Data Processing Agreement
Last updated: 2026-08-29
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between the customer ("Controller", "you") and LingoSeal ("Processor", "we"), and applies whenever we process personal data on your behalf in the course of providing the service. It is incorporated into the Agreement by reference and takes effect when you accept the Agreement; no signature is required.
1. Parties and roles
For personal data you and your workspace members store in the service — translation content, glossary entries, documents, screenshots, comments, and the personal data those may contain — you are the controller and LingoSeal is the processor. For the account data we need to run the service itself (your email address, sign-in and billing records), we are an independent controller; that processing is described in the Privacy Policy, not this DPA.
2. Subject matter, nature, and purpose
We process personal data only to provide, maintain, and secure the translation management service you have subscribed to: storing the content you upload, rendering it to the people you have invited into your workspace, delivering it through the export formats and integrations you configure, and sending the notifications the service generates.
3. Duration
Processing lasts for the term of the Agreement, plus the deletion window in section 10.
4. Categories of data subjects and personal data
Data subjects are the people whose personal data appears in the content you store — typically your own team, and any individuals mentioned in the text you translate. The categories of personal data are determined by you: the service imposes no schema on translation content, and we do not inspect it to find out. You are responsible for not storing special categories of data (Art. 9 GDPR) in the service; it is not designed for them.
5. Your obligations as controller
You warrant that you have a lawful basis for the personal data you ask us to process, that you have provided any required notices to data subjects, and that your instructions to us comply with applicable data protection law. Your instructions are: the Agreement, this DPA, and your use of the service's settings and features.
6. Our obligations as processor
- We process personal data only on your documented instructions as defined above, unless required to do otherwise by law — in which case we will inform you before processing, unless the law forbids it.
- Everyone we authorise to process personal data is bound by confidentiality.
- We assist you, insofar as possible, in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection). The service's export and deletion features cover most requests directly; for the rest, contact us at reza@lingoseal.com.
- We assist you with your obligations under Articles 32–36 GDPR (security, breach notification, and data protection impact assessments), taking into account the nature of the processing and the information available to us.
- We make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in section 11.
7. Sub-processors
You authorise us to engage the sub-processors listed in the Privacy Policy, which is the current list. Each sub-processor is bound by a written agreement imposing data protection obligations no less protective than this DPA. We remain fully liable to you for their performance.
We will update the published list at least 30 days before a new sub-processor begins processing personal data. You may object in writing within that period on reasonable data-protection grounds; if we cannot address the objection, you may terminate the Agreement and we will honour section 10.
8. Security
Taking into account the state of the art and the nature of the data, we implement and maintain these technical and organisational measures:
- Encryption in transit (TLS 1.2+) for all connections, and encryption at rest for the database and object storage, provided by our infrastructure sub-processors.
- Workspace-scoped access control: every read and write is authorised against workspace membership and role, and member access can be further restricted to specific projects.
- Third-party integration credentials you supply (such as WordPress application passwords) are stored encrypted, not in plain text.
- API access uses scoped, revocable tokens; audit logs record security-relevant actions in a workspace.
- Production access is limited to the operator, protected by multi-factor authentication on all operational accounts.
- Backups and infrastructure-level resilience are provided by the managed database and storage sub-processors.
9. Personal data breach
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will cooperate with you and provide the information you reasonably need to meet your own notification obligations.
10. Deletion and return on termination
When the Agreement ends, you can export your content in the service's supported formats up to the end of the retention window. Thirty days after termination we delete all personal data processed on your behalf, unless law requires us to retain it longer. You can request earlier deletion at any time.
11. Audits
Once per 12 months and on reasonable notice, you may audit our compliance with this DPA. We satisfy audit requests first through documentation — this DPA, the published sub-processor list, and the certifications our sub-processors publish. If that is genuinely insufficient, we will answer a written security questionnaire. On-site audits are not offered for a self-serve service at this scale.
12. International transfers
Our sub-processors operate globally, so personal data may be processed outside the EEA. Where it is, the transfer relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), module two (controller to processor) or module three (processor to processor) as applicable, as incorporated in our agreements with those sub-processors, together with any supplementary measures they publish.
13. Liability and governing law
The liability caps and exclusions of the Agreement apply to this DPA. This DPA is governed by the laws of Estonia, and the courts of Estonia have exclusive jurisdiction, without prejudice to rights data subjects hold under directly applicable data protection law.
14. Contact
Questions about this DPA: reza@lingoseal.com.