Data Processing Agreement
Last updated: August 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service and describes how i18nnn, acting as a data processor, processes personal data on behalf of its customers, acting as data controllers.
1. Scope and roles
The customer is the data controller. i18nnn is the data processor. i18nnn processes personal data only on the documented instructions of the customer, including for the purposes of providing the service described in the Terms.
2. Subprocessors
The customer authorises i18nnn to use the following subprocessors. i18nnn will notify the customer at least 30 days in advance of any new subprocessor.
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payments | US (EU via Stripe Europe) |
| WorkOS | Authentication | US |
| Resend | Transactional emails | US |
| OpenAI | AI translation (BYOK) | US |
| Anthropic | AI translation (BYOK) | US |
| Sentry | Error monitoring | US |
| AWS (Vapor) | Hosting | eu-west-3 (Paris) |
3. Data retention
Personal data is retained for the duration of the user's account. Audit logs are retained for 2 years. Backup retention is 30 days.
4. Transfers outside the EU
OpenAI, Anthropic, Sentry, WorkOS, Stripe, and Resend are based in the United States. We rely on Standard Contractual Clauses for these transfers.
5. Security measures
i18nnn implements appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS 1.3) and at rest (AES-256), least-privilege access controls, hardware-backed MFA on production access, and regular vulnerability scanning.
6. Personal data breaches
i18nnn will notify affected customers without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their data.
7. Data subject requests
i18nnn will assist the customer in fulfilling data subject requests (access, rectification, erasure, portability) by providing self-service tools and, where applicable, manual support.
8. Audit
Customers may audit i18nnn's compliance with this DPA once per year, with reasonable prior notice, during business hours, and at the customer's expense. Audits will be conducted in a manner that does not interfere with i18nnn's operations.
9. Contact
DPA questions can be sent to dpo@i18nnn.app.