Data Processing Addendum
Part of the Terms of Service and accepted with them. Nobody has to sign or send anything.
1. Parties and subject matter
The processor is Ing. Jiří Psota, company ID (IČO) 76072266, registered office Zborovská 1200/6, 150 00 Prague 5 – Smíchov, Czech Republic (the “processor”). The controller is the organisation that uses the Linguiqo service under the Terms of Service (the “customer”).
This addendum governs the processing of personal data that the customer puts into the service, under Article 28 of Regulation (EU) 2016/679 (GDPR).
This addendum is an integral part of the Terms of Service and the customer accepts it by accepting them; no handwritten signature is required (Article 28(9) GDPR). On matters of personal data protection it takes precedence over the Terms of Service.
2. Scope
The subject matter, nature and purpose of the processing and the categories of data and data subjects are set out in Annex 1. Processing lasts for as long as the service is used and until erasure under article 9.
3. Instructions
The processor processes personal data only on the customer's documented instructions. These are the Terms of Service, this addendum, and the customer's settings and use of the service. Otherwise only where EU or Czech law requires it; the processor informs the customer beforehand unless the law prohibits that.
If the processor considers an instruction unlawful, it tells the customer without delay.
4. Confidentiality
Everyone with access to the personal data is bound to confidentiality by contract or by law, including after the cooperation ends.
5. Security
The processor takes the measures under Article 32 GDPR listed in Annex 2. It may change them as long as the level of protection does not decrease.
6. Sub-processors
The customer gives general authorisation to engage the sub-processors listed at https://www.linguiqo.com/subprocessors.
The processor publishes the addition or replacement of a sub-processor on the same page at least 30 days in advance. The customer may object on reasonable grounds within that period. If the parties do not resolve the objection, the customer may end the service without penalty and receives a pro-rata refund of fees paid in advance.
The processor imposes the same data protection obligations on its sub-processors and is responsible for their compliance.
Providers that the customer connects to the service itself are not sub-processors: machine translation (for example OpenAI or DeepL) through the customer's own API key, git hosting (for example GitHub, GitLab or Azure DevOps) through the customer's token, the addresses the customer has webhooks sent to, and Google or Microsoft where a user signs in with their account. Data reaches them only on the customer's instruction and is governed by the customer's agreement with that provider.
7. Transfers outside the EEA
Personal data is stored in the EU (Google Cloud europe-west1, Belgium). It is transferred outside the EEA only to the extent stated in the list of sub-processors and only with a safeguard under Chapter V GDPR (an adequacy decision, including the EU-US Data Privacy Framework, or standard contractual clauses).
8. Assistance
The processor assists the customer:
- a) in responding to data subject requests, primarily through the service's export, correction and deletion features; a request sent to the processor directly is passed on to the customer;
- b) in meeting its obligations under Articles 32 to 36 GDPR.
The processor reports a personal data breach to the customer without undue delay after becoming aware of it. The report states the nature of the breach, the data concerned, the likely consequences and the measures taken.
9. Termination, return and erasure
Until the service ends, the customer can export its data: each language as a file, or everything at once through the API or the CLI.
The processor erases the personal data within 30 days of the team being deleted or the agreement ending; the same applies to a project the customer deletes. It disappears from backups as they rotate, no later than 35 days after that.
The processor may keep only data that the law requires it to keep (for example accounting records).
10. Information and audit
On request, the processor provides the information needed to demonstrate compliance with this addendum.
At most once a year, or after a personal data breach, the customer may carry out an audit itself or through an auditor bound to confidentiality, with 30 days' notice and at its own cost. For sub-processors, their public certifications and reports take the place of an audit.
11. Final provisions
Liability is governed by Article 82 GDPR and the Terms of Service. This addendum is governed by the law of the Czech Republic.
The processor announces changes to this addendum at least 30 days in advance by publishing them at https://www.linguiqo.com/dpa. A change that reduces the protection of personal data cannot be made without the customer's consent.
Contact for personal data protection: hello@linguiqo.com.
Annex 1 – Description of the processing
| Subject matter and purpose | Managing translations of the customer's application texts: importing and exporting language files, editing and checking translations, collaboration within a team, and synchronisation with the customer's git repositories. |
|---|---|
| Nature of the processing | Storage, display to authorised users, editing, export, transfer to services the customer connects, backup and erasure. |
| Data subjects | The customer's users: team members and invited translators. People whose data the customer may put into the content. |
| Categories of data | Users' name, email address, profile picture and interface language; the email address of invited people. The audit log (who did what, when and from which IP address), authorship and history of translations and comments, and the history of synchronisations with repositories. The customer's content: source texts, translations, comments, glossary and screenshots. Texts for translation do not usually contain personal data. If the customer puts any in, it is processed under this addendum. |
| Special categories of data | None. The service is not intended for them. |
| Duration | For as long as the service is used and until erasure under article 9. |
| Place of processing | EU – Google Cloud europe-west1, Belgium. Sub-processors and their locations: https://www.linguiqo.com/subprocessors. |
Annex 2 – Technical and organisational measures
- Location: the application, the database, files and database backups are in Google Cloud, region europe-west1 (Belgium).
- Encryption in transit: all communication over HTTPS (TLS) with HSTS enforced.
- Role-based access within a team: owner, administrator, member and external translator, who sees only the projects and languages assigned to them. Every request is checked against the role and the team.
- Audit log: who changed what, when and from which IP address. Visible to the team's administrators.
- Sign-in: passwords stored only as a hash (scrypt), access tokens valid for 15 minutes and sessions for 7 days, a password change signs out every device, and sign-in attempts are rate-limited.
- Credentials entrusted to the service: git repository tokens, machine translation API keys and webhook secrets are encrypted with a key held outside the database (Google Secret Manager) and are never shown again once saved. The service's own API keys are stored only as a hash.
- Files: screenshots are not public and are served only through the API after an authorisation check.
- Operations: only the processor has access to production systems, and service accounts hold only the permissions they need.
- No tracking: the service uses no analytics and no advertising or tracking scripts.
- Artificial intelligence: the processor does not use customer content to train models. Machine translation runs only through the customer's key and only when a user asks for it.
- Retention: the demo environment is deleted after 2 hours, synchronisation history after 30 days, the data of a deleted team or project within 30 days, and from backups as they rotate within 35 days after that.
Version history
- 1.0 · October 7, 2026 · First version.
Changes are published on this page at least 30 days before they apply.
Sub-processors: current list.