Data Processing Agreement

Last updated: 9 September 2026

This Data Processing Agreement (“DPA”) forms part of the Koesive Terms of Service or other agreement governing the Customer’s use of Koesive (the “Agreement”). It applies where iDISC Information Technologies, S.L. (“iDISC” or “Processor”) processes Personal Data on behalf of a customer (“Customer” or “Controller”) in connection with Koesive.

The DPA applies automatically to Customers acting as controllers and may also be signed separately. A signable copy is available from legal@koesive.com. If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA prevails.


1. Definitions

“Applicable Data Protection Law” means Regulation (EU) 2016/679 (“GDPR”), Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights, and other Union or Member State data-protection law applicable to iDISC’s processing of Customer Personal Data.

“Customer Personal Data” means Personal Data contained in customer documents, translation memories, glossaries, project instructions, or other Customer Content processed by iDISC on the Customer’s behalf.

“Personal Data”, “processing”, “Controller”, “Processor”, “Data Subject”, “Supervisory Authority”, and “Personal Data Breach” have the meanings given in the GDPR.


2. Roles and processing instructions

The Customer is Controller and iDISC is Processor for Customer Personal Data. iDISC will process Customer Personal Data only on documented Customer instructions, including the Agreement, this DPA, Orders, project instructions, and the Customer’s use of Koesive, unless Union or Member State law to which iDISC is subject requires otherwise. Where legally permitted, iDISC will inform the Customer of that legal requirement before carrying out the required processing.

iDISC will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. The Customer is responsible for the lawfulness, accuracy, and content of its instructions and for providing required notices and establishing a lawful basis.


3. Processing details

The subject matter, duration, nature and purpose of processing, data types, and Data Subject categories are described in Schedule 1.


4. Confidentiality

iDISC will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where needed for their assigned responsibilities.


5. Security

Taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to individuals, iDISC will maintain appropriate technical and organizational measures under Article 32 GDPR. These measures are governed through iDISC’s information-security management system and ISO/IEC 27001-certified scope. A summary appears in Schedule 2.

iDISC may update its measures where the overall level of protection is not materially reduced. Detailed security documentation and relevant ISO certificates may be provided subject to confidentiality and access controls.


6. Sub-processors

The Customer gives iDISC general written authorization to engage sub-processors. The current list is published on the Koesive Sub-processors page.

iDISC will impose by written agreement on each sub-processor the same data-protection obligations set out in this DPA insofar as they are applicable to the sub-processor’s services, limit processing to what is necessary for those services, and remain fully liable to the Customer for the sub-processor’s performance of those obligations to the extent required by Article 28(4) GDPR.

iDISC will specifically inform Customers in writing, with reasonable prior notice, of any intended addition or replacement of a sub-processor that will process Customer Personal Data, giving the Customer a meaningful opportunity to object before the sub-processor begins processing. Where an earlier change is reasonably necessary to address an emergency, security incident, service-continuity risk, or legal requirement, iDISC may implement the change sooner and will inform the Customer without undue delay. The Customer may send objections to privacy@koesive.com on reasonable data-protection grounds. iDISC will consider a timely objection in good faith and seek a reasonable solution. If none is available, the parties will address the affected processing under the Agreement and applicable law. No automatic refund right is created.


7. Data Subject requests

Taking account of the nature of processing, iDISC will provide the assistance reasonably required under Article 28 GDPR, using appropriate technical and organizational measures where possible, to enable the Customer to respond to Data Subject requests.

If iDISC receives a request relating to Customer Personal Data, it will notify or redirect the requester to the Customer unless iDISC is legally required to respond. The Customer remains responsible for determining and communicating the response.


8. Personal Data Breaches

iDISC will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will include available information reasonably required to support the Customer’s compliance, including information about the nature of the breach, affected data and individuals where known, likely consequences, mitigation, and a contact point. Information may be provided in phases as it becomes available.

Notification does not constitute an admission of fault or liability. iDISC will provide assistance reasonably required for the Customer’s compliance with Articles 33 and 34 GDPR.


9. Compliance assistance

Taking into account the nature of processing and the information available to iDISC, iDISC will provide the assistance reasonably required to enable the Customer to comply with its obligations under Articles 32 to 36 GDPR, including security, breach response, data-protection impact assessments, and prior consultation.

Assistance required because of iDISC’s breach of this DPA is provided without additional charge. Other assistance that exceeds iDISC’s legal or contractual responsibilities may be charged at agreed rates, or declined where unreasonable, disproportionate, legally restricted, or likely to compromise another customer’s security or confidentiality.


10. Audits and information

iDISC will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Evidence may include security documentation, ISO certificates, independent audit reports, written questionnaires, remote audits, or on-site inspections.

