Privacy Policy & Data Protection

Order your translation online 24/7

Upload your document or text and place your order here.

Do you need personal help or advice?

Contact us by email, and we will be happy to help you.

Privacy Policy – UK GDPR, ISO 27001 and Personal Data Protection

Protecting Your Personal Data and Confidential Documents

At The Native Translator, we place great importance on protecting personal data and maintaining the confidentiality of documents entrusted to us by our clients.

When you use our professional translation services, you should be able to trust that your information is handled responsibly, from your initial quotation request through to the delivery of your completed translation.

We provide professional translation services for legal documents, medical records, financial reports, corporate documentation, technical materials and personal documents.

We recognise that the documents submitted to us may contain sensitive personal data, commercially confidential information, trade secrets and other materials requiring careful protection.

The Native Translator is certified to ISO/IEC 27001, the internationally recognised standard for information security management systems. This certification demonstrates the implementation of a structured management system designed to identify, assess and manage information security risks.

We process personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Swiss Federal Act on Data Protection (FADP).

Where relevant, we also comply with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended, which govern certain electronic communications and the use of cookies and similar technologies in the United Kingdom.

This Privacy Policy explains what personal data we collect, why we process it, how we protect it and the rights available to you under applicable law.

1. Who Is Responsible for Processing Your Personal Data?

The data controller is the organisation that determines the purposes and means of the relevant processing of personal data.

Data Controller:

The Native Translator
Prologic GmbH
Dorfstrasse 29
CH-6390 Engelberg
Switzerland

Data Protection and Information Security:
dataprotection(at)prologic-corp.ch

General Enquiries:
office(at)the-native-translator.com

Where required by applicable legislation, we will also make available the contact details of any appointed UK representative, EU representative or Data Protection Officer.

2. What Personal Data Do We Collect?

We collect and process personal data only where necessary to provide our services, comply with legal obligations or pursue other lawful purposes.

Depending on how you use our services, we may process the following categories of information:

  • Contact information: Your name, email address, telephone number, company name and postal address.

  • Translation project information: Quotation requests, language combinations, project descriptions, orders, instructions and correspondence.

  • Documents submitted for translation: Files and supporting materials, including any personal data contained within them.

  • Billing and payment information: Information required to administer transactions, issue invoices and maintain financial records.

  • Technical information: IP addresses, browser details, device information and website usage data.

  • Additional information: Any other information you voluntarily provide when contacting our customer service team or submitting an enquiry.

Documents submitted for translation may contain special category personal data within the meaning of Article 9 of the UK GDPR, including information relating to health.

We process such information only where the applicable legal requirements are satisfied.

We recommend that clients provide only the personal information necessary for the relevant translation assignment.

3. Why Do We Process Your Personal Data?

We process personal data to provide, organise, perform and administer our professional translation services.

Our principal purposes include:

  • Receiving and responding to quotation requests.

  • Reviewing documents and assessing translation requirements.

  • Preparing, managing and completing translation projects.

  • Communicating with clients about ongoing and completed assignments.

  • Delivering completed translations.

  • Managing payments, invoicing and accounting.

  • Protecting our IT systems and preventing unauthorised access, fraud and security incidents.

  • Complying with applicable legal obligations.

  • Operating, maintaining and improving our website and services.

  • Analysing website usage where permitted by applicable law.

We do not use documents submitted for translation for unrelated purposes without an appropriate lawful basis.

4. Lawful Bases for Processing Under the UK GDPR

Where the UK GDPR applies, we process personal data on one or more of the lawful bases set out in Article 6.

Performance of a Contract – Article 6(1)(b)

We process personal data where necessary to provide a quotation at your request or perform a contract with you.

Compliance with a Legal Obligation – Article 6(1)(c)

We process information where necessary to comply with legal obligations, including those relating to taxation, accounting and record retention.

Legitimate Interests – Article 6(1)(f)

Where permitted, we may process personal data for legitimate business interests, including maintaining information security, preventing misuse and administering our operations.

Such processing is subject to an assessment of whether your interests, rights and freedoms override those interests.

Consent – Article 6(1)(a)

Where processing requires your consent, such as the use of certain non-essential cookies, we will obtain that consent beforehand.

You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Where we process special category personal data under Article 9 of the UK GDPR, an applicable Article 9 condition must also be satisfied.

Depending on the nature of an assignment, The Native Translator may act as a data processor on behalf of a client who is the data controller.

In such cases, processing is governed by the relevant contractual arrangements and, where required, a data processing agreement consistent with Article 28 of the UK GDPR.

5. ISO/IEC 27001 – Certified Information Security Management

The Native Translator is certified to ISO/IEC 27001.

