TRANSCREATE AI
Data Processing Agreement (DPA)
Between the Customer identified in the Order Form ("Customer") and Ready-to-Publish Translations, LLC ("Transcreate AI") · Version 1.1 (2026-09-15)
DRAFT TEMPLATE — this document is being reviewed by qualified counsel and any updates will be promptly communicated to our clients.
1. Subject Matter, Roles and Instructions
1.1 This DPA is incorporated into the Agreement and governs Transcreate AI's processing of Customer Personal Data contained in Customer Content and Customer Language Assets. Customer is the controller (or a processor acting for its own controllers); Transcreate AI is the processor. For CCPA purposes, Transcreate AI is a "service provider" and certifies it will not sell or share Personal Information, nor retain, use, or disclose it outside the direct business relationship.
1.2 Transcreate AI processes Customer Personal Data only on documented instructions (the Agreement, this DPA, and configuration made through the Services), including for international transfers, unless required by law — in which case Transcreate AI informs Customer before processing unless legally prohibited.
1.3 Details of processing are set out in Annex I (nature and purpose: AI-assisted translation, transcreation, quality evaluation, translation-memory construction, professional human review of output by engaged linguists, and invoicing of review services; duration: the subscription term plus deletion periods; categories of data subjects: Customer personnel and individuals referenced in submitted content; categories of data: any personal data the Customer elects to include in content, which may include special categories only where Customer so instructs and a lawful basis exists).
2. Confidentiality and Personnel
2.1 Persons authorized to process Customer Personal Data are bound by contractual or statutory confidentiality obligations and receive data-protection training. Access is role-based and least-privilege.
2.2 Human reviewers. Where Customer orders human review, the review is performed by vetted freelance linguists and project managers engaged by Transcreate AI as authorized personnel under written confidentiality and data-protection obligations (contractor agreement and NDA) no less protective than this DPA. Reviewers access only the Content of orders assigned to them, for the sole purpose of performing the ordered review; commercial terms between Transcreate AI and Customer are not disclosed to reviewers. Transcreate AI remains fully responsible for reviewers' processing as for its own.
3. Security (Art. 32 GDPR / equivalent)
- Encryption in transit (TLS 1.2+) and at rest (AES-256); secrets management with rotation.
- Multi-tenant logical isolation: organization-scoped access controls and database row-level security on all tenant tables, including vector indexes; the tenant filter is restated on both the read and the write of every identifier-scoped operation.
- JWT-verified authentication with pinned signature algorithms on every API route; signed webhooks; support access to customer workspaces is scope-checked and written to an audit log before any data is served, and is refused if the audit record cannot be written. Separately from that support tooling, a small number of named Transcreate AI personnel hold administrative access to the underlying database and infrastructure, used only for maintenance, incident diagnosis and the quality control described at §4(e); such access is restricted by role, logged by the infrastructure provider, and is not exposed through the Services. Where a diagnosis requires opening a specific Customer's workspace through the Services, that access is recorded in the support-access audit log as above, and any change made is recorded in the Customer's own activity log.
- Customer-created share links are protected by high-entropy tokens stored only as hashes, are read-only, and are revocable and expiring.
- Vulnerability management, dependency scanning, environment separation, and backups with tested restoration.
- A current description of technical and organizational measures (TOMs) is maintained in Annex II and updated without degrading protection.
4. Tenant Isolation of Language Assets; Prohibition on AI Model Training; Service Improvement
(a) Customer Language Assets. All Translation Memory entries, sentence alignments, brand glossaries, terminology databases, brand-voice profiles, linguistic rules, and any derivatives generated from Customer content within the Services (collectively, "Customer Language Assets") are and shall remain the exclusive property of the Customer organization to which they pertain.
(b) Strict Tenant Isolation. Customer Language Assets are stored and processed exclusively within logically isolated, tenant-scoped partitions keyed to the Customer's unique organization identifier and protected by row-level access controls. Customer Language Assets are never commingled with, made retrievable by, or used to generate output for, any other customer or tenant of the Services.
