Privacy Policy

Last updated: 9 September 2026

This Policy explains how iDISC Information Technologies, S.L., Passeig del Progrés 96, 08640 Olesa de Montserrat (Barcelona), Spain, VAT/CIF B-61284014, Commercial Registry of Barcelona, Volume 29643, Section 70, Page 158178, trading through Koesive, processes personal data as controller when people visit the website, register, purchase, use the account, obtain support, or receive marketing. Processing performed for a Customer on its instructions is covered by the DPA.


1. Data collected

Context Data
Company account Customer type, company/client, tax ID, billing currency, country, addresses, town, postal code, province, contact name, surname, email, phone, and language.
Individual account Customer type, name, surname, email, phone, language, tax ID, billing currency, country, address, town, postal code, and province.
Quotes and service Files, languages, service levels, instructions, quotes, Orders, statuses, deliverables, memories, glossaries, terminology, support data, and project metadata.
Billing Order, credit, currency, tax, invoice, billing, payment status, and transaction records. Stripe handles checkout and payment data.
Use and security Account activity, permissions, logs, IP address, device/browser data, timestamps, diagnostics, monitoring, and security events.
Marketing Contact details, preferences, messages, newsletter interactions, and campaign engagement.


2. Purposes and grounds

Purpose Ground
Registration, quoting, Orders, delivery, and support Contract and pre-contract steps for individual account holders; legitimate interests in administering organization accounts and authorized business users.
Payments, tax, accounting, and claims Contract; legal obligations relating to tax, accounting, and record keeping; and legitimate interests in preventing fraud and managing or defending claims.
Security, troubleshooting, and improvement Legitimate interests in protecting the Service and accounts, preventing abuse, diagnosing faults, and improving reliability and security; and legal obligations where applicable.
Essential communications Contract where necessary to provide the Service; and legitimate interests in service administration, security notices, and operational communications.
Marketing Consent where required. Where Spanish electronic-marketing rules permit communications to existing customers about iDISC’s own similar services, legitimate interests may also apply. Recipients can unsubscribe or object at any time through a simple and free method.
Optional cookies Consent for non-essential technologies, except where a technology is exempt from consent because it is strictly necessary or used solely to provide functionality expressly requested by the user.


3. Customer Content and roles

For account, billing, security, marketing, and service administration, iDISC generally acts as controller. For personal data inside customer documents, memories, glossaries, and project instructions processed on Customer instructions, iDISC acts as processor. Special-category data should be submitted only where necessary, lawful, and compatible with the selected service level and any applicable provider restrictions. Customers are responsible for the required lawful basis, minimization, notices, and compliant instructions; iDISC remains responsible for its own processor obligations under the DPA.


4. AI and recipients

Koesive may use one selected provider per translation request, including OpenAI, Anthropic, Google Gemini, Google machine translation, DeepL, and Microsoft Azure OCR. Authorized linguists, reviewers, project personnel, and support personnel may also access content where needed. Stripe processes payment-related data. See the Sub-processors page. Customer-provided data is not used by Koesive to train the models used in the Service.


5. International processing

Production data, backups, monitoring data, and customer files are stored in the EEA. Technology providers and authorized personnel outside the EEA may process or access data when required. Where GDPR applies, iDISC uses an applicable Chapter V transfer mechanism, which may include an adequacy decision, European Commission Standard Contractual Clauses, and supplementary safeguards. Contact privacy@koesive.com for information about the applicable transfer mechanism and, where required and available, how to obtain a copy of the relevant safeguards, subject to lawful confidentiality and third-party restrictions.


6. Retention

Controller records: Account, billing, support, security, marketing, and legal records are retained only for as long as necessary for the stated purpose. The retention period is determined by the duration of the account or customer relationship, transaction and statutory record-keeping requirements, applicable limitation periods for claims, security and fraud-prevention needs, and the status of any marketing consent, unsubscribe, or objection, as applicable.

Customer Personal Data processed under the DPA: At the end of the relevant Service, iDISC will return or make available an export and delete the data, or delete it without return, according to the Customer’s choice, unless law requires retention. Protected backup copies are removed through iDISC’s normal backup lifecycle.


7. Rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or object to processing, withdraw consent, and complain to a supervisory authority. Contact privacy@koesive.com. In Spain, complaints may be made to the Spanish Data Protection Agency.


8. Account deletion

Client Administrators may delete other users in their client account, but users cannot self-delete their own account. Request closure through the support module or support@koesive.com. Closure is subject to active Orders, Customer instructions, and required retention.


9. Security and children

Koesive follows iDISC security procedures and the ISO/IEC 27001-certified information-security management system. Report incidents to it-support@koesive.com. Koesive is not intended for children; account holders must be at least 18 or the age of legal majority.


10. Cookies, changes, and contact

See the Cookie Policy. Material policy changes may be communicated through the Service or email.

Privacy: privacy@koesive.com
Support: support@koesive.com
Security: it-support@koesive.com

Scroll to Top