Privacy Policy

Privacy Notice

Bureau Translations Inc., trading as wxrks Effective 08/17/2026 · Version 1.0

1. Scope

This notice explains how Bureau Translations Inc., trading as wxrks ("wxrks", "we", "us"), handles personal data across our website, our sales and marketing activity, and the wxrks platform at app.wxrks.com, including our API and command line interface.

wxrks is a translation and localization platform sold to businesses. Customers upload content, we process and translate it under their instructions, and we return it to them.

2. Our two roles

Which role applies determines everything else in this notice.

Controller. We decide the purposes and means for a limited set of data: the accounts of people who use the platform, people who contact us, visitors to our website, and our customers' billing contacts. Sections 3 to 9 describe that processing.

Processor. Everything inside the content a customer uploads for translation is processed only on that customer's documented instructions. We do not decide what goes into those files or why they are translated, and we do not use them for our own purposes. This is governed by our Data Processing Agreement, not by the controller sections below.

We use Customer Content to mean files, text, translation memories, glossaries and related material a customer submits, and the translations produced from it.

If your personal data appears inside Customer Content, the wxrks customer who uploaded it is your controller. Section 8 explains where to direct a request.

3. Personal data we handle as controller

  • Account data. Name, work email address, job title, platform role, hashed password, multi-factor enrolment.
  • Authentication, audit and usage data. Sign-in events, IP address, browser and device information, actions taken in the platform, features used and volumes processed.
  • Support data. Messages and tickets when you contact us.
  • Billing contact data. Name and business contact details of the person who administers an account.
  • Prospect and marketing data. Business contact details and correspondence, from you, your employer, or public business sources.
  • Website data. Pages viewed, referring page, approximate location derived from IP address, and cookie identifiers. See section 9.

We do not store payment card numbers. Card details are entered directly with our payment processor.

We do not ask for special category data as defined by Article 9 of the UK and EU GDPR, and we have no use for it in the controller role.

We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under United States state privacy laws.

4. Purposes and legal bases

Purpose

Legal basis

Providing the platform, administering accounts, supporting users

Performance of a contract, or steps before entering one

Billing and account administration

Performance of a contract; legal obligation for tax and accounting records

Securing the platform, including authentication, audit logging and abuse prevention

Legitimate interests in protecting the service and our customers' data

Diagnosing faults and maintaining the service

Legitimate interests in operating a reliable service

Business to business marketing

Legitimate interests in promoting our service to relevant businesses, or consent where required

Website analytics and advertising measurement

Consent, where required. See section 9

Meeting legal and regulatory obligations

Legal obligation

Providing account data is necessary to use the platform; without it we cannot create an account.

Where we rely on legitimate interests, we have assessed those interests against your rights, and you may object at any time using the details in section 10.

5. Customer Content

We process Customer Content to provide the service: storing it, matching it against the customer's translation memories and glossaries, translating it with the engine the customer selects, running automated quality checks, routing it through any human review the customer has configured, and returning it.

  • Customer Content is not used to train artificial intelligence models, ours or a provider's. Our agreements with model providers prohibit it, and integrated models are configured without memory between requests.
  • It is encrypted in transit and at rest.
  • Access by our personnel is role-based, limited to those who need it, and logged.
  • We do not inspect it, and we do not enrich it with data from other sources.

6. Recipients

We use third-party providers to operate the service. Each is engaged under a written contract with data protection terms and assessed before engagement.

Our current subprocessors, with the purpose, processing location and data category for each, are published at https://wxrks.com/subprocessors. Customers receive at least 30 days' notice before a new subprocessor is authorised and may object under the Data Processing Agreement.

We also disclose personal data to professional advisers and auditors under confidentiality obligations, to a buyer or successor in a merger or sale of assets, and where required by law. Where we receive a legally binding government request for Customer Content we follow the process in the Data Processing Agreement, including notifying the affected customer unless prohibited.

We do not disclose personal data to third parties for their own marketing.

7. International transfers and where data is held

The platform runs on Amazon Web Services. A customer tenant is provisioned in either eu-west-1 (Ireland) or us-east-1 (Northern Virginia) and remains in the region elected.

wxrks is a United States company and operates no premises of its own; our personnel work remotely and are located in the United States, Brazil and Qatar.

Where personal data protected by the UK GDPR or the EU GDPR is transferred outside those territories, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and equivalent measures for transfers from the United Kingdom, together with technical measures including encryption in transit and at rest and the access controls in section 8. A copy of the safeguards in place is available on request using the details in section 10.

8. Retention, security and your rights

Retention. Customer Content is deleted within 60 days of the termination effective date, or within 30 days of a verified deletion request at any time, whichever comes first; backup copies age out within a further 7 days. Deletion follows NIST SP 800-88 Rev 1 and a certificate of destruction is issued on completion. Other personal data is kept for as long as the account is open and afterwards only for as long as needed for the purpose it was collected for, to meet legal, accounting or tax obligations, or to resolve disputes.

Security. We operate an information security management system covering the platform and our corporate environment. Our controls are examined annually by an independent auditor under SOC 2 Type 2, held continuously since 2020, and the platform is tested at least annually by an independent penetration testing provider. Current attestations and security documentation are at trust.wxrks.com. Where a personal data breach affects a customer's personal data we notify that customer in line with the Data Processing Agreement.

Your rights. Subject to the law that applies to you, you may request access to your personal data, correction, deletion, restriction of or objection to processing, and portability, and you may withdraw consent where processing relies on it. You may complain to a supervisory authority: in the UK, the Information Commissioner's Office; in the EEA, your local authority.

For personal data we hold as controller, contact us using section 10. For personal data inside Customer Content, contact the wxrks customer who uploaded it; if you contact us we will promptly tell that customer and assist them, but we will not respond on the substance unless they authorise it. We will ask for information sufficient to verify your identity, and use it only for that.

United States. In relation to Customer Content, wxrks acts as a service provider, processor or contractor as the applicable state law defines it. We do not sell or share personal information, do not retain, use or disclose it for any purpose other than providing the service, and do not combine it with personal information from other sources. If we decline a request you may appeal using section 10.

9. Cookies

Our website uses cookies for functionality, analytics and advertising measurement. Where consent is required we obtain it through our cookie banner before non-essential cookies are set, and you can change your choices at any time through the preference link on our website.

Details of each cookie are in our Cookie Policy at https://wxrks.com/cookie-policy

The wxrks platform itself uses only cookies strictly necessary for the service to function, including session and authentication cookies.

10. Automated decision-making, children, changes and contact

Automated decision-making. We do not make decisions producing legal or similarly significant effects about individuals by automated means. Translation output is machine-generated content, not a decision about a person.

Children. The platform is a business tool, is not directed to children, and we do not knowingly collect personal data from anyone under 16.

Changes. The version and date at the top identify the current text. Where a change materially affects how we handle personal data as controller, we will give notice before it takes effect.

Contact.

Bureau Translations Inc., trading as wxrks 3515 Mt. Diablo Blvd, Lafayette, CA 94549, United States

Privacy enquiries and data subject requests:  privacy@wxrks.com 

Data Protection Officer: Rodrigo Demetrio, Director of Marketing, privacy@wxrks.com

Starten Siekostenlos

Testen Sie Bureau Works so lange, wie Sie möchten, mit unserem kostenlosen Starter-Plan. Erwerben Sie einen kostenpflichtigen Bureau Works-Plan, um das richtige Maß an Skalierbarkeit und Funktionen freizuschalten.

Loslegen — es ist kostenlos