Data Processing Addendum (DPA)
Data protection terms for customer-controlled personal data
Last updated: August 2025
This Data Processing Addendum (“DPA”) is entered into by and between the customer using Lara Translate (the “Controller”) and Translated S.r.l. (“Processor”, “Lara”, “we”, “us”), and forms an integral part of the agreement between the parties governing the use of Lara Translate (the “Agreement”).
This DPA reflects the parties’ agreement with regard to the processing of Personal Data in accordance with applicable data protection laws, including Regulation (EU) 2016/679 (“GDPR”).
1. Definitions
Terms such as “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” shall have the same meaning as in the GDPR.
"Sub-processor" means any third party authorized by the Processor to process Personal Data on its behalf.
2. Scope and Roles
This DPA applies to the extent that Lara processes Personal Data on behalf of the Controller while providing the translation service (including via web app, API, integrations, or plugins).
The Controller acts as Data Controller, and Lara acts as Data Processor.
The details of the Processing, including its subject matter, duration, nature and purpose, the types of Personal Data and the categories of Data Subjects, are set out in Schedule 1, which forms an integral part of this DPA.
The Controller is responsible for ensuring that its Processing instructions comply with applicable data protection laws and that it has provided all necessary notices and established an appropriate legal basis for the Personal Data submitted to the Service.
This DPA does not apply to Personal Data that Translated processes as an independent Data Controller, including, where applicable, account administration, billing, marketing and similar business relationship data. Such Processing is governed by Lara’s Personal Data Processing Policy.
3. Processor’s Obligations
Lara agrees to:
-
Process Personal Data only on documented instructions from the Controller, unless Lara is required to do otherwise by Union or Member State law. In such case, Lara shall inform the Controller of that legal requirement before Processing, unless the applicable law prohibits such information on important grounds of public interest;
-
Immediately inform the Controller if, in Lara’s opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection law;
-
Ensure that persons authorized to process the data are bound by confidentiality obligations;
-
Implement appropriate technical and organizational measures to ensure data security;
-
Assist the Controller in responding to data subject requests and in ensuring compliance with Articles 32 to 36 of the GDPR;
-
Notify the Controller without undue delay in the event of a Personal Data Breach;
-
Delete or return all Personal Data after the end of service provision unless legally required to retain it;
-
Make available to the Controller all information reasonably necessary to demonstrate compliance and, where applicable, to facilitate audits in accordance with this DPA.
4. Sub-processors
Lara may engage Sub-processors to perform specific processing activities.
Lara shall enter into a written agreement with each Sub-processor imposing, to the extent applicable to the Processing performed by that Sub-processor, the same data protection obligations as those imposed on Lara under this DPA. In particular, each Sub-processor shall provide sufficient guarantees to implement appropriate technical and organisational measures. Lara shall remain fully liable to the Controller for the performance of each Sub-processor’s data protection obligations.
A current list of Sub-processors, including their roles and data processing locations, is available here. Lara will inform the Controller by email, in-product notification or another reasonable electronic means of any intended addition or replacement of a Sub-processor at least 30 days before the relevant change takes effect. The Controller may object to the change on reasonable grounds relating to the protection of Personal Data by notifying support@laratranslate.com in writing within that notice period. Lara will provide the Controller with the information reasonably necessary to assess the proposed change.
In the event that the Controller raises a reasonable objection and the Parties are unable to agree on a solution within a reasonable time frame, Lara may either (i) not appoint the new Sub-processor for the Controller’s data, or (ii) if such exclusion is not technically or commercially feasible, the Controller may terminate the Agreement with respect to the Services affected. Such termination shall not entitle the Controller to any refund or credit of fees already paid for the Services, whether under a monthly, annual, or any other subscription plan. Continued use of the Services after the objection period shall constitute acceptance of the new Sub-processor.
5. International Transfers
Any transfer of Personal Data outside the EEA or Switzerland will be carried out in compliance with Chapter V of the GDPR.
Where applicable, Lara relies on Standard Contractual Clauses (SCCs), approved Binding Corporate Rules (BCR), or ensures compliance with the EU–US Data Privacy Framework (DPF) as appropriate to the specific transfer.
Processing and storage may take place within infrastructure located in the EEA or, for certain processing activities, outside the EEA, including in the United States, subject to appropriate safeguards in accordance with Chapter V of the GDPR.
Personal Data transferred internationally is protected by appropriate technical and organizational measures, including encryption in transit and, where applicable, encryption at rest. Encryption keys are managed using appropriate access controls and industry-standard key management practices.
6. Data Subject Rights
Lara shall, to the extent technically feasible and legally permitted, assist the Controller in fulfilling its obligations to respond to requests from data subjects under applicable data protection laws. The Controller remains responsible for determining the validity of any request and for the ultimate response to the data subject.
7. Security Measures
Lara implements appropriate technical and organizational measures to protect Personal Data. Depending on the nature and risks of the Processing, such measures include, but are not limited to:
-
Encrypted data transmission (HTTPS);
-
Access controls and authentication;
-
Logging and monitoring;
-
Isolated environments for sensitive operations;
- Measures designed to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- Measures designed to restore the availability of and access to Personal Data in a timely manner following a physical or technical incident;
- Processes for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures;
- Security risk assessment, vulnerability management and incident management processes;
- Secure deletion or anonymization procedures.
8. Retention and Deletion
Upon termination of the Agreement, Lara shall, at the Controller’s choice, delete or return all Personal Data processed on behalf of the Controller, unless applicable law requires retention. The Controller may communicate its choice by written request. In the absence of such request, Lara will delete the Personal Data in accordance with its standard retention procedures.
Retention periods vary depending on the type of data:
-
Content submitted for translation: Retained according to the selected mode.
-
In Learning Mode, content may be stored in accordance with the Terms and applicable product documentation. Where the service creates or updates Translation Memories (TM) associated with the Controller’s account, those TMs remain available for as long as the account remains open and active, unless the Controller requests deletion.
-
In Incognito Mode, content is discarded immediately after processing. Existing Translation Memories or glossaries, where configured, may still be used to guide the translation at request time, but no Translation Memory is created or updated from the content submitted in Incognito Mode.
-
-
User-uploaded resources (e.g., Translation Memories or glossaries): Retained for as long as the account remains open and active, unless the Controller requests deletion.
-
Technical and security logs: Automatically deleted after a limited retention period determined by Lara for security, debugging, and service integrity purposes.
-
Temporary copies of translated content: Where applicable, automatically deleted after the retention period necessary to complete processing and ensure service quality.
In all cases covered by this DPA, Personal Data is securely deleted or anonymized when no longer required for the purposes for which it was collected, or upon written request from the Controller, unless applicable law requires retention.
9. Audit and Documentation
Lara shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including relevant documentation, certifications, and security audit reports where available.
Where available and applicable to the Service, Lara may provide then-current independent certifications, audit or assurance reports, or other relevant security documentation to demonstrate compliance with this DPA. Confidential documentation may be provided subject to appropriate confidentiality obligations, including a separate non-disclosure agreement where reasonably required.
The Controller or an independent auditor mandated by the Controller may conduct audits, including inspections, upon reasonable prior written notice and no more than once per calendar year, unless otherwise required by applicable law or in the event of a confirmed Personal Data Breach.
The review of the documentation made available by Lara shall normally be the first method for demonstrating compliance. If such documentation is not reasonably sufficient, any further audit shall first be conducted remotely. A physical inspection of facilities may only be requested if the documentation and remote audit are insufficient to confirm compliance, unless otherwise required by applicable law or a competent Supervisory Authority.
All audits shall be conducted during normal business hours, in a manner that does not unreasonably interfere with Lara’s operations, and shall be subject to confidentiality obligations.
Any costs and expenses incurred in connection with an audit shall be borne by the Controller, unless otherwise required by applicable law.
10. Liability
The liability of each party under this DPA, including any liability for breaches of applicable data protection laws, shall be subject to the limitations and exclusions of liability set out in the main Agreement. Nothing in this DPA shall increase or expand either party’s liability beyond the limits agreed in the main Agreement.
11. Miscellaneous
In the event of a conflict between the Agreement and this DPA, the provisions of this DPA shall prevail with respect to the processing of Personal Data.
This DPA shall remain in effect for as long as Lara processes Personal Data on behalf of the Controller under the Agreement, and shall automatically terminate upon the deletion or return of all such Personal Data in accordance with Section 8.
Lara may update this DPA from time to time to reflect non-material changes, including clarifications, wording improvements, formatting changes, corrections of typographical errors, updates to links or references, or changes made to maintain consistency with the Terms, product documentation, or applicable law. Such updates may be made without prior notice, provided that they do not materially reduce the level of protection of Personal Data, materially expand the scope of Processing, materially reduce the Controller's rights, or materially reduce Lara's obligations as Processor.
Material changes to this DPA will be notified, and will take effect, in accordance with Section 9 (Changes to These Terms) of the Terms and Conditions. Changes to Sub-processors are governed by Section 4.
The version of this DPA in effect from time to time, as indicated by the "Last updated" date above, applies to the Controller's use of the Service. The "Last updated" date reflects the most recent material revision of this DPA; non-material updates may be made without changing this date.
12. Contact
For any privacy-related requests, please contact: support@laratranslate.com
You may also contact us via postal mail at:
Translated S.r.l.
Via Indonesia, 23
00144 Rome, Italy
Schedule 1 – Details of Processing
Subject Matter
The Processing of Personal Data contained in content submitted by or on behalf of the Controller in connection with Lara’s provision of the translation Service, including through the web application, API, integrations and plugins.
Duration
Personal Data is Processed for the duration of the Agreement and thereafter according to the retention and deletion provisions set out in this DPA, the Agreement and the applicable product documentation, unless applicable law requires further retention.
Nature and Purpose
Processing operations may include receiving, collecting, accessing, transmitting, organizing, structuring, storing where applicable, retrieving, consulting, adapting, translating, generating translation output, using configured Controller resources, restricting, deleting and returning Personal Data.
The purpose of the Processing is to provide, support, secure and maintain the Service, implement the service mode and configurations selected by the Controller and comply with the Controller’s documented instructions.
Types of Personal Data
Personal Data may include names, contact and professional information, identifiers and any other Personal Data contained in source content, translated content, documents, context information, Translation Memories, glossaries or other resources that the Controller elects to submit to the Service.
Categories of Data Subjects
Data Subjects may include the Controller’s personnel, contractors, customers, prospective customers, suppliers and business partners; users of the Controller’s products or services; authors, recipients and persons identified or identifiable in content submitted by or on behalf of the Controller; and any other individuals whose Personal Data the Controller elects to submit to the Service.
Special Categories of Personal Data
The Service does not require the submission of special categories of Personal Data. Where the Controller elects to submit such Personal Data, the Controller is responsible for ensuring that it has an appropriate legal basis and provides lawful documented instructions to Lara.
Frequency
Processing may take place on a continuous or occasional basis, depending on the Controller’s use of the Service.