Privacy Policy
Privacy Notice
Bureau Translations Inc., trading as wxrks Effective 08/17/2026 · Version 1.0
1. Scope
This notice explains how Bureau Translations Inc., trading as wxrks ("wxrks", "we", "us"), handles personal data across our website, our sales and marketing activity, and the wxrks platform at app.wxrks.com, including our API and command line interface.
wxrks is a translation and localization platform sold to businesses. Customers upload content, we process and translate it under their instructions, and we return it to them.
2. Our two roles
Which role applies determines everything else in this notice.
Controller. We decide the purposes and means for a limited set of data: the accounts of people who use the platform, people who contact us, visitors to our website, and our customers' billing contacts. Sections 3 to 9 describe that processing.
Processor. Everything inside the content a customer uploads for translation is processed only on that customer's documented instructions. We do not decide what goes into those files or why they are translated, and we do not use them for our own purposes. This is governed by our Data Processing Agreement, not by the controller sections below.
We use Customer Content to mean files, text, translation memories, glossaries and related material a customer submits, and the translations produced from it.
If your personal data appears inside Customer Content, the wxrks customer who uploaded it is your controller. Section 8 explains where to direct a request.
3. Personal data we handle as controller
- Account data. Name, work email address, job title, platform role, hashed password, multi-factor enrolment.
- Authentication, audit and usage data. Sign-in events, IP address, browser and device information, actions taken in the platform, features used and volumes processed.
- Support data. Messages and tickets when you contact us.
- Billing contact data. Name and business contact details of the person who administers an account.
- Prospect and marketing data. Business contact details and correspondence, from you, your employer, or public business sources.
- Website data. Pages viewed, referring page, approximate location derived from IP address, and cookie identifiers. See section 9.
We do not store payment card numbers. Card details are entered directly with our payment processor.
We do not ask for special category data as defined by Article 9 of the UK and EU GDPR, and we have no use for it in the controller role.
We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under United States state privacy laws.
4. Purposes and legal bases
Purpose
Legal basis
Providing the platform, administering accounts, supporting users
Performance of a contract, or steps before entering one
Billing and account administration
Performance of a contract; legal obligation for tax and accounting records
Securing the platform, including authentication, audit logging and abuse prevention
Legitimate interests in protecting the service and our customers' data
Diagnosing faults and maintaining the service
Legitimate interests in operating a reliable service
Business to business marketing
Legitimate interests in promoting our service to relevant businesses, or consent where required
Website analytics and advertising measurement
Consent, where required. See section 9
Meeting legal and regulatory obligations
Legal obligation
Providing account data is necessary to use the platform; without it we cannot create an account.
Where we rely on legitimate interests, we have assessed those interests against your rights, and you may object at any time using the details in section 10.
5. Customer Content
We process Customer Content to provide the service: storing it, matching it against the customer's translation memories and glossaries, translating it with the engine the customer selects, running automated quality checks, routing it through any human review the customer has configured, and returning it.
- Customer Content is not used to train artificial intelligence models, ours or a provider's. Our agreements with model providers prohibit it, and integrated models are configured without memory between requests.
- It is encrypted in transit and at rest.
- Access by our personnel is role-based, limited to those who need it, and logged.
- We do not inspect it, and we do not enrich it with data from other sources.
6. Recipients
We use third-party providers to operate the service. Each is engaged under a written contract with data protection terms and assessed before engagement.
Our current subprocessors, with the purpose, processing location and data category for each, are published at https://wxrks.com/subprocessors. Customers receive at least 30 days' notice before a new subprocessor is authorised and may object under the Data Processing Agreement.
We also disclose personal data to professional advisers and auditors under confidentiality obligations, to a buyer or successor in a merger or sale of assets, and where required by law. Where we receive a legally binding government request for Customer Content we follow the process in the Data Processing Agreement, including notifying the affected customer unless prohibited.
We do not disclose personal data to third parties for their own marketing.
7. International transfers and where data is held
The platform runs on Amazon Web Services. A customer tenant is provisioned in either eu-west-1 (Ireland) or us-east-1 (Northern Virginia) and remains in the region elected.
wxrks is a United States company and operates no premises of its own; our personnel work remotely and are located in the United States, Brazil and Qatar.
Where personal data protected by the UK GDPR or the EU GDPR is transferred outside those territories, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and equivalent measures for transfers from the United Kingdom, together with technical measures including encryption in transit and at rest and the access controls in section 8. A copy of the safeguards in place is available on request using the details in section 10.
8. Retention, security and your rights
Retention. Customer Content is deleted within 60 days of the termination effective date, or within 30 days of a verified deletion request at any time, whichever comes first; backup copies age out within a further 7 days. Deletion follows NIST SP 800-88 Rev 1 and a certificate of destruction is issued on completion. Other personal data is kept for as long as the account is open and afterwards only for as long as needed for the purpose it was collected for, to meet legal, accounting or tax obligations, or to resolve disputes.
Security. We operate an information security management system covering the platform and our corporate environment. Our controls are examined annually by an independent auditor under SOC 2 Type 2, held continuously since 2020, and the platform is tested at least annually by an independent penetration testing provider. Current attestations and security documentation are at trust.wxrks.com. Where a personal data breach affects a customer's personal data we notify that customer in line with the Data Processing Agreement.
Your rights. Subject to the law that applies to you, you may request access to your personal data, correction, deletion, restriction of or objection to processing, and portability, and you may withdraw consent where processing relies on it. You may complain to a supervisory authority: in the UK, the Information Commissioner's Office; in the EEA, your local authority.
For personal data we hold as controller, contact us using section 10. For personal data inside Customer Content, contact the wxrks customer who uploaded it; if you contact us we will promptly tell that customer and assist them, but we will not respond on the substance unless they authorise it. We will ask for information sufficient to verify your identity, and use it only for that.
United States. In relation to Customer Content, wxrks acts as a service provider, processor or contractor as the applicable state law defines it. We do not sell or share personal information, do not retain, use or disclose it for any purpose other than providing the service, and do not combine it with personal information from other sources. If we decline a request you may appeal using section 10.
9. Cookies
Our website uses cookies for functionality, analytics and advertising measurement. Where consent is required we obtain it through our cookie banner before non-essential cookies are set, and you can change your choices at any time through the preference link on our website.
Details of each cookie are in our Cookie Policy at https://wxrks.com/cookie-policy
The wxrks platform itself uses only cookies strictly necessary for the service to function, including session and authentication cookies.
10. Automated decision-making, children, changes and contact
Automated decision-making. We do not make decisions producing legal or similarly significant effects about individuals by automated means. Translation output is machine-generated content, not a decision about a person.
Children. The platform is a business tool, is not directed to children, and we do not knowingly collect personal data from anyone under 16.
Changes. The version and date at the top identify the current text. Where a change materially affects how we handle personal data as controller, we will give notice before it takes effect.
Contact.
Bureau Translations Inc., trading as wxrks 3515 Mt. Diablo Blvd, Lafayette, CA 94549, United States
Privacy enquiries and data subject requests: privacy@wxrks.com
Data Protection Officer: Rodrigo Demetrio, Director of Marketing, privacy@wxrks.com
Inizia subitogratis
Prova Bureau Works per tutto il tempo che desideri con il nostro piano Starter gratuito. Acquista un piano a pagamento di Bureau Works per sbloccare il giusto grado di scalabilità e caratteristiche.
Inizia subito — è gratis



