Last Updated: March 05, 2020
Thanks for entrusting Lokalise with your localization projects and your personal information. Lokalise, Inc. and its affiliates (collectively, "Lokalise", "we" and "us") respect your privacy.
This policy describes how we use Personal Data (as defined below), with whom we share it, your rights and choices and how you can contact us about our privacy practices.
If you're visiting us from the European Union (EU), European Economic Area (EEA), Switzerland, or the United Kingdom (UK), please see our global privacy practices: we comply with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks (the "Privacy Shield"), and we are compliant with the EU General Data Protection Regulation (the "GDPR").
If you are visiting us from California, the USA, please note that you may have specific rights under the California Online Privacy Protection Act, the California Consumer Privacy Act of 2018 and certain other privacy and data protection laws.
No matter where you are, where you live, or what your citizenship is, we provide a high standard of privacy protection to all our users around the world, regardless of their country of origin or location.
Of course, the short version doesn't tell you everything, so please read on for more details!
1. What information do we collect
A. Personal Data Subjects. We collect information from visitors to our Platform, our potential and our existing customers, usually companies (the “Customers”) represented by the authorized individuals who are registered or permitted by a Customer to access a Team’s Workspace and/or use the Services (the “Authorized Users”). For example, localization managers, CTOs, CPOs or external translators working on a translation project in the Team’s Workspace.
B. Types of Information. Information about you can be divided in two groups:
|Information you provide to us: “personally identifiable information” or personal data that we can use to identify or contact you (the “Personal Data” or “PII”). See Subsection C below.||Information that is automatically collected: “Aggregated Information” - information or data we collect where individual user identities have been removed. See Subsection D below.|
Generally, no one is under a statutory or contractual obligation to provide any Personal Data or Aggregated Information. Certain Customer Data about you has been collected automatically and, if some Customer Data such as the names and emails of the Authorized Users is not provided, we may be unable to provide the Services.
C. Personal Data. Personal Data is any piece of information that can potentially be used to identify, contact, or locate a user uniquely. We need this information so we can interact with each other and so that we can provide our Services in a high-quality way which is specific to your needs. You provide your Personal Data, for example, by signing up on our Platform or paying for the Services. Personal Data collected by us is protected as personal data under applicable data protection laws, for example, under the GDPR.
You are responsible for ensuring the accuracy of all Personal Data that you submit to us. Inaccurate Personal Data may affect your experience when using the Services and/or our ability to contact you as described in this Policy.
D. Aggregated Information. Aggregated Information is non-personally identifiable/anonymous Information about users of the Platform. Aggregated Information is information that you give to us by using our Platform or the Services. Aggregated Information is used in a collective manner and no single person can be identified by the information compiled.
For example, when you visit our Website, our systems automatically maintain web logs to record data about all visitors who use our Website and store this information in our database. These weblogs may contain information about you including the following: IP address, type(s) of operating system you use, type of device you use, date and time you visited our Website, your activity and/or referring websites and the pages most frequently accessed.
We may de-identify or anonymize your Personal Data so that you are not individually identified and provide that information to our partners and/or affiliates. We also may combine your de-identified information with that of other users to create aggregate de-identified data that may be disclosed to third parties who may use such information to understand how often and in what ways people use our Services so that they can provide you with an optimal online experience. For example, we may use the information gathered to create a composite profile of all the users of the Platform to understand users’ needs in order to design appropriate features and tools. However, we never disclose Aggregated Information in a manner that would identify you personally and as an individual.
2. How do we collect your Personal Data
The Information that you provide directly to us will be apparent from the context in which you provide the data. In particular, we collect the following Customer Data :
A. Contact Information. When you create or update your Team’s Workspace we collect your full name, email address, phone number, company's name, role in your team and account login credentials (audit logs).
When you fill in our online form to contact our sales team (e.g., schedule a call), we collect your full name, email, country, your guests' emails, phone number and anything else you tell us about your project, needs and timeline.
When you respond to Lokalise emails, newsletters or surveys, we collect your email address, name and any other information you choose to include in the body of your email or responses.