(c) No Foundation-Model Training. Transcreate AI shall not — and shall contractually ensure that its subprocessors (including any provider of large language models, embeddings, or optical character recognition) do not — use Customer Content or Customer Language Assets to train, fine-tune, retrain, calibrate, or otherwise improve any foundational, general-purpose, or third-party artificial intelligence or machine-learning model, whether during the term of the agreement or after its termination. Customer Content is submitted to model providers solely for real-time inference, and no Customer Content or Customer Language Asset is incorporated into model weights, training corpora, or evaluation datasets of any third-party model. Transcreate AI configures each model provider to the strictest data-handling terms that provider makes available to it, and discloses the resulting position: optical character recognition is performed on a zero-retention basis, with no provider-side caching of the submitted document; large language model inference is performed with provider-side training use disabled, and prompts and outputs may be retained by the provider for a limited period (not exceeding 30 days) solely for the provider's detection of abuse and policy violations, after which they are deleted. Transcreate AI does not authorise, and no provider is permitted, any other use of Customer Content. Where a provider offers a contractual zero-retention mode, Transcreate AI will enable it and update the disclosure at Annex III accordingly.
(d) Internal Service Improvement (limited; opt-out after pilot program). Separately from (c), Transcreate AI may use the linguistic corrections its own engaged reviewers make to AI output during paid human review — after removal of customer identifiers, names, and customer-specific terminology — in aggregated, de-identified form, solely to improve the quality of the Services. This program never includes Customer Language Assets, never discloses one customer's content to another, and never feeds any third-party or foundation model. Nor does it produce one: the outputs of this program are written guidance, checklists and rule-based heuristics used by Transcreate AI's own personnel and pipeline, and nothing arising from it is used to train, fine-tune or otherwise fit the parameters of any machine-learning model, whether Transcreate AI's or a third party's. Concretely, what this program produces is material that is READ WHEN A PROMPT IS ASSEMBLED or by a person doing a review — terminology entries, do-not-translate rules, style and tone guidance, and reviewer checklists. No weights are altered, no model is fitted, and no artefact of this program is submitted to any provider as training data. This is a commitment about the method as well as the data. Customer may opt out of this program entirely at any time after its pilot period has ended — participation during a pilot is part of the pilot terms — (effected by Transcreate AI on request, or via the account where the control is exposed); on opt-out, nothing arising from Customer's orders is used, and the exclusion fails closed.
(e) Quality Control Sampling. To verify and improve the linguistic quality of the Services, Transcreate AI retains (i) the model inputs and outputs for processing steps that failed, were retried, or required a fallback, for incident diagnosis; and (ii) a random sample of approximately five percent (5%) of ordinary processing steps, for quality control by Transcreate AI's own personnel. Before storage, the sample at (ii) has direct contact identifiers — email addresses, telephone numbers, web addresses, and long numeric identifiers such as account or order numbers — automatically replaced with placeholders; the sample otherwise remains Customer Content, is stored in tenant-scoped storage accessible only to Transcreate AI's authorized personnel, is never disclosed to any other customer, is never used to train, fine-tune or otherwise improve any third-party or foundation model, and is deleted on the Customer's retention schedule (ninety (90) days unless the Customer has configured another period, which the Services permit to be set anywhere from seven (7) days to ten (10) years), and never later than that schedule. This paragraph describes review by Transcreate AI's own team; it does not create a subprocessor and does not extend the disclosure at (c). Pseudonymization is not anonymization and Transcreate AI does not treat the sample as anonymous data. Customer may request that its organization be excluded from the sampling at (ii) at any time, in which case only the diagnostic retention at (i) applies.
(f) Survival; Deletion. This Section survives termination. Upon termination or upon Customer's verified request, Customer Language Assets will be exported to Customer in a portable format (CSV/TMX) and permanently deleted from production systems within thirty (30) days and from backups within ninety (90) days.
