Data Protection
How we meet our data protection obligations as a controller and as a processor, and how we protect the documents clients send us.
Last updated: 25 September 2026
Our two roles
The company is The Translation Department Limited, trading as Transferendum. We are registered in Ireland under company number 695147. Our registered office is Unit C, First Floor, 34 Usher's Quay, Dublin 8, D08 XA07, Ireland. Our postal address is 1st Floor, 34 Usher's Quay, Dublin 8, D08 XA07, Ireland.
We hold two roles under the General Data Protection Regulation. For the personal data inside the documents a client instructs us to translate, the client is the controller and we are the processor. For our own customers, suppliers, linguists and website visitors, we are the controller.
This policy sets out what each role means in practice. Our record keeping, our security measures and our retention periods apply in both roles.
When we are a processor
A client sends us documents for translation. The personal data inside those documents sits in the client's relationship with the people named in them. The client decides what is translated, why it is translated, and how long the material is kept after the job. We act on the documented instructions of the client.
We process that personal data only to produce the translation the client asked for. We do not use it for our own purposes. We do not sell it. We do not build a profile of anyone from it.
Our standard data processing agreement under Article 28 of the Regulation governs this work. The agreement covers the subject matter and the duration of the processing, the nature and the purpose of the processing, the types of personal data and the categories of data subject, the obligations of both parties, and the security measures. A copy of the agreement is available on request.
Where we are the processor, a person who wants to exercise a data protection right writes to the client that instructed us. We pass any request we receive to that client, and we give the client the help they need to answer it.
Sub-processors and linguists
Freelance and agency linguists are the main category of sub-processor. We engage each linguist as a sub-processor and contractor under a written contract that carries confidentiality and data protection terms. A linguist receives only the material needed for the job assigned, and works on it under our instructions.
The other categories of recipient are our translation management system, Microsoft 365 and SharePoint for email and document storage, Odoo for our enterprise resource planning, our customer relationship management and this website, Cloudflare Turnstile for the anti-bot check on the contact form, our payment providers, and our hosting provider. The privacy policy lists the recipients in full.
Our Article 28 agreement states how we appoint a sub-processor on a client's work and how we tell the client about a change. A client can give general written authorisation for the categories of sub-processor we use. Where a client does, we tell them before we add or replace a sub-processor on their work, and they may object to the change. A client can also ask us for the categories of sub-processor engaged on their work, and for the countries in which those sub-processors process the data.
When we are a controller
We are the controller of the personal data of our customers, our suppliers, our linguists and the visitors to this website. That data covers contact details, project and order details, correspondence, billing records, recruitment records and website records.
We process it to answer enquiries, to deliver our services and to invoice them, to keep statutory records, to keep the website secure and to assess the people who apply to work with us. The bases are Article 6(1)(b) for the performance of a contract, Article 6(1)(c) for a legal obligation, and Article 6(1)(f) for our legitimate interests. We rely on consent under Article 6(1)(a) only for optional marketing email, and we do not send marketing email today.
The privacy policy describes each purpose, its basis and the personal data the website collects.
Special category data
Documents sent for translation can contain special category data within the meaning of Article 9 of the Regulation. Medical reports, immigration files, court documents, Garda documents, birth records, adoption records and other official records are common in our work.
Where a client instructs us to translate their own documents, the client is the controller of that data and the client establishes the Article 9 condition for processing it. We process the data on the documented instructions of the client, and only to produce the translation.
We limit access to the people who work on the job, on a need to know basis. Every employee and every linguist signs a written confidentiality and data protection undertaking. We do not reuse client content for any other purpose. We delete the material as the retention schedule below provides.
Translation work is carried out by people. A qualified linguist translates or post-edits the text, and a second qualified linguist checks it before delivery. We use the material only for the job you asked for. We do not use it for profiling or analysis, and no recipient may use it for a purpose of their own.
Retention schedule
We keep personal data for the periods in the table below. Each period starts at the completion of the job.
| Record | Retention period |
|---|---|
| Hard copy documents, including working copies and notebooks | Destroyed by shredding, or returned to you, within 4 weeks of job completion |
| Electronic working files | Destroyed within 24 weeks of job completion |
| Certified translated documents | Purged from our archives and backups within 180 days of job completion, with a reference to the certification of the job kept |
| Translation memory entries | Stored in a form that does not allow the reconstruction of personal data |
| Job accounts | Reconciled within 6 months of job completion |
| Transactional and accounting records, including invoices | Kept for 6 years under tax law |
We delete other records, including enquiries that do not lead to a job, when we no longer have a business reason to keep them. We do not keep personal data for longer than the schedule allows, and we do not keep it for a longer period because it might be useful one day.
Security measures
We protect personal data against unauthorised access, accidental disclosure, loss and destruction. We apply the measures below to hard copy and to electronic records.
- Access is limited to the people who need it for the job. Each person has their own account, and we remove access when the person stops working with us.
- Hard copy stays secure while a job runs. We shred it or return it to the client at the end, as the retention schedule provides.
- Email and document storage run inside Microsoft 365 and SharePoint, under our own accounts.
- Job files run in our translation management system, and our customer records and this website run in Odoo.
- The contact form carries a Cloudflare Turnstile check, which confirms that a submission comes from a person rather than a bot.
- Where a supplier processes personal data for us, we engage them under a written contract with confidentiality and data protection terms, and we record the countries in which they process the data.
Where a supplier processes personal data outside the EEA, we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses together with a transfer risk assessment. The privacy policy sets out those mechanisms.
Data breaches
A personal data breach is an incident that leads to the accidental or unlawful destruction, loss, alteration or disclosure of personal data.
We record every incident in a breach register, and we assess the risk it creates for the people affected.
Where we are the processor and a breach affects a client's data, we tell that client without undue delay after we learn of the incident. The client is the controller, and the client decides what to report and to whom.
Where we are the controller and a breach is likely to create a risk to the rights and freedoms of the people affected, we notify the Data Protection Commission within 72 hours of learning of the incident. Where the breach is likely to create a high risk to those people, we also tell them directly.
You can report a suspected breach to privacy@transferendum.eu. We investigate every report and reply to the person who made it.
Confidentiality and quality
Every employee, every contractor and every linguist signs a confidentiality undertaking before receiving client material. The obligation continues after the engagement ends.
We are certified to ISO 9001:2015 and EN 17100:2015. Our quality management system covers the translation process: the selection of the people who do the work, the checks on each job, and the records we keep for an audit.
We hold client content for the purpose of the job we were instructed to do. We do not reuse it for another purpose, we do not sell it, and we do not disclose it outside the recipients named in the privacy policy.
Your rights and how to complain
The privacy policy lists the rights you hold and explains how to make a request. Send a request to privacy@transferendum.eu, or to our postal address. We answer within one month.
You can complain to the Data Protection Commission. The address is Canal House, Station Road, Portarlington, R32 AP23, Co. Laois. The telephone numbers are 0761 104800 and 1890 252231. The email address is info@dataprotection.ie.
How to contact us
Our data protection contact is Ronan Power, Managing Director. Email: privacy@transferendum.eu. General enquiries: info@transferendum.eu, telephone +353 1 963 1720. Postal address: 1st Floor, 34 Usher's Quay, Dublin 8, D08 XA07, Ireland.
This policy can change. We publish the date of the last update at the top of the page. A change to the retention schedule appears in the table above.