B. Billing Details. When you subscribe to a paid plan version of the Services, our payment processor or bank collects your billing details. Different payment methods may require the collection of different types of information, such as your payment card number, CVC, expiration date and/or bank account number and/or a billing address.
Please note that payment information submitted by you will be processed by our payment processor or bank. We do not intentionally receive or process your billing information. However, we have access to some of our Customers’ billing details via our account with the payment processor or bank. Please review our Data Processing Addendum for details.
C. Information we collect automatically. Even if you do not provide information to us, we automatically collect Aggregated Information about your use of and interaction with our Platform and/or Services as described in Section 1 above. We use your Aggregated Information to troubleshoot problems, gather demographic information, customize your experience when accessing our Platform, Services and for other business purposes.
D. Data from Third-Party Services. Our Customers can choose to permit or restrict Third-Party Services needed for better collaboration in their Team’s Workspace. Typically, Third-Party Services refer to software that integrates into our Platform (e.g., Jira, Asana, GitHub) and the Customer can enable and disable these integrations. For more information on Third-Party Services (available integrations, plugins and libraries), click here.
Once enabled, the provider of a Third-Party Service may share certain information with Lokalise and vice versa. For example, if a cloud storage application is enabled to permit the import of files to your Team’s Workspace, we may receive a user's name and email address, along with additional information that the application has elected to make available to Lokalise to facilitate the integration.
Authorized Users should check the privacy settings and notices in these Third-Party Services to understand what data may be disclosed to Lokalise. We do not, however, receive or store passwords for any of these Third-Party Services when connecting them to the Platform.
E. Third-Party Data. We may receive Information about you from outside sources, such as commercially available demographic or marketing information, and add or combine it with your information to provide better service to you and inform you of Services or other information that may be of interest to you. This data may be combined with the Customer Data we collect and might include aggregate level data, such as which IP addresses correspond to which zip codes or countries, or it might be more specific: for example, how well an online marketing or email campaign performed.
We also offer you the functionality of using your social media credentials (e.g., Google, GitHub, Microsoft) for single sign-on to enter our Platform, and in that manner, we may also collect certain information from you as you log on. We will not collect more information from you when using your social media credentials beyond the information that third parties disclose to us.
F. Additional Information. We receive your Personal Data when you submit it to our Platform, if you participate in an offer, program or promotion, focus group, contest, activity or event, apply for a job, request support, interact with our social media accounts, give us your business card or contact details at conferences or other events, provide feedback or otherwise communicate with our team.
3. What is our legal basis for processing information
Under specific laws (including the GDPR), we are required to notify you about the legal basis on which we process your Personal Data. We will only collect and process personal data about you where we have a lawful basis. Lawful basis includes:
- Consent (where you have given explicit consent);
- Contract (where processing is necessary to take steps to enter into or perform a contract with you);
- Compliance with a legal obligation, e.g. where we need your data for compliance with specific laws;
- Vital or public interest, where processing is necessary for the performance of a task carried out in the public interest of a data subject or another person;
- “Legitimate interests”, except where such interests are overridden by the interests, rights or freedoms of a data subject.
Where we rely on your consent to process Personal Data, you have the right to withdraw or decline your consent at any time and where we rely on legitimate interests, you have the right to object.
If you have any questions about the lawful basis upon which we collect and use your personal data, please feel free to contact our Data Protection Officer at: email@example.com.
4. How will we use your Personal Data
How we use your Personal Data will depend on which Services you use, how you use the Platform and the choices you make in your settings. Personal Data will be used and processed by us in compliance with the Customer’s instructions, including any applicable contract terms, and as required by applicable law.
We use the Customer Data in furtherance of our legitimate interests in operating our Platform, delivering Services, and doing business. In determining business purposes that we have identified as legitimate; we balance our interests against the legitimate interests and rights of the individuals whose Personal Data we process.
