Skip to content

Diese Seite gibt es auch auf Deutsch. Auf Deutsch anzeigen

vizvuz
Pricing Docs Languages Status
Sign in Start free

Legal

Privacy policy

Version of Sep 1, 2026, 12:00 AM

This policy explains what happens to personal data when you visit vizvuz.com or call api.vizvuz.com. It is written to satisfy Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the equivalent provisions of the UK GDPR and the Data Protection Act 2018.

Controller

PRALOJ LTD, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom, registered in the Companies House, England and Wales under company number 17216920, is the controller for the processing described in this policy.

Contact for all data protection matters: [email protected]

We have not appointed a data protection officer, because neither our core activities nor our scale trigger the obligation under Article 37 GDPR. Enquiries to the address above are handled by the director.

Where we process personal data on your behalf — that is, the content you send to the API for translation — we act as a processor and you are the controller. That relationship is governed by our data processing agreement, which forms part of our contract with you.

What this policy covers

ContextOur role
The marketing website and documentationController
Your account, team, billing and supportController
Text you send to the API for translationProcessor, on your instructions

Data we process

1. Website usage

When you load a page, our server processes your IP address, the requested URL, the time, the referrer and your browser's user agent string. These entries are necessary to deliver the page and to detect attacks. They are deleted or truncated after seven days.

We do not use analytics, tracking pixels, advertising cookies or third-party scripts. There is no consent banner because there is nothing to consent to.

2. The live demo on the home page

The demo translates without an account. To stop it being abused as a free unlimited service, we count the characters translated per network. We do not store your IP address for this: we store a truncated one-way hash of it together with a counter, and the entry expires automatically after 24 hours. The text you type into the demo is sent to the translation engine and is not stored by us.

3. Account and team data

Registration requires an e-mail address, a name and a password. We also store your interface language, the teams you belong to, your role in them, the time of your last sign-in and — if you switch it on — the settings for two-factor authentication.

Passwords are stored only as an Argon2id hash. API keys are stored only as a SHA-256 hash plus a short prefix; we cannot recover the key itself.

4. Billing data

For paid accounts we process the billing name and address, the country, an optional VAT identification number, the chosen currency, invoices, payment status and the reference assigned by the payment service provider. We never see or store your card number or bank details — those are collected and held by the payment service provider.

Where you supply a VAT identification number, we validate it against the European Commission's VIES service and cache the result for 30 days, in order to apply the correct tax treatment.

5. API usage records

Every API request produces a usage record containing the team, the key, a request identifier, the number of characters, the language pair, whether the answer came from cache, the latency and the resulting cost.

Usage records never contain the text you sent or the translation you received. That is a design decision, not a policy promise: the field does not exist.

6. Translation content

The text you send to the API is transmitted to the translation engine provider, translated and returned to you. Unless you switch caching off for your team, the translation is stored in our cache with a hash of the input as the key — the input text itself is not stored in a readable form, but the translated output is. You can switch caching off per team in the dashboard at any time, with immediate effect.

Do not send special categories of personal data under Article 9 GDPR through the API unless your own legal basis covers it; see the data processing agreement.

7. Support correspondence

If you write to us we process your message, your address and any information you choose to include, in order to answer.

Legal bases

ProcessingLegal basis
Providing the website and delivering pagesArt. 6(1)(f) — our legitimate interest in operating a functioning, secure site
Server logs, rate limiting, abuse preventionArt. 6(1)(f) — legitimate interest in security and availability
The live demo and its per-network limitArt. 6(1)(f) — legitimate interest in offering a trial without abuse
Account creation and operation of the serviceArt. 6(1)(b) — performance of a contract
Billing, invoicing, VAT validationArt. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation
Retaining invoices and accounting recordsArt. 6(1)(c) — legal retention obligations
Security e-mails and service noticesArt. 6(1)(b) — performance of a contract
Translation contentArt. 28 — processing on behalf of the customer

We do not send marketing e-mail and therefore rely on no consent for it. If we ever do, it will be by separate, freely revocable opt-in.

