Data Processing Addendum
Our data processing addendum for customers with GDPR and other data-processing obligations.
Last updated: July 7, 2026
1. Purpose and scope
This Data Processing Addendum ("DPA") forms part of the agreement between transglot ("Processor") and the customer ("Controller") for use of the Service, and applies to the extent transglot processes personal data on the Controller’s behalf in the course of providing the Service.
This DPA reflects our standard commitments and is intended to help customers meet obligations under regulations such as the GDPR. Customers with specific contractual requirements should contact us to discuss an executed DPA.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law (including the GDPR, where applicable).
3. Details of processing
3.1 Subject matter
Processing of personal data that may be contained within project content (e.g. source or translated strings) or account data, as necessary to provide the Service.
3.2 Duration
For the duration of the Controller’s subscription, plus any post-termination retention period described in our Privacy Policy.
3.3 Nature and purpose
Hosting, storage, AI-assisted translation, translation memory matching, and transmission of data via the REST API and webhooks, solely to provide the Service the Controller has configured.
3.4 Categories of data subjects
Controller’s account users (employees, contractors) and, where project content includes personal data, any individuals referenced in that content.
4. Processor obligations
As Processor, transglot will:
- Process personal data only on documented instructions from the Controller, including with regard to transfers, unless required otherwise by law.
- Ensure personnel authorized to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures (see Section 6).
- Assist the Controller, where reasonably possible, in responding to data subject rights requests and regulatory inquiries.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data.
5. Subprocessors
The Controller authorizes transglot to engage subprocessors to provide the Service, including infrastructure hosting, AI translation (Anthropic), email delivery, and payment processing. transglot remains responsible for subprocessors’ compliance with data-protection obligations equivalent to those in this DPA, and will provide notice of material subprocessor changes on request.
6. Technical and organizational measures
Our technical and organizational measures include:
- Encryption of data in transit.
- Hashed account credentials and sha256-stored API access tokens.
- HMAC-SHA256-signed webhook payloads to verify authenticity.
- Role-based access control at the organization and project level.
- Rate limiting on API endpoints to reduce abuse.
7. International transfers
Where personal data is transferred outside the Controller’s jurisdiction, transglot relies on appropriate safeguards recognized under applicable law, such as standard contractual clauses, where required.
8. Audit rights
On reasonable request and subject to confidentiality obligations, transglot will make available information reasonably necessary to demonstrate compliance with this DPA.
9. Deletion or return of data
On termination of the Service, transglot will delete or return personal data processed on the Controller’s behalf in line with the retention terms in our Privacy Policy, unless retention is required by law.
10. Contact us
To request an executed DPA or ask questions about our data-processing practices, contact legal@transglot.ai or through our contact page.