Mentions légales
Privacy policy
Disponible en anglais uniquement pour le moment ; le texte anglais fait foi.
Version datée du 7 sept. 2026, 00:00
Whenever you open a page on langapi.xyz or send a request to api.langapi.xyz, some personal data is processed. This page sets out what that data is, why we need it, how long we keep it and what you can do about it. It is our information notice under Articles 13 and 14 of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). The German version of this policy is the authoritative one.
Summary
- We run no analytics, no tracking pixels, no advertising and no third-party
scripts, and therefore no consent banner.
- One cookie,
la_sess, keeps you signed in; there is no other. - The text you translate is never written to our usage records. If caching is on
for your team, the translated output is stored under a hash of the input; you can turn caching off at any time.
- Our servers are in Germany. The translation engine may run in the EU or the
United States depending on configuration; transfers outside the EEA rest on the European Commission's standard contractual clauses.
- You can export all your data as JSON and delete your account yourself in the
dashboard.
Controller and contact
The controller for everything described here is Baduno GmbH, Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany, entered in the Handelsregister des Amtsgerichts Frankfurt am Main under HRB 111727.
Data protection enquiries: [email protected]. We have not appointed a data protection officer — neither our core activity nor our size makes one mandatory under Article 37 GDPR — so enquiries are handled by the management.
Our two roles
Depending on what you do, we act in one of two capacities:
- For the website, the documentation, your account, your team, invoicing and
support, we decide why and how data is processed. Here we are the controller, and this policy applies in full.
- For the text you send to the API to be translated, you decide. Here we are your
processor, and the data processing agreement, which is part of our contract with you, governs the processing.
Cookies
We set a single cookie:
| Name | What it does | How long it lives |
|---|---|---|
la_sess | Holds your sign-in session and the CSRF token | 14 days, or until you sign out |
Because it is strictly necessary to provide the service you asked for, Article 5(3) of the ePrivacy Directive does not require consent for it. The cookie is flagged HttpOnly and SameSite=Lax, and Secure over HTTPS. There are no analytics cookies, no advertising cookies and no cookies from third parties, and we do not fingerprint browsers.
Processing activities in detail
Visiting the website
Each page request leaves a server log entry with your IP address, the URL requested, the time, the referrer and your browser's user-agent string. We need these entries to serve the page and to spot attacks. They are truncated or deleted after seven days.
Trying the demo
The demo on the home page translates without an account. So that nobody can use it as an unlimited free service, we count how many characters have been translated per network. Your IP address itself is not stored for this purpose; what we keep is a truncated one-way hash of it next to a counter, and the entry expires automatically after 24 hours. The text you type is forwarded to the translation engine and is not retained by us.
Account and team
To register you give us an e-mail address, a name and a password. We additionally record your interface language, the teams you are a member of and your role in each, the time of your most recent sign-in and, if you enable it, your two-factor authentication settings.
Passwords exist only as an Argon2id hash. API keys exist only as a SHA-256 hash plus a short prefix — the key itself cannot be reconstructed from what we hold.
Billing
For paid accounts we process the billing name and address, the country, an optional VAT identification number, the chosen currency, invoices, the payment status and the reference issued by the payment service provider. Card numbers and bank details never reach us; the payment service provider collects and holds them.
A VAT identification number you enter is checked against the European Commission's VIES service so that the right tax treatment is applied; the result is cached for 30 days.
API usage records
Every request to the API produces a usage record: team, key, request identifier, character count, language pair, whether the answer came from the cache, latency and the resulting cost.
No usage record ever contains the text you sent or the translation returned. This is not a promise that could be broken by accident — the record simply has no field for it.
Translation content
Text sent to the API goes to the translation engine provider, is translated and comes back to you. Unless you have disabled caching for your team, the translation is then stored in our cache, keyed by a hash of the input: the input is not kept in readable form, but the output is. Caching can be turned off per team in the dashboard, with immediate effect.
Special categories of personal data under Article 9 GDPR should not be sent through the API unless your own legal basis covers it — see the data processing agreement.
Support
When you write to us we process your message, your address and whatever you choose to tell us, for the purpose of replying.
Legal bases
Grouped by the provision of Article 6(1) GDPR we rely on:
- Point (b) — performance of a contract: creating and running your account,
providing the service, sending security and service notices, invoicing.
- Point (c) — legal obligation: validating VAT numbers and applying the right
tax, keeping invoices and accounting records for the statutory period.
