Privacy Policy
Effective date: July 17, 2026
The German version of this document is legally authoritative.
1. Introduction — Controller Information
This Privacy Policy explains how Tratext GmbH ("Tratext", "we", "us", or "our") collects, uses, stores, and protects personal data when you use our Translation Management System (TMS) platform and related services (the "Service").
Tratext operates a professional translation and language services platform serving business clients (B2B), consumers (B2C), and government entities (B2G). Through the Service, clients submit documents for translation, receive custom quotations, accept and pay for orders, and receive translated deliverables.
Data Controller:
Tratext GmbH Postfach 80 10 24, 51010 Köln DE
Represented by the CEO (Geschäftsführer): Anas Rahman Commercial Register: Amtsgericht Köln, HRB 104022 VAT ID: DE341211510 D-U-N-S® Number: 343451082
The controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 ("GDPR") is Tratext GmbH.
2. Data Protection Officer (DPO)
If you have any questions about data protection or wish to exercise your rights, you may contact our Data Protection Officer:
- Email: datenschutz@tratext.de
- Postal address: Tratext GmbH — Data Protection Officer, Postfach 80 10 24, 51010 Köln, DE
3. What Personal Data We Collect
We collect and process the following categories of personal data, depending on your relationship with us (client, translator, staff member, or website visitor):
| Category | Data Fields |
|---|---|
| Identity Data | First name, last name, salutation, date of birth, place of birth, country of birth, nationality |
| Contact Data | Email address, phone number (including for OTP/two-factor authentication) |
| Company Data | Company name, company VAT number, company registration number, Leitweg-ID (for B2G clients) |
| Address Data | Street address (lines 1 and 2), city, state/province, postal code, country (ISO 3166-1 alpha-2), latitude, longitude |
| Financial Data | Stripe customer ID, bank account details (IBAN, BIC, account holder name), business tax ID, payment card data (processed by Stripe — we do not store full card numbers) |
| Authentication Data | Password (stored only in bcrypt-hashed form with a salt factor of 12), OAuth tokens (Google, Apple Sign-In), one-time password (OTP) codes, session tokens, refresh tokens |
| Technical Data | IP address, user agent string, device tokens (Firebase Cloud Messaging), platform identifier (Android/iOS), public IP address used for geolocation, mobile device permissions (Camera, Microphone, Location, FaceID/Biometrics for local authentication) |
| Document Data | Documents uploaded for translation, voice notes and audio recordings uploaded for transcription/translation, signed contracts (qualified and advanced electronic signatures), signature metadata (full name, phone number) |
| Communication Data | Conversation messages within the platform, complaint descriptions, notification content |
| Staff and Translator Data | Mother tongue, signature documents, contract file paths, language pair qualifications, claimed identity for electronic signatures, credential IDs, certificate serial numbers |
4. How We Collect Your Data
We obtain personal data from the following sources:
4.1 Directly from You
- When you register an account or complete your user profile
- When you fill in forms (order requests, quotation forms, contact forms, complaint forms)
- When you upload documents for translation
- When you communicate with us through the platform's messaging features
- When you provide payment information during checkout
4.2 From Third-Party Authentication Providers
- Google Sign-In and Apple Sign-In: If you choose to authenticate via an OAuth provider, we receive your name, email address, and a unique provider identifier. We do not receive your password from these providers.
4.3 Automatically Collected Data
- Technical data: Your IP address, user agent string, and device information are collected automatically when you access the Service.
- Device tokens: If you use our mobile application and enable push notifications, we collect your Firebase Cloud Messaging (FCM) device token.
- Location data: When you use address-related features, approximate location data (latitude/longitude) may be derived via Google Maps/Places API or your device's GPS.
- Mobile Device Features: If authorized by you, the mobile app accesses your device's camera (for document scanning/photos), microphone (for voice notes), and biometric authentication (e.g., FaceID for secure local login. Note: Biometric data remains securely on your device and is never transmitted to our servers).
- Website server log files: When you visit our public website, our hosting provider (Vercel Inc.) automatically collects and stores information in so-called server log files that your browser transmits. These include your browser type and version, operating system, referrer URL, hostname of the accessing device, time of the server request, and IP address (anonymized). These data are not merged with other data sources and are processed on the basis of our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR).
4.4 From Third-Party Service Providers
- Stripe: Transaction status, payment confirmation, and Stripe customer identifiers are received as part of payment processing.
