Legal

Privacy

This notice explains how Deepglot processes personal data for accounts, translation projects, integrations, support, security, and billing. Last updated: 14 July 2026.

1. Controller

The controller is Ostheimer OG, Fabriksgasse 20, 2230 Gänserndorf, Austria. Privacy requests can be sent to office@ostheimer.at or made by telephone at +43 699 1726 3544.

2. Account and authentication data

We process names, email addresses, password hashes, account and organization memberships, roles, login sessions, invitation and password-reset data, and optional GitHub or Google OAuth identifiers. The legal basis is performance of the user contract and pre-contract steps; security logging and abuse prevention rely on our legitimate interest in a secure, reliable service. Where consent is specifically requested, consent is the legal basis and can be withdrawn for the future.

3. Projects and translation content

We process project domains, languages, settings, API-key identifiers, exclusions, glossaries, imported files, source and translated text, URL and page statistics, manual translations, editor sessions, and translation usage records to provide the contracted features. Depending on the selected configuration, content is transmitted to a translation provider API such as OpenAI, DeepL, Google Gemini, OpenRouter, or a customer-specified OpenAI-compatible or self-hosted endpoint. Customer-supplied provider API keys are stored encrypted and used only for the configured provider connection.

4. WordPress, runtime sync, and webhooks

The WordPress plugin sends its API key, site URL, language and routing settings, runtime configuration requests, translation segments, request URLs, titles, bot classification, and connection-status probes to Deepglot as needed. If you configure webhooks, selected project events and signed delivery metadata are sent to the destination you provide, and delivery status, response codes, and limited response bodies are stored for operation and troubleshooting. Dynamic translation uses same-origin and short-lived security controls and can fall back to cached content.

5. Billing and support

For paid subscriptions, Stripe processes customer, checkout, payment-method, invoice, subscription, tax, and transaction data. Deepglot stores Stripe customer, subscription and price references, plan status, billing address details needed by the product, and quota information; Deepglot does not receive full card numbers. We process support messages and related technical context to answer requests. Contract performance and pre-contract steps are the main legal basis; tax, accounting, and other statutory records are processed to meet legal obligations.

6. Hosting, email, and processors

We use service providers as processors or independent controllers according to their role: Vercel for application hosting and runtime logs, Neon for managed PostgreSQL storage, Cloudflare Email Sending for transactional email, Stripe for billing and payments, and GitHub or Google when their OAuth login is selected. Translation providers process the content sent to the provider selected for a project. Customer-configured webhooks, custom gateways, and self-hosted services are recipients chosen by the customer. We limit disclosures to what is needed for the stated purpose and review data-processing terms with relevant processors.

7. Logs, analytics, and security

We process request times, route and error information, hashed rate-limit subjects, usage counters, translation batch metadata, webhook delivery history, and security events to operate, secure, debug, and protect the service. Optional project page-view analytics records translated URLs and aggregate use only after the feature is enabled. Deepglot does not currently use its own advertising or cross-site marketing-tracking cookies. The legal basis is contract performance and our legitimate interests in service security, fraud prevention, troubleshooting, and product reliability.

8. Cookies and local storage

The hosted application uses technically necessary authentication, locale, and interface-state cookies. Short-lived browser storage can be used to display a newly generated API key once and is removed after it is read. Third-party services reached through login or billing may set their own cookies under their notices. Optional technologies requiring consent will not be activated without the required choice.

9. International transfers

Some providers or their subprocessors may process data outside Austria or the European Economic Area. Where required, the transfer must be covered by an adequacy decision, standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. The applicable destination depends in particular on the hosting, OAuth, payment, email, and translation provider selected or configured.

10. Retention and deletion

Account, organization, project, translation, import/export, glossary, webhook, and related operational data are generally retained while needed to provide the account or associated project and are deleted or anonymized after deletion or a valid request unless another user still requires the organization data or a legal obligation applies. Billing and transaction records are retained for applicable statutory tax and accounting periods. Security, support, and runtime records are kept only as long as reasonably needed for their purpose. Backups can retain deleted data for a limited rotation period before overwrite. Data sent to external providers is subject to their documented retention and the customer's provider configuration.

11. Your rights and data export

Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, and portability of personal data, object to processing based on legitimate interests, and withdraw consent for the future. The project import/export tools can export translations, glossaries, and URL slugs; other privacy requests and account deletion can be made through the product or by email. You may lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority. We may verify identity before fulfilling a request.

12. Changes and contact

We update this notice when material product, processor, legal-basis, or retention changes occur. For privacy questions, objections, or deletion and export requests, contact office@ostheimer.at.

Questions? Contact us at office@ostheimer.at.

Back to homepage