Skip to content

Data Processing Agreement

Updated 27 Sept 2026

DRAFT — to be reviewed by counsel. This text describes what the platform actually does today. It is not yet final legal wording.

1. Parties and roles

  • The customer (the firm or person who uploads documents) is the controller: you decide which documents are translated and why.
  • The platform (Translate, translate.developeroffice.com) is the processor: we process the personal data in your documents only to provide the translation, certification and verification service you ask for.

2. Subject and duration

This agreement covers the personal data contained in documents you upload, and the translations, certificates and records made from them. It lasts as long as you use the service, and after that until the content has been deleted under section 9.

3. Nature and purpose

We receive your uploaded files, read their text (including reading scanned pages), produce a machine translation draft, have it reviewed and certified by a sworn translator where you order certification, generate PDFs, and keep a certificate record that anyone can verify by serial number at /v. We process your data for these purposes only.

4. Categories of data

  • The content of your documents, which may include names, dates of birth, addresses, identity numbers, family, education, employment, legal, financial or medical details — whatever the documents contain.
  • Account data: names and email addresses of your users.
  • Records of activity: who opened, shared, certified or downloaded a document, and when.

5. Our obligations

  • We process your data only on your instructions, as given through the service.
  • Everyone who works on your documents — platform staff and sworn translators — is bound to confidentiality.
  • Staff access: platform staff can open a document's content only through a purpose-gated reveal. A stated purpose is required and recorded before anything is shown, and your firm's owners and admins are notified.
  • We will help you answer requests from the people whose data is in your documents (see section 10).

6. Security measures

  • The service is served only over HTTPS (TLS).
  • API keys and other secret settings are encrypted with AES-256-GCM before they are stored.
  • Share-link tokens and passcodes are kept only as hashes; a viewer's IP address is kept only as a keyed hash.
  • Every certificate is signed (Ed25519) over a hash of the certified text, so any alteration can be detected at /v.
  • Access to document content by staff is purpose-gated, recorded in the audit trail and notified to your firm.
  • Database backups are encrypted (AES-256). Cloudflare R2 and Backblaze B2 also encrypt stored data at rest by default (the provider's default).

7. Sub-processors

We use these providers to run the service:

  • Anthropic — machine translation (and reading scanned pages as a fallback).
  • Datalab, or the platform's own GPU server — reading scanned pages (OCR).
  • Cloudflare — hosting the application and storing files (R2).
  • Hetzner — hosting the platform's own database servers.
  • Backblaze B2 — storing encrypted database backups.
  • Postal (with Resend as a fallback) — sending email.

We will tell you before we add or replace a sub-processor.

8. Data location

  • Database: the platform's own PostgreSQL cluster on Hetzner — primary in Helsinki (Finland), standby in Germany.
  • Uploaded files and generated PDFs: Cloudflare R2, bucket region Asia-Pacific.
  • Database backups: Backblaze B2, US-East region, encrypted and rotated.

9. Retention and deletion

We delete the content and keep the proof:

  • A finished document stays active for 6 months from completion. You can extend it, up to 1 year in total.
  • Reminders are sent 30 days and 7 days before it expires.
  • It is then archived for 30 days, after which its content — files, texts, PDFs and share links — is permanently deleted.
  • The certificate record stays verifiable at /v permanently, and financial and audit records are kept.
  • Deleted content can remain in encrypted database backups for about 3–4 weeks until those backups rotate out.

10. Your rights and our assistance

  • You can export your firm's access-audit trail for any date range (Compliance page, CSV).
  • You can download a chain-of-custody certificate for each document.
  • We will help you respond to requests to access, correct or delete personal data, within what the service can do.

11. Personal data breaches

If we become aware of a breach affecting your data, we will notify you without undue delay, with what we know about its nature, the data involved and the steps we are taking.

12. End of the service

When you stop using the service, your document content is deleted under section 9. Before that, you can download your translations, certificates and audit records. Certificate records stay verifiable at /v.

13. Governing law

[to be confirmed]

Was this helpful?