Data Processing Agreement

Last updated: August 6, 2026
Version: 1.0

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Transistor, Inc. ("Transistor", "we", "us") and the customer that has accepted the Agreement ("Customer", "you").

This DPA applies where and to the extent that Transistor processes Personal Data on your behalf as a Processor in connection with providing the Services. It is incorporated into the Agreement by reference. Where this DPA conflicts with the rest of the Agreement, this DPA controls with respect to the processing of Personal Data.

You do not need to sign anything for this DPA to apply. It takes effect automatically when you accept the Agreement. See Signature and execution below.


1. Definitions

Capitalised terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.

  • "Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), applicable US state privacy laws including the California Consumer Privacy Act as amended ("CCPA") and the Colorado Privacy Act, and Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") where applicable.

  • "Personal Data" means information relating to an identified or identifiable natural person that Transistor processes on your behalf under the Agreement.

  • "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the GDPR.

  • "Sub-processor" means a third party engaged by Transistor to process Personal Data on your behalf.

  • "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.

  • "Services" means the podcast hosting, distribution, analytics, transcription, website, and related services provided under the Agreement.

2. Roles of the parties

For Personal Data processed in connection with your use of the Services — including podcast listener data and the account data of collaborators you invite — you are the Controller and Transistor is the Processor.

Transistor acts as an independent Controller for a limited set of processing carried out for its own purposes, including account administration, billing, fraud prevention, security monitoring, product analytics, and compliance with legal obligations. That processing is described in our Privacy Policy and is not governed by this DPA.

Where you and Transistor are each independent Controllers, neither party is the other's Processor and each is responsible for its own compliance.

3. Scope and instructions

Transistor will process Personal Data only:

  • to provide, maintain, secure, and support the Services in accordance with the Agreement;

  • in accordance with your documented instructions, including instructions given through the configuration options and features of the Services; and

  • as required by applicable law.

The Agreement, this DPA, and your use of the Services constitute your complete documented instructions. If Transistor is required by law to process Personal Data other than as instructed, we will inform you before processing unless the law prohibits it on important grounds of public interest.

Transistor will inform you if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out a legal review of your instructions.

Transistor does not sell or share Personal Data, does not retain, use, or disclose it for any purpose other than performing the Services, and does not combine it with Personal Data received from other sources except as permitted under Data Protection Law. For the purposes of the CCPA, Transistor is a "service provider" and this section constitutes the required restrictions.

4. Confidentiality

Transistor ensures that all personnel and contractors authorised to process Personal Data are bound by written confidentiality obligations that survive the end of their engagement. Access is granted on a least-privilege basis and only to those who need it to perform the Services.

5. Security

Transistor implements and maintains appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as required by Article 32 GDPR. Those measures are described in Annex II and summarised on our Security page.

Transistor may update these measures over time, provided the overall level of protection is not reduced.

6. Sub-processors

You give Transistor general written authorisation to engage Sub-processors to process Personal Data in connection with the Services.

Transistor will:

  • maintain a current list of Sub-processors at transistor.fm/subprocessors/;

  • impose data protection obligations on each Sub-processor that are no less protective than those in this DPA;

  • remain fully liable to you for the performance of each Sub-processor's obligations; and

  • publish any intended addition or replacement of a Sub-processor on the Sub-processor page in advance of that Sub-processor beginning to process Personal Data, so that you have an opportunity to object.

You may object to a new Sub-processor on reasonable data protection grounds by writing to mail@transistor.fm before that Sub-processor begins processing. We will work in good faith to address your concern. If we cannot do so, you may terminate the affected Services by giving written notice, and we will refund any prepaid fees covering the period after termination.

7. Data subject requests

Taking into account the nature of the processing, Transistor will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from Data Subjects exercising their rights under Data Protection Law.

The Services include self-service functionality that allows you to access, correct, export, and delete Personal Data. Where those tools are not sufficient, Transistor will provide reasonable additional assistance at your request.

If Transistor receives a request directly from a Data Subject relating to Personal Data processed on your behalf, we will not respond to the substance of the request except as legally required, and will promptly direct the Data Subject to you or forward the request where we can identify the relevant Customer.

8. Personal Data Breach

Transistor will notify you without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf.

The notification will describe, to the extent known at the time: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information is not all available at once, we will provide it in phases as it becomes available.

Transistor will provide reasonable assistance to help you meet your own notification obligations to supervisory authorities and Data Subjects. Our notification is not an acknowledgement of fault or liability.

9. Data protection impact assessments

Taking into account the nature of the processing and the information available to us, Transistor will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR. For most Customers, the documentation published on our Security and Sub-processor pages, together with Annexes I and II of this DPA, will be sufficient.

