current subprocessors are listed at https://www.nutrient.io/legal/subprocessor-list/(opens in a new tab) (the “Subprocessor List”). (b) Nutrient will inform you of any intended addition or replacement of a subprocessor before the new subprocessor begins processing Customer Personal Data, by updating the Subprocessor List and notifying those who have subscribed to updates through Nutrient’s trust center. You are responsible for subscribing if you wish to receive that notice. (c) You may object to a new subprocessor by emailing legal@nutrient.io before the end of that notice period. If you object, your sole and exclusive remedy is to stop using the API and cancel your subscription under Section 6, without refund of fees already paid or credit for unused API Credits. (d) Nutrient will impose on each subprocessor, by written contract, the same data protection obligations as those set out in this Section 9, to the extent applicable to the services the subprocessor provides, in particular sufficient guarantees to implement appropriate technical and organizational measures. Subject to Section 7, Nutrient remains liable to you for the performance of each subprocessor’s data protection obligations.
9.8. International transfers. You instruct Nutrient to transfer Customer Personal Data to the extent necessary to provide the API, subject to this Section 9.8. Nutrient will transfer Customer Personal Data to, or permit access to it from, a country outside the European Economic Area, the United Kingdom, or Switzerland only in compliance with Data Protection Law, using an adequacy decision (including the EU-U.S. Data Privacy Framework and its UK and Swiss extensions), the European Commission’s standard contractual clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism. If you are located in a country that is not covered by an adequacy decision and Nutrient’s return of Customer Personal Data to you is a transfer subject to Chapter V of the GDPR, the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Four (processor to controller), are incorporated into this Agreement by reference, with Nutrient as data exporter and you as data importer, the optional Clause 7 omitted, and the laws of Austria and the courts of Vienna, Austria selected under Clauses 17 and 18.
9.9. Assistance and breach notification. (a) Taking into account the nature of the processing, Nutrient will assist you by appropriate technical and organizational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects to exercise their rights. You agree that the design and functionality of the API are the principal such measure, including the deletion of submitted files after processing on plans where data retention is not enabled and your ability to retrieve and delete stored files and runs through the API. If Nutrient receives a request from a data subject that Nutrient can reasonably identify as relating to your Customer Personal Data, Nutrient will refer the data subject to you and will not otherwise respond, except on your instructions or as required by law. (b) Taking into account the nature of the processing and the information available to Nutrient, Nutrient will provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), primarily by making available the information described in Section 9.11. (c) Where assistance under this Section 9.9 requires work beyond the standard functionality, documentation, and support included in your plan, Nutrient may charge reasonable fees based on its costs, except where the assistance is required because of Nutrient’s breach of this Section 9. (d) Nutrient will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, by email to the address associated with your account, and will provide the information reasonably available to Nutrient that you require to meet your own breach-notification obligations. You are responsible for keeping that email address current. Nutrient’s notification is not an acknowledgment of fault or liability.
9.10. Return and deletion. On plans where data retention is not enabled, files submitted for processing are deleted as described in Section 5.5 and our Privacy Policy. Customer Personal Data stored by an API feature at your direction remains available for you to retrieve or delete through the API during the Term; retrieval through the API is the means of return, and you are responsible for retrieving any Customer Personal Data you wish to keep. After this Agreement terminates or expires, Nutrient will delete any remaining Customer Personal Data from its active systems within a reasonable time after your written request to legal@nutrient.io. Copies in backups, logs, or other systems from which immediate deletion is not reasonably practicable are isolated from further active use and deleted in the ordinary course of Nutrient’s backup and log retention cycles, unless Required Law requires Nutrient to store them. This Section 9 continues to apply to Customer Personal Data until it is deleted. This Section 9.10 does not apply to content Nutrient retains as an independent controller under Section 5.7.
9.11. Information and audits. Nutrient will make available to you the information necessary to demonstrate compliance with Article 28 of the GDPR, consisting of this Section 9, Schedule 1, and, on your written request no more than once in any twelve-month period, a copy or summary of Nutrient’s most recent independent third-party security audit report (such as a SOC 2 Type 2 report) or other security documentation, subject to your acceptance of Nutrient’s confidentiality terms. You will first use that information to assess Nutrient’s compliance. If you reasonably demonstrate that it is insufficient to demonstrate Nutrient’s compliance with this Section 9, or if a supervisory authority or Data Protection Law requires it, Nutrient will allow for and contribute to an audit, including an inspection where legally required, of its processing of Customer Personal Data, on the following conditions: (a) no more than once in any twelve-month period, unless a supervisory authority requires otherwise or following a personal data breach affecting your Customer Personal Data; (b) at least thirty (30) days’ written notice, except where a supervisory authority requires shorter notice; (c) during normal business hours, remotely where possible, and without unreasonable disruption to Nutrient’s operations; (d) conducted by you or by a qualified, independent auditor that is not a Nutrient competitor and is bound by confidentiality obligations acceptable to Nutrient; (e) without access to other customers’ data, information that would create a security risk, or information unrelated to the processing of your Customer Personal Data; and (f) you bear all costs of the audit and reimburse Nutrient’s reasonable costs of supporting it at Nutrient’s then-current rates, except where prohibited by law. Nothing in this Section 9.11 limits the powers of a competent supervisory authority.
9.12. Liability and self-serve terms. To the fullest extent permitted by applicable law, Section 7, including the limitations of liability in Section 7.4, applies to this Section 9 and to all claims arising out of the processing of Customer Personal Data. Nothing in this Agreement limits the rights of data subjects under Article 82 of the GDPR, the powers of a supervisory authority, or any liability that cannot be limited under applicable law. This Section 9 contains Nutrient’s complete data processing commitments for Free and self-serve Paid plans. Under those plans, Nutrient is not required to sign your form of data processing agreement or to provide additional contractual, audit, security, support, or compliance commitments; such commitments are available only under an Executed DPA as described in Section 8.5.
Subject matter. Nutrient’s provision, security, maintenance, and support of the API.
Duration. The Term, and afterwards the period needed to delete Customer Personal Data under Section 9.10.
Nature and purpose. Receiving, transmitting, accessing, organizing, converting, parsing, extracting, modifying, rendering, generating, temporarily storing, storing where an API feature stores data at your direction, securing, troubleshooting, returning, and deleting Customer Personal Data as necessary to provide and support the API in accordance with your instructions.
Categories of data subjects. Your users, employees, job applicants, contractors, and representatives; your customers and their users; your suppliers and business contacts; and any other individuals whose personal data you submit to the API.
Types of personal data. Any personal data you submit in documents, files, API requests, or associated metadata. This may include identification, contact, employment, commercial, financial, transactional, technical, and document-content data. Special categories of personal data may be included only as permitted by Section 9.4 and Section 5.7.
Retention. On plans where data retention is not enabled, for the time needed to process and return the applicable request, as described for each API in our Privacy Policy. For data stored by an API feature at your direction, until you delete it or as provided in Section 9.10. Section 5.7 governs retention on plans where data retention is enabled.
Technical and organizational measures. Nutrient maintains measures appropriate to the risk, including: