Data Processing Agreement
Data Processing Agreement — template version 1.1-EN, in force since 8 August 2026
Concluded under Article 28(3) GDPR in connection with the use of the translation service at Translate in Context by a business customer.
You conclude this agreement in the service, before submitting your first file, by ticking the acceptance statement. The controller details you provide (company name, VAT ID, registered address) go into the PDF copy we email to the address on your account. We record the template version, the date and time of acceptance, and a SHA-256 digest of the exact text you accepted.
1. Parties and subject matter
- The controller is [company name], [registered address], VAT ID [VAT ID] (the "Controller").
- The processor is Localize.pl Agenor Hofmann-Delbor, ul. Włościańska 57/13, 70-021 Szczecin, Poland, VAT ID PL9551885714 — operator of Translate in Context (the "Processor").
- The Controller entrusts the Processor with processing personal data contained in the files submitted for translation and in the accompanying context material, solely for the purpose of performing the translation service ordered through Translate in Context.
- This agreement is concluded under Article 28(3) of Regulation (EU) 2016/679 (GDPR) and binds the parties for as long as the service is provided to the Controller.
2. Nature and scope of processing
- Nature of processing: automated translation of file content using artificial intelligence models, technical validation of the result, and preparation of a report of the context decisions made.
- Type of data: personal data that the Controller itself places in the content of the submitted files. The Processor has no influence over its scope and does not classify it separately.
- Categories of data subjects: people whose data the Controller included in the submitted files (for example the Controller's employees, customers or business partners).
- The Controller undertakes not to submit special categories of data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). The service is not designed to process such data.
- Duration of processing: from submission of the file until its deletion in accordance with section 4(1).
3. Obligations of the Processor
- Processes the data only on documented instructions from the Controller, the instruction being the placing of an order in the service, and informs the Controller without delay if an instruction infringes the GDPR.
- Ensures that persons authorised to process the data have committed themselves to confidentiality.
- Applies technical and organisational measures corresponding to Article 32 GDPR: encryption in transit (TLS), access control to the database, separation of environments, and automatic deletion of content in accordance with section 4.
- Assists the Controller in responding to requests from data subjects and in complying with Articles 32 to 36 GDPR, to the extent appropriate to the nature of the processing and the information available to the Processor.
- Notifies the Controller of a personal data breach affecting the entrusted data, by email to the address on the account, without undue delay and no later than 24 hours after becoming aware of it.
- Makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for audits — conducted remotely, at a time agreed in advance, no more than once a year unless a personal data breach has occurred.
4. Deletion of data
- The content of the source file and of the result is deleted automatically 7 days after the translation is made available. After that, what remains in the system is a quality report stripped of content (number of escalations, quality scores, technical validation result), with no fragments of the document.
- At the request of the Controller made by email, the Processor deletes the entrusted data earlier, without undue delay after receiving the request.
- Billing data (the buyer details on the invoice) is not entrusted data. The payment is handled by the Paddle entity applicable to the buyer's location as merchant of record and a separate controller.
5. Sub-processing
- The Controller gives general authorisation for the Processor to engage the sub-processors listed below.
- The Processor imposes on its sub-processors obligations corresponding to those in this agreement and remains liable for their acts and omissions as for its own.
- The Processor informs the Controller by email of any intended change to the list, 14 days in advance. The Controller may object within that period; an objection is treated as termination of the service contract effective on the day the change takes effect.
6. Transfers outside the EEA
- Providers established in the United States and listed below either participate in the EU–US Data Privacy Framework, or the transfer takes place on the basis of Standard Contractual Clauses concluded with those providers.
- On request, the Processor tells the Controller which mechanism applies to a specific provider.
7. Liability and final provisions
- The Controller declares that it is entitled to entrust the data contained in the submitted files and that processing it for translation has a legal basis.
- Liability of the parties is governed by Article 82 GDPR. Limitations of liability in the Terms of Service do not apply to damage caused by an infringement of data protection law.
- This agreement is concluded electronically, by ticking the relevant statement in Translate in Context before the first file is submitted. The Processor sends the Controller confirmation of conclusion together with the text of the agreement, by email, as a PDF.
- Matters not covered here are governed by the GDPR and by Polish law. Any change to the template requires a new document version and fresh acceptance.
List of sub-processors
- Anthropic PBC (USA) — translation and verification of content by AI models (API, no model training)
- OpenAI, L.L.C. (USA) — translation of content by AI models (API, no model training)
- CloudFerro S.A. (Poland) — fluency scoring of translated fragments (Bielik model, Polish target only)
- Vercel Inc. (USA) — application hosting and server infrastructure
- Neon Inc. (USA) — database hosting
- Plus Five Five, Inc. (Resend) (USA) — sending transactional email
How we handle account data and billing data — the data for which we are the controller — is described in our Privacy Policy.