10. Deletion and return

You may export or delete Personal Data at any time using the Services.

On termination or expiry of the Agreement, Transistor will delete Personal Data processed on your behalf within ninety (90) days, except where retention is required by applicable law. Server and application logs are retained for a maximum of one week and are then permanently deleted in the ordinary course.

Backups are deleted on the standard backup rotation cycle. Personal Data held in backups remains subject to this DPA until it is deleted.

At your written request made before deletion, Transistor will provide a copy of Personal Data in a commonly used machine-readable format.

11. Audits and information

Transistor will make available all information reasonably necessary to demonstrate compliance with this DPA and with Article 28 GDPR.

Transistor does not currently hold SOC 2 or ISO 27001 certification. In place of on-site audits, Transistor will:

  • maintain and keep current the documentation published at transistor.fm/security/ and transistor.fm/subprocessors/; and

  • respond within a reasonable period to reasonable written questions about our processing that are not already answered by that documentation and by the Annexes to this DPA.

Where Data Protection Law requires an audit or inspection beyond the above, the parties will first attempt to satisfy the requirement using the materials described in this section. Any audit that remains necessary must be: requested with at least thirty (30) days' written notice; limited to once per twelve (12) month period unless required by a supervisory authority or following a Personal Data Breach; conducted during business hours; subject to confidentiality obligations; scoped so as not to disrupt the Services or compromise the security or confidentiality of other customers' data; and carried out at your expense.

12. International transfers

Transistor is established in the United States. Where you transfer Personal Data from the EEA, the United Kingdom, or Switzerland to Transistor, the following applies.

Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference and constitute the transfer mechanism for such transfers. They apply as follows:

  • Module Two (Controller to Processor) applies, with you as data exporter and Transistor as data importer.

  • Clause 7 (docking clause) does not apply.

  • In Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 6.

  • In Clause 11, the optional independent dispute resolution language does not apply.

  • In Clause 17, the governing law is the law of Ireland.

  • In Clause 18(b), the forum is the courts of Ireland.

  • Annexes I, II, and III of the SCCs are populated by Annex I, Annex II, and the Sub-processor list referenced in this DPA.

For transfers subject to the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018. For transfers subject to the Swiss FADP, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

Onward transfers. Where Transistor engages a Sub-processor located outside the country from which the Personal Data was transferred, Transistor ensures that the onward transfer is covered by the SCCs, by the sub-processor's own certification under an applicable adequacy framework, or by another lawful transfer mechanism, in accordance with Clause 8.8 of the SCCs. The location of each Sub-processor is set out on the Sub-processor page.

Transfer impact assessment. Transistor will provide, on request, the information reasonably necessary for you to carry out a transfer impact assessment, including information about the categories of Personal Data transferred, the technical and organisational measures applied, and Transistor's history of receiving government access requests.

Government and law enforcement access. Transistor will, to the extent permitted by law:

  • notify you promptly if it receives a legally binding request from a public authority for disclosure of Personal Data processed on your behalf;

  • notify you if it becomes aware of any direct access by a public authority to such Personal Data;

  • where notification is prohibited, use reasonable efforts to obtain a waiver of the prohibition and document its efforts so it can demonstrate them on request;

  • review the legality of each request, challenge requests it concludes are unlawful or overbroad under applicable law, and pursue available avenues of appeal; and

  • disclose only the minimum amount of Personal Data permissible when responding to a request, based on a reasonable interpretation of it.

Transistor has not implemented, and will not implement, any backdoor or similar programme allowing a public authority direct or unrestricted access to Personal Data. Transistor is not, to its knowledge, subject to any law that would prevent it from complying with this section or with the SCCs. If Transistor becomes subject to such a law, or determines it can no longer comply with the SCCs, it will notify you promptly, and you may suspend the transfer or terminate the affected Services.

13. Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits either party's liability to Data Subjects under Data Protection Law.

14. Signature and execution

This DPA is already legally binding on both parties through the Agreement, and no signature is required. Accepting the Agreement constitutes acceptance of this DPA, and the published version at transistor.fm/dpa/ is the operative one.

Transistor does not countersign individual copies of this DPA and does not negotiate amendments to it.

15. Changes to this DPA

Transistor may update this DPA to reflect changes in the Services, our Sub-processors, or Data Protection Law. Changes are published on this page with an updated version number and date above. We will not make changes that materially reduce the protections in this DPA without publishing them in advance. Previous versions remain available on request.

16. Term

This DPA takes effect when you accept the Agreement and remains in force for as long as Transistor processes Personal Data on your behalf.

