How DeepReference handles document data
This page describes where processing happens, how traffic and accounts are protected, and what deletion and model-improvement controls do.
EU Data Residency
Application processing and storage are configured on infrastructure hosted in the European Union.
Service Processing
Uploaded documents are processed for the translation, editing, terminology, and review functions you request.
Deletion Controls
Deleting a document schedules its file and generated translation data for removal from the active service.
Model Improvement Is Opt-in
Customer documents are excluded from model improvement unless the account owner turns the setting on.
Infrastructure and data location
The application servers are in the European Union. Cloudflare sits in front of them to handle network protection. For supported routes, the browser seals document and application content before it crosses that intermediary; glossary imports and other multipart transfers use TLS.
Encryption
TLS protects traffic in transit. Supported API requests and responses also use browser-side HPKE sealing based on RFC 9180. Multipart file uploads use TLS. Passwords are salted and hashed rather than stored as readable text.
Authentication Security
Sessions use HttpOnly, Secure cookies. Rate limiting, lockout controls, and email verification for new sign-ins help protect accounts from repeated or suspicious login attempts.
Document Lifecycle
Uploaded files are linked to the account that submitted them and processed for translation workflows. Account owners can delete documents and related translation data from the workspace.
Data and privacy
The Privacy Policy and GDPR page explain personal data, legal bases, retention, user rights, and model-improvement consent in more detail.
Reporting an issue
Send security reports to [email protected]. Security reports are reviewed as a priority.