Back to home

Privacy Policy

Last updated: 24 August 2026

This policy explains how Localeo B.V. (“Localeo”, “we”, “us”) collects and uses personal data when you use our translation management platform, our API, and our website.

Registered officeDi Cambioweg 14, 5624 CK Eindhoven, the Netherlands
Chamber of Commerce (KvK)42132557
VAT identification numberNL869868329B01
Privacy contact[email protected]

For the account and billing data described below we act as the data controller. For the content you upload into your workspace we act as a data processor on your behalf, and we only process it on your documented instructions. The terms governing that role are set out in our Data Processing Agreement, which forms part of your contract with us.

1. What we collect

Account data

  • Your name and email address.
  • Authentication identifiers issued by Google Firebase Authentication. Passwords are handled entirely by Firebase in your browser — we never receive, see, or store your password, and there is no password field anywhere in our own systems.
  • Your interface language and notification preferences.
  • Your organization and project memberships, and your role in each.

Billing data

  • Company name, billing address, VAT identification number, and an optional phone number.
  • Payment and invoice records: amount, currency, status, and dates. We do not receive or store your card or bank details — those go directly to Mollie, our payment processor.

Content you create

  • Translation keys, source strings, translations, and their workflow status.
  • Notes, review feedback, and @mentions, together with the identity of the person who wrote each one.
  • An audit log of significant actions, recording who did what and when.
  • Where AI translation is enabled, machine-generated draft translations, recorded against the job that produced them and the person who started it. A draft is an ordinary translation in every other respect, and is reviewed by a person like any other.

Translation strings are ordinary product copy in normal use. Please do not put personal data of third parties into them.

Technical data

  • Server logs, including IP address, user agent, request path, and timing, used for security and troubleshooting.
  • Strictly necessary cookies and browser storage used to keep you signed in and to remember your selected workspace, language, and theme. Section 11 lists every one of them.

We do not use analytics, advertising, or cross-site tracking of any kind, and we do not build behavioural profiles of you.

2. Why we use it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the service and your accountPerformance of a contract
Billing, invoicing, VAT, and bookkeepingContract; legal obligation
Transactional email (invitations, mentions, weekly digests)Contract; legitimate interests
Generating draft translations with our own AI model, where enabledPerformance of a contract
Security, abuse prevention, and audit loggingLegitimate interests
Product improvement and supportLegitimate interests
Marketing email, if we ever send anyConsent (withdrawable at any time)

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you may object at any time using the contact details in section 13. Digest, assignment, and mention emails can be turned off per user under Settings → Notifications, without affecting your use of the service.

3. Who we share it with

We do not sell personal data and we do not share it for anyone else’s marketing. We share it only with the subprocessors below, each of which is bound by a data processing agreement and may use the data only to provide its service to us:

SubprocessorPurposeData
Hetzner Online GmbH (Germany; servers in Finland)Application, worker, and database hostingAll service data
Cloudflare, Inc. (EU region)DNS, TLS termination, CDN, R2 object storage for release artifacts and encrypted database backupsPublished translation files, encrypted backups, request metadata
Google (Firebase Authentication)Sign-in and identityEmail address, authentication identifiers
Mollie B.V. (the Netherlands)Payment processingBilling details, payment records
Brevo / Sendinblue SAS (France)Transactional emailName, email address, message content
Moneybird B.V. (the Netherlands)Accounting and bookkeeping of invoices, where enabledCompany name, billing details, invoice records

Two things are deliberately absent from that table, because they run on our own infrastructure rather than someone else’s. Invoice PDFs are generated on our own servers and are not sent to a third-party document service. And where AI translation is enabled, it runs on a machine we operate in the EEA: your source strings and the generated translations are never sent to a third-party AI provider, and are never used to train any model — ours or anyone else’s. Neither adds a subprocessor to the list above.

We publish changes to this list here; customers who need advance notice of a new subprocessor should see the Data Processing Agreement, which gives a 30-day objection window.

We may also disclose data where the law requires it, or to a successor entity in a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

4. Published release files are public

When you publish a release, the compiled translation files are served from our CDN over unauthenticated URLs. The URLs contain random, unguessable identifiers, but they carry no password, token, or expiry: anyone holding a URL can download the file behind it. Treat published release content as public, and never place personal data in it.

5. Where your data is processed

Our servers and database are located in Helsinki, Finland, and our object storage carries a Western Europe location hint, so service data is processed inside the European Economic Area by default.

Where AI translation is enabled, the model runs on a server we operate in the EEA and the model weights are stored on that server. Your content is sent to that machine over a private network and to no external inference service, so using the feature moves nothing outside the arrangements described on this page.

