Skip to content

Lieber auf Deutsch lesen? Zur deutschen Fassung

Lisez cette page en français. Passer au français

Leggi questa pagina in italiano. Passa all'italiano

Lea esta página en español. Cambiar a español

Lees deze pagina in het Nederlands. Overschakelen naar het Nederlands

Leia esta página em português europeu. Mudar para português europeu

Przeczytaj tę stronę po polsku. Przełącz na polski

Läs den här sidan på svenska. Byt till svenska

Læs denne side på dansk. Skift til dansk

Les denne siden på norsk. Bytt til norsk

Lue tämä sivu suomeksi. Vaihda suomeksi

Přečtěte si tuto stránku v češtině. Přepnout do češtiny

Prečítajte si túto stránku v slovenčine. Prepnúť na slovenčinu

Preberite to stran v slovenščini. Preklopite na slovenščino

Pročitajte ovu stranicu na hrvatskom. Prebaci na hrvatski

Pročitajte ovu stranicu na srpskom. Pređite na srpski

Pročitajte ovu stranicu na bosanskom. Prebacite se na bosanski

Прочетете тази страница на български. Превключете на български

Прочитајте ја оваа страница на македонски. Префрлете се на македонски

Читайте цю сторінку українською. Перемкнути на українську

Прочитайте эту страницу на русском. Переключиться на русский

Skaitykite šį puslapį lietuvių kalba. Perjungti į lietuvių kalbą

Izlasi šo lapu latviešu valodā. Pārslēgties uz latviešu valodu

Lugege seda lehte eesti keeles. Lülitu eesti keelele

Olvassa el ezt az oldalt magyarul. Váltás magyarra

Citiți această pagină în română. Comutați la română

Διαβάστε αυτή τη σελίδα στα ελληνικά. Μετάβαση στα ελληνικά

Llegiu aquesta pàgina en català. Canvia al català

Le esta páxina en galego. Cambiar ao galego

Léigh an leathanach seo i nGaeilge. Athraigh go Gaeilge

Lestu þessa síðu á íslensku. Skipta yfir á íslensku

Bu sayfayı Türkçe okuyun. Türkçeye geçin

Aqra din il-paġna bil-Malti. Aqleb għall-Malti

Lexoni këtë faqe në shqip. Kaloni në shqip

Irakurri orri hau euskaraz. Aldatu euskarara

Language API_
Menu
Pricing Docs Languages Status Sign in
Start free

Legal

Data processing agreement

Version dated Sep 7, 2026, 12:00 AM

When you send text containing personal data to the API, we process that data for you. This agreement is the contract that Article 28(3) of the General Data Protection Regulation requires for such processing. The German version is the authoritative one.

1. Purpose, parties and conclusion

The parties are you, the customer, as controller, and Baduno GmbH, Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany, entered in the Handelsregister des Amtsgerichts Frankfurt am Main under HRB 111727, as processor.

The agreement is part of the terms of service and comes into force together with them, the moment you accept the terms. It needs no signature. If your organisation requires a countersigned copy, request one from [email protected].

Its purpose is to implement Article 28 GDPR for the processing described in Annex I.

2. Scope

2.1 Processing on your behalf

The personal data contained in the text you submit to the API is your data: you determine why it is processed, and you are responsible for having a legal basis for the processing and for the lawfulness of what you submit. We handle that data only for you and only as set out here.

2.2 Processing for our own purposes

Account, team, billing and support data — everything described in our privacy policy — we process as controller in our own right. That processing lies outside this agreement.

3. Description of the processing

3.1 Subject matter, nature and purpose

The subject matter is the machine translation of text that reaches us through the API. Processing consists of receiving the text, forwarding it to the translation engine, returning the translation to you and — unless you have disabled caching — storing the translated output under a hash of the input so that an identical request can be served without a new computation. It happens continuously, with each API request, for as long as the terms of service are in force plus the deletion periods in clause 7.

3.2 Data subjects and types of data

What you submit is up to you, so the categories follow from your use. Typically the data subjects are your customers, employees and users, and any other person mentioned in the text; the data types are whatever personal data the text contains — names, contact details, correspondence, order or support information most commonly.

