Privacy Notice

Last updated: 15 January 2026

1. About this notice

This notice explains how Maven International collects, uses, stores, and protects personal data, and what rights you have over that data. It applies to our websites, our client and vendor relationships, and our language service delivery.

It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable data protection law in the other jurisdictions in which we operate.

This notice covers personal data — information that identifies a living individual. It is separate from our Confidentiality Standards and our Data Protection policy, which describe how we protect client content and project material.

2. Who is responsible for your data

Maven International operates through separate legal entities. The entity responsible for your personal data — the “data controller” — depends on where you are and which office you deal with.

If you are in the European Economic Area, the United Kingdom, or Switzerland

Maven International Language Solutions Limited
Registered in Ireland, company registration number 801072
Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, Co. Cork, T23 AT2P, Ireland

Controller for visitors to our websites from the EEA, UK and Switzerland, and for clients, vendors, and contacts managed through our Ireland office.

If you are in the United States or Canada

Maven International LLC
Registered in Indiana, USA, Business ID 202504091881444
12205 Sunrise Circle, #32, Fishers, Indiana 46038, USA

Controller for visitors from the United States and Canada, and for clients, vendors, and contacts managed through our US office.

Other regions

Maven International Sdn Bhd — Registration number 201301001641, Unit 325, Level 3, Menara AIA Sentral, No. 30 Jalan Sultan Ismail, 50250 Kuala Lumpur, Malaysia

Maven International Solutions LLC — Licence number 2326469.01, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, UAE, 515000

If you are unsure which entity holds your data

Contact admin@maven-international.com. We will confirm which entity is responsible and route your request. You do not need to work this out yourself.

3. Who this notice applies to

  • Clients and client personnel
  • Vendors, linguists, and vendor applicants
  • Website visitors — whether or not you contact us
  • Enquirers — anyone who submits a form, requests a quote, books a meeting, or emails us
  • Business contacts we identify through business intelligence sources
  • Job applicants
  • Third parties named in project material — individuals whose data appears in documents we translate or proceedings we interpret

If you fall into any of these categories, the rights in Section 7 apply to you.

4. What data we collect

From clients and client personnel

Name, job title, employer, business email, business phone, postal address, billing and payment details, project correspondence, and records of services provided.

From vendors, linguists, and vendor applicants

Name, contact details, language pairs and specializations, qualifications, professional history, rates, tax identifiers where legally required, banking details for payment, and records of assignments completed.

From website visitors

Technical data including IP address, browser type, device type, pages visited, and referring source. Where you consent, this may be used to identify the organization you are visiting from — see Section 9.3.

From enquirers

Whatever you provide — typically name, email, organization, and a description of your requirement.

From business intelligence sources

Business contact information — name, job title, employer, business email or phone — obtained from third-party providers and public professional sources.

From job applicants

Name, contact details, CV, work history, qualifications, right-to-work information where legally required, and anything you provide in support of your application.

Personal data within project material

Documents we translate and proceedings we interpret frequently contain personal data about third parties. Where a client sends us such material, the client is the controller and Maven acts as a processor on their instructions, under a data processing agreement.

5. Why we process your data, and our lawful basis

Performance of a contract (Art. 6(1)(b))

  • Delivering translation and interpretation services
  • Managing project intake, scheduling, and delivery
  • Engaging linguists and vendors, and assigning work
  • Invoicing, processing payments, and paying vendors
  • Support and queries about live projects

Legitimate interests (Art. 6(1)(f))

  • Responding to enquiries and quote requests
  • Maintaining our vendor network and assessing vendor suitability
  • Keeping project and communication records for quality assurance, dispute resolution, and continuity
  • Securing our systems, detecting fraud, preventing misuse
  • Business-to-business contact with organizations in the sectors we serve, using business contact data obtained from business intelligence providers and public professional sources

Where we contact you using data obtained from a third-party source, we tell you where we got it, as required by Art. 14. You may object or ask for deletion at any time — see Section 7.

You have the right to object to any processing based on legitimate interests.

Legal obligation (Art. 6(1)(c))

  • Retaining financial and tax records
  • Responding to lawful requests from regulators, courts, or authorities
  • Verifying right-to-work or contractor status where legally required

Consent (Art. 6(1)(a))

We rely on consent for three things, each separately controlled and each off until you turn it on:

  • Analytics cookies — see Section 9.2
  • Visitor identification — see Section 9.3
  • Marketing email — withdraw via the unsubscribe link in any message, or by emailing admin@maven-international.com

Withdrawing consent does not affect the lawfulness of processing before withdrawal, and does not restrict your use of our websites or services.

Special category data (Art. 9)

Project material may contain special category data — health information in medical translation, or data revealing racial or ethnic origin, political opinions, or religious beliefs in asylum and human rights work. We process such data as a processor on our client's instructions and under their lawful basis, subject to a data processing agreement and enhanced confidentiality controls.

6. Who we share your data with

We do not sell personal data. We share it only as follows:

  • Linguists and vendors — project material limited to what the assignment requires, under confidentiality agreement
  • Technology providers — translation management platform, secure file exchange, email, and business systems, acting as processors under contract
  • Analytics and business intelligence providers — where you have consented; named in Section 9
  • Professional advisers — accountants, auditors, legal counsel
  • Payment providers and banks
  • Authorities — where required by law, court order, or regulatory obligation

Each processor is engaged under written contract requiring them to process data only on our instructions and maintain appropriate security.

7. Your rights

If you are in the EEA or UK you have the rights below. We extend them, as a matter of policy, to everyone whose data we hold — regardless of location or category.