Some of our subprocessors are established outside the EEA or have a parent company that is (Google and Cloudflare in particular). Where a transfer outside the EEA takes place, we rely on the EU–US Data Privacy Framework, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with the supplementary measures described in section 10. You can request a copy of the safeguards in place.

6. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects for you, and we do not profile you. Rate limiting and abuse protection are technical thresholds, not decisions about you as a person.

AI translation is not automated decision-making either. It writes a draft into a field that a person then reads, edits, approves or discards; it decides nothing about any individual and produces no legal or similarly significant effect. Nothing it writes is published without a person acting on it.

7. Children

The service is offered to businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

8. How long we keep it, and how deletion actually works

We are deliberately precise here, because how our deletion works matters to you.

When you delete an organization, a project, or your account, the record is marked as deleted and disappears from the interface immediately: it can no longer be opened, listed, or accessed through the API. The underlying rows are retained rather than destroyed at that moment, so that an accidental deletion can be reversed and so that audit history remains intelligible.

To have your data permanently erased, ask us. Email [email protected] and we will erase or irreversibly anonymise your personal data within 30 days, other than the records listed below that we are required or entitled to keep. We do this on request rather than automatically, and we would rather tell you that plainly than describe a deletion schedule we do not operate.

  • Account and workspace data — kept for as long as your account is open, and after closure until you ask us to erase it.
  • Invoices and financial records — kept for 7 years, the statutory retention period for accounting records in the Netherlands (art. 52 of the Algemene wet inzake rijksbelastingen). An erasure request does not override this.
  • Audit log entries — kept for as long as the workspace they belong to exists, since they are the record of who changed what. On erasure the entry is retained but the actor is anonymised.
  • Server logs — rotated automatically on a rolling basis. Each service keeps only its most recent log files and older entries are discarded as new ones are written, which in normal operation is a matter of days rather than months. We do not ship logs to any third-party log service.
  • Backups — encrypted database backups roll off on approximately a four-week cycle. Data you have asked us to erase disappears from backups as that cycle completes; we do not restore a backup to remove individual records from it.

9. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time without affecting processing already carried out.

Exercise any of these by emailing [email protected]. We respond within one month, and will tell you if we need longer because a request is complex. We do not charge for this unless a request is manifestly unfounded or excessive.

You may also lodge a complaint with a supervisory authority. Ours is the Autoriteit Persoonsgegevens in The Hague (autoriteitpersoonsgegevens.nl), and you may also complain to the authority where you live or work.

If your data sits inside someone else’s workspace, they are the controller for it and we are their processor. We will forward your request to them and support them in answering it.

We have not appointed a data protection officer. We are not required to under Art. 37 GDPR: our core activities do not consist of large-scale monitoring or of processing special categories of data. Privacy questions go to [email protected] and are handled by our management.

10. Security

All traffic to the application, the API, and the CDN is served over TLS. Access to production systems is restricted to the people who need it, significant actions are recorded in an audit log, and database backups are encrypted before they leave our server and are restored on a scheduled basis to verify that they work. Section 4 of our Data Processing Agreement lists our technical and organisational measures in full.

No system is perfectly secure, but we work to protect your data with measures appropriate to the risk. If a personal data breach is likely to result in a high risk to your rights, we will notify you and the Autoriteit Persoonsgegevens as the law requires, and we will notify customers of a breach affecting their workspace without undue delay.

Reporting a vulnerability

If you believe you have found a security vulnerability, please email [email protected] with enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly. We will acknowledge your report, keep you updated, and will not pursue legal action over research carried out in good faith under those conditions. Please do not access other people’s data, degrade the service, or run automated scans against it while testing.

11. Cookies and browser storage

We use only strictly necessary cookies and browser storage. Because none of it is used for analytics, advertising, or tracking, no consent banner is required under the Dutch Telecommunicatiewet, and you will not see one. This is the complete list:

NameTypePurpose
Firebase authentication sessionBrowser storageKeeps you signed in between visits
localeo_selected_orgLocal storageRemembers the organization you last worked in
localeo_selected_projectLocal storageRemembers the project you last worked in
themeLocal storageRemembers your light, dark, or system theme
localeCookie (1 year)Remembers your interface language
sidebar_stateCookie (7 days)Remembers whether the sidebar is expanded or collapsed

Clearing this storage signs you out and resets those preferences; nothing else is affected.

12. Changes to this policy

We may update this policy. Material changes will be announced by email or in the app at least 30 days before they take effect, and the “last updated” date above will change.

13. Contact

Privacy questions and data-subject requests: [email protected]. Security reports: [email protected]. Everything else: [email protected].

Postal address: Localeo B.V., Di Cambioweg 14, 5624 CK Eindhoven, the Netherlands.

Privacy Policy · Localeo