Your data stays in the EU.
Contracts, patents, financial reports, strategy papers. Data protection starts with where your files are processed. By default that is European servers, inside an information security management system certified to ISO/IEC 27001. If your own rules go further, we can run a project on servers in Germany only or with no server storage at all. Encrypted, documented, NDA ready, with no detour through US cloud services.
Philipp Walzok is your contact · service@tolingo.com
Companies with sensitive content have trusted tolingo since 2007

Security and data protection at a glance
The risk starts with the first upload.
A contract, a patent description, an internal strategy draft, pasted into a free online tool. It looks convenient, and it is one of the most common data protection issues in day to day compliance work. Text that runs through tools like Google Translate, DeepL Free or ChatGPT is usually processed on servers outside the EU. At that point it leaves your control, and it falls under a foreign legal system as well.
US legislation such as the CLOUD Act and FISA lets state authorities reach data held by US providers, even when the servers sit in Europe.
Text you enter can be used to train future models. Who sees your wording later is no longer something you can trace.
Passing personal or confidential data to systems without adequate safeguards is already a problem under the GDPR, with consequences for liability and for what you have to demonstrate to supervisory authorities.
If you work across several languages regularly, it pays to set up one route that holds up against your own compliance standards. There is more on this on our page about GDPR-compliant translation.
What happens to your data at tolingo.
The moment you upload a document, it enters a controlled process that has been certified to ISO/IEC 27001 since 2018. Every step is documented and every access is logged. Nothing runs outside Europe.
Your file and your request travel through our intake with 256-bit SSL encryption. No detour through outside providers, nothing parked with third parties.
Processing in European data centres, backups encrypted. Access is strictly role based: the project team assigned to your job, not the whole company. That is the standard. Less is available on request, see security levels.
Specialist translators bound by confidentiality, trained on information security every year. No processing through public AI tools, not even for research.
Documents are kept only as long as they are needed or legally required. On request we delete source and target files once the project closes.
From the standard setup to a separate procedure.
EU servers are the standard here, at no surcharge and with no lead time. Some companies have stricter requirements, whether from their own policy, from a framework agreement or from their end client. Two further levels cover that, and you agree them with your dedicated contact before the project starts.
The default on every project: processing in European data centres, a certified information security management system, and a confidentiality agreement or DPA whenever you want one. Nothing to arrange separately.
If your internal policy or your own client requires the data to stay in Germany, we set the project up that way. We put it in writing, so you can produce it in an audit.
For particularly sensitive content we work in a walled-off environment where your documents are not stored on servers. We agree the scope and the setup with you beforehand.
Documents that carry an official classification follow a separate procedure under the German Verschlusssachenanweisung (VSA). It runs apart from the standard process on this page, with its own rules, its own routes and its own contacts.
Security in four layers.
Data protection is not a box you tick once. ISO/IEC 27001 requires security to work on four layers at the same time and to keep improving. Here is how tolingo does that.
256-bit SSL encryption, European data centres, encrypted backups, access logs and multi-factor sign-in for staff.
Role-based access, documented incident and emergency procedures, and annual security training for everyone involved.
NDA templates ready to go, or yours if you prefer. Confidentiality agreements for every translator and project manager, and GDPR data processing agreements on request.
An annual TÜV audit, internal reviews, lessons learned after every security incident and regular penetration tests by outside specialists.
For a supplier audit or a data protection impact assessment, we provide the ISO/IEC 27001 certificate, an NDA template and, on request, a data processing agreement (DPA), usually within one working day. The scope of the standard and its audit history are on our quality and security pages.
More on quality and security.
How a translation gets checked: five stages, the four-eyes principle and your right to corrections.
The four ISO standards in detail: 17100, 18587, 9001 and 27001. With audit history and certificates.
Who works for tolingo, how we select them and which dedicated team handles your text.
Case studies and feedback from clients who have worked with us for years.
When documents carry an official classification, a separate procedure with its own rules applies.
Servers, encryption, NDAs, AI.
Where is our data stored?
On servers in the EU by default. Processing, backup and storage all happen in European data centres. Data is not processed in US cloud services that fall under the CLOUD Act or FISA. On request we can also set a project up so that it runs on servers in Germany only.
Can you provide higher security levels than the standard?
Yes. The standard is processing on EU servers. On request we work on servers in Germany only, or with no server storage at all in a walled-off environment. Which one makes sense in your case is something you settle with your dedicated contact before the project starts. Documents that carry an official classification follow a separate procedure: VS-NfD compliant translation.
Can we put a non-disclosure agreement in place?
Yes, and on confidential projects it is the norm. We sign an NDA before the first data is exchanged, either on our template or on yours. Every translator and project manager involved works under a duty of confidentiality.
What happens to our texts after the project?
Source and target files are held for the statutory retention periods. On request we delete the content earlier, once the project closes. We only build a translation memory if you explicitly ask for one.
Is our content used to train AI?
No. Your texts do not go into the training data of public AI models. Our translators are not allowed to put your content through Google Translate or ChatGPT either, not even for research. There is more on this on our page about GDPR-compliant translation.
Which documents do we get for our compliance audit?
On request we provide the ISO/IEC 27001 certificate, an NDA template and a data processing agreement (DPA) under Art. 28 GDPR. The documents usually reach you within one working day.
Do you have compliance requirements that need checking?
Tell us which rules apply to you, and we will supply the matching evidence and set the workflow up around them.
