Back to home

Data Processing Agreement

Last updated: 24 August 2026

This Data Processing Agreement (the “DPA”) applies whenever Localeo B.V. (“Localeo”, the “Processor”) processes personal data on behalf of a customer (“you”, the “Controller”) in providing the Localeo service.

It is concluded under Article 28(3) of the General Data Protection Regulation and forms an integral part of our Terms of Service. By accepting those Terms you also accept this DPA, and no separate signature is required. If you need a countersigned copy for your own records, email [email protected].

Localeo B.V. is registered with the Dutch Chamber of Commerce under number 42132557 and has its registered office at Di Cambioweg 14, 5624 CK Eindhoven, the Netherlands.

1. Roles and scope

  • You are the controller for the personal data contained in the content you and your users upload into your workspace. We are your processor for it.
  • We are the controller, not your processor, for the data we need in order to run our own business: account identities, billing and invoicing data, security logs, and product usage. That processing is described in our Privacy Policy and falls outside this DPA.
  • The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
  • This DPA lasts for as long as we process personal data on your behalf, and its obligations survive termination of the Terms for as long as we hold any of that data.

2. Processing on your instructions

We process personal data only on your documented instructions, including as to transfers to a third country, unless EU or Dutch law requires otherwise — in which case we will inform you of that requirement before processing, unless the law prohibits us from doing so.

Your instructions are: these Terms, this DPA, your configuration and use of the service, and any further written instruction you give us. If we consider an instruction to infringe the GDPR or other data protection law, we will tell you without undue delay and may suspend that processing until it is resolved.

You are responsible for the lawfulness of the personal data you put into the service and for having a legal basis for it. Translation strings are not intended to hold personal data, and the service is not designed for special categories of personal data under Art. 9 GDPR or criminal conviction data under Art. 10.

3. Confidentiality

Everyone we authorise to process personal data — employees, contractors, and administrators — is bound by an obligation of confidentiality that survives the end of their engagement, and is granted access only to what their role requires.

4. Security measures

We implement appropriate technical and organisational measures under Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures in force are listed in Annex II. We may update them over time, provided the level of protection is not reduced.

You are responsible for the parts of security that sit with you: choosing strong credentials, managing who has access to your workspace, removing users who leave, keeping project API tokens secret, and deciding what content you publish. Note in particular that published release files are served over unauthenticated URLs — see section 6 of the Terms — so personal data must not be placed in content that you publish.

5. Subprocessors

You give us general authorisation to engage the subprocessors below. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

SubprocessorPurposeLocation
Hetzner Online GmbHApplication, worker, and database hostingHelsinki, Finland
Cloudflare, Inc.DNS, TLS termination, CDN, object storage for release artifacts and encrypted backupsEuropean Union (Western Europe region)
Google (Firebase Authentication)Sign-in and identityEuropean Union / United States
Mollie B.V.Payment processingThe Netherlands
Brevo / Sendinblue SASTransactional emailEuropean Union
Moneybird B.V.Accounting and bookkeeping of invoices, where enabledThe Netherlands

AI translation adds no subprocessor. Where the feature is enabled, translations are generated by a model running on infrastructure we operate within the EEA, under the same hosting arrangement as the rest of the service. Content is not sent to an external AI provider and is not used to train any model.

We will inform you of any intended addition or replacement of a subprocessor at least 30 days in advance, by email to the account owner or by a notice in the application. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the service and we will refund any fees paid for service not yet delivered.

6. Assisting you

  • Data subject requests. Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures in fulfilling requests to exercise data subject rights. Much of this you can do yourself in the application: content, memberships, and comments can be viewed, corrected, and deleted directly. If a data subject contacts us about data in your workspace, we will not respond substantively ourselves; we will forward the request to you without undue delay.
  • Security, breach, and impact assessments. We will assist you in complying with Art. 32 to 36 GDPR, taking into account the nature of processing and the information available to us — including data protection impact assessments and prior consultation with a supervisory authority where required.
  • We may charge for assistance that goes materially beyond what the service provides by default, at our then-current rates, after telling you in advance.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.

Notifying a supervisory authority or affected data subjects is your decision and responsibility as controller. We will not make such a notification on your behalf unless you ask us to, and we will support you in making it.

8. International transfers

Personal data is stored and processed within the European Economic Area by default: our servers and database are in Finland and our object storage is in Western Europe.

Where a subprocessor transfers personal data outside the EEA, that transfer takes place on the basis of an adequacy decision, the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses together with any supplementary measures required, and we will provide you with details on request.

9. Audits and information

We will make available to you all information necessary to demonstrate compliance with Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In practice we ask that you first accept the documentation we can provide — this DPA, Annex II, our subprocessor list, and answers to a reasonable security questionnaire. If that is not sufficient, an on-site or remote audit may be carried out at most once per calendar year (and additionally after a personal data breach affecting your data), on 30 days’ written notice, during business hours, without disrupting our operations, by an auditor who is not a competitor of ours and who is bound by confidentiality. Audits are at your cost.

10. Return and deletion

At the end of the provision of services, we will, at your choice, delete or return all personal data processed on your behalf, and delete existing copies, unless EU or Dutch law requires us to keep them.

We describe honestly how this works in practice. Deleting an organization or project removes it from the application immediately, so it can no longer be accessed by anyone, but the underlying records are retained so an accidental deletion can be reversed. Permanent erasure is carried out on your request to [email protected], within 30 days of that request. You may export your content before then, and for 30 days after termination, as described in section 19 of the Terms.

Encrypted database backups roll off on approximately a four-week cycle; data you have asked us to erase disappears from backups as that cycle completes, and we do not restore a backup in order to remove individual records from it. Until it does, that data remains protected by this DPA. Records we are legally required to keep — invoices and the underlying accounting data, for seven years under Dutch tax law — are retained and are not deleted on request.

11. Liability and order of precedence

The limitations and exclusions of liability in the Terms of Service apply to this DPA and to any claim arising from it, to the extent permitted by law. Nothing here limits a data subject’s rights under the GDPR.

In case of conflict, this DPA prevails over the Terms of Service in matters of data protection; the Standard Contractual Clauses, where they apply, prevail over both.

Annex I — Details of the processing

Subject matterProvision of the Localeo translation management platform to the Controller.
DurationFor the term of the Terms of Service, plus any period before erasure under section 10.
Nature and purposeHosting and storage; collaborative editing, review, and approval of translations; commenting and @mentions; notification email; generating draft translations with a machine-learning model operated by us, where the Controller enables that feature; compiling and publishing release bundles; backup, security monitoring, and support.
Categories of data subjectsThe Controller’s users: employees, contractors, translators, reviewers, and other collaborators invited to a workspace; and any individuals whose personal data the Controller chooses to include in translation content.
Types of personal dataName and email address; authentication identifiers; organization and project memberships and roles; interface language and notification preferences; authorship and timestamps of translations, comments, review feedback, and @mentions; audit log entries recording who performed which action; the identity of the user who starts an AI translation job, where that feature is enabled; and any personal data the Controller places in translation content.
Special categoriesNone. The service is not designed for special categories of personal data and the Controller undertakes not to submit them.
FrequencyContinuous, for the duration of the service.

Annex II — Technical and organisational measures

The measures below are the ones actually in force. They are described at the level of detail a security review needs, without disclosing information that would itself create a risk.

Encryption and network security

  • All traffic to the application, the API, and the CDN is served over TLS; plaintext HTTP is redirected.
  • Database backups are encrypted with AES-256 on our own server before being transmitted to off-site object storage, so the storage provider holds only ciphertext.
  • Internal service traffic between the application, worker, database, and cache is confined to a private network and is not exposed to the public internet.

Access control

  • End-user authentication is delegated to Google Firebase Authentication. Passwords are never transmitted to, processed by, or stored on our servers.
  • Application access is governed by organization and project membership with roles, so users see only the workspaces they belong to, and within a project only the languages assigned to them where that applies.
  • Access to production infrastructure is limited to the administrators who require it, over authenticated remote access, on the principle of least privilege, and is revoked when no longer needed.
  • Public API access is scoped to a single project through revocable tokens, and is rate limited per token.

Integrity, availability, and resilience

  • Continuous write-ahead log archiving plus scheduled full and incremental database backups to off-site, encrypted storage in a different location from the production server.
  • Backups are restored automatically on a scheduled basis and checked, so restorability is verified rather than assumed.
  • Changes reach production through version control and an automated pipeline, with database schema changes applied as reviewed, sequential migrations.

Accountability and monitoring

  • An in-application audit log records significant actions — who did what, to which object, and when — and is visible to organization administrators.
  • Server-side request logging supports security investigation and troubleshooting. Logs are rotated automatically on a rolling basis so that older entries are discarded as new ones are written, and they are not shipped to any third-party log service.
  • Comment and note content is sanitised on write against a strict allowlist to prevent stored cross-site scripting.
  • Personnel with access to personal data are bound by confidentiality obligations.

Measures we do not currently offer

Stated plainly so that you can assess the risk yourself: we do not currently offer multi-factor authentication, single sign-on, IP allowlisting, customer-managed encryption keys, or an independent third-party security certification such as ISO 27001 or SOC 2.

Contact

Questions about this DPA, requests for a countersigned copy, and data-subject matters: [email protected]. Security reports: [email protected].

Data Processing Agreement · Localeo