ISO/IEC 27001 is an internationally recognised standard that specifies requirements for establishing, implementing, maintaining and continually improving an information security management system.

The standard provides a structured approach to identifying information security risks and selecting appropriate measures to manage them.

Our information security management system is based on three fundamental principles.

Confidentiality: Protecting information against unauthorised access or disclosure.

Integrity: Protecting information against unauthorised or accidental alteration.

Availability: Ensuring that authorised individuals can access information when required.

Our management system incorporates technical and organisational safeguards appropriate to the risks associated with our activities.

ISO/IEC 27001 certification demonstrates that our information security management system meets the requirements of an internationally recognised standard.

However, certification does not mean that all security risks can be eliminated, nor does it independently guarantee compliance with every applicable data protection requirement.

6. How Do We Protect Your Documents and Personal Data?

Protecting confidential client information is an essential part of our professional translation services.

We implement technical and organisational measures designed to protect personal data and documents against unauthorised access, loss, improper alteration and unlawful disclosure.

These measures include:

  • Access controls based on assigned permissions.

  • Secure client and supplier portals for transferring files.

  • Encrypted data transmission using HTTPS/TLS when accessing our web portals.

  • Contractual confidentiality obligations for translators, revisers and project managers.

  • Procedures for identifying and managing information security risks.

  • Technical and organisational safeguards designed to prevent unauthorised access and other security incidents.

The specific measures applied are proportionate to the nature of the processing and the associated risks.

7. Confidentiality Obligations for Translators and Project Managers

Many of our clients entrust us with documents containing confidential business or personal information.

Our translators, linguistic revisers and project managers are subject to contractual confidentiality obligations.

Information accessed during an assignment must not be used for unauthorised purposes or disclosed to third parties without appropriate authorisation.

Access to documents is limited to activities necessary to perform the assignment and any other processing permitted by law.

We follow the principle that only individuals with a legitimate professional need should have access to the relevant information.

8. Do We Share Your Personal Data with Third Parties?

We do not sell your personal data to third parties.

However, providing our services may require us to share certain information with selected recipients, including:

  • Translators, revisers and project managers involved in your assignment.

  • Providers of IT systems, hosting, data storage and technical support.

  • Payment service providers.

  • Administrative service providers, where necessary.

  • Public authorities or other authorised recipients where disclosure is required by law.

Where external service providers process personal data on our behalf, we implement the contractual and organisational safeguards required by applicable legislation.

We limit disclosures to the information necessary for the relevant purpose.

9. International Transfers of Personal Data

The Native Translator works with an international network of qualified translators and other service providers.

Consequently, certain assignments may involve personal data being processed by recipients in different countries, including countries outside the United Kingdom, European Union and European Economic Area.

Where the UK GDPR or Swiss data protection legislation applies, international transfers are carried out in accordance with the relevant legal requirements.

For transfers subject to the UK GDPR, we assess whether the destination is covered by applicable UK adequacy regulations.

Where an appropriate adequacy arrangement is unavailable, suitable safeguards may be required.

These may include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the European Commission's Standard Contractual Clauses, or other transfer mechanisms permitted by law.

Where required, we also consider the risks associated with the transfer and implement supplementary protective measures.

For transfers subject to Swiss or EU data protection legislation, the relevant adequacy rules and approved contractual safeguards are considered separately.

The appropriate safeguards depend on the destination country, the nature of the data and the circumstances of the transfer.

10. Payments and Protection of Payment Information

For payment of our translation services, we may use external payment service providers such as PayPal or Saferpay, where these payment options are offered during the ordering process.

These providers may collect and process information necessary to complete transactions, prevent fraud and comply with their legal obligations.

We may receive certain payment-related information, including transaction status, payment references and billing details.

For further information about how payment service providers process personal data, please consult their respective privacy policies.

11. How Long Do We Retain Personal Data and Translation Documents?

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless legal obligations or other lawful reasons justify a longer retention period.

As a general rule, documents submitted for translation are retained for 90 days following completion of the assignment.

After this period, the documents are deleted from our active systems unless a legal obligation or another lawful reason requires continued retention.

Different retention periods may apply to certain categories of information, including:

  • Invoices and accounting records subject to statutory retention requirements.

  • Information necessary to manage ongoing matters.

  • Documentation required for the establishment, exercise or defence of legal claims.

  • Information that must be retained under other applicable legal provisions.

Backup systems may be subject to separate technical deletion cycles.

When information is no longer required and there is no lawful basis for continued retention, we delete or anonymise it in accordance with our applicable procedures.

12. Cookies and Similar Technologies

Our website may use cookies and similar technologies to support essential functions, remember user preferences and understand how visitors interact with our website.

Cookies are small text files stored on your device when you visit a website.

Cookies may be classified according to how long they remain on your device.