5. Legal Basis for Processing (Art. 6 GDPR)
We process your personal data on the following legal bases:
| Legal Basis | Applicable Processing Activities |
|---|---|
| Art. 6(1)(b) — Performance of a contract | Account creation, order processing, document translation services, quotation generation, payment processing, delivery of translated documents, electronic signature processing for contracts |
| Art. 6(1)(a) — Consent | Optional analytics (Google Analytics), marketing communications (where applicable), use of non-essential cookies, session replay for product improvement (Sentry) |
| Art. 6(1)(c) — Legal obligation | Retention of financial records for tax purposes (§ 147 AO, § 257 HGB — German fiscal law), audit log retention, compliance with lawful data access requests from public authorities |
| Art. 6(1)(f) — Legitimate interest | Platform security (login attempt logging, CSRF protection, CAPTCHA verification, fraud prevention), error tracking and performance monitoring (Sentry), system administration, improvement of service quality |
Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. You can withdraw consent by contacting us at datenschutz@tratext.de or adjusting your preferences within the Service.
6. Purposes of Processing
We process personal data for the following specific purposes:
- Service delivery: Facilitating translation orders, generating quotations, processing payments, delivering translated documents, and managing client-translator workflows (including audio/voice note transcription).
- Account management: Creating and maintaining user accounts, authenticating users (including via OTP/2FA, OAuth, and local biometrics), managing session security.
- Communication and Marketing: Sending transactional emails (order confirmations, status updates, invoices), SMS/WhatsApp notifications, push notifications, platform messages, and—subject to your explicit consent—promotional and marketing newsletters.
- Payment processing: Processing payments through Stripe, issuing invoices, managing refunds, and maintaining financial records.
- Electronic signatures: Facilitating qualified electronic signatures (QES) and advanced electronic signatures (AdES) on contracts and documents via Swisscom AIS.
- Document management: Storing, processing, and delivering documents uploaded for translation; generating PDFs; verifying document integrity via SHA-256 hashing; performing virus scans.
- Shipping: Generating shipping labels and tracking shipments for physical document delivery via DHL.
- Security and fraud prevention: Logging login attempts (IP address, user agent), implementing CAPTCHA protection (Cloudflare Turnstile), CSRF token validation, bot detection.
- Error tracking and performance: Monitoring application errors, performance metrics, and crash reports (Sentry, Firebase Crashlytics) to maintain and improve service reliability.
- Legal compliance: Retaining financial and audit records as required by German tax law, responding to data subject requests, maintaining GDPR deletion logs.
- Address validation: Using Google Maps/Places API for address autocomplete and geolocation to ensure accurate delivery and billing addresses.
7. Recipients and Sub-Processors
We share personal data with the following categories of recipients and sub-processors, solely for the purposes described in this Privacy Policy:
| Sub-Processor | Purpose | Data Shared | Country / Region |
|---|---|---|---|
| Freelance translators (contracted sub-processors) | Human translation/proofreading | Document content incl. personal data in source texts | EU/EEA (contractually restricted) |
| Translation Agency Partners (TAP, contracted sub-processor agencies) | Translation fulfillment via vetted partner agencies | Document content incl. personal data in source texts | EU/EEA (contractually restricted) |
| Stripe, Inc. | Payment processing | Payment details, Stripe customer ID, billing information | United States (EU data processing available) |
| Apple Inc. / Google LLC | Payment processing (Apple Pay / Google Pay) | Payment confirmation tokens | United States |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payment processing | Payment details, transaction data | Luxembourg |
| Klarna Bank AB | Payment processing | Payment details, transaction data | Sweden |
| Twilio, Inc. (SendGrid) | Transactional and marketing email delivery | Email address, email content | United States |
| Resend, Inc. | Website contact-form email delivery and related notifications | Name, email address, message content | United States (EU-U.S. Data Privacy Framework) |
| Twilio, Inc. | SMS delivery, OTP verification, WhatsApp messaging, push notifications | Phone number, message content | United States |
| Google LLC (Firebase) | Push notifications (FCM), crash reporting (Crashlytics) | Device tokens, crash data, app diagnostics, sender names, partial chat message content | United States |
| Apple Inc. (APNs) | Push notifications delivery for iOS | Device tokens, sender names, partial chat message content | United States |
| Google LLC (Gemini) | AI-assisted translation and data analysis | Uploaded document content, translated text | United States |
| OpenAI, L.L.C. | AI-assisted translation and data analysis | Uploaded document content, translated text | United States |
| Amazon Web Services (AWS) — S3 | Document and file storage | Uploaded documents, signed PDFs, generated files | European Union (configurable region) |
