I used to shrug at "just upload it to that free merge site" notes in internal wikis. Then I watched an onboarding checklist tell new hires to combine their passport scan and signed NDA on a consumer PDF host before dropping the pack into our HR portal. We had a DPA for the portal. We had nothing for the random merge site in the middle.
That ticket changed how I talk about PDF utilities in docs, READMEs, and product reviews. Client-side processing isn't a buzzword for the privacy page. It's a custody decision you can explain to security in one diagram.
When the tab closes, the working copy goes with the session. No retention job for that operation. No "wipe my file" ticket for a merge that never landed on your disks.
Who on your team should care
Internal tools. HR kits, KYC flows, "combine these attachments before submit." Pointing staff at an upload SaaS can fight your DPA language. Recommend or embed a local path instead.






