Privacy policy
Last updated: 2026-10-09
This policy explains what data Report PDF Studio (the "App") processes. The App is provided by Elektraset, s.r.o. ("we", "us"). Contact: help@elektraset.com.
1. Where the App runs
The App is a Salesforce managed package. It runs inside your Salesforce org. Reports run as the Salesforce user who requests a PDF (or as the owner of a schedule), with that user's sharing and field-level security. The PDF files, the job history, the branding profiles, the schedules and the settings are stored in your Salesforce org as Salesforce Files and custom object records. We have no access to them.
2. Data that leaves your org
Only when an administrator turns on "Use the chart renderer" in the App settings, and only for pie, donut, line and scatter charts, the App sends
a chart request to our chart renderer at https://report-pdf-studio.apps.elektraset.com/api/v1/charts/render. The request contains:
- the chart type, title and axis labels of the report chart;
- the group labels of the chart and the aggregated values per group (for example the sum of an amount). Group labels are the values of the field that the report chart groups by — for example stage names, months or account names. If a report chart groups by a field that holds personal data, such as the opportunity owner, a contact name or an email address, these values are sent as labels;
- colors and the image size;
- your Salesforce organization Id in a request header (used only for rate limiting).
The request never contains detail rows, record Ids, session credentials, or any field that the chart does not group by. Admins who do not want personal data in group labels can keep the renderer off (pie, donut and line charts are then drawn as columns inside Salesforce) or group those charts by non-personal fields.
We process the request in memory to draw a PNG image and return it in the same HTTPS response. We do not store, log or share the request or the image. Our server logs keep only technical data (time, HTTP status, error messages without request content), and only as long as needed to run the service. The org Id and the client IP address are held in memory for rate limiting for at most about two minutes after the last request.
When the chart renderer is off (the default), no data leaves your Salesforce org.
3. Website
The pages on https://report-pdf-studio.apps.elektraset.com set no cookies and use no analytics or tracking.
4. Email delivery
PDFs that users email with the App are sent by Salesforce from your org (Apex email), to the recipients that your users choose and that your administrator allows. We do not receive these emails.
5. Legal basis and roles (GDPR)
For chart renderer requests you are the controller and we act as your processor. We process the data only to provide the chart image you request (Art. 6(1)(b) and Art. 28 GDPR). A data processing agreement is available on request.
6. Sub-processors
The chart renderer runs on the application host that Elektraset, s.r.o. operates for the App. We use no other sub-processors for the App.
7. Security
All traffic uses HTTPS (TLS 1.2+). The renderer accepts only validated chart requests with limits on size and rate.
8. Your rights
You can turn off the chart renderer at any time in the App settings, and uninstall the App. Because we store no personal data from your org, there is nothing for us to delete; requests about this policy go to help@elektraset.com.
9. Changes
We will post changes to this policy on this page and update the date above.