1. Scope and Applicability
This Data Processing Addendum ("DPA") supplements the Tranee Terms of Service and applies where Tranee processes Personal Data on behalf of Customer as a Data Processor in the course of providing Tranee services.
Under applicable Data Protection Laws (including the EU GDPR, UK GDPR, and CCPA), Customer acts as Data Controller and Tranee acts as Data Processor.
This DPA governs the processing of Personal Data in connection with bilingual subtitle rendering, AI translation queries, vocabulary book storage, and user account management.
2. Processing of Personal Data
Tranee shall process Personal Data solely in accordance with Customer's documented instructions and for the explicit purposes set out in the Terms of Service.
Categories of Personal Data processed include user profile details (email address, preferred target languages), subtitle text excerpts submitted for translation, and interactive reading highlights.
- Purpose: Delivery of bilingual subtitles, contextual AI translation, flashcard synchronization, and user account verification.
- Duration: Data is processed for the duration of Customer's active subscription and retained up to 30 days post-account deletion for recovery purposes.
- Data Subjects: Users, students, professionals, and enterprise account members using the Tranee Chrome extension and web platform.
3. Security Measures & Confidentiality
Tranee implements robust technical and organizational measures (TOMs) designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
All personnel authorized to process Personal Data are bound by strict contractual confidentiality obligations.
- Encryption in Transit: All API traffic and subtitle data transfers are encrypted using TLS 1.3.
- Encryption at Rest: Saved vocabulary and user profile databases are encrypted at rest using AES-256.
- Access Controls: Strict role-based access control (RBAC) and multi-factor authentication (MFA) for administrative systems.
- Vulnerability Scans: Continuous automated vulnerability scanning and third-party security assessments.
4. Sub-processors
Customer provides general authorization for Tranee to engage third-party sub-processors to fulfill operational services. Our primary sub-processors include Cloud Infrastructure Providers (Vercel, Cloudflare), Database Hosts (Supabase), and AI Translation Partners (OpenAI, Anthropic).
Tranee executes legally binding data processing agreements with all sub-processors, ensuring data protection standards equivalent to those set out in this DPA.
5. Data Subject Rights & Incident Notification
Tranee shall assist Customer in fulfilling data subjects' requests to exercise their rights under GDPR/CCPA (including access, correction, erasure, and data portability).
In the event of a confirmed Personal Data Breach impacting Customer data, Tranee will notify Customer without undue delay and no later than 42 hours after becoming aware of the breach.
6. International Data Transfers & Deletion
For transfers of Personal Data originating from the EU/EEA or UK to third countries, Tranee relies on European Commission Standard Contractual Clauses (SCCs) to ensure lawful data transfers.
Upon termination of services or written request by Customer, Tranee will securely delete or return all Personal Data, unless retention is required by applicable statutory law.