Retention

DataRetained for
Server logs7 days
Demo rate-limit counters24 hours
Translation cache entries7 days in memory, and until deletion in the database; removed immediately when a team disables caching
Account dataFor the life of the account
Account data after deletion30 days, then irreversibly deleted; a further 90-day window applies to team data so that a deletion in error can be undone
Usage records24 months, then aggregated to monthly totals without key-level detail
Invoices and accounting records10 years, as required by tax law
Support correspondence24 months

Recipients and Sub-processors

We use a small number of service providers. Each is bound by a data processing agreement under Article 28 GDPR, and each is listed here by function. We deliberately describe the translation engine provider by role rather than by name, because the engine is a component of our service that we may change; material changes are announced in advance under the data processing agreement.

FunctionProviderProcessing location
Translation engineAI translation engine provider (EU/US hosting per configuration)European Union or United States, depending on configuration
Hosting of servers and databasesInfrastructure and hosting providerGermany
Content delivery, TLS termination and DDoS protectionCDN and network security providerGlobal network with European points of presence; operator established in the United States
Payment processingPayment service providerEuropean Union
Transactional e-mail deliveryE-mail delivery providerEuropean Union

Beyond these, we disclose personal data only where we are legally obliged to do so, or where it is necessary to establish, exercise or defend legal claims. We do not sell personal data, and we do not share it for advertising purposes.

International transfers

Our own infrastructure is located in Germany. Two of the functions above may involve a transfer outside the European Economic Area:

  • Where the translation engine is configured to a provider hosting in the United

States, the text you send is transferred there for the duration of the request.

  • Our content delivery and security provider is established in the United States,

although European traffic is served from European points of presence.

Such transfers are made on the basis of the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3 where we act as processor and Module 2 where we act as controller), supplemented by the UK International Data Transfer Addendum for UK GDPR purposes, and accompanied by a transfer impact assessment and technical measures including encryption in transit. Where a recipient is certified under the EU–US Data Privacy Framework, we also rely on the corresponding adequacy decision.

The United Kingdom, where we are established, benefits from an adequacy decision of the European Commission, so transfers from the EEA to us require no additional safeguard.

You may request a copy of the safeguards we rely on by writing to [email protected].

Your rights

Under the GDPR and the UK GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability in a structured, machine-readable format (Art. 20);
  • object to processing based on legitimate interests, on grounds relating to

your particular situation (Art. 21);

  • withdraw consent at any time, where processing is based on consent, without

affecting the lawfulness of processing before the withdrawal.

Two of these are built into the product rather than handled by e-mail: the settings page in the dashboard offers a full data export as JSON and an account deletion that starts a 30-day countdown, which you can cancel by signing in again. For everything else, write to [email protected]. We answer within one month, and we tell you if we need longer, as Article 12(3) allows.

We will not charge you for exercising these rights, and we do not require you to justify a request for access, erasure or portability.

Complaints

If you believe we process your data unlawfully, please tell us first — most problems are faster to fix directly. You also have the right to complain to a supervisory authority.

Because we are established in the United Kingdom, our supervisory authority is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. If you are in the European Union, you may instead complain to the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.

Cookies and local storage

We set exactly one cookie:

NamePurposeLifetime
vz_sessKeeps you signed in and carries the CSRF token14 days, or until you sign out

It is strictly necessary for the service you requested, so no consent is required under Article 5(3) of the ePrivacy Directive. It is set with HttpOnly, SameSite=Lax and, over HTTPS, Secure. There are no analytics cookies, no advertising cookies and no third-party cookies. We do not use browser fingerprinting.

Security

We protect personal data with, among other measures: TLS for every connection, HSTS, a content security policy without inline scripts, Argon2id password hashing, hashed API keys, CSRF tokens on every form, prepared statements for every database query, rate limiting on sign-in and on the API, role-based access within teams, and separation of secrets from the code base. Access to production systems is limited to the people who need it and is authenticated by key, not by password.

Automated decision-making

We do not carry out automated decision-making producing legal effects concerning you, and we do not profile you within the meaning of Article 22 GDPR. Machine translation is an automated process, but it produces text — it makes no decisions about people.

Children

The service is directed at businesses and developers, not at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.

Changes to this policy

We update this policy when the service changes. The version date is at the top of this page. Where a change materially affects how we process personal data of account holders, we announce it by e-mail at least 30 days before it takes effect.

Imprint Terms Data processing agreement

vizvuz

Translation API for Europe

Product

  • Pricing
  • Languages
  • Status

Developers

  • Quickstart
  • API reference
  • Migrate from DeepL

Legal

  • Imprint
  • Privacy
  • Terms
  • Data processing agreement

PRALOJ LTD, company number 17216920, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom.