GDPR & HIPAA Compliance Audit

Official compliance framework for secure, serverless file conversions.

For organizations operating in regulated sectors, including healthcare, legal, and financial services, data governance is paramount. PixelShift.cc is designed to satisfy the most stringent privacy frameworks by removing the risk of external data storage. Because your files never cross the network boundary, PixelShift eliminates data processor liabilities.

General Data Protection Regulation (GDPR)

Under Article 4 of the European Union General Data Protection Regulation (GDPR), personal data is defined as any information relating to an identified or identifiable natural person. Images, document graphics, and embedded metadata qualify as personal data.

Why PixelShift Does Not Act as a "Data Processor"

A "Data Processor" (Article 4(8)) is an entity that processes personal data on behalf of a controller. Because the PixelShift application runs purely client-side inside the user's browser sandbox:

  • We do not receive, store, transmit, or have access to any image or document content.
  • No data transfer (Chapter V) occurs, as files are not uploaded to our infrastructure.
  • No Data Processing Agreement (DPA) is required for file content, because we never receive customer image or document data.

Website Analytics (Opt-In Only)

Separately from file conversion, PixelShift uses Google Analytics 4 to collect anonymous usage metadata (such as page views and session duration). This analytics data does not include image files, document content, filenames, or other personally identifiable information from your conversions.

  • Analytics cookies are blocked by default until you explicitly accept via our cookie consent banner.
  • You can reject analytics at any time or reopen your choice from Cookie Preferences in the site footer.
  • Rejecting analytics has no effect on the local file conversion pipeline — your files still never leave your browser.

Health Insurance Portability and Accountability Act (HIPAA)

HIPAA regulates the protection of Protected Health Information (PHI) in the United States. Medical scans, patient charts, and treatment photographs are strictly classified under HIPAA security rules.

Bypassing the Need for a Business Associate Agreement (BAA)

Usually, healthcare providers must sign a BAA with online conversion websites to process patient documents. With PixelShift, a BAA is not required:

  • Since files are processed on the local terminal, there is no third-party exposure.
  • There is zero risk of PHI retention or breach, complying directly with HIPAA’s Security and Privacy Rules.
  • You maintain complete, end-to-end custody of your files at all times.

Enterprise Compliance Matrix

Regulatory FrameworkRequirementPixelShift Implementation Status
GDPR Article 28Formal DPA executionBypassed for file content (no image/document data collected)
GDPR Article 32Secure transport & processing encryptionFully Compliant (Local sandbox execution)
HIPAA Security RulePHI protection and BAA complianceFully Compliant (No PHI data exposure)
CCPA / CPRAPrevention of personal info sales/sharingFully Compliant (no telemetry on source files; opt-in analytics only)
GDPR Article 7Freely given consent for non-essential cookiesCompliant (Google Consent Mode v2 + cookie banner)

Need technical details of our sandbox or compliance audit?

PixelShift.cc

Secure Client-Side Converter...