Audit arrangements will be determined case by case and must be reasonable, proportionate, scoped to Customer Personal Data and relevant controls, conducted under confidentiality, and designed to avoid disruption or exposure of other customers’ data or iDISC confidential information. iDISC may ordinarily provide suitable certifications, independent reports, written responses, or remote evidence first. Where that evidence is not reasonably sufficient for the Customer to verify compliance with Article 28 GDPR, iDISC will allow and contribute to an additional audit or inspection reasonably required by the Customer, subject to appropriate security and confidentiality safeguards. Reasonable Customer-specific audit costs may be charged where permitted, provided they are not disproportionate or set at a level that would improperly deter the exercise of the Customer’s audit rights; costs attributable to a material breach by iDISC will not be charged to the Customer.


11. Return and deletion

At the end of the relevant Services, and at the Customer’s choice, iDISC will return or make available an export of Customer Personal Data and then delete it from active systems, or delete it without return, unless Union or Spanish law requires retention. Export, migration, or restoration work beyond standard functionality may be charged.

Deletion from active systems will be initiated promptly after the Customer’s choice or, where no choice is communicated, after termination handling is completed. Copies remaining in protected backups will be isolated from ordinary use and removed through iDISC’s normal backup lifecycle, unless retention is legally required. Customer Personal Data retained by law remains protected under this DPA and will be processed only for the required purpose.


12. International transfers

Production data, backups, monitoring data, and customer files are stored in the EEA. Where iDISC or a sub-processor transfers or permits access to Customer Personal Data outside the EEA, iDISC will ensure that a lawful Chapter V GDPR mechanism applies. Depending on the destination and recipient, this may include an adequacy decision, the European Commission Standard Contractual Clauses under Decision (EU) 2021/914, and supplementary contractual, technical, and organizational safeguards.

Where the EU Standard Contractual Clauses are required for a transfer from the Customer to iDISC, or onward from iDISC, the appropriate module and annexes will apply or be executed as required. iDISC will provide relevant transfer information on reasonable request, subject to confidentiality and third-party restrictions.


13. Liability

Each party’s liability arising from this DPA is subject to the liability provisions in the Agreement, except where Applicable Data Protection Law does not permit limitation. Separately negotiated enterprise terms take priority where expressly agreed.


14. Term and termination

This DPA takes effect with the Agreement and continues while iDISC processes Customer Personal Data on the Customer’s behalf. Provisions that must continue to protect retained Personal Data survive termination.


15. Governing law

This DPA is governed by Spanish law. The courts determined under the Agreement and applicable procedural law have jurisdiction, without limiting the authority of competent supervisory authorities or mandatory Data Subject rights.


16. Contact

Privacy: privacy@koesive.com
Legal and signed copies: legal@koesive.com
Security incidents: it-support@koesive.com


Schedule 1. Details of processing

Subject matter Provision of Koesive translation, localization, quoting, project management, language-asset, support, and delivery services.
Duration For the duration of the applicable Service and until Customer Personal Data is returned or deleted under this DPA, subject to legally required retention and protected backup lifecycles.
Nature and purpose Receiving, storing, organizing, extracting, analysing, translating, transforming, reviewing, quality checking, delivering, supporting, securing, backing up, returning, and deleting Customer Content on the Customer’s instructions.
Types of Personal Data Any Personal Data the Customer includes in documents, translation memories, glossaries, terminology, project instructions, prompts, support requests, or related Customer Content. This may include identification, contact, professional, financial, communication, location, online identifier, and special-category data.
Special-category data The Service is not intended to require special-category data. If the Customer chooses to submit such data, it must do so only where necessary, lawful, and compatible with the selected service level and any applicable provider restrictions. The Customer is responsible for establishing the required Article 9 GDPR condition or other lawful basis, providing compliant instructions and notices, and applying data minimization. iDISC remains responsible for its own obligations as Processor under Applicable Data Protection Law.
Data Subjects Customer personnel, customers, prospects, suppliers, contractors, partners, users, website visitors, patients, beneficiaries, members of the public, and any other individuals whose data the Customer submits.
Frequency As determined by Customer Orders and use of the Service.


Schedule 2. Technical and organizational measures

  • Information-security governance aligned with iDISC’s ISO/IEC 27001-certified information-security management system.
  • Documented risk assessment, security policies, access governance, incident handling, business continuity, and supplier-management processes.
  • Access restricted according to business need and assigned roles, with authentication and access controls appropriate to the relevant system.
  • Measures designed to protect confidentiality, integrity, availability, authenticity, and traceability throughout the information lifecycle.
  • Encrypted communications and protected storage where appropriate to the system, data, and assessed risk.
  • Logging, monitoring, vulnerability handling, backup, recovery, and change-management controls appropriate to the Service.
  • Personnel confidentiality commitments, security awareness, and controlled access for linguists, reviewers, support staff, and project personnel.
  • Sub-processor assessment and written contractual data-protection obligations.
  • Incident-response processes supporting notification and cooperation obligations under this DPA.
  • Periodic review and improvement of controls under iDISC’s management systems.
Scroll to Top