Skip to content
legal / subprocessors

Who else can see your text.

The contractual half of the subprocessor question: the categories, the notice period, the right to object, and why the list itself lives in one place instead of two.

  • effective september 8, 2026
  • disclosure enforced by a test
privacy at transglot
Effective September 8, 2026

Subprocessors

the human version

The current list of subprocessors, with the purpose, the region and the condition for each, lives in the Trust Center, which reads it from configuration. This page is the contract around that list: what the categories are, how we give notice before a new one starts, and how you object. We publish the list in one place on purpose, because a list retyped into a second document is a list that goes stale the day a vendor changes.

01

What this document is

This is the contractual statement about subprocessors that Article 28(2) and 28(4) of the GDPR, and the equivalent provisions of other data protection laws, require a processor to make. It is incorporated into the Data Processing Addendum and completes Annex III of it. The operative categories are published in the Trust Center, and the named vendors behind them are furnished on request under a non-disclosure agreement. Together they are the general written authorisation you give us to engage subprocessors, and the mechanism by which that authorisation stays informed.

02

Where the list lives, and why it is not copied here

The Trust Center renders the subprocessor table directly from the configuration file that the application itself reads, so what you see published and what the system is permitted to call are one thing rather than two. Copying that table into this page would create a second source that drifts silently: a legal document that names five vendors while the platform calls six is worse than a link, because it reads as a guarantee. So this page describes the categories, states the commitments, and points at the table. If you need a dated snapshot of the list for a diligence file, ask and we will send you one.

03

The categories, and what each one receives

AI translation and quality: receives source strings, their surrounding context, glossary terms and style instructions, and returns translations, quality findings and suggestions. Text embeddings for near-match memory: receives source strings, and is engaged only when a project turns semantic translation memory on. An alternative translation engine, reached through an API router and hosted separately: receives source strings, and is engaged only when an operator routes a tier to it. Cloud hosting, the database and object storage: holds everything the platform stores. Payment processing: receives billing contact details and payment instrument data, and is engaged only for paid plans. Transactional email delivery: receives the recipient address and the message body of a product email. In-product support messaging: receives the name, the email address and the account identifier of a signed-in user who opens a conversation, and is engaged only when the support messenger is enabled.

04

Regions

The Trust Center names the region each subprocessor operates in. As at the effective date, AI translation and embedding processing takes place in the United States, one optional translation engine is hosted in Singapore, payment processing takes place in the United States and the European Union, and hosting runs in one cloud region fixed at deployment. There is no per-project or per-customer region pinning today and we do not sell one. Clause 14 of the Privacy Policy and clauses 15 and 16 of the Data Processing Addendum set out the transfer safeguards.

05

Always, and conditional

Some subprocessors are in the path whenever you use the Service. Others are conditional, and the Trust Center states the condition in the row rather than in a footnote: the embeddings provider is engaged only when a project enables semantic translation memory, which is off by default; the alternative translation engine is engaged only when an operator routes a tier, the canary or the evaluation harness to it, which is off by default; the payment processor is engaged only for a paid plan; the support messenger is engaged only when it is enabled. A conditional subprocessor that your configuration never triggers never receives your data.

06

The disclosure is enforced, not promised

The application knows which translation providers a deployment can actually call, and an automated test compares that set against the published disclosure list. If a provider becomes reachable without a row that names it, with a real region and a truthful engagement condition, the build fails. This is the mechanism behind the claim that we tell you before a new engine sees your text: routing a vendor without disclosing it stops being possible rather than merely being discouraged. Adding a vendor speculatively is refused for the same reason in reverse, because a subprocessor listed before it can be reached is its own kind of false statement.

07

Notice before a change

We give at least thirty days notice before a new subprocessor begins processing customer personal data, by email to the notice contact on the account and by publishing the change in the Trust Center. Notice is given before processing starts rather than after, and it names the vendor, the purpose, the region and the condition. Where a change is forced on us at shorter notice, for example because an existing vendor is acquired or discontinues a service, we tell you as soon as we can and explain why the period was shorter.

08

Your right to object

You may object to a new subprocessor on reasonable, documented data protection grounds within the notice period, by writing to the privacy address. We will work with you in good faith to find a way to avoid the processing, which may include a configuration change that keeps the conditional subprocessor out of your path. If we cannot within a reasonable time, you may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid unused fees. We will not treat a good faith objection as a breach or as a reason to degrade your service.

09

What we require of a subprocessor before engaging it

We assess a prospective subprocessor for its security posture, its data protection commitments, its retention and deletion behaviour, its transfer mechanism, and, for an AI vendor, its position on training. We enter into a written contract that imposes data protection obligations no less protective than those in our own Data Processing Addendum, including confidentiality, security measures, assistance, breach notification, deletion and audit. We remain fully liable to you for the performance of a subprocessor’s obligations. Where an AI vendor is engaged, the contract prohibits training on your content, which is the single commitment we will not trade away for a better price.

10

Third parties you connect are not our subprocessors

When you connect a repository, a content platform, a storage bucket, a chat workspace or an issue tracker, that system is your provider rather than ours: you supply the credentials, you set the scope, and you decide what moves. The same is true of a webhook endpoint you register and of a machine translation vendor you configure with your own key. We are the processor of the data while it is in our systems, and the transfer to your own third party is made on your instruction. Their terms and privacy policy govern what they do with it, and we do not list them here because listing somebody else’s processor as ours would be misleading in both directions.

11

Affiliates

Where we engage a corporate affiliate to process customer personal data, that affiliate is treated as a subprocessor and appears on the list with the same purpose, region and condition detail as any third party. We do not use an affiliate as a way to move processing to a new country without disclosure.

12

Getting told when the list changes

Notice goes to the account’s notice contact by email, so the first thing to do is make sure that address is a mailbox somebody reads rather than a founder’s personal address. If you want a second recipient, or a change feed for a compliance team, write to privacy@transglot.ai and we will add it. We keep a dated record of changes to the list and will provide it on request for a diligence file.

13

Who to ask

Questions about a subprocessor, an objection, a dated snapshot of the list, or a transfer mechanism for a specific vendor go to privacy@transglot.ai. The Trust Center is the fastest answer to most of them, and it is designed so that a reviewer does not have to write to anybody to finish an assessment.

privacy@transglot.ai
procurement, unblocked

Legal should not be the slow part.

Fourteen documents, each on its own URL, with the subprocessor list, the data posture and the compliance status published exactly as they stand today.

An executed Data Processing Addendum is a mail to privacy@transglot.ai.
Works with the tools you already run