Legal
Privacy policy
Version of Sep 1, 2026, 12:00 AM
This policy explains what happens to personal data when you visit vizvuz.com or call api.vizvuz.com. It is written to satisfy Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the equivalent provisions of the UK GDPR and the Data Protection Act 2018.
Controller
PRALOJ LTD, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom, registered in the Companies House, England and Wales under company number 17216920, is the controller for the processing described in this policy.
Contact for all data protection matters: [email protected]
We have not appointed a data protection officer, because neither our core activities nor our scale trigger the obligation under Article 37 GDPR. Enquiries to the address above are handled by the director.
Where we process personal data on your behalf — that is, the content you send to the API for translation — we act as a processor and you are the controller. That relationship is governed by our data processing agreement, which forms part of our contract with you.
What this policy covers
| Context | Our role |
|---|---|
| The marketing website and documentation | Controller |
| Your account, team, billing and support | Controller |
| Text you send to the API for translation | Processor, on your instructions |
Data we process
1. Website usage
When you load a page, our server processes your IP address, the requested URL, the time, the referrer and your browser's user agent string. These entries are necessary to deliver the page and to detect attacks. They are deleted or truncated after seven days.
We do not use analytics, tracking pixels, advertising cookies or third-party scripts. There is no consent banner because there is nothing to consent to.
2. The live demo on the home page
The demo translates without an account. To stop it being abused as a free unlimited service, we count the characters translated per network. We do not store your IP address for this: we store a truncated one-way hash of it together with a counter, and the entry expires automatically after 24 hours. The text you type into the demo is sent to the translation engine and is not stored by us.
3. Account and team data
Registration requires an e-mail address, a name and a password. We also store your interface language, the teams you belong to, your role in them, the time of your last sign-in and — if you switch it on — the settings for two-factor authentication.
Passwords are stored only as an Argon2id hash. API keys are stored only as a SHA-256 hash plus a short prefix; we cannot recover the key itself.
4. Billing data
For paid accounts we process the billing name and address, the country, an optional VAT identification number, the chosen currency, invoices, payment status and the reference assigned by the payment service provider. We never see or store your card number or bank details — those are collected and held by the payment service provider.
Where you supply a VAT identification number, we validate it against the European Commission's VIES service and cache the result for 30 days, in order to apply the correct tax treatment.
5. API usage records
Every API request produces a usage record containing the team, the key, a request identifier, the number of characters, the language pair, whether the answer came from cache, the latency and the resulting cost.
Usage records never contain the text you sent or the translation you received. That is a design decision, not a policy promise: the field does not exist.
6. Translation content
The text you send to the API is transmitted to the translation engine provider, translated and returned to you. Unless you switch caching off for your team, the translation is stored in our cache with a hash of the input as the key — the input text itself is not stored in a readable form, but the translated output is. You can switch caching off per team in the dashboard at any time, with immediate effect.
Do not send special categories of personal data under Article 9 GDPR through the API unless your own legal basis covers it; see the data processing agreement.
7. Support correspondence
If you write to us we process your message, your address and any information you choose to include, in order to answer.
Legal bases
| Processing | Legal basis |
|---|---|
| Providing the website and delivering pages | Art. 6(1)(f) — our legitimate interest in operating a functioning, secure site |
| Server logs, rate limiting, abuse prevention | Art. 6(1)(f) — legitimate interest in security and availability |
| The live demo and its per-network limit | Art. 6(1)(f) — legitimate interest in offering a trial without abuse |
| Account creation and operation of the service | Art. 6(1)(b) — performance of a contract |
| Billing, invoicing, VAT validation | Art. 6(1)(b) and Art. 6(1)(c) — contract and legal obligation |
| Retaining invoices and accounting records | Art. 6(1)(c) — legal retention obligations |
| Security e-mails and service notices | Art. 6(1)(b) — performance of a contract |
| Translation content | Art. 28 — processing on behalf of the customer |
We do not send marketing e-mail and therefore rely on no consent for it. If we ever do, it will be by separate, freely revocable opt-in.