| Amazon Web Services (AWS) — EventBridge | DHL shipment tracking automation | Shipment tracking data | European Union (configurable region) |
| Functional Software, Inc. (Sentry) | Error tracking, performance monitoring, session replay | IP address, user agent, error context, session replay data (all text masked, all media blocked) | United States |
| Swisscom Trust Services AG | Qualified and advanced electronic signatures (QES/AdES) and identity verification | Signer full name, phone number, identity verification data | Switzerland |
| Deutsche Post DHL (INTERNETMARKE) | Shipping stamp generation | Recipient name and address | Germany |
| Google LLC (Maps/Places API) | Address autocomplete, geolocation | Partial address data, geographic coordinates | United States |
| Cloudflare, Inc. (Turnstile) | CAPTCHA and bot protection | IP address, browser fingerprint data | United States |
| Gotenberg | PDF generation from documents | Document content | Self-hosted (no data leaves our infrastructure) |
| Tiny Technologies, Inc. (TinyMCE) | Rich text editing | Text content (processed client-side in the user's browser) | United States (client-side only) |
| Vercel Inc. | Hosting and content delivery of our public website (including server log files) | IP address, browser/user-agent, referrer URL, hostname, request timestamp | United States (EU-U.S. Data Privacy Framework, SOC 2 Type II) |
We require all sub-processors to process personal data only on our documented instructions and to implement appropriate technical and organizational security measures. We have entered into data processing agreements (Art. 28 GDPR) with each sub-processor. The current list of sub-processors is published at www.tratext.de/subprozessoren.
8. International Data Transfers
Several of our sub-processors are established in the United States or process data outside the European Economic Area (EEA). For all international transfers of personal data, we ensure an adequate level of protection through one or more of the following safeguards:
- EU-U.S. Data Privacy Framework: Where a sub-processor is certified under the EU-U.S. Data Privacy Framework (and, where applicable, the UK and Swiss extensions), we rely on that adequacy decision as the transfer mechanism.
- Standard Contractual Clauses (SCCs): We have executed the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with sub-processors that process personal data outside the EEA and are not covered by an adequacy decision.
- Adequacy decisions: Transfers to Switzerland are covered by the European Commission's adequacy decision.
For transfers to our self-hosted services (Gotenberg), no international transfer occurs as data remains within our own EU-hosted infrastructure.
You may request a copy of the applicable transfer safeguards by contacting us at datenschutz@tratext.de.
9. Cookies and Local Storage
9.1 Cookies We Use
Our Service uses the following cookies:
| Cookie Name | Purpose | Duration | Type |
|---|---|---|---|
access_token |
JWT-based user authentication | 8 hours | Strictly necessary (httpOnly, secure) |
tms_session |
Session identification flag | Session (expires when browser closes) | Strictly necessary |
customer_session |
Customer portal session verification | Session (expires when browser closes) | Strictly necessary |
NEXT_LOCALE |
Stores your language preference | Persistent | Strictly necessary |
XSRF-TOKEN |
Cross-site request forgery (CSRF) protection | Session (expires when browser closes) | Strictly necessary |
sidebar_state |
Remembers sidebar open/closed UI preference | 7 days | Functional |
All cookies listed above — except sidebar_state — are strictly necessary for the operation of the Service and do not require consent. The sidebar_state cookie is a functional cookie that enhances your user experience; it does not track you across websites and stores no personal data.
The storage of, and access to, information on your terminal device is governed by § 25 of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz — TDDDG, formerly TTDSG). Strictly necessary cookies are stored on the basis of § 25(2) TDDDG without consent; all non-essential cookies as well as analytics and marketing services are set only with your prior consent pursuant to § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You can adjust or withdraw your cookie preferences at any time with effect for the future via the "Cookie settings" link in the footer of our website.
9.2 Local Storage and Session Storage
In addition to cookies, we heavily use localStorage and sessionStorage (HTML5 web storage) to provide core application functionality. These technologies allow us to store data locally in your browser. We use them for purposes such as storing access tokens, preserving your UI state across reloads, and managing signing modes during electronic signature processes. The data stored in local and session storage is strictly necessary for the Service to function.
9.3 Email Tracking Pixels
Our transactional and marketing emails (delivered via SendGrid) contain tracking pixels (web beacons). These are miniature, invisible graphics embedded in emails that allow us to record whether an email has been opened and which links within the email were clicked. We use this data based on our legitimate interest (Art. 6(1)(f) GDPR) to ensure deliverability of critical system notifications, defend against claims of non-receipt, and perform statistical analysis to improve our communications.