- Point (f) — legitimate interests: serving the website reliably and securely,
keeping server logs, rate limiting and abuse prevention, and running the demo with a per-network limit so that it can be offered without being abused.
- Article 28 — processing on behalf of the customer: the content you send for
translation.
We do not send marketing e-mail and therefore need no consent for it. Should that ever change, it will happen only through a separate opt-in that you can withdraw at any time.
Retention
| What | For how long |
|---|---|
| Demo rate-limit counters | 24 hours |
| Server logs | 7 days |
| Translation cache entries | 7 days in memory and until deleted in the database; removed immediately when a team disables caching |
| Account data | While the account exists |
| Account data after deletion | 30 days, then irreversibly erased; team data has a further 90-day window so that an accidental deletion can be reversed |
| Support correspondence | 24 months |
| Usage records | 24 months, then condensed into monthly totals without key-level detail |
| Invoices and accounting records | 10 years, as tax law requires |
Security
Among other measures we use TLS on every connection, HSTS, a content security policy that forbids inline scripts, Argon2id hashing for passwords, hashed API keys, CSRF tokens on every form, prepared statements for all database access, rate limiting on sign-in and on the API, role-based permissions within teams, and strict separation of secrets from source code. Only the people who need it can reach production systems, and they authenticate with keys rather than passwords.
Recipients and Sub-processors
We rely on a small set of service providers, each bound by a contract under Article 28 GDPR. They are listed here by function. The translation engine provider in particular is named by role rather than by company, because the engine is a replaceable component of our service; a material change is announced in advance under the data processing agreement.
| Function | Provider | Where the processing happens |
|---|---|---|
| Hosting of servers and databases | Infrastructure and hosting provider | Germany |
| Translation engine | AI translation engine provider (EU/US hosting per configuration) | European Union or United States, depending on configuration |
| Content delivery, TLS termination and DDoS protection | CDN and network security provider | Global network with European points of presence; operator established in the United States |
| Payment processing | Payment service provider | European Union |
| Transactional e-mail delivery | E-mail delivery provider | European Union |
Apart from these providers, personal data is disclosed only where the law obliges us to, or where it is necessary to establish, exercise or defend legal claims. Personal data is never sold and never shared for advertising.
International transfers
Our own infrastructure runs in Germany, and because we are established inside the European Economic Area, sending your data to us is not a third-country transfer and needs no safeguard at that step.
Two of the functions listed above can involve a transfer outside the EEA:
- if the translation engine is configured to a provider hosting in the United
States, submitted text is sent there for the duration of the request;
- the CDN and network security provider is established in the United States, even
though European traffic is handled at European points of presence.
These transfers rest on the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914 — Module 3 where we act as processor, Module 2 where we act as controller), backed by a documented transfer impact assessment and technical measures including encryption in transit. Where a recipient is certified under the EU–US Data Privacy Framework, the corresponding adequacy decision applies in addition.
A copy of the safeguards is available on request from [email protected].
Your rights
The GDPR gives you the right to obtain access to your personal data (Art. 15), to have inaccurate data rectified (Art. 16), to have data erased (Art. 17), to have processing restricted (Art. 18), to receive your data in a structured, machine-readable form (portability, Art. 20), to object to processing based on legitimate interests for reasons arising from your particular situation (Art. 21), and, where processing rests on consent, to withdraw that consent at any time without affecting the lawfulness of earlier processing.
In the dashboard
Two of these rights are built into the product. The settings page offers a full export of your data as JSON and an account deletion that starts a 30-day countdown — sign in again within that time and the deletion is cancelled.
By e-mail
Everything else goes to [email protected]. We reply within one month; should we need longer, as Article 12(3) permits, we tell you. Exercising your rights costs nothing, and we do not ask you to justify a request for access, erasure or portability.
Complaints
If you think we are processing your data unlawfully, please raise it with us first; most issues are resolved faster that way. Independently of that, you may lodge a complaint with a supervisory authority.
Our lead authority, because we are established in Hesse, is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany. You may equally turn to the authority of the place where you live, where you work or where the alleged infringement occurred.
Automated decisions
We make no automated decisions that produce legal effects for you and do no profiling within the meaning of Article 22 GDPR. Machine translation is automated, but what it produces is text; it decides nothing about anyone.
Minors
The service is aimed at businesses and developers. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, tell us at [email protected] and we will delete it.
Updates to this policy
This policy is revised when the service changes; the date of the current version appears at the top. A change that materially affects how we process account holders' data is announced by e-mail at least 30 days before it takes effect.