17. Contact

Questions about this DPA, data protection, or our processing practices: mail@transistor.fm

Security vulnerability reports: mail@transistor.fm

EU and UK representative. Transistor has appointed Prighter Group and its local partners as its representative under Article 27 of the GDPR and Article 27 of the UK GDPR. Data Subjects in the European Union and the United Kingdom may contact Prighter, or exercise their data protection rights, at app.prighter.com/portal/transistor.


Annex I — Description of processing

A. Parties

Data exporter (Controller): the Customer identified in the Agreement, using the Services to host, distribute, and measure podcasts.

Data importer (Processor): Transistor, Inc., a Delaware corporation with its principal place of business at 242 Linden Street, Fort Collins, Colorado, United States. Contact: mail@transistor.fm.

Data importer's EU and UK representative: Prighter Group and its local partners, appointed under Article 27 GDPR and Article 27 UK GDPR. Contact: app.prighter.com/portal/transistor.

B. Description of the processing

Subject matter. Provision of podcast hosting, distribution, analytics, transcription, website, and related services.

Duration. For the term of the Agreement, plus the deletion window set out in Section 10.

Nature and purpose. Storing, transmitting, transcoding, distributing, measuring, and providing support in relation to podcast content and associated data, in order to deliver the Services.

Categories of Data Subjects:

  • Listeners of podcasts hosted on the Services

  • The Customer's personnel, collaborators, and invited team members

  • Subscribers to private podcast feeds operated by the Customer

  • Individuals whose personal data appears in podcast audio, video, transcripts, show notes, or artwork uploaded by the Customer

Categories of Personal Data:

  • Listener data: IP address, user agent, approximate geographic location derived from IP address, request timestamps, referring application or client, and playback and download events

  • Account and collaborator data: name, email address, hashed password, sign-in and sign-out events, feature interaction events, and error and crash events

  • Private podcast subscriber data: email address and subscription status, and where enabled, individual feed identifiers

  • Content data: any personal data contained within audio, video, transcripts, episode titles, show notes, or images that the Customer uploads or generates through the Services

  • Billing data: billing contact name and email, billing address, and payment card token. Full card numbers are handled by Stripe and never stored on or passed through Transistor's servers.

Special category data. The Services are not designed for the processing of special categories of personal data under Article 9 GDPR. The Customer is responsible for the content it uploads and should not use the Services to process special category data unless it has independently determined that it is lawful to do so.

Frequency. Continuous, for the duration of the Agreement.

Retention. Account and content data are retained for the term of the Agreement and deleted per Section 10. Server and application logs are retained for a maximum of one week. Aggregate and anonymised analytics that no longer identify any individual may be retained indefinitely.

C. Competent supervisory authority

Determined in accordance with Clause 13 of the SCCs, based on the Customer's place of establishment or, where the Customer is not established in the EEA, the place where its EU representative is established or where the relevant Data Subjects are located.


Annex II — Technical and organisational measures

These measures reflect the practices published at transistor.fm/security/.

Access control. Access to servers, source code, and third-party tools requires two-factor authentication wherever it is supported. Passwords are strong, randomly generated, and never reused. Contractors receive the lowest level of access necessary to perform their work. Production data is not copied to personal devices.

Authentication. Customer passwords are hashed with BCrypt before storage. Passwords are never stored in plain text and are filtered out of application logs.

Encryption in transit. All communication between the Transistor application and its backend services is encrypted using TLS. Certificates are managed automatically through Let's Encrypt.

Encryption at rest and database isolation. Customer data is stored in Amazon Web Services RDS PostgreSQL with encryption at rest. The database is reachable only from Transistor's application servers within the same private network.

Payment security. Payment cards are encrypted, stored, and processed by Stripe using AES-256. Transistor stores only a Stripe-issued token. Card numbers and details are not stored on, and do not pass through, Transistor's servers.

Vulnerability management. Automated tooling monitors dependencies for known security issues and alerts the team. Patches are applied and deployed promptly.

Logging and retention. Server and application logs are retained for a maximum of one week and are then permanently deleted.

Sub-processor governance. Sub-processors are assessed before engagement and bound by written data protection terms no less protective than this DPA.

Incident response. Security concerns and vulnerability reports are received at mail@transistor.fm and escalated to the engineering team. Personal Data Breaches are handled in accordance with Section 8.

Certifications. Transistor does not currently hold SOC 2 or ISO 27001 certification.


Annex III — Sub-processors

The current list of Sub-processors, including the processing each performs, its location, and the transfer mechanism relied on, is published and maintained at:

transistor.fm/subprocessors/

That page forms part of this DPA and of Annex III to the SCCs. Changes are notified in accordance with Section 6.