Skip to content

Diese Seite gibt es auch auf Deutsch. Auf Deutsch anzeigen

vizvuz
Pricing Docs Languages Status
Sign in Start free

Legal

Data processing agreement

Version of Sep 1, 2026, 12:00 AM

This agreement is concluded between you, the customer ("controller"), and PRALOJ LTD, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom, registered in the Companies House, England and Wales under company number 17216920 ("processor"). It forms part of the terms of service and takes effect when you accept them. No signature is required; if your organisation needs a signed counterpart, write to [email protected].

It implements Article 28 of the EU General Data Protection Regulation and the corresponding provisions of the UK GDPR.

1. Roles

You are the controller of the personal data contained in the text you submit to the API. We process that data solely on your behalf, as your processor. You are responsible for having a legal basis for the processing and for the lawfulness of the content you submit.

For the account, billing and support data described in our privacy policy, we act as controller in our own right. That processing is outside the scope of this agreement.

2. Subject matter, duration, nature and purpose

Subject matter: machine translation of text submitted through the API.

Duration: for as long as the terms of service are in force, plus the deletion periods in clause 11.

Nature and purpose: receiving text, transmitting it to the translation engine, returning the translated text, and — unless you disable caching — storing the translated output against a hash of the input so that a repeated request can be answered without recomputation.

3. Types of personal data and categories of data subjects

We do not control what you submit. The categories therefore depend on your use. Typically they are:

Categories of data subjects: your customers, employees, users and any other person referred to in the text you translate.

Types of personal data: any personal data that appears in submitted text — commonly names, contact details, correspondence content, order or support information.

Special categories: you must not submit data falling under Article 9 GDPR or data relating to criminal convictions under Article 10 GDPR unless you have confirmed to us in writing that your legal basis and your own assessment permit it. Our standard technical measures are not designed for that data.

4. Instructions

We process personal data only on your documented instructions, including as regards transfers to a third country, unless required to do otherwise by EU or member state law to which we are subject; in that case we inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

Your instructions are: this agreement, the terms of service, the documentation, and the settings you make in the dashboard — in particular the per-team caching switch. Sending a request through the API is an instruction to translate its content.

We inform you if, in our opinion, an instruction infringes the GDPR or other data protection law, and may suspend execution of that instruction until you confirm or change it.

5. Confidentiality

Every person authorised to process personal data under this agreement is bound by a duty of confidentiality that survives the end of their engagement. Access is limited to those who need it to operate and support the service.

6. Security of processing

We implement the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk to data subjects (Article 32 GDPR).

We review the measures regularly and may change them, provided the level of protection is not reduced.

7. Sub-processors

You give general written authorisation for the engagement of sub-processors. The sub-processors engaged at the date of this agreement are listed in Annex III, by function.

We will inform you at least 30 days before adding or replacing a sub-processor that processes content submitted through the API, by e-mail to your account address and by updating Annex III. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service with effect from the date of the change and receive a pro rata refund of any prepaid fee for the unused period.

We impose on each sub-processor, by contract, data protection obligations no less protective than those in this agreement, and we remain fully liable to you for their performance.

We describe the translation engine provider by function rather than by name in public documents. On request under a confidentiality undertaking, we disclose the identity, the processing location and the transfer safeguards of every sub-processor to you as controller — that information is never withheld from the controller.

8. Assisting you with data subject requests

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights.

If a data subject contacts us directly about data we process on your behalf, we do not respond substantively; we forward the request to you without undue delay.

Because usage records contain no submitted text, and because cached entries are keyed by a hash rather than by an identifier of a data subject, we cannot search processed content by data subject. The practical means of erasure is deletion of the cache for your team, which the dashboard performs immediately when caching is disabled.

9. Assisting you with your other obligations

We assist you, taking into account the nature of processing and the information available to us, in complying with your obligations under Articles 32 to 36 GDPR — security of processing, breach notification, data protection impact assessments and prior consultation. We make available all information necessary to demonstrate compliance with Article 28.

10. Personal data breaches

We notify you of a personal data breach affecting personal data processed on your behalf without undue delay and in any event within 48 hours of becoming aware of it, by e-mail to your account address.

The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not all available at once, we provide it in phases without undue further delay.

Notifying the supervisory authority and the data subjects is your responsibility as controller; we support you with the information we hold.

11. Deletion and return

On termination of the terms of service, we delete personal data processed on your behalf. Cached translations are deleted within 90 days of termination, or immediately if you disable caching before then.

You can export your account data at any time through the dashboard, in JSON. Because submitted text is not retained in usage records, there is no separate return of processed content: what exists is the cache, which is deleted rather than returned.

We may retain personal data where and for as long as EU or member state law requires. In that case the data is restricted to that purpose and is not otherwise processed.