3.3 Special categories

Data falling under Article 9 GDPR and data on criminal convictions under Article 10 GDPR must not be submitted unless you have confirmed to us in writing that your legal basis and your own assessment permit it. Our standard technical measures are not designed for such data.

4. Our obligations as processor

4.1 Acting on instructions

We process personal data only on your documented instructions, including with regard to transfers to third countries, unless Union or member state law that applies to us requires otherwise — in which case we inform you of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

Your instructions consist of this agreement, the terms of service, the documentation and the settings you make in the dashboard, above all the per-team caching switch. Each API request is an instruction to translate its content.

If we consider an instruction to infringe the GDPR or other data protection law, we tell you so and may hold off executing it until you have confirmed or amended it.

4.2 Confidentiality of personnel

Everyone authorised to process personal data under this agreement is bound to confidentiality, and that duty continues after their engagement ends. Access is restricted to the people who need it to operate and support the service.

4.3 Security measures

We implement the technical and organisational measures described in Annex II, having regard to the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing and the risk to data subjects (Article 32 GDPR). We review them regularly and may adapt them, provided the level of protection does not fall.

4.4 Assistance with data subject requests

Taking the nature of the processing into account, we assist you with appropriate technical and organisational measures, as far as this is possible, in responding to requests from data subjects exercising their rights.

If a data subject approaches us directly about data we process for you, we do not answer on the merits; we pass the request on to you without undue delay.

Usage records contain no submitted text, and cache entries are keyed by a hash rather than by any identifier of a person, so we cannot search processed content for a particular data subject. The practical way to erase is to clear your team's cache, which the dashboard does immediately when caching is disabled.

4.5 Assistance with security, DPIAs and consultations

Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation of the supervisory authority.

4.6 Notification of personal data breaches

A personal data breach affecting data processed on your behalf is notified to you without undue delay and at the latest within 48 hours of our becoming aware of it, by e-mail to the address on your account.

The notification sets out the nature of the breach, the categories and approximate number of data subjects and records affected as far as known, the likely consequences, the measures taken or proposed, and a point of contact. If not all of this is known at once, we supply it in stages without undue further delay.

Notifying the supervisory authority and the data subjects remains your task as controller; we support you with the information we hold.

4.7 Information and audits

We make available to you all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by you or an auditor you appoint.

The ordinary route is written: we answer your questions and hand over our documentation within 30 days. Where that does not suffice, you may audit on site once per calendar year, on 30 days' written notice, during business hours, without disrupting operations, under confidentiality and at your own expense — unless the audit reveals a material breach on our part, in which case we bear the cost. A further audit is possible where a supervisory authority demands one or after a personal data breach affecting your data.

5. Sub-processors

5.1 Authorisation and current list

You grant general written authorisation for the engagement of sub-processors. Those engaged when this agreement is concluded are listed by function in Annex III.

Each sub-processor is bound by contract to data protection obligations no less protective than those in this agreement, and we remain fully liable to you for its performance.

5.2 Changes and your right to object

Before we add or replace a sub-processor that handles content submitted through the API, we notify you at least 30 days in advance — by e-mail to your account address and by updating Annex III. Within that period you may object on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service with effect from the date of the change and receive a pro rata refund of any fee prepaid for the unused period.

5.3 Disclosure of identities

In public documents the translation engine provider is described by function, not by name. As controller you are entitled to know the identity, processing location and transfer safeguards of every sub-processor; we disclose them to you on request under a confidentiality undertaking, and never withhold them from the controller.

6. Transfers outside the EEA

Our own infrastructure is located in Germany, and we are established inside the European Economic Area. A transfer from you to us is therefore not a third-country transfer and needs no further safeguard.

Where a sub-processor processes data outside the EEA — see Annex III — the transfer takes place under the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), Module 3, processor to processor. For each such transfer we carry out and document a transfer impact assessment and apply supplementary measures, encryption in transit among them.

If you are established in the United Kingdom, your transfer to us is covered by the United Kingdom's adequacy regulations for the EEA. Should those regulations cease to apply, or should you require a contractual safeguard regardless, the International Data Transfer Addendum issued by the UK Information Commissioner (the "UK Addendum") to the standard contractual clauses is incorporated for that transfer at your request.

