Legal
Privacy policy
Information on the processing of personal data under Art. 13 and Art. 14 GDPR when using the InTO Translation service (uxp.in2go.io), including the InDesign plugin.
This is a courtesy translation. The German version is the legally binding one.Read the German version
Controller
The controller within the meaning of the GDPR is:
- Provider
- lindner software & consulting GmbH
- Address
- Postkamp 6, 30159 Hannover, Germany
- Represented by
- Dipl.-Ing. Reinhard Lindner
- Phone
- +49 (0)511 30 17 90-30
- info@lisocon.de
General information on processing
We process personal data only as far as this is necessary to provide a working service together with our content and features. Processing takes place on the basis of your consent or where the law permits it.
Legal bases
- Art. 6(1)(a) GDPR: consent of the data subject
- Art. 6(1)(b) GDPR: performance of a contract or pre-contractual steps
- Art. 6(1)(c) GDPR: compliance with a legal obligation
- Art. 6(1)(f) GDPR: legitimate interests of the controller
Erasure and storage periods
Personal data is erased once the purpose of storage no longer applies. Data may be stored beyond that point where European or national law requires it, in particular under commercial and tax retention periods.
Hosting
The service is hosted with[hosting provider: company, address, country]. The servers are located in a data centre in[location]. The provider processes the data arising when the service is accessed (see “Server log files”) solely on our behalf and on our instructions; a data processing agreement under Art. 28 GDPR is in place.
We use no content delivery network (CDN) and no upstream proxy or security service. All page content, scripts, stylesheets, fonts and images are delivered directly from our own server under the domain uxp.in2go.io.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, reliable and fast service) and Art. 6(1)(b) GDPR for operating your account.
Server log files
Every request is logged automatically by the web server. This is technically necessary for the page to be delivered at all. The following is processed:
- IP address of the requesting system
- Date and time of the request
- Page, file or endpoint requested
- HTTP status code and amount of data transferred
- Referrer URL (the previously visited page)
- Browser, operating system and device information
This data serves the technical operation and security of our systems and the investigation of faults. It is not combined with other sources and is not evaluated for marketing purposes. To protect against automated sign-in attempts we additionally count failed logins per account and origin and temporarily block further attempts.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable and secure service). Storage period: at most 30 days, unless a specific security incident requires longer.
Cookies and local storage
We use no analytics, tracking or advertising services. No cookies are set for statistics or marketing, and no data is passed to third parties for those purposes. A consent banner is therefore not required.
After you sign in, the application stores only the following strictly necessary items in your browser'slocalStorage:
- translate.access andtranslate.refresh: your session tokens. Without them you would have to sign in again on every page.
- ui-lang: the interface language you chose (German or English).
These items stay in your browser, are not passed to third parties, and can be deleted at any time through your browser settings; signing out removes the session tokens as well.
Legal basis: § 25(2) no. 2 TDDDG (strictly necessary for a service you explicitly requested) in conjunction with Art. 6(1)(b) GDPR.
Registration and user account
Using the service requires an account. We process:
- Email address (your sign-in name and the address for system messages)
- Password — stored only as a cryptographic hash, never in clear text
- Confirmation status of the email address and the time of registration
- Plan, monthly character quota, wallet balance and the history of your transactions and translation jobs (see “Translation of your content”)
Confirming the email address is mandatory: without a confirmed address there is no sign-in. This makes sure an account really belongs to the person who created it.
Signing in works with an email address and a password only. We do not offer sign-in through third-party accounts — social networks or providers such as Google — so no data is exchanged with such a provider at any point.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Storage period: for the lifetime of the account; see “Deleting your account”.
Translation of your content (DeepL)
Machine translation is the core of the service. The texts you submit for translation — text entered in the web application, or the text content of the InDesign document open in the plugin — are transmitted to and processed by DeepL SE, Maarweg 165, 50825 Cologne, Germany.
If your texts contain personal data, that data is transmitted with them. We therefore recommend checking documents for personal content that is not needed before translating.
A data processing agreement under Art. 28 GDPR is in place with DeepL. We use the paid API variant: DeepL does not retain the submitted texts after translation and does not use them to train its translation models.
Your texts are not stored on our servers. For a translation job we keep figures only: time, language direction, number of characters processed and the resulting cost. We need these for billing, quota and your history view.
Legal basis: Art. 6(1)(b) GDPR (providing the service you asked for). Storage period for the figures: for the lifetime of the account, at most within the commercial and tax retention periods. More information:deepl.com/privacy.
InDesign plugin
The plugin runs inside your local Adobe InDesign installation. It reads the text content of the open document, sends it to our server for translation (and from there to DeepL, see above) and writes the result back into the document. The document itself never leaves your machine and is not stored by us.
The plugin additionally transmits your credentials or session tokens for authentication, plus technical details of the job (character count, language direction) so that quota and billing can be maintained. Adobe receives no data from us.
Legal basis: Art. 6(1)(b) GDPR.
Payment processing (Stripe)
Paid plans and wallet top-ups are handled by Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
You enter your payment details (e.g. card number) directly with Stripe; they do not reach our servers and are not stored by us. From Stripe we receive a customer identifier, the payment status, the amount and the details required for invoicing.
Processing in the USA by Stripe, Inc. cannot be ruled out; Stripe is certified under the EU-U.S. Data Privacy Framework and EU standard contractual clauses are additionally in place.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (commercial and tax obligations). Storage period: as required by law, generally 10 years. More information:stripe.com/privacy.
Transactional email
We only send email that is necessary to operate your account: confirming your email address, resetting your password, and notices about your plan or payment. We do not send a newsletter.
For delivery we use[email provider to confirm: company, address]; your email address and the content of the message are processed in the course of this.
Legal basis: Art. 6(1)(b) GDPR.
Fonts
The fonts used (Inter and JetBrains Mono) are delivered exclusively from our own server (self-hosting). Loading them establishes no connection to servers operated by Google or any other third party. We do not use the online variant of Google Fonts, so displaying the fonts transmits no IP address to Google.
Contact by email or phone
If you contact us by email or phone, your details (name, contact data, content of the message) are stored in order to handle your request and any follow-up questions. We do not pass this data on without your consent.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual or contractual) and Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).
Deleting your account
You can delete your account yourself at any time, under “Settings” in the application. Deletion removes your credentials and profile. Records we are required to retain under commercial and tax law (in particular invoicing and payment data) are kept until those periods expire and are used for no other purpose.
Ongoing contracts are cancelled on the dedicated page (cancel contracts here).
Your rights as a data subject
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (“right to be forgotten”, Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent with future effect (Art. 7(3) GDPR)
An informal message to the contact details above is enough to exercise them.
Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz NiedersachsenPrinzenstraße 5, 30159 Hannover, Germany
Phone: +49 (0)511 120-4500
Web: lfd.niedersachsen.de
SSL encryption
For security and to protect the transmission of confidential content, this service uses SSL/TLS encryption throughout. You can recognise an encrypted connection by the address bar switching from “http://” to “https://” and by the padlock symbol in your browser. The same applies to the connection between the InDesign plugin and our server.
Changes to this policy
We reserve the right to amend this privacy policy so that it always meets current legal requirements, or to reflect changes to our services. The current version applies to your next visit.
Last updated: August 2026