Retention
| Data | Retained for |
|---|---|
| Server logs | 7 days |
| Demo rate-limit counters | 24 hours |
| Translation cache entries | 7 days in memory, and until deletion in the database; removed immediately when a team disables caching |
| Account data | For the life of the account |
| Account data after deletion | 30 days, then irreversibly deleted; a further 90-day window applies to team data so that a deletion in error can be undone |
| Usage records | 24 months, then aggregated to monthly totals without key-level detail |
| Invoices and accounting records | 10 years, as required by tax law |
| Support correspondence | 24 months |
Recipients and Sub-processors
We use a small number of service providers. Each is bound by a data processing agreement under Article 28 GDPR, and each is listed here by function. We deliberately describe the translation engine provider by role rather than by name, because the engine is a component of our service that we may change; material changes are announced in advance under the data processing agreement.
| Function | Provider | Processing location |
|---|---|---|
| Translation engine | AI translation engine provider (EU/US hosting per configuration) | European Union or United States, depending on configuration |
| Hosting of servers and databases | Infrastructure and hosting provider | Germany |
| Content delivery, TLS termination and DDoS protection | CDN and network security provider | Global network with European points of presence; operator established in the United States |
| Payment processing | Payment service provider | European Union |
| Transactional e-mail delivery | E-mail delivery provider | European Union |
Beyond these, we disclose personal data only where we are legally obliged to do so, or where it is necessary to establish, exercise or defend legal claims. We do not sell personal data, and we do not share it for advertising purposes.
International transfers
Our own infrastructure is located in Germany. Two of the functions above may involve a transfer outside the European Economic Area:
- Where the translation engine is configured to a provider hosting in the United
States, the text you send is transferred there for the duration of the request.
- Our content delivery and security provider is established in the United States,
although European traffic is served from European points of presence.
Such transfers are made on the basis of the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914, Module 3 where we act as processor and Module 2 where we act as controller), supplemented by the UK International Data Transfer Addendum for UK GDPR purposes, and accompanied by a transfer impact assessment and technical measures including encryption in transit. Where a recipient is certified under the EU–US Data Privacy Framework, we also rely on the corresponding adequacy decision.
The United Kingdom, where we are established, benefits from an adequacy decision of the European Commission, so transfers from the EEA to us require no additional safeguard.
You may request a copy of the safeguards we rely on by writing to [email protected].
Your rights
Under the GDPR and the UK GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure (Art. 17);
- restriction of processing (Art. 18);
- data portability in a structured, machine-readable format (Art. 20);
- object to processing based on legitimate interests, on grounds relating to
your particular situation (Art. 21);
- withdraw consent at any time, where processing is based on consent, without
affecting the lawfulness of processing before the withdrawal.
Two of these are built into the product rather than handled by e-mail: the settings page in the dashboard offers a full data export as JSON and an account deletion that starts a 30-day countdown, which you can cancel by signing in again. For everything else, write to [email protected]. We answer within one month, and we tell you if we need longer, as Article 12(3) allows.
We will not charge you for exercising these rights, and we do not require you to justify a request for access, erasure or portability.
Complaints
If you believe we process your data unlawfully, please tell us first — most problems are faster to fix directly. You also have the right to complain to a supervisory authority.
Because we are established in the United Kingdom, our supervisory authority is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom. If you are in the European Union, you may instead complain to the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement.
Cookies and local storage
We set exactly one cookie:
| Name | Purpose | Lifetime |
|---|---|---|
vz_sess | Keeps you signed in and carries the CSRF token | 14 days, or until you sign out |
It is strictly necessary for the service you requested, so no consent is required under Article 5(3) of the ePrivacy Directive. It is set with HttpOnly, SameSite=Lax and, over HTTPS, Secure. There are no analytics cookies, no advertising cookies and no third-party cookies. We do not use browser fingerprinting.
Security
We protect personal data with, among other measures: TLS for every connection, HSTS, a content security policy without inline scripts, Argon2id password hashing, hashed API keys, CSRF tokens on every form, prepared statements for every database query, rate limiting on sign-in and on the API, role-based access within teams, and separation of secrets from the code base. Access to production systems is limited to the people who need it and is authenticated by key, not by password.
Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you, and we do not profile you within the meaning of Article 22 GDPR. Machine translation is an automated process, but it produces text — it makes no decisions about people.
Children
The service is directed at businesses and developers, not at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to [email protected] and we will delete it.
Changes to this policy
We update this policy when the service changes. The version date is at the top of this page. Where a change materially affects how we process personal data of account holders, we announce it by e-mail at least 30 days before it takes effect.