7. End of the processing

When the terms of service end, we delete the personal data processed on your behalf. Cached translations are erased within 90 days of termination, or at once if you disable caching beforehand.

You can export your account data as JSON from the dashboard at any time. Because submitted text is not kept in usage records, there is no separate return of processed content: all that exists is the cache, and it is deleted rather than returned.

Where Union or member state law requires us to keep personal data for longer, we keep it for that purpose only and process it for nothing else.

8. Liability, precedence and duration

Liability under this agreement follows clause 11.2 of the terms of service, save where Article 82 GDPR provides otherwise; nothing here limits either party's liability towards a data subject or a supervisory authority.

Where this agreement and the terms of service conflict, this agreement prevails for the processing of personal data on your behalf. Where this agreement and the standard contractual clauses conflict, the clauses prevail.

The agreement runs for as long as the terms of service are in force, and beyond that for as long as we still hold personal data processed on your behalf.


Annex I — Description of the processing

ItemDetail
ControllerYou, the customer identified by the account
ProcessorBaduno GmbH, Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany
Processor contact[email protected]
Subject matterMachine translation of text submitted through the API
Nature and purposeReceipt, translation via the engine, return of the output; optional caching under a hash of the input
Categories of data subjectsAny person mentioned in submitted text
Types of personal dataAny personal data contained in submitted text
Special categoriesNot permitted without prior written confirmation (clause 3.3)
FrequencyContinuous, on every API request
DurationTerm of the contract plus the deletion periods in clause 7
Competent supervisory authorityDer Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden, Germany

Annex II — Technical and organisational measures

AreaMeasures
Transport encryptionTLS 1.2 or higher on every connection, enforced with HSTS
Storage of secretsPasswords as Argon2id hashes; API keys as SHA-256 hashes; cache entries addressed by a SHA-256 hash of the input, never by the input itself; secrets kept outside the document root and outside version control
Access controlRole-based permissions within teams; administrative access limited to named individuals and authenticated by key; the application runs under an unprivileged system account; database access exclusively through prepared statements; network access to database and cache restricted to the application host
IntegrityContent Security Policy without inline scripts; CSRF tokens on every state-changing form; session identifiers rotated at sign-in and on change of privileges; an append-only ledger for every balance movement; idempotent background jobs
Availability and resilienceDaily database backups retained off-host; job queue with retries and a record of failed jobs; rate limiting on sign-in and on the API; independent heartbeat monitoring published on the status page
RecoveryDocumented restore procedure; backups verified by restoring them into a separate environment
Testing and reviewAutomated test suite run on every change, including tests that assert the security properties above; deliberately minimal dependency surface
Data minimisation by designUsage records hold counters only — never submitted text or translations; the demo rate limiter stores a truncated hash of the network address, never the address itself; caching can be disabled per team with immediate effect

Annex III — Sub-processors

FunctionProviderProcessing locationTransfer safeguard
Hosting of servers and databasesInfrastructure and hosting providerGermanyNone needed — within the EEA
Translation engineAI translation engine provider (EU/US hosting per configuration)European Union or United States, depending on configurationStandard contractual clauses, Module 3, where processing takes place outside the EEA
Content delivery, TLS termination, DDoS protectionCDN and network security providerEuropean points of presence; operator established in the United StatesStandard contractual clauses, Module 3
Payment processingPayment service providerEuropean UnionNone needed — within the EEA; independent controller for payment data
Transactional e-mail deliveryE-mail delivery providerEuropean UnionNone needed — within the EEA

Each provider's identity is disclosed to you as controller on request under a confidentiality undertaking (clause 5.3).

Legal notice Privacy policy Terms of service

Language API

Translation as an HTTP endpoint

Product

  • Pricing
  • Languages
  • Status

Developers

  • Quickstart
  • Endpoint reference
  • Switching from DeepL

Legal

  • Legal notice
  • Privacy policy
  • Terms of service
  • Data processing agreement

Baduno GmbH · HRB 111727 · Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany