GDPR Information

Last updated: September 2026 · Information for customers and users who need EU data protection details.

Who is responsible and how to contact us

DeepReference is responsible for personal data used to manage accounts, billing, support, and service security. Contact [email protected] about personal data and [email protected] about contractual data protection arrangements. If an organisation uploads personal data for translation, it normally determines the purpose of that processing and acts as controller; DeepReference processes the uploaded content on its instructions. Your organisation may also act as a processor for its own client. The applicable agreement must identify these roles.

Personal data and its sources

Information comes from you, your workspace administrator, content you upload, and the services involved in your account. It can include your name, email, account and organisation identifiers, language preferences, source text, documents, translations, revision history, comments, glossaries, termbases, and translation memory. Operational records include usage counts, subscription and invoice information, support correspondence, consent choices, IP addresses, browser or device details, sign-in times, and security events. Uploaded files can contain personal data about people who are not account holders.

Purposes and legal bases

We use account and workspace information to perform the service contract, including translation, editing, exports, usage accounting, and support (Article 6(1)(b)). Fraud prevention, account protection, abuse detection, and operational security rely on legitimate interests, subject to the rights of affected people (Article 6(1)(f)). Applicable accounting and regulatory duties rely on legal obligations (Article 6(1)(c)). Optional marketing and model-improvement participation rely on consent (Article 6(1)(a)). For personal data inside customer documents, the controller must establish its own lawful basis and give appropriate instructions.

Required information and optional choices

An account identifier and authentication information are needed to provide a signed-in workspace. Billing information is needed for a paid subscription. You choose which text, documents, and language assets to submit. Without the information necessary for a requested feature, we may be unable to provide that feature. Marketing consent, optional preference cookies, and model-improvement consent are separate choices; declining them does not prevent ordinary translation use.

Sensitive content and customer responsibilities

Documents may include health information, political or religious views, or other special-category data. Customers must establish an applicable Article 9 condition in addition to an Article 6 legal basis where required, and meet the rules for criminal-offence information under Article 10. Minimise or redact information unnecessary for translation. An account owner cannot give consent on behalf of every person named in an uploaded document merely by enabling an account option. Contact us about contractual and security requirements before submitting restricted material.

Recipients, providers, and international transfers

Authorised workspace users can access content according to their permissions. Infrastructure, email delivery, payment, and security providers process the data needed for their functions. The service identifies Stripe for payments, Namecheap PrivateEmail for email delivery, Cloudflare for security and delivery, and Google when you choose Google sign-in. These providers can have independent responsibilities for their own services; not every provider is a sub-processor of document content. Document processing and storage are configured for EU residency. This does not mean that every identity, payment, email, or network service is confined to the EU. Where an international transfer occurs, an applicable GDPR transfer mechanism and any necessary safeguards must be identified in the relevant arrangements. Request the current provider, location, and transfer details from [email protected].

Retention, deletion, and backups

Account information is kept while needed to operate the account. Documents, glossaries, termbases, and translation-memory entries can be removed from the workspace; supported retention settings can also apply. Ending a sign-in session invalidates that session. Account deletion starts removal of the account and its active workspace data. Security and audit records have configured cleanup periods. Backup copies expire through their separate retention cycle, so deleting active data is not a promise of immediate removal from every backup. Billing records, dispute evidence, or information subject to a legal obligation may need to be retained for the applicable period. Ask the privacy contact for the current retention schedule and any contractual exceptions.

Security and access controls

Controls include TLS transport, application-level encryption for supported browser API traffic, encrypted storage where configured, authentication, workspace permissions, session management, upload validation, and security or audit logging. Translation infrastructure must process readable content to perform the requested task; encryption does not mean that the service never processes plaintext. Access and sharing should be limited to the people who need the document. These controls reduce risk but are not a guarantee that an incident can never occur.

Marketing and model-improvement consent

Marketing messages and customer participation in private model improvement are separate opt-ins. Both are off unless enabled. You can change the choices in account settings, and marketing emails include an unsubscribe option. Essential service and security messages are separate from marketing. Withdrawing consent stops future consent-based processing and does not invalidate earlier lawful processing. Questions about material already used in model improvement, including an erasure request, should be sent to the privacy contact for an individual assessment.

Your rights and how to make a request

Depending on the circumstances, you may request access and a copy, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time and object to direct marketing. Send the request to [email protected], identifying the account or processing concerned. We may request proportionate information to verify identity. Requests are normally free and answered without undue delay, within one month; a permitted extension of up to two further months must be explained within the first month. Exceptions or refusals must be explained. If we hold your data on behalf of an organisation, we will help route the request to that controller and assist it under the applicable agreement.

Automated processing and human review

Translation and terminology generation are automated. Account limits and security checks may also act automatically. A translation output is not itself a decision about a person’s legal rights or eligibility, and customers remain responsible for reviewing output before making consequential decisions. Contact support if an automated security or account restriction appears incorrect. Any processing that falls within Article 22 requires the applicable conditions and safeguards, including rights to human involvement and challenge where required.

Data Processing Agreements

Organisations can contact [email protected] to request a Data Processing Agreement. The agreement should define the processing instructions, purpose, duration, data categories, confidentiality, security measures, sub-processor arrangements, assistance with rights and incidents, return or deletion, and audit information. A general webpage does not replace the signed agreement or a review of your particular processing requirements.

Personal data breaches

When acting as processor, we must notify the controller of a personal data breach without undue delay. When acting as controller, a breach that is not unlikely to create a risk to people must be notified to the competent authority without undue delay and, where feasible, within 72 hours of awareness. Affected people must be informed without undue delay when high risk makes that necessary, subject to the legal exceptions. Notifications describe the available facts and protective steps; additional information may follow as the investigation develops.

Complaints and further information

You can complain to a supervisory authority, especially in the EU/EEA country where you live, work, or consider an infringement occurred. You do not have to contact us first, and judicial remedies remain available. The European Data Protection Board directory below lists national authorities, including Italy’s Garante. This page should be read together with the Privacy Policy, Cookie Policy, and applicable service agreement. Material changes to purposes or practices require an updated notice and, where appropriate, a new choice.

GDPR contact

For GDPR requests, contact [email protected].

Legal entity
DeepReference
Postal address
Via Sandro Pertini 7, 00054 Fiumicino, Italy
Privacy and data-rights requests
[email protected]
Data Protection Officer contact
[email protected]