More specifically, we use Customer Data :
- To facilitate contractual and pre-contractual business relationships. We use Personal Data to enter into business relationships with prospective customers and to perform the contractual obligations under the contracts that we have with existing Customers. For example, we may collect your Personal Data to schedule calls and meetings for the Platform’s demo, preparing offers to you or setting up and managing a Team’s Workspace on the Platform and performing certain accounting, auditing and billing activities.
- To comply with our regulatory and other legal obligations, including Data Processing requirements of the GDPR and U.S.-EU Privacy Shield as well as any “Anti-Money Laundering” (AML) and “Know-Your-Customer” (KYC) obligations,
- To personalize the Platform for you by understanding your needs. We use the Customer Data to customize our Services for you, including providing recommendations for translations, personalized content and the Team’s Workspace management. For example, our built-in translation memory saves all the information that you upload or set via API for later, automated use in the course of translating.
- To create new features, tools and products. For example, we may improve functionality by using the Customer Data to help determine and rank the relevance of content to you and make Services suggestions based on historical use and predictive models. For example, based on your translation history, thus we may identify organizational trends and insights based on the translation history of projects on the Platform.
- For research and analysis. We conduct aggregate analysis, market research and planning, develop business intelligence, generate statistical studies that enable us to operate, protect, make informed decisions and report on the performance of our business;
- For customer support. Your emails, calls and other correspondence to and from us may be recorded for various purposes including monitoring customer service quality or compliance, checking the accuracy of the information you provide us or providing training for our personnel or customer service representatives. Any information obtained from you through Customer support will be treated according to the provisions of this Policy.
- To protect Lokalise, our Customers and the public. We use your Personal Data to ensure network and information security throughout the Platform, to prevent, investigate or address service errors, security or technical issues and abuses that could harm Lokalise, our Customers or the public.
- For marketing and events-related communications. We sometimes send emails about new product features, promotional communications or other news about Lokalise, our products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so per the applicable consent requirements. These are marketing messages (described in more detail below), so you can control whether you receive them.
- For interest-based advertising. When you visit our Platform, both we and certain third parties collect information about your online activities over time and across different sites to provide you with advertising about products and services tailored to your specific interests (this type of advertising is called “interest-based advertising”). These third parties may place or recognize a unique cookie or other technology on your browser (including the use of pixel tags). Where required by applicable law, we will obtain your consent before processing your information for interest-based advertising.
5. Personal Data Lokalise does not collect
No Sensitive Data. We do not intentionally collect, store, process or transmit any sensitive personal information, such as social security numbers, genetic data, health information or religious information. If you store any sensitive personal information on our servers, you are responsible for complying with any regulatory controls regarding that data. We might erase the sensitive information that is uploaded to the Platform or otherwise provided to us without our request or consent, if such erasure is necessary for the public interest or compliance with our legal obligations.
You further acknowledge that Lokalise is not a Business Associate or subcontractor (as those terms are defined in the United States Health Insurance Portability and Accountability Act of 1996 (the “HIPAA”) or a payment card processor and that our Services are neither HIPAA nor PCI DSS compliant. Lokalise will have no liability for any Sensitive Personal Information, notwithstanding anything to the contrary herein.
No Minorities Data. If you're a child under the age of 16, you may not have an account on Lokalise. We do not knowingly direct any of our content specifically to or collect information from children under 16. If we learn or have reason to suspect that you are a user who is under the age of 16, we will, unfortunately, have to close your account. Other countries may have different minimum age limits and if you are below the minimum age for providing consent for data collection in your country, you may not use Lokalise. You may not use Lokalise in California if you are a California resident under 16.
No End-User Data. We do not intentionally collect the Personal Data of Customers’ end-users that might be stored in your account. Information and content in a Customer's accounts belong to the Customer, and the Customer is fully responsible for it, as well as for making sure that your content complies with our Terms of Service. Any Personal Data within a Team’s Workspace is the responsibility of the Customer, namely the account's owner. The Customer shall be considered as the controller for the purposes of the GDPR. Please see Section 12 below for details.
6. How We Disclose Personal Data
Please note that our Customers determine their policies and practices for the sharing and disclosure of the Personal Data under their control and Lokalise does not control how they or any other third parties choose to share or disclose such Personal Data.