5. Subprocessors
5.1 Customer grants general authorization for the subprocessors listed in Annex III ([Cohere — LLM inference/embeddings], [Google LLC — LLM inference, interim/regional capacity where in use], [LlamaCloud — OCR], [Supabase — database/auth/storage], [Stripe — payments], [Postmark — transactional email], [Render — application hosting: API and background workers], [Vercel — web application hosting], [Upstash — rate-limit counters only, keyed by user identifier or, for unauthenticated requests, a non-reversible token derived from the caller's address; no Customer Content], [Functional Software, Inc. d/b/a Sentry — application error monitoring; receives diagnostic error reports only, from which request bodies, headers, cookies, query-string values and stack-frame variables are removed before transmission, and in which remaining free text has direct contact identifiers replaced with placeholders by the same mechanism as §4(e)], [Backblaze Inc. — off-site backup storage; receives only client-side encrypted archives and files, to which Backblaze holds no key], [Microsoft Corporation — email hosting for Transcreate AI's own mailboxes; receives Customer Personal Data only where Customer or a data subject sends it to us by email]). Transcreate AI will provide at least 30 days' notice of additions or replacements (email or in-app), during which Customer may object on reasonable data-protection grounds; unresolved objections permit termination of affected Services with a pro-rata refund.
5.1.1 Model and provider changes. Transcreate AI selects the models and providers used to deliver the Services and may change them to maintain output quality; no particular model, model version or provider is warranted. Every such change is a subprocessor change and is made through §5.1: Annex III is updated, and notice is given by email to the Customer's account administrators and to the legal or data-protection contact the Customer has nominated, with the same notice period and the same objection right. A change to a different model offered by a subprocessor already listed in Annex III, on the same data-handling terms, does not require new notice — but the no-training obligations of §4(c) apply to every model without exception, and Transcreate AI will not route Customer Content to a provider or a mode that does not carry them.
5.2 Transcreate AI imposes data-protection obligations on subprocessors no less protective than this DPA — including the no-training prohibition in Section 4(c) — and remains fully liable for their performance. For the avoidance of doubt, individual freelance reviewers under §2.2 are authorized personnel, not subprocessors; Transcreate AI is responsible for them as for its own staff.
6. Data Subject Requests and Assistance
Taking into account the nature of processing, Transcreate AI assists Customer with appropriate technical and organizational measures to respond to data-subject requests (access, rectification, erasure — including deletion of derived TM segments and embeddings — restriction, portability, objection) under GDPR, UK GDPR, CCPA, LGPD, PIPL, APPI, PIPA, PDPA, LFPDPPP, PIPEDA, and GCC laws. The tenant-visible activity log assists Customer's accountability record. Requests received directly are forwarded to Customer without response, unless legally required.
7. Personal Data Breach
Transcreate AI notifies Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, providing the information reasonably required for Customer's notification duties (nature, categories and approximate volumes, likely consequences, measures taken), supplemented as it becomes available. Transcreate AI does not notify authorities or data subjects on Customer's behalf unless instructed or legally required.
8. DPIAs and Audits
8.1 Transcreate AI provides reasonable assistance with data protection impact assessments (including PIPL PIPIAs and Quebec Law 25 assessments) and prior consultations.
8.2 Audit rights: on 30 days' notice, no more than annually (except after a breach or on supervisory-authority request), Customer may audit compliance via (i) Transcreate AI's then-current certifications and third-party reports, written responses, and (ii) where those are insufficient, a remote or on-site audit under confidentiality, during business hours, without access to other tenants' data.
9. International Transfers
9.1 Transfer mechanisms by region:
- EEA/UK/Switzerland: EU SCCs (Module 2 or 3, as applicable) are incorporated by reference with Transcreate AI as data importer; the UK IDTA Addendum and Swiss adaptations apply as relevant. Annexes I–III of this DPA serve as the SCC appendices.
- China (PIPL): where Customer transfers personal information from mainland China, the parties will execute the CAC Standard Contract and Transcreate AI will provide PIPIA support; Customer remains responsible for separate consent and any required CAC assessment/filing.
