Privacy Policy
This policy explains how DocTransform handles data when you use the service to move rows from a source file into another system.
Our role
For your account data (your name, email and billing details), DocTransform acts as the data controller: {{LEGAL_ENTITY}}, {{ADDRESS}}.
For the contents of the files you upload and transform, DocTransform acts only as a data processor, acting on your instructions.
Contact us about privacy matters at privacy@doctransform.xyz.
Where your data lives
The rows you upload live in your browser, in IndexedDB, with a session snapshot kept in localStorage so you can resume an interrupted session.
When a transformation needs server-side processing, the uploaded file is held on the server's local disk only for the duration of your editing session, and is removed after 30 minutes of inactivity or when you close the session.
A file too large to hold in memory may spill rows to temporary local disk storage during processing; that spill is removed once processing finishes.
Subprocessors
We share data with the following subprocessors to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Hosting | EU |
| Stripe | Billing | US transfer under Standard Contractual Clauses |
| {{EMAIL_PROVIDER}} | Transactional email | TBD |
| Google (Gemini API) | AI transformation planning | US, transfer under Standard Contractual Clauses |
Retention
- Request logs, AI request logs and pipeline telemetry (both database rows and JSONL files) are kept for 90 days, then deleted.
- The audit log (which records the IP address and user agent behind account actions) is kept for 12 months (365 days), then deleted.
Deletion and cookies
To delete your account and its data, email privacy@doctransform.xyz; we complete the deletion within 30 days.
We set one cookie: an httponly authentication cookie needed to keep you signed in. We do not use analytics or tracking cookies.