Subprocessors
The third parties that may process customer data on our behalf. This list is the complete set — we notify customers of material changes before a new subprocessor goes live, and each links to its own DPA.
| Subprocessor | Purpose | Region | When engaged | DPA |
|---|---|---|---|---|
| Anthropic (Claude) | AI translation, automated QA, glossary extraction, and in-context vision suggestions. | United States | Always, for AI features. | View ↗ |
| OpenAI | Text embeddings for semantic (fuzzy) Translation Memory. | United States | Only when a project enables semantic Translation Memory (off by default). | View ↗ |
| Amazon Web Services (AWS) | Cloud hosting, the PostgreSQL database, and object storage. | Configurable region | Always (core infrastructure). | View ↗ |
| Stripe | Billing and payment processing. | United States / EU | Only for customers on a paid plan. | View ↗ |
Data Processing Addendum
Our DPA reflects our standard processing commitments and is designed to help you meet GDPR obligations. Read it in full, or request a counter-signed copy for your records — we typically return one within a couple of business days.
Translation memory: the anonymization guarantee
Exact-match translation memory is pooled so a string already translated once can be reused instantly at $0. That pool is anonymized: entries carry no link to the customer, project, user, or context that produced them. Here is exactly what that means — no marketing gloss.
What is shared into the pool
- · The source string and its translation (the linguistic pair only), keyed by a hash of the source.
- · Plural forms, where the string is pluralized.
- · Aggregate reuse counters (how often an entry was reused) for savings analytics.
What is stripped
- · Any link to the organization, project, user, or team that produced the entry — the pool has no owner columns.
- · The translation key name, file path, screenshots, comments, and every other piece of surrounding context.
- · Request bodies: metering records token counts for billing, never the content of a request.
The straight answer, and how to opt out
To be precise: the source string and its translation can be reused across workspaces — that reuse is the point of a shared memory — but nothing tying an entry to you ever is. If your strings are sensitive enough that even the anonymized pair should not leave your project, Turning off "Use translation memory" on a project stops it from both contributing to and drawing on the shared memory — the kill-switch is per project and available on every plan.
We do not train any models on your content. Our AI subprocessors process it under commercial terms and are called for inference only.
Compliance, honestly
We will not claim a certification we do not hold. Here is the real state of each — where a certification is in progress, we say so.
SOC 2 Type II
Audit in progressAudit in progress. Type I readiness first, then the Type II observation window — we will publish the report here once complete.
ISO/IEC 42001 (AI management)
Pursuing — not yetPursuing early: the newest AI-governance standard. On the roadmap, not yet certified.
GDPR
AlignedGDPR-aligned processing with a signable DPA, EU data-subject export and deletion on request. GDPR is a regulation we comply with, not a certificate.
CCPA / CPRA
AlignedWe honor California consumer access and deletion rights; we do not sell personal information.
If a control matters to your procurement, ask — we would rather tell you where we are than paper over it. Reach us at privacy@transglot.ai.
Uptime & SLA
Uptime is published on an independently-hosted status page. Business and Enterprise plans carry a contractual SLA with service credits.
External status page ↗Data rights
Data-subject access, export, and deletion on request under GDPR and CCPA/CPRA. See the Privacy Policy and security overview.
Responsible disclosure
Found a vulnerability? Email security@transglot.ai. We acknowledge within two business days and will not pursue good-faith research under this policy.