Data Protection

This Data Protection policy applies to Maven International and to the two specialised websites it operates: maven-international.com for translation and localisation, and maven-interpreted.com for interpretation and interpretation equipment. Whether the work is written or spoken, the same commitments apply.

1. Purpose and scope

Maven International handles personal data in the course of delivering interpretation, translation, and related language services. This policy covers our role as a processor of personal data in client project material, and as a controller of our own staff, freelance linguist, supplier and client contact records.

Our public commitments as a controller, including how individuals can exercise their rights, are set out in our Privacy Notice. This policy focuses on how we handle personal data as part of delivering a client's project.

The confidentiality of client content as a whole, including material that contains no personal data at all, is governed separately by our Confidentiality Standards. The conduct obligations that sit above both are set out in our Code of Conduct and Ethics.

2. Our role: controller and processor

Which obligations fall on us depends on the capacity in which we are acting, and we act in both:

  • As a processor. When we translate or interpret material a client supplies, we process any personal data in that material on the client's instructions and for the client's purposes. The client remains the controller. Our processing is governed by the contract and by a data processing agreement where one is in place.
  • As a controller. For our own business records, including staff and supplier onboarding, contracting, invoicing, and client contact details, we determine the purposes ourselves and act as controller. Our Privacy Notice sets out how we handle this data and the rights individuals have over it.

Where a client requires a specific data processing agreement, standard contractual clauses, or a controller-to-processor annex, we review and enter into it as part of contracting.

3. What personal data we handle as a processor

In project material, personal data reaches us because it is present in the content a client asks us to translate or interpret. We do not select it and we do not seek it out. Depending on the assignment it may include names, contact details, identification and case-file details, employment or financial information, and, particularly in asylum, medical, legal, and humanitarian work, information that data protection law treats as a special category.

4. Lawful basis

Where we act as processor, the lawful basis for the underlying processing is the client's to establish as controller. Where we act as controller for our own business records, our lawful bases are set out in the Privacy Notice.

Personal data is not used for any purpose beyond the one it was obtained for. We do not sell personal data, and we do not use client project content to market our services.

5. Data minimisation and retention

We ask for the minimum personal data needed for the purpose. Information that is not required for delivery, contracting, or a statutory obligation is not requested.

Retention of project material is set by the contract and by applicable law rather than by a single universal period:

  • Where a client specifies a retention or deletion requirement for project material, that requirement governs.
  • Client-owned language assets, such as translation memories, glossaries, and term bases, are retained for reuse only while the relationship is live, and are returned or deleted on request.

Material held beyond its purpose or its contractual mandate is deleted. A retention period can be fixed contractually for a given engagement. Retention of our own business records is described in the Privacy Notice.

6. Security of processing

The technical and organisational measures we apply are these:

  • Role-based, project-scoped access. Access is granted on a need-to-know basis. Project managers, linguists, and revisers see only the material required for the assignment in front of them.
  • Project segregation. Client assets are held separately by project. Material from one engagement is not visible from another.
  • Controlled platform environment. Work is carried out inside our project management and CAT environment rather than by circulating files. Export of source and translated documents is restricted; the operative rule, including who the narrow exceptions apply to, is set out in our Confidentiality Standards.
  • Access withdrawal. Access rights are withdrawn when the assignment closes or the engagement ends.
  • Binding obligations on people. Everyone who handles the data is under a signed non-disclosure agreement before any material reaches them, and is bound by our Code of Conduct and Ethics.

7. Platforms and sub-processors

Our translation project management and CAT (Computer-Assisted Translation) tools are provided by third-party vendors and act as sub-processors when client material passes through them. A current list of sub-processors engaged on a specific assignment is available to buyers on request, and can be fixed contractually where a client requires prior notification of changes.

8. International transfers

We operate across multiple jurisdictions and work with linguists located internationally, so personal data in project material may be accessed from, or hosted in, a country other than the one it originated in. Where a transfer is subject to UK or EU data protection law, it takes place under a recognised transfer mechanism, such as an adequacy decision or Standard Contractual Clauses with the necessary supplementary measures. Where a client requires data to remain within a defined jurisdiction, or requires linguists to be located in a specified country, that is a condition we accept contractually at the point of engagement.

9. Requests about project data

Where a request concerns personal data we hold as a processor on a client's behalf, we do not action it directly. We refer it to the client as controller without undue delay and assist them in responding. Requests about our own business records are handled as described in our Privacy Notice.

10. Personal data breaches

Suspected breaches, unauthorised access, and loss of personal data must be reported immediately through our internal escalation channels, and by suppliers to their project manager or to admin@maven-international.com. Suppliers must report without delay and must not attempt to resolve or conceal an incident first.

On becoming aware of a personal data breach:

  • Where we act as processor, we notify the affected client without undue delay so that they can meet their own notification obligations as controller.
  • Where we act as controller, our notification obligations are described in the Privacy Notice.
  • We record every breach, including those that are not notifiable, together with the facts, the effect, and the remedial action taken.

11. Governance and review

  • Policy owner: Director, at company group level
  • Operational oversight: Project Management
  • Review cycle: every year, or sooner on a material change to our operating model, to client compliance requirements, or to applicable law

Related documents: Code of Conduct and Ethics · Confidentiality Standards · Privacy Notice · Modern Slavery Statement

12. Information for institutional buyers

For procurement, compliance, and vendor-management teams, including UN agencies, IGOs, government bodies, and NGOs, we can provide:

  • A signed data processing agreement, or review of your own
  • Standard Contractual Clauses and transfer documentation
  • A current sub-processor list for a given assignment
  • Completed data protection and information security questionnaires
  • Project-specific confidentiality undertakings

Requests can be sent to admin@maven-international.com.

Last updated: September 25, 2026

Let's start a conversation

Tell us what you need and we'll map the right approach with you.

Contact us