- Korea (PIPA): overseas-transfer disclosure items are set out in Annex I and may be published by Customer.
- Japan (APPI): Transcreate AI maintains safeguards equivalent to APPI requirements and provides foreign-system information for Customer disclosures.
- Brazil (LGPD), Mexico (LFPDPPP), Singapore (PDPA), Canada (PIPEDA/Law 25), UAE and Saudi PDPL: transfers proceed under this DPA's contractual safeguards and any locally recognized clauses, filings, or SDAIA/ANPD instruments as required.
10. HIPAA (Conditional)
Customer shall not submit Protected Health Information unless the parties execute the BAA at Annex IV. Where executed, Transcreate AI acts as Business Associate: it implements the HIPAA Security Rule safeguards, reports Security Incidents and Breaches of Unsecured PHI without unreasonable delay (and within ten (10) business days), makes PHI available for individual rights requests, and ensures subcontractor BAAs. Zero-retention processing is enabled by default for BAA-covered workspaces; accordingly, BAA-covered workspaces are offered only where a zero-retention agreement with the applicable model provider is in force for that workspace's languages, and Transcreate AI will not accept Protected Health Information under this Agreement until it is. Human review is not available for BAA-covered workspaces unless the assigned reviewers are covered by the BAA chain.
11. Return and Deletion
Upon termination, Customer may export Customer Content and Customer Language Assets (CSV/TMX/JSON) for 30 days. Thereafter Transcreate AI deletes Customer Personal Data from production within 30 days and from backups within 90 days, and certifies deletion on request, unless retention is required by law (in which case the data remains protected by this DPA and isolated from further processing). Issued invoices and billing records are retained as required by tax law.
12. Liability and Order of Precedence
Liability is governed by the Agreement's limitations to the extent permitted by law (which do not limit liability that cannot be limited, including where prohibited under GDPR Art. 82). In case of conflict: SCCs (or other mandatory transfer instruments) prevail over this DPA, which prevails over the Agreement for data-protection matters.
Annex I — Processing Details
This Annex serves as Appendix I to the Standard Contractual Clauses where those apply (§9).
- Data exporter (controller, or processor acting for its own controllers). The Customer identified in the Order Form, at the address and with the data-protection contact stated there. Where the Customer is itself a processor, Module 3 of the SCCs applies in place of Module 2.
- Data importer (processor). Ready-to-Publish Translations, LLC, trading as Transcreate AI — a limited liability company organized under the laws of Delaware, United States, at 902 Secor Rd, Toledo, Ohio, 43623. Data-protection contact: hello@transcreateai.com. Representative in the Union for the purposes of GDPR Art. 27: not appointed. Transcreate AI will appoint one, and name it here, before offering the Services to data subjects established in the Union.
- Categories of data subjects. (i) The Customer's personnel and authorized users of the Services; (ii) any individual whose personal data the Customer elects to include in Customer Content — which, because Content is free text supplied by the Customer, is determined by the Customer and not by Transcreate AI; (iii) individuals identified in correspondence sent to Transcreate AI about the Customer's account.
- Categories of personal data. (i) Account and identity data: name, business email address, organization, role, authentication identifiers, and the sign-in metadata the authentication provider records; (ii) any personal data embedded in Customer Content or in Customer Language Assets; (iii) service metadata: job records, source and target languages, word counts, timestamps, and the activity log; (iv) support-access records naming the Transcreate AI person, the workspace opened and the time; (v) billing data — invoices, amounts and billing contact. Card numbers are never received by Transcreate AI: payment credentials are entered directly into the payment processor.
- Sensitive data. Only where the Customer instructs it and has a lawful basis to do so. Protected Health Information may be submitted only under an executed BAA (Annex IV), and Transcreate AI will not accept it before the conditions at §10 are met. Beyond the measures in Annex II, no additional restrictions are applied to special-category data unless separately agreed in writing.
- Frequency of the transfer. Continuous for the duration of the subscription term, on a Customer-initiated basis: data is transferred when the Customer or its users submit a job, invite a user, or order human review.