Session Cookies: These are generally used during a single browsing session and expire when that session ends.

Persistent Cookies: These remain on your device for a defined period or until you delete them.

Cookies may also be categorised according to their purpose.

Strictly Necessary Cookies: These support essential website functions or enable services explicitly requested by the user.

Analytics Cookies: These may help us understand website usage and improve our content and functionality.

Third-Party and Other Cookies: These may support additional website features or services provided by external organisations.

Where applicable law requires consent, we use non-essential cookies and similar technologies only after obtaining your consent.

For processing subject to UK law, we take account of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), as amended, and applicable guidance issued by the Information Commissioner's Office (ICO).

Any statutory exception to consent requirements depends on the purpose, configuration and conditions applicable to the particular technology. We do not assume that all analytics cookies are automatically exempt.

You may withdraw your consent at any time, with effect for the future.

13. Analytics Tools and Third-Party Cookies

Our website may use analytics tools such as Google Analytics or Matomo to understand website usage and performance.

Depending on their technical configuration, these tools may process information such as IP addresses, device details and pages visited.

We use analytics tools in accordance with applicable legislation and any relevant consent requirements.

Information about the tools actually deployed, the cookies used and their retention periods should reflect the website's current technical configuration and be made available to visitors.

14. How Can You Manage or Delete Cookies?

You can manage cookies through your web browser settings.

Most browsers allow you to block cookies, delete previously stored cookies or set preferences for particular websites.

Please note that blocking strictly necessary cookies may affect the operation of certain website features.

Further information is available from the following browser support pages:

Google Chrome:
https://support.google.com/chrome/answer/95647?hl=en-GB

Mozilla Firefox:
https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox

Safari:
https://support.apple.com/en-gb/guide/safari/sfri11471/mac

Microsoft Edge:
https://support.microsoft.com/microsoft-edge

Where our website provides a cookie preference management tool, you may also use it to change your selections or withdraw previously given consent.

15. Your Rights Under the UK GDPR and Applicable Data Protection Law

Where the UK GDPR applies, you may exercise the rights provided by the legislation, subject to applicable conditions and exceptions.

These include:

  • Right of Access: The right to access your personal data under Article 15.

  • Right to Rectification: The right to request correction of inaccurate personal data under Article 16.

  • Right to Erasure: The right to request deletion of personal data in qualifying circumstances under Article 17.

  • Right to Restriction of Processing: The right to request restricted processing in certain circumstances under Article 18.

  • Right to Data Portability: The right to receive or transfer certain personal data where the relevant conditions are met under Article 20.

  • Right to Object: The right to object to certain processing activities under Article 21.

  • Right to Withdraw Consent: The right to withdraw consent where processing is based on consent.

  • Right to Complain: The right to lodge a complaint with a competent data protection supervisory authority.

Depending on the circumstances, you may also have rights concerning decisions based solely on automated processing, including profiling, under Article 22 of the UK GDPR.

These rights are subject to statutory conditions and exceptions.

For example, a request for erasure may not always be fulfilled in full where certain information must be retained to comply with a legal obligation.

Swiss data protection legislation also provides individuals with certain rights, including rights of access and, subject to legal conditions, rectification and other remedies.

We assess each request in accordance with the legislation applicable to the relevant processing activity.

16. Your Right to Object to Processing

Where we process personal data on the basis of legitimate interests under Article 6(1)(f) of the UK GDPR, you may object to that processing on grounds relating to your particular situation, in accordance with Article 21.

Following a valid objection, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

17. Your Right to Complain to the Information Commissioner's Office

If you believe that your personal data has been processed in breach of applicable data protection law, you are welcome to contact us so that we can investigate your concerns.

Where the UK GDPR applies, you also have the right to complain to the Information Commissioner's Office (ICO), the UK's independent data protection regulator.

Information Commissioner's Office (ICO)

Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Website: https://ico.org.uk

In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) is the relevant federal supervisory authority within the scope of Swiss data protection legislation.

Website: https://www.edoeb.admin.ch

18. Changes to This Privacy Policy

We may update this Privacy Policy when our services, technical systems, internal procedures or applicable legal requirements change.

The latest version will be published on our website.

Where significant changes occur, we will provide additional information to affected individuals when legally required or otherwise appropriate.

19. Contact Us About Data Protection and Information Security

If you have questions about how your personal data is processed, wish to exercise your rights or need to report a potential data protection or information security incident, please contact us.

Data Protection and Information Security:
dataprotection(at)prologic-corp.ch

General Enquiries:
office(at)the-native-translator.com

At The Native Translator, we provide professional translation services where linguistic quality, confidentiality and information security are integral to every assignment.

These companies believe in our quality:

<
>