Back to home

Privacy Policy

Last updated: [EFFECTIVE DATE]

This policy explains how [COMPANY NAME] (“Localeo”, “we”), of [COMPANY ADDRESS], collects and uses personal data when you use our translation management platform and website.

For the account data described below we act as the data controller. For the content you upload into your workspace we act as a data processor on your behalf, and we only process it on your instructions.

1. What we collect

Account data

  • Your name and email address.
  • Authentication identifiers issued by Google Firebase Authentication. We never see or store your password.
  • Your interface language and notification preferences.
  • Your organization and project memberships, and your role in each.

Billing data

  • Billing address, VAT identification number, and an optional phone number.
  • Payment and invoice records: amount, currency, status, and dates. We do not receive or store your card or bank details — those go directly to Mollie.

Content you create

  • Translation keys, source strings, translations, and their status.
  • Notes, review feedback, and @mentions, together with the identity of the person who wrote each one.
  • An audit log of significant actions, recording who did what and when.

Translation strings are ordinary product copy in normal use. Please do not put personal data of third parties into them.

Technical data

  • Server logs, including IP address, user agent, request path, and timing, used for security and troubleshooting.
  • Strictly necessary cookies and local storage used to keep you signed in and to remember your selected workspace and theme.

2. Why we use it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the service and your accountPerformance of a contract
Billing, invoicing, and tax recordsContract; legal obligation
Transactional email (invitations, mentions, weekly digests)Contract; legitimate interests
Security, abuse prevention, and audit loggingLegitimate interests
Product improvement and supportLegitimate interests
Marketing email, if we ever send anyConsent (withdrawable at any time)

Digest and mention emails can be turned off per user under Settings → Notifications, without affecting your use of the service.

3. Who we share it with

We do not sell personal data. We share it only with the subprocessors below, each of which is bound by a data processing agreement:

SubprocessorPurposeData
Google (Firebase Authentication)Sign-in and identityEmail address, authentication identifiers
Mollie B.V.Payment processingBilling details, payment records
Brevo (Sendinblue)Transactional emailName, email address, message content
Cloudflare (R2 and CDN)Hosting and delivery of release artifactsPublished translation files, request metadata
[HOSTING PROVIDER]Application and database hostingAll service data

We may also disclose data where the law requires it, or to a successor entity in a merger or acquisition — in which case we will tell you before your data becomes subject to a different policy.

4. Published release files are public

When you publish a release, the compiled translation files are served from our CDN over unauthenticated URLs. The URLs contain random, unguessable identifiers, but they carry no password, token, or expiry: anyone holding a URL can download the file behind it. Treat published release content as public, and never place personal data in it.

5. International transfers

Our infrastructure is located in [HOSTING REGION]. Some subprocessors may process data outside the European Economic Area. Where that happens we rely on the European Commission’s Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism. You can request a copy of the safeguards in place.

6. How long we keep it

  • Account and workspace data — for as long as your account is open.
  • Deleted organizations and projects — these are marked as deleted and removed from the interface immediately, and the underlying records are retained for [RETENTION PERIOD] so that an accidental deletion can be reversed, then permanently erased.
  • Closed accounts — erased or irreversibly anonymised within [RETENTION PERIOD] of closure.
  • Invoices and financial records — retained for the statutory period, which is [7] years in [JURISDICTION].
  • Server logs[LOG RETENTION] days.
  • Backups — overwritten on a rolling [BACKUP RETENTION] cycle.

7. Your rights

Under the GDPR and comparable laws you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time without affecting processing already carried out.

Exercise any of these by emailing [PRIVACY EMAIL]. We respond within one month. You may also lodge a complaint with your local supervisory authority — in [JURISDICTION] that is [SUPERVISORY AUTHORITY].

If your data sits inside someone else’s workspace, they are the controller for it. We will forward your request to them and support them in answering it.

8. Security

We encrypt data in transit with TLS, restrict access to production systems to the people who need it, keep an audit log of significant actions, and take regular backups. No system is perfectly secure, but we work to protect your data with measures appropriate to the risk. If a breach is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as the law requires.

9. Cookies

We use only strictly necessary cookies and browser local storage — to keep you signed in, remember your selected organization and project, and remember your light or dark theme. We do not use advertising or cross-site tracking cookies. [UPDATE IF ANALYTICS ARE ADDED]

10. Children

The service is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes will be announced by email or in the app at least [NOTICE PERIOD] days before they take effect, and the “last updated” date above will change.

12. Contact

Privacy questions: [PRIVACY EMAIL]. Postal address: [COMPANY NAME], [COMPANY ADDRESS]. Our data protection officer, where one is appointed, can be reached at [DPO CONTACT].

Privacy Policy · Localeo · Localeo