- Nature and purpose of the processing. As §1.3: AI-assisted translation and transcreation, quality evaluation, translation-memory and glossary construction, professional human review of output by engaged linguists, provision and support of the Services, and invoicing.
- Duration of the processing, and retention. For the subscription term plus the deletion periods at §11. The applicable periods, which are those published at §5 of the Privacy Policy, are: Customer Content and job outputs — 90 days by default, or any period from 7 days to 10 years configured by the Customer in Settings; Customer Language Assets (translation memories and glossaries) — until deleted by the Customer; account data — the life of the account plus 24 months; the activity log and the support-access audit log — 24 months each; invoices and billing records — as required by tax law, typically 7 to 10 years; encrypted backup copies of the database — 90 days, after which they are pruned off-site as well as locally; the encrypted off-site copy of Customer files — the Customer's own retention period as configured above, plus up to seven (7) days for the deletion to propagate and the copy to be erased.
- Processing locations. The Services are operated in the United States. Each subprocessor's location is stated in Annex III. Human reviewers engaged under §2.2 work from their own countries of residence; they are authorized personnel rather than subprocessors, and are bound by the confidentiality and data-protection terms described there.
- Transfers to subprocessors. As set out in Annex III, for the purposes stated in each entry, for the duration of this Agreement, and subject to §5 and §9.
- PIPA (Republic of Korea) overseas-transfer disclosure items. Recipient: Ready-to-Publish Translations, LLC (United States), contact hello@transcreateai.com. Items transferred: account and identity data, and any personal data embedded in Customer Content. Country and date/method of transfer: the United States, continuously during the term, by TLS-encrypted transfer to the Services' API. Purpose of use by the recipient: provision of the Services as described above. Period of retention and use: as stated in this Annex. The data subject may refuse the overseas transfer by contacting the Customer, in which case the Customer should not submit that individual's data to the Services.
Annex II — Technical and Organizational Measures
Art. 32 GDPR / SCC Annex II. This Annex describes the measures in force as at the date of this DPA. Measures may be updated, but not in a way that degrades the level of protection (§3).
- Encryption. In transit: TLS 1.2 or higher on every connection, between the browser and the application, between the application and the database, and on every call to a subprocessor. At rest: AES-256 on the managed database and on object storage. Backups: the nightly database archive is encrypted with AES-256 before it leaves Transcreate AI's control, so the off-site storage provider holds no decryption key for it. Customer files are mirrored separately, encrypted file by file on the client side, to storage under Transcreate AI's physical control. An off-site copy of that file mirror is held with the off-site storage provider named in Annex III, encrypted file by file on the client side with file and directory names also encrypted, so that provider holds no decryption key and cannot read a file name. Deletion propagates to that copy: when Customer Content is deleted from the Services — whether on the Customer's configured retention schedule or on the Customer's request — the corresponding files are removed from the off-site copy on the next mirroring run and permanently erased there within seven (7) days. The off-site copy of Customer files is therefore pruned on the Customer's own retention schedule plus that seven-day window, and not on any longer fixed period of its own.
- Secrets management. Credentials and API keys are held in the hosting platform's environment store, are never committed to the source repository, are not written to disk by the application, and are rotated on personnel change and on suspicion of exposure. Backup encryption passphrases are held separately from the backups themselves.
- Access control. Access is role-based and least-privilege. Within a Customer workspace the roles are viewer, editor, admin and owner, and the role is checked on write as well as on read. SAML single sign-on is available, and where a Customer enables it, that Customer's identity provider governs authentication and de-provisioning. Passwords are held by the authentication provider and never by the application; Transcreate AI personnel cannot read a Customer's password, and no Transcreate AI script or endpoint creates accounts or handles credentials. A small number of named personnel hold administrative access to the underlying database and infrastructure for maintenance and incident diagnosis; that access is restricted by role and logged by the infrastructure provider.
