Confidentiality is Part of our Service

Data Protection and IT Security in Specialised Translations

Your documents often contain some of the most sensitive information that a company owns. We process them in compliance with the GDPR on EU servers with access controls and full traceability.

  • GDPR & German Federal Data Protection Act · ISO 17100 · ISO 18587 · ISO 9001 · ISO 27001-oriented · NDA practice
Quanos Übersetzer
ISO9001:2015

What needs to be translated is rarely trivial: design documents, approval dossiers, contracts, patent specifications and internal reports, which are often unpublished and highly sensitive. Translation is one of the few moments when these documents leave your company. This is precisely why we treat data protection and information security as integral components of our service.

In regulated and security-critical industries, confidentiality is often the most important factor in awarding contracts, ahead of price and delivery time. We align our practices with the GDPR and the German Federal Data Protection Act (BDSG), process data on EU-based servers, and base our concepts on ISO 27001. ISO 27001We are also preparing for ISO 27001 certification.

The sections below show what this looks like in practice in terms of organisation, technology and the use of AI.

Three Pillars of Trust

Confidentiality: Organisational

All employees and external partners are bound by confidentiality obligations. Access is granted on a project-by-project basis in line with the need-to-know principle. Project and terminology data are kept separate for each client. You can request a written non-disclosure agreement (NDA) in advance.

Security: Technical

We process your data on secured, redundant servers in the EU. Data is backed up via a dedicated backup system (NAS) in a secure server room. Access is restricted to authenticated users only. Transmission is encrypted (TLS) and protected by a firewall and VPN. Cloud systems are secured with two-factor authentication.

AI: Without Compromise

AI-assisted translations take place exclusively on protected European servers, never on US servers. Your content is contractually excluded from AI model training. The service used is integrated as a processor with documented safeguards.

Request a project & receive expert advice

Do you have technical documents that need translating? Send us 1–2 sample files. You will receive a specific recommendation and a quote within 24 hours.

Measures

Organisational

  • We have a confidentiality obligation towards third parties for all documents provided
  • Access is strictly on a project-by-project basis and according to the need-to-know principle
  • We have client separation in project and terminology systems
  • We provide regular data protection and security training
  • Our external specialist translators are under a written NDA with a deletion obligation after project completion
  • We have a documented incident reporting process for security events

Technical

  • Redundant, secure server infrastructure in the EU
  • Data backup via a dedicated backup system (NAS) in a secure server room
  • Strict access control; only authenticated users
  • Access security for office premises and servers separately
  • Two-factor authentication (2FA) for cloud systems
  • Encrypted transmission (TLS), firewall and VPN
  • Regular updates and support from a specialised IT service provider
Four Protection Goals of Our Communication: Access control: only authenticated users. Authentication: messages are clearly attributable. Integrity: no undetected alterations during transmission. Confidentiality: internal and external transmission is exclusively encrypted.

AI-assisted Translation and Data Protection

Machine translation and AI are now part of the professional process, but only under controlled conditions. At COMLOGOS, AI-assisted translations are carried out exclusively on protected European servers. Sensitive customer data is not processed on US servers. Your content is contractually excluded from AI model training.

The AI translation service is engaged as a data processor and has a data processing agreement (DPA) in place, as well as documented technical and organisational measures and disclosed subprocessors. A release policy governs which content can be entered into AI systems internally; personal or sensitive data is not permitted in public AI systems.

At COMLOGOS, machine post-editing is carried out in accordance with ISO 18587 . AI is not an end in itself, but is embedded in a quality-assured, human-revised process. Our technology page describes how we apply the technology methodically. AI-assisted Translation.

Standards and Legal Framework

Framework Relevance to your data
GDPR and BDSGLegal framework for all processing; processing on servers in the EU
ISO 27001Concepts aligned with this; certification in preparation
ISO 17100Confidentiality and the four-eyes principle as integral parts of our process (certified since 2015)
ISO 18587Controlled use of AI within a standardised process (certified since 2019)
ISO 9001Controlled access, responsibilities and traceability

Confidentiality in writing on request

If you wish, we can arrange a separate written confidentiality agreement (NDA) before the project begins. This can be done quickly and without delaying the process. Regardless, all parties involved are bound by confidentiality obligations.

Request an NDA

Frequently asked questions on IT security and data protection

How does COMLOGOS protect confidential customer data?
Through a combination of organisational and technical measures. Organisatorically, confidentiality obligations apply to everyone involved, access is granted on a need-to-know basis, and strict client separation is maintained. Technically, we process data on secured EU servers with access control, encrypted transmission and data backup via a dedicated backup system (NAS) in a secured server room.
Is my data processed in compliance with GDPR?
Yes. Our work is guided by the GDPR and the German Federal Data Protection Act, and we process your data on servers located in the EU. We never process sensitive data on US servers.
Do you use AI, and is it compliant with data protection regulations?
We use AI-assisted translation, but only under controlled conditions, such as on protected servers in Europe and with no processing of sensitive data on US servers. Machine post-editing is standardised under ISO 18587 and is always part of a human-revised process.
Is my text used to train AI models?
No. The exclusion from training is contractually regulated. Your content is not used for the training of AI models.
Do I receive a non-disclosure agreement (NDA)?
Yes, upon request. We are happy to arrange a separate written confidentiality agreement before the project begins. Regardless, all parties involved are bound by confidentiality obligations.
How is data transmitted and stored securely between us?
Transmission is encrypted (TLS) and cloud access is secured with two-factor authentication. Data is stored on redundant EU servers with strict access control and backup at two separate locations.
Are your external translators bound by confidentiality obligations?
Yes. Written data protection and non-disclosure agreements are in place with all external specialist translators, and project-related data sharing includes an obligation to delete data after project completion.
Is COMLOGOS certified to ISO 27001?
Our concepts and processes align with ISO 27001, and we are currently preparing for certification. We are already certified under ISO 17100 for translation services (since 2015), ISO 18587 for machine translation and post-editing (since 2019), and ISO 9001 for quality management.

Let’s talk about protecting your data

Tell us about your project. We will explain transparently how we process your documents and can provide a confidentiality agreement in advance upon request.

GDPR & German Federal Data Protection Act · ISO 17100 · ISO 18587 · ISO 9001 · ISO 27001-oriented · NDA practice