Privacy Policy

ARCHIVED 2023-08-27, DATE APPROXIMATE · VERSION 20230827_rev01 · COMPARED WITH 20230724_rev01

Full text changes — 20230724_rev01 to 20230827_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

264264
265265 | TechnologyLocal Storage | Expiry7 days | OwnerDeepL |
266266| DeepL Pro-User Login/Session | IDdl\_auth | Description
267267
268268Stores the "login state" of a user, the account type and sets a reminder for login. When user gets logged out accidentally, user will be helped with an error message.
269269
270 | TechnologyLocal Storage | ExpiryPersistent | OwnerDeepL |
270 | TechnologyLocal Storage | ExpiryPersistent Data | OwnerDeepL |
271271| Release process | IDreleaseGroups | Description
272272
273273Used for gradual, controlled releases to ensure stability, quality and performance of our service and infrastructure.
274274
275275 | TechnologyCookie | Expiry1 month | OwnerDeepL |
276276| Release process | IDdapGid | Description
559559- Right to withdraw your consent - Should you wish to revoke any previously granted consent, we will comply with your request. Revocation does not affect the permissibility of the processing of your data up to now.
560560
561561**In addition, you can object to the further processing of your data if we process your data based on our legitimate interest (Art. 6 para. 1 sentence 1 lit. f), Art. 21 GDPR). If we process your data for the purpose of direct advertising, you have a general right to object. If we do not process your data for advertising purposes, the objection must be based on your particular situation.**
562562
563563You also have the right to lodge a complaint regarding the processing of your personal data with a supervisory authority, such as the data protection supervisory authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2 - 4, 40213 Düsseldorf, email: [poststelle(at)ldi.nrw.de](mailto:poststelle@ldi.nrw.de).
564564
565## 20\. Changes to the Privacy Policy
565## 20\. Special provisions for users from South Korea
566566
567### 20.1 Contact and DeepL Chief Privacy Office (CPO)
568
569If you have any specific questions or concerns about privacy and data protection in South Korea, also with regard to previous versions of this privacy policy, please contact privacy(at)deepl.com.
570
571DeepL's Chief Privacy Officer for South Korea is Dr. J. M. Schäfer (Legal Department).
572
573### 20.2 Data Deletion and Retention Periods
574
575As described above, we will process your data for as long as is necessary for the stated purpose and if applicable, to the extent that you have consented to. Subsequently, we will delete your personal data without undue delay. We will permanently destroy any personal data saved in electronic format in a way that it cannot be restored and recovered. Personal information printed on paper will be destroyed by shredding thereof.
576
577However, as outlined above in section 6.2, DeepL is obliged to retain certain personal data of users as required by applicable laws. Relevant laws under Korean law include, in particular, the Act on the Consumer Protection in Electronic Commerce (Article 6) which provides for the retention of data on contract as well as withdrawals and revocations thereof for 5 years, data on the provision of services for 5 years and data on consumer complaints or consumer disputes for 3 years. The Protection of Communications Secrets Act provides in Article 15-2 to retain records of computer communication or internet log and trace data of access point for 3 months.
578
579### 20.3 Data Security and Pseudonymisation
580
581In addition to the measures set out in section 18 of this privacy policy, under the Korean Personal Information Protection Act we take various technical, administrative and physical measures to ensure data security and the security of personal data. For example, we manage access rights to our systems that contain personal data as well as pseudonymized data in a traceable manner; we take various measures to prevent unauthorised access to personal and pseudonymized data, including maintaining a VPN network; we regularly train our employees in the handling of personal data, including pseudonymized data and data security. We regularly evaluate our data processing procedures and modify them as necessary. In addition, we work with strict physical access controls to e.g. our IT infrastructure and data storage systems as well as to documents that contain personal data.
582
583## 21\. Changes to the Privacy Policy
584
567585We reserve the right to amend this privacy policy. The current version of the privacy policy can be accessed at any time on our [website](https://www.deepl.com/privacy).
568586
569Last update: May 2023
587Last update: August 2023