We share your Personal Data with trusted entities with your explicit consent, based on our instructions and in compliance with appropriate confidentiality and security measures, as outlined below:
- To Third-Party Services. Our Platform enables integrations with third-party software that our Customers may use (e.g., Jira, Asana, GitHub). Available integrations, plugins and libraries can be found here. The Customer has sole discretion over whether to use these integrations. Once enabled, Lokalise may share certain information with a Third-Party Service provider and vice versa. For example, we will share configuration parameters, including emails linked to the Team’s Workspace to allow software management tools to integrate into said Workspace.
- To Corporate Affiliates. We share Customer Data with our corporate affiliates (parents and/or subsidiaries) for internal administrative, operational, and group business purposes.
- To Customer's Representatives. Authorized Customer representatives and personnel designated as 'owners' of a Team’s Workspace may be able to access, modify, or restrict access to Personal Data of the Customer’s Authorized Users. It may include, for example, your employer using Service features to export activity logs from a Team’s Workspace or accessing or modifying your profile details.
- During a Change to Lokalise's Business. Some or all Customer Data may be shared or transferred, subject to standard confidentiality arrangements, if Lokalise engages in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of Lokalise's assets or stock, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g., legal due diligence).
- To Share Aggregated Data. We may disclose or use aggregated or de-identified Information with others about how our customers, collectively, use Lokalise, or how our customers respond to our other offerings, such as conferences and events. For instance, we may compile statistics on the proportion of customers by industry and size. However, we do not sell this information to advertisers or marketers.
- To Collaborate with Others. When an Authorized User submits Personal Data, it may be displayed to other Authorized Users. For example, your profile information, including email address, may be shared with other Authorized Users working in the same Team’s Workspace.
- To Share in Public. When you comment on our blogs or in our community forums, the information you provide on these resources may also be read, collected, used and shared by any visitors to these resources. It would be best if you were cautious when deciding whether to disclose your Personal Data in these areas related to the Platform. To request removal of your Personal Data from our community forums or social media pages, contact us at: firstname.lastname@example.org. We may not be able to remove your Personal Data, in which case we will let you know if we are unable to do so and why.
- To Comply with Laws. If we receive a request for information, we may disclose Customer Data if we reasonably believe disclosure is in accordance with or required by any applicable law, regulation, or legal process. Please find more in Section 15 hereof to understand how Lokalise responds to requests to disclose data from government agencies and other sources.
- To enforce our rights, prevent fraud and for safety. To protect and defend the rights, property or safety of Lokalise or third parties, including enforcing contracts or policies, or in connection with investigating and preventing fraud or security issues.
We do not share, sell, rent or trade your Personal Data with third parties for their commercial purposes, except where you have specifically told us to (such as by activating an integration with third-party service providers).
We do not host advertising on Lokalise. We may occasionally embed content from third-party sites, such as YouTube and that content may include ads. While we try to minimize the number of ads our embedded content contains, we cannot always control what third parties show. Any advertisements on individual Lokalise web pages are not sponsored or tracked by Lokalise.
We do not disclose your Personal Information outside Lokalise, except in the situations listed in this section.
7. What are your data protection rights
A. Your data protection rights. We provide many choices about the collection, use and sharing of your Personal Data. Depending on your location and subject to applicable law, you may have the following rights concerning the Personal Data we hold on you:
● Delete Data: You can ask us to erase or delete all or some of your Personal Data (e.g., if it is no longer necessary to provide Services to you).
● Change or Correct Data: You can review, correct, or update your Personal Data through your account on the Platform or by contacting us at: email@example.com. You can also ask us to change, update or fix your Personal Data in some instances, mainly if it is inaccurate.
● Object to, Limit or Restrict the Use of Data: You have the right to withdraw your consent to the processing of your Personal Data at any time. You can ask us to stop using all or some of your Personal Data (e.g. if we have no legal right to keep using it) or to limit our use of it (e.g., if your Personal Data is inaccurate or unlawfully held).