9.4 Analytics
Google Analytics may be enabled on an optional, per-tenant basis. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Where enabled, the Google Analytics measurement ID is configurable. We operate Google Analytics exclusively with IP anonymization enabled and in Consent Mode; it is activated only after your prior consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG) given via our cookie banner. You may decline or withdraw your consent at any time with effect for the future — including by adjusting your cookie settings or installing the browser add-on to opt out of Google Analytics (tools.google.com/dlpage/gaoptout).
9.5 Session Replay (Sentry)
We use Sentry Session Replay to record anonymized replays of user sessions for the purpose of diagnosing errors and improving the user experience. The following privacy safeguards are in place:
- All text is masked (
maskAllText: true) — no readable text content is captured. - All media is blocked (
blockAllMedia: true) — images, videos, and other media are replaced with placeholders. - Sampling rates: 10% of normal sessions and 100% of sessions that encounter an error are recorded.
- Sensitive form fields are additionally protected with
data-sentry-maskattributes.
Session replay data is processed on the legal basis of our legitimate interest in maintaining and improving the Service (Art. 6(1)(f) GDPR). Given the extensive masking and blocking measures, no readable personal data is captured in session replays.
10. Data Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
| Data Category | Retention Period | Justification |
|---|---|---|
| Personal account data | Stored indefinitely until user/tenant explicitly deletes it | Contractual necessity, continuous access to past translations |
| Project/order documents & translation memories | Stored indefinitely until explicitly deleted | Contractual necessity, continuous access to past translations |
| Financial and billing data | 10 years from the end of the relevant fiscal year | German tax law (§ 147 AO, § 257 HGB) |
| Platform audit logs | 7 years | Legal compliance, fraud prevention |
| Signing service audit logs | 90 days | Operational diagnostics for electronic signature processing |
| GDPR deletion request logs | Retained to demonstrate compliance with erasure obligations | Art. 5(2) GDPR — accountability principle |
User accounts, project documents, and translation memories are stored indefinitely to provide continuous access to past translations, unless the user actively deletes their account or requests erasure under Art. 17 GDPR.
After the applicable retention period expires, personal data is securely deleted or anonymized. Where data must be retained for legal obligations but is no longer needed for active processing, it is archived with restricted access.
Retention periods are configurable per tenant to accommodate differing contractual or regulatory requirements.
11. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights with respect to your personal data. To exercise any of these rights, please contact us at datenschutz@tratext.de.
11.1 Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation as to whether we process your personal data and, if so, to receive a copy of that data together with information about the purposes of processing, the categories of data concerned, the recipients, and the envisaged retention periods.
11.2 Right to Rectification (Art. 16 GDPR)
You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data. You may also update much of your data directly through your account settings in the Service.
11.3 Right to Erasure (Art. 17 GDPR) and Account Deletion
You have the right to request the deletion of your personal data where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw consent and there is no other legal basis for processing;
- You object to processing and there are no overriding legitimate grounds;
- The data has been unlawfully processed.
Mobile App Users: If you use our iOS or Android mobile applications, you can request the deletion of your account and all associated personal data directly within the app by navigating to Profile > Settings > Delete Account, or by emailing us at datenschutz@tratext.de.
Important Exception regarding Certified Translations (Soft Deletion): Because we provide Certified Translations (beglaubigte Übersetzungen) with Qualified Electronic Signatures (QES) which are submitted to courts and public authorities, we are legally required to maintain an unbroken audit trail. Therefore, when you request account deletion, your profile will undergo a "soft deletion." Your account will be deactivated and blocked from active use, but your core identity data, order history, and signed documents will be securely archived and retained. This retention overrides the Right to Erasure pursuant to Art. 17(3)(b) GDPR (compliance with a legal obligation under German commercial/tax law, e.g., § 257 HGB and § 147 AO, requiring 10-year retention) and Art. 17(3)(e) GDPR (for the establishment, exercise, or defence of legal claims regarding the authenticity of certified documents).
All erasure/deactivation requests are logged in our GDPR Deletion Log, which records the user ID, a hash of the user's email address, the requestor's IP address, and the categories of data archived, in accordance with our accountability obligations under Art. 5(2) GDPR.
11.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request the restriction of processing where you contest the accuracy of the data, the processing is unlawful, we no longer need the data but you require it for legal claims, or you have objected to processing pending verification.
11.5 Right to Data Portability (Art. 20 GDPR)
Where processing is based on your consent or on a contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
11.6 Right to Object (Art. 21 GDPR)
You have the right to object at any time to the processing of your personal data based on our legitimate interests (Art. 6(1)(f) GDPR). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
11.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where we process your data based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
11.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. You may contact the supervisory authority in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. The lead supervisory authority for Tratext GmbH is:
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) or the competent State Data Protection Authority (Landesdatenschutzbeauftragte) for the German federal state in which Tratext GmbH is registered.
