Your documents are the most private thing you will send a stranger. This page says exactly what happens to them, who reads them, and when they are destroyed.
Last updated: August 2026
Who we are
EnLatin L.L.C. — offices in Baytown, Texas; Voula, Attica; and Gelibolu, Çanakkale — is the data controller for everything described here. This notice covers the website, the order process, the order portal, and any correspondence with us.
We operate under the General Data Protection Regulation and applicable national law, and under ISO/IEC 27001:2022 certification for information security management (TÜV NORD, certificate No. 44121231258) — audited, and checkable in the certifier’s own database.
What we collect
What you give us
- Contact details — your name, email address, and a telephone number if you choose to give one. The phone number is optional and the order proceeds without it.
- Order details — document type, page or word count, language pair, turnaround, and anything you tell us about the receiving authority or the spelling of your name.
- Your documents — the files you upload for translation, and the translations produced from them.
- Correspondence — messages sent through the order portal, by email, or through the chat panel.
Payment details are not among them. Card data goes directly to PayU/Prosus, a PCI-DSS Level 1 certified processor. EnLatin never receives, sees, or stores a card number.
What is collected automatically
Less than you are used to. There is no analytics on this site, no advertising pixel, no tracking of any kind, and no cookie. What remains is narrow and named:
- Your approximate country, derived from your IP address at page load, so we can show Turkish visitors the currency their regulations require. The IP itself is not stored.
- Verification lookups — when anyone checks an order code at our verification page, the lookup is logged with a timestamp and an origin summary. This is fraud prevention on a public endpoint, and it is disclosed on that page.
- Ordinary server logs kept by our host for security and availability, as every web server keeps.
- One item in your browser — your answer to the cookie question, stored locally, never transmitted to us. The complete list is here, and it is one line long.
What we use it for
- To translate your documents and deliver them.
- To tell you what is happening with your order, and to answer you when you write.
- To take payment and issue refunds.
- To operate the free page ticket, which counts certified pages against your email address and nothing else.
- To meet tax, accounting and legal obligations, and to resolve a dispute if one arises.
We do not sell your data, and we do not market to you. There is no mailing list, no profiling, no third party receiving your information for their own purposes. Your documents are never used as samples, never shown to anyone outside the chain below, and never fed to a machine-learning system.
Who actually sees your documents
Three people, in sequence, and no others: the specialist who translates, the reviser who checks the rendering against the source, and the senior philologist who certifies it. All are bound by non-disclosure. Nothing is subcontracted to an unknown hand.
Our infrastructure providers hold the encrypted files but do not read them: Supabase, Inc. for database and file storage, and Resend, Inc. for the emails that carry your order links. Both are contracted as processors under GDPR terms. PayU/Prosus handles payment and receives no document.
Where your firm or institution requires its own confidentiality undertaking or data processing agreement, send it and we will sign it before any file is transferred.
On what legal basis
- Performance of a contract — everything needed to translate and deliver what you ordered.
- Legal obligation — tax and accounting records, and anything a competent authority may lawfully require.
- Legitimate interests — security of the platform, fraud prevention on the public verification endpoint, and keeping the order record that lets a translation be verified afterwards.
- Consent — only for the cookie question. We ask for no other consent because we do nothing else that would require it.
How long we keep it
The distinction that matters: your files are destroyed, the order record is not. The record is what allows a receiving institution to verify your translation years later, when the documents themselves are long gone.
| What | How long |
|---|---|
| Your uploaded documents and their translations | 45 days after delivery, then permanently deleted — earlier at your request, always |
| Messages in your order portal | Duration of the order, plus one year |
| Order record — what was translated, when, and the verification code | 7 years, as tax and accounting law requires |
| Free page ticket counter, held against your email | Until you ask us to remove it |
Your rights
Under GDPR you may ask us to do any of the following, and we will do it — within thirty days, and usually the same week.
- See what we hold about you.
- Correct anything inaccurate.
- Delete it. Your files can go immediately on request; the order record is kept only where tax law obliges us, and we will tell you which is which.
- Restrict what we do with it while a question is being resolved.
- Take it with you, in a structured, machine-readable form.
- Object to processing we base on legitimate interests.
You may also complain to a supervisory authority. Ours is the Hellenic Data Protection Authority in Athens; you may equally approach the authority where you live. We would rather you wrote to us first — but the right is yours, not ours.
How it is protected
Not as a list of adjectives, but as the specific measures our ISO/IEC 27001 certification is audited against:
- Encrypted in transit over TLS, and encrypted at rest in storage.
- Access limited by role: the specialist and reviser assigned to your order can reach your file, and nobody else can.
- Order portals reached by a signed link sent to your email — no password to be guessed, no session left open on a shared machine.
- Card processing entirely outside our systems, at PCI-DSS Level 1.
- Deletion on schedule at day 45, applied to the file and everything derived from it.
Cookies
We set none. One item sits in your browser’s local storage — your answer to the cookie question itself — and it is never transmitted to us. The full policy is here, and it is short because there is little to describe.
Contact
For anything in this notice, or to exercise any right above, write to us. A person answers.
Email — salve@enlatin.net
Data Protection Officer — same address, marked DPO
Post — EnLatin L.L.C., 25 I. Metaxa, 16673 Voula, Attica, Greece