Правно
Data processing agreement
Za sada dostupno samo na engleskom; engleski tekst je merodavan.
Verzija od 7. 9. 2026. 00:00
When you send text containing personal data to the API, we process that data for you. This agreement is the contract that Article 28(3) of the General Data Protection Regulation requires for such processing. The German version is the authoritative one.
1. Purpose, parties and conclusion
The parties are you, the customer, as controller, and Baduno GmbH, Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany, entered in the Handelsregister des Amtsgerichts Frankfurt am Main under HRB 111727, as processor.
The agreement is part of the terms of service and comes into force together with them, the moment you accept the terms. It needs no signature. If your organisation requires a countersigned copy, request one from [email protected].
Its purpose is to implement Article 28 GDPR for the processing described in Annex I.
2. Scope
2.1 Processing on your behalf
The personal data contained in the text you submit to the API is your data: you determine why it is processed, and you are responsible for having a legal basis for the processing and for the lawfulness of what you submit. We handle that data only for you and only as set out here.
2.2 Processing for our own purposes
Account, team, billing and support data — everything described in our privacy policy — we process as controller in our own right. That processing lies outside this agreement.
3. Description of the processing
3.1 Subject matter, nature and purpose
The subject matter is the machine translation of text that reaches us through the API. Processing consists of receiving the text, forwarding it to the translation engine, returning the translation to you and — unless you have disabled caching — storing the translated output under a hash of the input so that an identical request can be served without a new computation. It happens continuously, with each API request, for as long as the terms of service are in force plus the deletion periods in clause 7.
3.2 Data subjects and types of data
What you submit is up to you, so the categories follow from your use. Typically the data subjects are your customers, employees and users, and any other person mentioned in the text; the data types are whatever personal data the text contains — names, contact details, correspondence, order or support information most commonly.
3.3 Special categories
Data falling under Article 9 GDPR and data on criminal convictions under Article 10 GDPR must not be submitted unless you have confirmed to us in writing that your legal basis and your own assessment permit it. Our standard technical measures are not designed for such data.
4. Our obligations as processor
4.1 Acting on instructions
We process personal data only on your documented instructions, including with regard to transfers to third countries, unless Union or member state law that applies to us requires otherwise — in which case we inform you of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
Your instructions consist of this agreement, the terms of service, the documentation and the settings you make in the dashboard, above all the per-team caching switch. Each API request is an instruction to translate its content.
If we consider an instruction to infringe the GDPR or other data protection law, we tell you so and may hold off executing it until you have confirmed or amended it.
4.2 Confidentiality of personnel
Everyone authorised to process personal data under this agreement is bound to confidentiality, and that duty continues after their engagement ends. Access is restricted to the people who need it to operate and support the service.
4.3 Security measures
We implement the technical and organisational measures described in Annex II, having regard to the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing and the risk to data subjects (Article 32 GDPR). We review them regularly and may adapt them, provided the level of protection does not fall.
4.4 Assistance with data subject requests
Taking the nature of the processing into account, we assist you with appropriate technical and organisational measures, as far as this is possible, in responding to requests from data subjects exercising their rights.
If a data subject approaches us directly about data we process for you, we do not answer on the merits; we pass the request on to you without undue delay.
Usage records contain no submitted text, and cache entries are keyed by a hash rather than by any identifier of a person, so we cannot search processed content for a particular data subject. The practical way to erase is to clear your team's cache, which the dashboard does immediately when caching is disabled.
4.5 Assistance with security, DPIAs and consultations
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations under Articles 32 to 36 GDPR: security of processing, breach notification, data protection impact assessments and prior consultation of the supervisory authority.
4.6 Notification of personal data breaches
A personal data breach affecting data processed on your behalf is notified to you without undue delay and at the latest within 48 hours of our becoming aware of it, by e-mail to the address on your account.
The notification sets out the nature of the breach, the categories and approximate number of data subjects and records affected as far as known, the likely consequences, the measures taken or proposed, and a point of contact. If not all of this is known at once, we supply it in stages without undue further delay.
Notifying the supervisory authority and the data subjects remains your task as controller; we support you with the information we hold.
4.7 Information and audits
We make available to you all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by you or an auditor you appoint.
The ordinary route is written: we answer your questions and hand over our documentation within 30 days. Where that does not suffice, you may audit on site once per calendar year, on 30 days' written notice, during business hours, without disrupting operations, under confidentiality and at your own expense — unless the audit reveals a material breach on our part, in which case we bear the cost. A further audit is possible where a supervisory authority demands one or after a personal data breach affecting your data.
5. Sub-processors
5.1 Authorisation and current list
You grant general written authorisation for the engagement of sub-processors. Those engaged when this agreement is concluded are listed by function in Annex III.
Each sub-processor is bound by contract to data protection obligations no less protective than those in this agreement, and we remain fully liable to you for its performance.