11.9 Response Time
We will respond to all data subject requests without undue delay and in any event within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of the request.
12. Artificial Intelligence and Machine Learning
Our Service utilizes artificial intelligence (AI) and machine learning tools, including Google Gemini and OpenAI, to process translations, analyze data, and improve translation quality.
By using our Service, you acknowledge and agree that:
- Transmission to AI Providers: Document content, translated text, and related data are transmitted to these third-party AI providers (Google LLC and OpenAI, L.L.C.).
- Model Training: Data processed by these AI providers may be used for AI model training and to improve their respective services.
- Sensitive Personal Data (Art. 9 GDPR): Clients must not upload documents containing special categories of personal data (such as health data, biometric data, or data revealing racial or ethnic origin, political opinions, or religious beliefs) unless they have secured all necessary rights, explicit consents, and authorizations to process such data through these AI platforms.
We require our AI sub-processors to implement appropriate security measures, but users must exercise caution and adhere to this restriction regarding sensitive personal data.
13. Automated Decision-Making
We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
14. Security Measures and Support Access
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Password security: All user passwords are hashed using the bcrypt algorithm with a salt factor of 12. We never store passwords in plain text.
- Document integrity: Uploaded documents are verified using SHA-256 cryptographic hashing to ensure integrity. All uploaded files are scanned for viruses and malware using ClamAV.
- Transport encryption: All data in transit is encrypted using TLS (HTTPS).
- CSRF protection: Cross-site request forgery tokens (XSRF-TOKEN) are used to protect against unauthorized actions.
- Bot and abuse protection: Cloudflare Turnstile CAPTCHA is deployed to prevent automated abuse.
- Security audit trail: Login attempts are logged (including IP address and user agent) to enable detection and investigation of unauthorized access attempts.
- Session management: Authentication tokens have limited validity (8 hours) and are transmitted via httpOnly, secure cookies to mitigate cross-site scripting (XSS) risks.
- Privacy-by-design in monitoring: Sentry is configured with personally identifiable information (PII) handling disabled in the signing service production environment. Session replay masks all text and blocks all media. Sensitive form fields carry
data-sentry-maskattributes. - Support Access & Impersonation: To provide technical support, resolve critical platform errors, and assist with complex order issues, authorized senior administrators have the technical capability to temporarily access ("impersonate") user accounts. This capability is strictly restricted by role-based access controls and every access event is permanently logged in a tamper-proof
PermissionAuditLog(recording the administrator ID, user ID, and timestamp) to ensure strict accountability and prevent abuse. - Infrastructure: Document storage (AWS S3) is configured within the European Union. Self-hosted services (Gotenberg for PDF generation) process data without any external transfer. Our public website is hosted by Vercel Inc., which is SOC 2 Type II certified and adheres to the EU-U.S. Data Privacy Framework.
15. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16 without valid parental consent, we will take steps to delete that data promptly. If you believe that a child under 16 has provided personal data to us, please contact us at datenschutz@tratext.de.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements, or Service features. Where changes are material, we will notify you by:
- Posting the updated Privacy Policy on our website with a revised "Last updated" date;
- Sending you an email notification or in-app notification where appropriate.
We encourage you to review this Privacy Policy periodically. Continued use of the Service after the effective date of a revised Privacy Policy constitutes acceptance of the changes, except where further consent is required by law.
17. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Tratext GmbH Postfach 80 10 24, 51010 Köln DE
- Data Protection Officer: datenschutz@tratext.de
- Central Hotline (Toll-free): +49 800 8728398
- Phone: +49 221 95673 200 / +49 1573 5996 200
- WhatsApp: +49 1573 5996 200
- General Contact: info@tratext.de
- Support: support@tratext.de
- Quotations: angebot@tratext.de
- Authorities: behoerde@tratext.de
- Accounting: Buchhaltung@tratext.de
- PO Box: postfach@tratext.de
For matters requiring postal correspondence, please write to:
Tratext GmbH — Data Protection Officer Postfach 80 10 24, 51010 Köln DE
This Privacy Policy is governed by the General Data Protection Regulation (EU) 2016/679 and applicable German data protection law (Bundesdatenschutzgesetz — BDSG; Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz — TDDDG). It should be read in conjunction with our Terms and Conditions (AGB) and Right of Withdrawal (Widerrufsbelehrung).