Last updated July 3, 2026
Data Processing Agreement
Processor terms for business customers whose personal data is processed through Transmutify.
Parties and roles
The customer organization is the controller for personal data it submits to Transmutify for transformation. Transmutify acts as a processor for that customer personal data and processes it only to provide, secure, support, and maintain the service, unless applicable law requires otherwise.
For account administration, website operation, security logging, support, and business communications, Transmutify may act as an independent controller as described in the Privacy Policy.
Processing instructions
The customer's instructions are documented in the Terms of Service, this Data Processing Agreement, the customer's product configuration, API requests, dashboard actions, schemas, provider settings, storage settings, and webhook settings. Transmutify will not process customer personal data for other purposes unless required by Union or Member State law.
Subject matter and duration
The subject matter is the provision of Transmutify's dashboard, API, playground, transformation workflow, provider integration, storage, and webhook functionality. Processing continues for the term of the customer's use of the service and for any retention period needed to provide the service, resolve disputes, secure the service, or comply with legal obligations.
Transmutify-controlled transformation input and output files are retained for 7 days. Customer-configured custom storage may follow the retention behavior selected by the customer.
Nature and purpose of processing
- Creating and managing organization workspaces.
- Authenticating users and API requests.
- Receiving, storing, inspecting, and transforming input.
- Preparing review mappings and schema suggestions.
- Creating output files and temporary download URLs.
- Sending webhook notifications selected by the customer.
- Providing support, security monitoring, and abuse prevention.
- Recording operational usage and transformation status.
Personal data and data subjects
Customer personal data may include any personal data contained in submitted files, raw input, schemas, review mappings, preview rows, output files, webhook payloads, support requests, and API metadata. The categories depend on what the customer chooses to submit.
Data subjects may include the customer's employees, contractors, customers, suppliers, business partners, leads, or other individuals represented in the customer's input data.
Security measures
- Organization-level access controls and tenant scoping.
- API key authentication for API requests.
- Encrypted storage of selected secrets, including AI provider credentials, custom storage credentials, and webhook secrets.
- Encrypted at-rest storage of transformation row data held in the application database, including input headers, sample rows, preview and validation row contents, and review data edits.
- Private Transmutify-controlled transformation storage in AWS Europe (Frankfurt) (
eu-central-1). - Time-limited temporary upload and download URLs.
- Sample-row masking for common sensitive values before file-based mapping and schema samples are sent to configured AI providers.
- Rate limits, abuse prevention, operational monitoring, and security logging.
- Customer-controlled custom AWS S3 storage and webhook settings where enabled.
Raw transformations are different from file-based mapping: unless the request is marked as a dry run, raw input content is sent to the configured AI provider for processing.
Confidentiality
Transmutify will ensure that persons authorized to process customer personal data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.
Subprocessors and customer-selected providers
Transmutify may use the subprocessors below to provide the service. Customer-selected AI providers, custom storage, and webhook endpoints are used only when configured or selected by the customer organization.
| Provider | Purpose | Location / safeguards |
|---|---|---|
| Laravel Cloud (Laravel Holdings Inc.) | Application hosting and managed database, cache, and queue infrastructure for the service. | United States based provider running on AWS infrastructure; hosting region as configured for the deployment; transfers outside the EEA rely on the provider's data processing terms and standard contractual clauses. |
| Amazon Web Services | Object storage for Transmutify-controlled transformation input and output files. | AWS Europe (Frankfurt, eu-central-1) for transformation storage; international support or access, if any, must rely on appropriate safeguards. |
| OpenAI | Customer-selected AI provider for mapping, schema generation, or raw transformations when configured. | May involve processing outside the EEA; customer and Transmutify must rely on the provider's applicable terms, DPA, adequacy decision, or standard contractual clauses. |
| Anthropic | Customer-selected AI provider for mapping, schema generation, or raw transformations when configured. | May involve processing outside the EEA; customer and Transmutify must rely on the provider's applicable terms, DPA, adequacy decision, or standard contractual clauses. |
| Customer-selected Gemini AI provider when configured, and Google social login when a user chooses it. | May involve processing outside the EEA; safeguards depend on the selected Google service terms and transfer mechanism. | |
| xAI | Customer-selected AI provider for mapping, schema generation, or raw transformations when configured. | May involve processing outside the EEA; safeguards depend on the selected provider terms and transfer mechanism. |
| OpenRouter | Customer-selected AI routing provider when configured. | May involve processing outside the EEA and onward processing by model providers selected through OpenRouter; safeguards depend on provider terms and selected models. |
| GitHub | Social login when a user chooses GitHub authentication. | May involve processing outside the EEA; safeguards depend on GitHub's applicable terms and transfer mechanism. |
| Mailgun (mailgun.com) | Transactional email, support email, and service communications. | Email delivery provider; processing and international transfers, if any, rely on Mailgun's data processing terms and applicable transfer safeguards. |
| Customer-configured S3-compatible storage | Custom transformation file storage selected and controlled by the customer organization. | Region, provider, endpoint, access controls, and transfer mechanism are configured by the customer. |
| Customer-configured webhook endpoints | Delivery of final transformation notifications for finished or failed runs, selected by the customer organization. | Endpoint location and safeguards are controlled by the customer. |
If Transmutify adds or replaces a Transmutify-controlled subprocessor, it should update this list and provide reasonable notice where required by the customer agreement.
International transfers
Where customer personal data is transferred outside the European Economic Area, Transmutify will use a valid transfer mechanism, such as an adequacy decision, standard contractual clauses, or another lawful safeguard. Customer-selected providers may apply their own transfer terms and safeguards, and customers should review those terms before configuring a provider.
Assistance and data subject requests
Transmutify will reasonably assist the customer, taking into account the nature of processing and the information available to Transmutify, with data subject requests, security of processing, breach notifications, data protection impact assessments, and consultations with supervisory authorities where required by applicable data protection law.
Deletion and return
At the customer's request or at the end of service use, Transmutify will delete or return customer personal data as reasonably available through the service, unless continued retention is required by law, security, dispute resolution, abuse prevention, backups, or legitimate business records. Transformation files in Transmutify-controlled storage are retained for 7 days according to the service retention policy. Encrypted row data stored in the application database for the review workflow is deleted when the mapping is re-run, when a review is canceled, or when the transformation run is deleted.
Audit and information
Transmutify will make information reasonably necessary to demonstrate compliance with this Data Processing Agreement available to the customer, subject to confidentiality, security, and protection of other customers. Audit procedures, notice periods, scope, and cost allocation should be completed in the final signed agreement.