● Right to Access and/or Take Your Data: You can ask us for a copy of your Personal Data and can ask for a copy of the personal data you provided in machine-readable form.
● Right to file a complaint to the supervisory authority if you consider your rights to have been violated. See Section 17 for details.
● Right to unsubscribe. We will only send you marketing and events-related communications if you expressly consent to this. We provide you with the opportunity to “unsubscribe” from having and using your Personal Data for specific marketing-related purposes at any time. Please note that it may take several working days to process a request for an unsubscription or opting-out. In particular, Lokalise offers you the following unsubscription rights:
▪ Opt-out from Newsletters. If you no longer want to receive marketing-related emails or newsletters from us, you may opt-out via the unsubscribe link included in such emails. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.
▪ Opt-out from Advertising Networks. We work with Google AdWords and other advertising networks. To learn how to opt-out of behavioral advertising delivered by Network Advertising Initiative member companies, please visit the Network Advertising Initiative and Digital Advertising Alliance. You may download the AppChoices app to opt out in mobile apps.
▪ Opt-out from Hotjar. We also use Hotjar, a technology service that helps us better understand our users' needs and to optimize this service and experience. This enables us to build and maintain our service with user feedback. You can opt-out of the creation of a user profile, Hotjar’s storage of data about your usage of our Platform and Hotjar’s use of tracking cookies on other websites by following this opt-out link.
B. Exercising other data protection rights. To use your data protection rights, you can contact us at: firstname.lastname@example.org. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.
C. Verification Procedure. For your protection, we may need to verify your identity before responding to your request, such as by verifying that the email address from which you sent the request matches the email address that we have on file for you. If we no longer need to process Personal Data about you to provide our Services, we will not maintain, acquire or additionally process information to identify you in order to respond to your request.
D. Notice to California residents. If you are a natural person resident in California, then, subject to certain limits under California law, you have the right under the California Consumer Privacy Act of 2018 (CCPA) and certain other privacy and data protection laws, as applicable, to exercise free of charge:
(1) Disclosure of Personal Information We Collect About You. You have the right to know:
- The categories of personal information we have collected about you;
- The categories of sources from which the personal information is collected;
- Our business or commercial purpose for collecting or selling personal information;
- The categories of third parties with whom we share personal information, if any; and
- The specific pieces of personal information we have collected about you.
Please note that we are not required to:
- Retain any personal information about you that was collected for a single one-time transaction if, in the ordinary course of business, that information about you is not retained;
- Reidentify or otherwise link any data that, in the ordinary course of business, is not maintained in a manner that would be considered personal information; or
- Provide the personal information to you more than twice in a 12-month period.
(2) Disclosure of Personal Information Sold or Used for a Business Purpose. In connection with any personal information we may sell or disclose to a third party for a business purpose, you have the right to know (i) the categories of personal information about you that we sold and the categories of third parties to whom the personal information was sold; and, (ii) the categories of personal information that we disclosed about you for a business purpose.
(3) Protection Against Discrimination. You have the right to not be discriminated against by us because you exercised any of your rights under the CCPA. This means we cannot, among other things:
- Deny goods or services to you;
- Charge different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
- Provide a different level or quality of goods or services to you; or
- Suggest that you will receive a different price or rate for goods or services or a different level or quality of goods or services.
Please note that we may charge a different price or rate, or provide a different level or quality of services to you, if that difference is reasonably related to the value provided to us by your personal information.
9. How do we store your data
Data Retention Period. We will process and store the Customer Data no longer than necessary. In general, your Personal Data will be stored during the term of our contractual relationships and after that for a maximum of ten (10) years with regard to rules of limitation. In some cases, Personal Data may be saved for longer due to laws applicable to Lokalise.
This may include keeping your Personal Data after you have deactivated your account for the necessary period for us to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes and enforce our agreements.
10. Security of Customer Data
We take the security of data very seriously. We work hard to protect Customer Data from loss, misuse and unauthorized access or disclosure. Lokalise has received internationally recognized SOC 2 Type 2 security certification confirming that Lokalise has system and organization controls to safeguard the processing, integrity, confidentiality and security of the Customer Data. To learn more about current practices and policies regarding the security and confidentiality of the Services, please see our documentation and Contracts.
