πŸŽ‰ Free Express Delivery on all orders over €99 Β· Use code EXPRESS24 Β· See pricing β†’ Γ—
Home GDPR Information
Data Protection

GDPR Information

EU General Data Protection Regulation · Information pursuant to Art. 13 & 14 GDPR

This page provides the formal Art. 13 & 14 GDPR disclosure required by the EU General Data Protection Regulation (Regulation (EU) 2016/679). It supplements our Privacy Policy, which contains full operational detail.

1. Identity and contact details of the controller

Transzlate, A Linguidoor Company
Donaustraße 44, 12043 Berlin, Germany
Email: hello@transzlate.com
Phone: +49 176 77882375

Data Protection Officer: hello@transzlate.com

2. Categories of personal data processed

  • Identification data: First name, last name
  • Contact data: Email address, telephone number (optional)
  • Delivery data: Postal address (for printed original delivery)
  • Document content: Content of uploaded documents (processed solely for translation purposes)
  • Transaction data: Order reference, document type, language pair, timestamp, payment status
  • Technical data: IP address (anonymised), browser type, server log data
  • Communication data: Content of enquiries submitted via our contact form or by email

3. Purposes and legal bases of processing (Art. 13(1)(c) GDPR)

Performance of contract (Art. 6(1)(b) GDPR)
Processing of identification, contact, delivery, document and transaction data to fulfil the certified translation contract, including translator assignment, quality review, digital and postal delivery.

Legal obligation (Art. 6(1)(c) GDPR)
Retention of invoices and transaction records for 10 years pursuant to § 257 HGB (German Commercial Code) and § 147 AO (German Fiscal Code).

Legitimate interests (Art. 6(1)(f) GDPR)
Server log processing for IT security; fraud and abuse prevention. The legitimate interest is the operational security of our systems. Your interests do not override this interest because IP addresses are anonymised after 7 days and logs are not used for profiling.

Consent (Art. 6(1)(a) GDPR)
Newsletter subscriptions; non-essential analytics cookies (where applicable). Consent may be withdrawn at any time without affecting the lawfulness of prior processing.

4. Recipients of personal data (Art. 13(1)(e) GDPR)

  • Sworn translators: Assigned translator receives the source document and relevant order data under a GDPR-compliant data processing agreement. Purpose: production of the certified translation.
  • Payment service providers: Stripe AB (Sweden), PayPal (Europe) S.à.r.l. β€” under their own GDPR-compliant privacy policies. We share only the data necessary for payment processing.
  • Cloud hosting provider: AWS, servers located within the EEA, under a data processing agreement pursuant to Art. 28 GDPR.
  • Email delivery provider: Google, EEA-based, under a data processing agreement.
  • Supervisory authorities: If required by applicable law.

No personal data is sold, shared with advertising networks, or transferred to recipients not listed above.

5. International transfers (Art. 13(1)(f) GDPR)

All personal data is processed and stored within the European Economic Area (EEA). Where payment processors have infrastructure outside the EEA, data is transferred under Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR. Stripe AB is established in Sweden (EEA). PayPal (Europe) is established in Luxembourg (EEA).

6. Retention periods (Art. 13(2)(a) GDPR)

  • Uploaded source documents: Automatically deleted 30 days after order completion
  • Completed translations: Retained for 90 days to allow for the acceptance guarantee; then deleted
  • Invoices and transaction records: 10 years (statutory retention, § 257 HGB, § 147 AO)
  • Contact enquiries: 6 months after resolution
  • Server log files: 30 days (IP anonymised after 7 days)
  • Newsletter subscriptions: Until consent is withdrawn

7. Your rights as a data subject (Art. 13(2)(b)–(d) GDPR)

You have the following rights, exercisable by contacting hello@transzlate.com:

▸ Art. 15 — Access

Request a copy of all personal data held about you.

▸ Art. 16 — Rectification

Correct inaccurate or incomplete personal data.

▸ Art. 17 — Erasure

Request deletion where no legitimate purpose justifies retention.

▸ Art. 18 — Restriction

Request restriction of processing in certain circumstances.

▸ Art. 20 — Portability

Receive data provided by you in a structured, machine-readable format.

▸ Art. 21 — Object

Object to processing based on legitimate interests.

We will respond to any exercise of rights within 30 calendar days. No fee is charged for reasonable requests. Requests deemed manifestly unfounded or excessive may attract a reasonable fee or be refused (Art. 12(5) GDPR).

8. Right to lodge a complaint (Art. 13(2)(d) GDPR)

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or place of the alleged infringement.

The supervisory authority competent for Transzlate, A Linguidoor Company is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
Phone: +49 176 77882375
Email: hello@transzlate.com
Website: www.datenschutz-berlin.de

9. Obligation to provide data / consequences of not providing

The provision of your name, email address and a legible copy of the source document is a contractual requirement to conclude and perform the translation contract. Without this data, we cannot provide the service.

The provision of your telephone number and postal delivery address is optional and only required if you select postal delivery of the printed certified original.

No personal data is processed for automated decision-making (including profiling) that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR.

10. Technical and organisational measures (Art. 32 GDPR)

Transzlate, A Linguidoor Company implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • SSL/TLS encryption of all data in transit (minimum TLS 1.2)
  • Encryption of stored documents at rest using AES-256
  • Role-based access controls: document access limited to the assigned translator only
  • Automatic deletion of source documents 30 days after order completion
  • ISO 27001:2013 certified information security management system
  • Regular penetration testing and vulnerability assessments
  • Data processing agreements with all processors pursuant to Art. 28 GDPR
  • Staff data protection training
  • Data breach response procedure with 72-hour supervisory authority notification (Art. 33 GDPR)
GDPR & data protection enquiries
Order Now