5.2 Changes and your right to object
Before we add or replace a sub-processor that handles content submitted through the API, we notify you at least 30 days in advance — by e-mail to your account address and by updating Annex III. Within that period you may object on reasonable data protection grounds. If we cannot resolve the objection, you may terminate the affected part of the service with effect from the date of the change and receive a pro rata refund of any fee prepaid for the unused period.
5.3 Disclosure of identities
In public documents the translation engine provider is described by function, not by name. As controller you are entitled to know the identity, processing location and transfer safeguards of every sub-processor; we disclose them to you on request under a confidentiality undertaking, and never withhold them from the controller.
6. Transfers outside the EEA
Our own infrastructure is located in Germany, and we are established inside the European Economic Area. A transfer from you to us is therefore not a third-country transfer and needs no further safeguard.
Where a sub-processor processes data outside the EEA — see Annex III — the transfer takes place under the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), Module 3, processor to processor. For each such transfer we carry out and document a transfer impact assessment and apply supplementary measures, encryption in transit among them.
If you are established in the United Kingdom, your transfer to us is covered by the United Kingdom's adequacy regulations for the EEA. Should those regulations cease to apply, or should you require a contractual safeguard regardless, the International Data Transfer Addendum issued by the UK Information Commissioner (the "UK Addendum") to the standard contractual clauses is incorporated for that transfer at your request.
7. End of the processing
When the terms of service end, we delete the personal data processed on your behalf. Cached translations are erased within 90 days of termination, or at once if you disable caching beforehand.
You can export your account data as JSON from the dashboard at any time. Because submitted text is not kept in usage records, there is no separate return of processed content: all that exists is the cache, and it is deleted rather than returned.
Where Union or member state law requires us to keep personal data for longer, we keep it for that purpose only and process it for nothing else.
8. Liability, precedence and duration
Liability under this agreement follows clause 11.2 of the terms of service, save where Article 82 GDPR provides otherwise; nothing here limits either party's liability towards a data subject or a supervisory authority.
Where this agreement and the terms of service conflict, this agreement prevails for the processing of personal data on your behalf. Where this agreement and the standard contractual clauses conflict, the clauses prevail.
The agreement runs for as long as the terms of service are in force, and beyond that for as long as we still hold personal data processed on your behalf.
Annex I — Description of the processing
| Item | Detail |
|---|---|
| Controller | You, the customer identified by the account |
| Processor | Baduno GmbH, Mainzer Landstraße 166, 60327 Frankfurt am Main, Germany |
| Processor contact | [email protected] |
| Subject matter | Machine translation of text submitted through the API |
| Nature and purpose | Receipt, translation via the engine, return of the output; optional caching under a hash of the input |
| Categories of data subjects | Any person mentioned in submitted text |
| Types of personal data | Any personal data contained in submitted text |
| Special categories | Not permitted without prior written confirmation (clause 3.3) |
| Frequency | Continuous, on every API request |
| Duration | Term of the contract plus the deletion periods in clause 7 |
| Competent supervisory authority | Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Wiesbaden, Germany |
Annex II — Technical and organisational measures
| Area | Measures |
|---|---|
| Transport encryption | TLS 1.2 or higher on every connection, enforced with HSTS |
| Storage of secrets | Passwords as Argon2id hashes; API keys as SHA-256 hashes; cache entries addressed by a SHA-256 hash of the input, never by the input itself; secrets kept outside the document root and outside version control |
| Access control | Role-based permissions within teams; administrative access limited to named individuals and authenticated by key; the application runs under an unprivileged system account; database access exclusively through prepared statements; network access to database and cache restricted to the application host |
| Integrity | Content Security Policy without inline scripts; CSRF tokens on every state-changing form; session identifiers rotated at sign-in and on change of privileges; an append-only ledger for every balance movement; idempotent background jobs |
| Availability and resilience | Daily database backups retained off-host; job queue with retries and a record of failed jobs; rate limiting on sign-in and on the API; independent heartbeat monitoring published on the status page |
| Recovery | Documented restore procedure; backups verified by restoring them into a separate environment |
| Testing and review | Automated test suite run on every change, including tests that assert the security properties above; deliberately minimal dependency surface |
| Data minimisation by design | Usage records hold counters only — never submitted text or translations; the demo rate limiter stores a truncated hash of the network address, never the address itself; caching can be disabled per team with immediate effect |
Annex III — Sub-processors
| Function | Provider | Processing location | Transfer safeguard |
|---|---|---|---|
| Hosting of servers and databases | Infrastructure and hosting provider | Germany | None needed — within the EEA |
| Translation engine | AI translation engine provider (EU/US hosting per configuration) | European Union or United States, depending on configuration | Standard contractual clauses, Module 3, where processing takes place outside the EEA |
| Content delivery, TLS termination, DDoS protection | CDN and network security provider | European points of presence; operator established in the United States | Standard contractual clauses, Module 3 |
| Payment processing | Payment service provider | European Union | None needed — within the EEA; independent controller for payment data |
| Transactional e-mail delivery | E-mail delivery provider | European Union | None needed — within the EEA |
Each provider's identity is disclosed to you as controller on request under a confidentiality undertaking (clause 5.3).