Please note that no method of transmission, or method of electronic storage, is 100% secure. Therefore, we cannot guarantee its absolute security and safety. In the event of a data breach that affects your Personal Data, we will act promptly to mitigate the impact of a breach and notify any affected users without undue delay.
11. Privacy Policies of other websites
Our Platform provides the ability to connect to the websites of other Third-Party Services providers. Please see Section 6 above for details. These Third-Party Services are not owned or controlled by Lokalise, and third parties that have been granted access to your Personal Data may have their own policies and practices for data collection and use. Please check the privacy settings and notices in these Third-Party Services or contact the relevant provider with any questions you may have.
You may see our ads on other websites or mobile apps because we participate in advertising networks. Ad networks allow us to target our message to users based on a range of factors, including demographic data, users' inferred interests and browsing context (for example, the time and date of your visit to our Platform, the pages that you viewed and the links that you clicked on). This technology also helps us track the effectiveness of our marketing efforts and understand if you have seen one of our advertisements.
Please see Subsection 7A above to learn more about for various un-subscription options from Third-Party Services you have.
12. Identifying Data Controller and Processor
Data protection law in certain jurisdictions (e.g., the GDPR) differentiates between the “controller” and “processor” of information. In general, the Customer is the controller of the Personal Data. Lokalise is the processor of the Personal Data. However, Lokalise is deemed a controller of the Personal Data that is processed for its legitimate interests as described in Sections 4-6 above.
If you are an Authorized User or end-user of our Customer, you have the right to address your requests on the Personal Data protection directly to the Customer as your data controller.
13. International Data Transfers
We are a global business. Personal Data may be stored and processed in any country where we have operations or where we engage service providers. We may transfer Personal Data that we maintain about you to recipients in countries other than the country in which the Personal Data was originally collected, including to the United States. Those countries may have data protection rules that are different from those of your country.
If you are located in the EEA or Switzerland, we comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Data to the USA. Lokalise, Inc. is certified under the EU-U.S. and the Swiss-U.S. Privacy Shield Framework and adheres to the Privacy Shield Principles. For more details, see the Lokalise Privacy Shield Policy.
Where applicable law requires us to ensure that an international data transfer is governed by a data transfer mechanism, we use one or more of the following mechanisms: EU Standard Contractual Clauses with a data recipient outside the EEA, verification that the recipient has implemented Binding Corporate Rules, or verification that the recipient adheres to the EU-U.S. and Swiss-U.S. Privacy Shield Framework.
15. How we respond to compelled disclosure
We may disclose personally-identifying information or other information we collect about you to law enforcement in response to a valid subpoena, court order, warrant or similar government order, or when we believe, in good faith, that disclosure is reasonably necessary to protect our property or rights, or those of third parties or the public at large.
In complying with court orders and similar legal processes, Lokalise strives for transparency. When permitted, we will make a reasonable effort to notify Customers and Authorized Users of any disclosure of their information, unless we are prohibited by law or court order from doing so, or in rare, exigent circumstances.
16. How to contact us
If you have concerns about the way Lokalise is handling your Personal Data, please let us know immediately. We want to help.
You may contact us by sending an email to: email@example.com with the subject line "Privacy Concerns". We will respond promptly — within 30 calendar days, at the latest.
You may also contact our Data Protection Officer directly as follows:
|Our United States HQ||Our EU Office|
|Lokalise, Inc.||SIA Lokalise|
|2035 Sunset Lake Road, Suite B-2,||13. Janvara Str. 33-6|
|Newark, Delaware DE 19702, USA||Riga LV-1050|
17. How to contact the appropriate authorities
If you are a resident of the EEA and believe we maintain your Personal Data within the scope of the GDPR, you also have the right to (a) restrict Lokalise’s use of the information that constitutes your Personal Data and (b) lodge a complaint with your local data protection authority.
A current list of National Data Protection Authorities, members of the European Data Protection Board can be found here.