12. Audits

We make available to you all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.

In practice: we answer your written questions and provide our documentation within 30 days. Where that is not sufficient to demonstrate compliance, you may conduct an on-site audit once per calendar year, on 30 days' written notice, during business hours, without disrupting operations, subject to confidentiality, and at your own cost — except where the audit reveals a material breach by us, in which case we bear the cost. Additional audits may be conducted where a supervisory authority requires one or after a personal data breach affecting your data.

13. International transfers

Our own infrastructure is located in Germany. Where a sub-processor processes data outside the European Economic Area — see Annex III — the transfer is made on the basis of the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), Module 3 (processor to processor) for onward transfers, and Module 2 (controller to processor) where you transfer to us as a UK-established processor.

For transfers subject to the UK GDPR, the clauses are supplemented by the UK Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (the International Data Transfer Addendum to the EU SCCs, version B1.0).

The United Kingdom benefits from an adequacy decision of the European Commission, so a transfer from the EEA to us requires no further safeguard for as long as that decision remains in force. Should it lapse, the standard contractual clauses in this clause apply to that transfer automatically, without further action by either party.

We carry out and document a transfer impact assessment for each transfer outside the EEA and apply supplementary measures including encryption in transit.

14. Liability

Liability under this agreement follows clause 13 of the terms of service, except where Article 82 GDPR provides otherwise; nothing here limits the liability of either party towards a data subject or a supervisory authority.

15. Order of precedence

Where this agreement conflicts with the terms of service, this agreement prevails in respect of the processing of personal data on your behalf. Where it conflicts with the standard contractual clauses, the clauses prevail.


Annex I — Details of processing

ItemDetail
ControllerYou, the customer identified by the account
ProcessorPRALOJ LTD, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom
Processor contact[email protected]
Categories of data subjectsAny person referred to in text submitted through the API
Types of personal dataAny personal data contained in submitted text
Special categoriesNot permitted without prior written confirmation (clause 3)
Nature and purposeMachine translation of submitted text; optional caching of output
FrequencyContinuous, on each API request
DurationTerm of the contract, plus the deletion periods in clause 11
Competent supervisory authorityInformation Commissioner's Office, United Kingdom

Annex II — Technical and organisational measures

Pseudonymisation and encryption. All connections use TLS 1.2 or higher with HSTS. Passwords are stored as Argon2id hashes; API keys as SHA-256 hashes. Cache entries are addressed by a SHA-256 hash of the input rather than by the input itself. Secrets are held outside the document root and outside version control.

Confidentiality. Role-based access control within teams; administrative access limited to named individuals and authenticated by key; the application runs under an unprivileged system account; database access via prepared statements only; network access to database and cache restricted to the application host.

Integrity. Content Security Policy without inline scripts, CSRF tokens on every state-changing form, session identifiers rotated on sign-in and on privilege change, an append-only ledger for all balance movements, and idempotent background jobs.

Availability and resilience. Daily database backups with off-host retention; an automatic queue with retry and a failed-job record; rate limiting on sign-in and on the API; independent heartbeat monitoring published on the status page.

Restoration. Documented restore procedure from backup; backups tested by restore into a separate environment.

Testing and evaluation. Automated test suite executed on every change, including tests that assert the security properties above; dependency surface kept deliberately minimal.

Data minimisation by design. Usage records contain counters only — never submitted text or translations. Demo rate limiting stores a truncated hash of the network address, never the address itself. Caching can be disabled per team, with immediate effect.

Annex III — Sub-processors

FunctionProviderProcessing locationTransfer safeguard
Translation engineAI translation engine provider (EU/US hosting per configuration)European Union or United States, depending on configurationSCCs Module 3 plus UK Addendum where processing is outside the EEA
Hosting of servers and databasesInfrastructure and hosting providerGermanyNot applicable — within the EEA
Content delivery, TLS termination, DDoS protectionCDN and network security providerEuropean points of presence; operator established in the United StatesSCCs Module 3 plus UK Addendum
Transactional e-mail deliveryE-mail delivery providerEuropean UnionNot applicable — within the EEA
Payment processingPayment service providerEuropean UnionNot applicable — within the EEA; acts as an independent controller for payment data

The identity of each provider is disclosed to you as controller on request under a confidentiality undertaking (clause 7).

Imprint Privacy Terms

vizvuz

Translation API for Europe

Product

  • Pricing
  • Languages
  • Status

Developers

  • Quickstart
  • API reference
  • Migrate from DeepL

Legal

  • Imprint
  • Privacy
  • Terms
  • Data processing agreement

PRALOJ LTD, company number 17216920, 71-75 Shelton Street, Covent Garden, WC2H 9JQ London, United Kingdom.