- Tenant isolation. Every identifier-scoped operation restates the organization filter in the application layer, and row-level security is enabled on tenant tables — including the vector index — as an independent second control, so that a defect in either one is not sufficient to expose another tenant's data. Customer-created share links carry high-entropy tokens that are stored only as hashes, are read-only, and are revocable and expiring; possession of a link URL grants no access to any other record.
- Support access, audited before it is served. Where a Transcreate AI staff member opens a Customer workspace through the Services, the access is scope-checked and written to the support-access audit log BEFORE any Customer data is returned, and the request is refused outright if that audit record cannot be written. Every change made during such access is written to the Customer's own activity log, where the Customer can see it; the access record itself is held in the support-access audit log and is produced to the Customer on request.
- Audit-log integrity. The activity log and the support-access audit log are append-only in the database itself, not merely by convention: a trigger refuses every UPDATE to either table, from every role, with no exception path. A DELETE is possible only from the scheduled retention purge, only for records older than 31 days, and only when the purge is running under its own privileged routine — three conditions that must hold together. A correction to a log entry is therefore made by appending a correction entry that references the original, never by altering it.
- Application security. Authentication tokens are verified on every API route with the signature algorithm pinned, so a token presented with an unexpected algorithm is rejected rather than trusted. Inbound payment webhooks are verified against the raw request body and are rejected if the signature is missing, malformed or wrong; a missing verification secret fails the endpoint closed rather than open. Requests are rate-limited per route and per identity. Uploads are capped and the read is aborted at the limit rather than after it, filenames are normalized against directory traversal before use, and temporary files are written to a private directory and removed on every exit path. The application renders no user-supplied HTML anywhere: document text reaches the page as text nodes.
- Error monitoring. Application errors are reported to the monitoring subprocessor with personally identifying data disabled at the client, request bodies, HTTP headers, cookies, query-string values and stack-frame local variables removed in-process before transmission, session replay not enabled, and direct contact identifiers in remaining free text replaced with placeholders.
- Logging and retention of records. The activity log and support-access audit log are retained for 24 months and then purged on a schedule, which is the same window in both cases because both answer the same question in a dispute.
- Backup and continuity. The database is backed up nightly to an encrypted volume on equipment under Transcreate AI's physical control in the United States; each archive is integrity-checked after it is written, and a copy is held off-site with a 90-day rotation enforced by a retention rule on the off-site storage itself. The credential the backup process holds can add archives but cannot delete them, so a compromise of the machine that makes the backups cannot destroy the off-site history. Restoration from backup is exercised at least annually and after any change to the backup mechanism, and the result is recorded.
- Secure development. Production credentials are not present in development environments. Dependencies are pinned and scanned. Database migrations are reviewed and applied deliberately rather than automatically. An automated test suite — including tests that assert the security properties described in this Annex — runs before deployment.
- Vulnerability and patch management. Dependencies and platform images are updated on a regular cadence and out of cadence for security advisories affecting components in use.
- Personnel. All persons authorized to process Customer Personal Data are bound by written confidentiality obligations and receive data-protection training. Engaged reviewers are contracted under a written contractor agreement and NDA no less protective than this DPA, are assigned only the Content of orders allocated to them, and do not see the commercial terms between Transcreate AI and the Customer. Access is removed on offboarding.
- Incident response. A named owner, a documented triage path, and notification to the Customer without undue delay and in any event within 72 hours of Transcreate AI becoming aware of a Personal Data Breach, with the information required by §7.
- Deletion and return. Export in a portable format and deletion on termination or on verified request, per §11, extending to Translation Memory segments and embeddings derived from the deleted Content.
- Physical security. Transcreate AI operates no data centre of its own. Physical and environmental security is inherited from the infrastructure providers named in Annex III, each of which operates certified facilities.
Annex III — Authorized Subprocessors
Processing locations for the components Transcreate AI deploys — the application, the background workers, the database and the rate-limit store — are those stated at Annex I as the United States. Transcreate AI enters into each provider's data-processing addendum, incorporating the EU Standard Contractual Clauses where the provider is outside the EEA or the UK, before Customer Content or Customer Personal Data is routed to that provider; the executed addenda are available to the Customer on request. The "no-training flow-down" below records that the provider's terms prohibit the use of data submitted through the API to train that provider's models, as required by §4(c).
- Cohere Inc. (Canada) — large language model inference and multilingual embeddings. Receives Customer Content submitted for processing, and the text from which embeddings are computed. No-training flow-down: yes; the API terms prohibit training on submitted data.
- Google LLC (global endpoint: Google may process at any of its regions unless a specific region is pinned; see Privacy Policy §4(b)) — large language model inference, where a Google model is in use for a language pair or as interim capacity. Receives Customer Content submitted for processing. No-training flow-down: yes.
- LlamaIndex, Inc. (LlamaCloud) (United States) — optical character recognition and document parsing for uploaded files. Receives the uploaded document. Processing is on a zero-retention basis, with no provider-side caching of the submitted document. No-training flow-down: yes.
- Supabase, Inc. (hosting region as above) — managed Postgres database, authentication and file storage. Holds Customer Content, Customer Language Assets, account data and the logs described in Annex II, encrypted at rest. This is the primary store; every other entry in this list is narrower. No-training flow-down: not applicable — no model is trained by this provider.
- Render Services, Inc. (hosting region as above) — application hosting for the API and the background workers. Customer Content passes through in transit and in process memory only; the service holds no durable copy. No-training flow-down: not applicable.
- Vercel Inc. (hosting region as above) — hosting for the web application, which serves the browser client and proxies API requests. No durable storage of Customer Content. No-training flow-down: not applicable.
- Upstash, Inc. (hosting region as above) — Redis, used only for rate-limit counters. Keys are the authenticated user identifier or, on unauthenticated routes, a keyed hash of the caller's IP address; the address itself is never transmitted. Values are request counts that expire within the rate-limit window. Never receives Customer Content. No-training flow-down: not applicable.
- Stripe, Inc. (United States) — payment processing and subscription billing. Receives billing contact data and payment credentials entered directly by the Customer; Transcreate AI does not receive card numbers. Never receives Customer Content. No-training flow-down: not applicable.
- ActiveCampaign, LLC (Postmark) (United States) — transactional email: sign-in, notification and billing messages. Receives recipient email addresses and message content generated by the Services. Never receives Customer Content beyond a job title where one appears in a notification. No-training flow-down: not applicable.
- Functional Software, Inc. d/b/a Sentry (United States) — application error monitoring. Receives stack traces and error metadata for failed requests and background jobs, with the removals described in Annex II. Customer Content is not intentionally transmitted, but an exception message may incidentally contain a fragment of it. No-training flow-down: not applicable.
- Backblaze Inc. (United States) — off-site backup storage (B2). Receives the nightly database archive, encrypted with AES-256 before it leaves Transcreate AI's control. Backblaze holds no decryption key and cannot read it. Copies are removed on the 90-day backup schedule stated in Annex I, enforced by a provider-side retention rule; the credential Transcreate AI's backup process holds is scoped to write and read only, and cannot delete. No-training flow-down: not applicable.
- Microsoft Corporation (United States) — email hosting for Transcreate AI's own mailboxes at transcreateai.com. NOT part of the processing pipeline: the Services route no Customer Content to it. It receives Customer Personal Data only where the Customer, the Customer's personnel or a data subject sends it to Transcreate AI by email — a question, a data-subject request, or an attached document — which then rests in Transcreate AI's Microsoft tenancy under Transcreate AI's own mailbox retention rather than under the Customer's configured retention period. Transcreate AI asks Customers to submit job content through the Services rather than by email for that reason. This is distinct from a Customer's OWN Microsoft identity provider under a SAML connection, which is the Customer's processor and not a subprocessor of Transcreate AI. No-training flow-down: not applicable.
Annex IV — Business Associate Agreement
[Attach standard BAA — executed only for HIPAA-covered engagements. Not in force unless signed by both parties; until it is, §10 prohibits the submission of Protected Health Information.]