  • Access — obtain a copy of the personal data we hold about you
  • Rectification — have inaccurate or incomplete data corrected
  • Erasure — request deletion, where we have no overriding legal or contractual reason to retain it
  • Restriction — ask us to limit use while a query is resolved
  • Portability — receive data you provided in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time
  • Withdraw consent — where processing is based on consent
  • Not be subject to solely automated decision-making producing legal or similarly significant effects. We do not carry out such decision-making.

How to exercise your rights

Email admin@maven-international.com. Tell us what you want and, if you can, which office you have dealt with.

We respond within one month. Complex requests may be extended by two further months, and we will tell you if so. No charge, unless a request is manifestly unfounded or excessive. We may ask you to verify your identity first.

Requests about project content

If your data appears in a document we translated or a proceeding we interpreted, we are usually a processor for our client. We will direct your request to them as controller and support them in responding, and we will tell you when we do.

Complaints

  • Ireland / EU — Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — www.dataprotection.ie
  • United Kingdom — Information Commissioner's Office — www.ico.org.uk

You may also complain to the authority where you live. We would ask that you raise it with us first so we can put it right.

8. International data transfers

We operate offices in Ireland, the United States, Malaysia, and the UAE, and work with linguists in many countries. Personal data may therefore be transferred outside the EEA, or accessed from outside it.

Where data is stored

Personal data belonging to EEA and UK individuals, and client project content handled through our Ireland office, is hosted on servers located within the European Union.

Why storage location alone is not enough

Storing data in the EU does not remove the need for a transfer safeguard. Where a linguist, project manager, or office outside the EEA accesses that data, that access is a restricted transfer under the GDPR even though the data remains on an EU server. Safeguards apply to the access, not only the storage.

The safeguards we apply

  • Standard Contractual Clauses — We use the European Commission's SCCs (Implementing Decision (EU) 2021/914) in agreements with vendors, linguists, group entities, and service providers outside the EEA, UK, and adequate countries. For UK transfers we use the UK International Data Transfer Addendum.
  • Transfer risk assessment — Where required, we assess whether destination country law undermines the protection the SCCs provide, and apply supplementary measures.
  • Confidentiality agreements — All linguists and vendors are bound by confidentiality obligations. These sit alongside the SCCs; they are not themselves a transfer mechanism and we do not rely on them as one.
  • Technical measures — Role-based access, project-scoped permissions, restrictions on bulk download, encryption in transit and at rest.

Transfers to the United States

Transfers to Maven International LLC, and to US-based service providers including Apollo.io, are made under the Standard Contractual Clauses.

Obtaining a copy

Request a copy of the safeguards applying to a transfer at admin@maven-international.com.

9. Cookies and tracking technologies

We use three categories. They are treated differently and you control two.

9.1 Strictly necessary — always active

Required for the site to work. Set without consent, as permitted under the ePrivacy Directive.

CookiePurposeRetention
mvnCookieConsentRecords which categories you accepted, when, and against which version of this notice12 months
Webflow session and security cookiesPage delivery, form handling, abuse preventionSession to 12 months

These do not track you across sites and are not used for advertising.

9.2 Analytics — consent required, off by default

Helps us understand in aggregate which pages are used and where visitors have difficulty.

Provider: Google Analytics (Google Ireland Limited).

CookiePurposeRetention
_gaDistinguishes visitors2 years
_ga_<ID>Maintains session state2 years
_gidDistinguishes visitors24 hours

IP anonymisation is enabled. We do not use Google Analytics for advertising or remarketing. Analytics data is retained for a maximum of 14 months. If you decline, these scripts do not execute.

9.3 Visitor identification — consent required, off by default

Disclosed separately because it does more than measure behaviour: it attempts to identify the organization, and potentially individuals, behind a visit.

Provider: Apollo.io (Apollo.io, Inc., United States).

What it does. Matches your visit — typically by IP address — against a commercial database to identify the organization you are visiting from, and may enrich that with business contact information about individuals at that organization.

What we use it for. Identifying organizations in the sectors we serve that have shown interest in our services, so our team can follow up in a professional capacity.

Lawful basis: consent. Off unless you turn it on. If you decline, the script does not execute and no identification takes place.

Where the data goes. Apollo.io is based in the United States. Transfers are made under Standard Contractual Clauses — see Section 8.

Your rights. Withdraw consent at any time via the Cookie preferences link in our footer. You may also ask what data we hold about you, or ask for deletion, at admin@maven-international.com — see Section 7.

9.4 What we do not use

We do not use advertising cookies, cross-site advertising tracking, or social media tracking pixels. We do not sell personal data and do not share it with advertising networks.

9.5 Your choice

On your first visit you are asked to choose. Accept all and Reject all are equally prominent and both a single click — we do not make refusing harder than accepting. Manage preferences lets you set each category individually.

If you make no choice, only strictly necessary cookies are set. Silence is treated as refusal.

You can change your choice at any time via the Cookie preferences link in our footer. Turning a category off stops collection immediately and clears cookies already set by it.

9.6 How long your choice lasts

Stored for 12 months, then we ask again. We also ask again whenever we change the categories or their purpose, so a preference is never carried over onto something different from what you agreed to.

9.7 Browser controls

You can block or delete cookies in your browser. Blocking strictly necessary cookies may break parts of the site. Blocking the other categories has no effect on functionality.

10. How long we keep your data

CategoryRetention periodReason
Client contact and project recordsDuration of relationship, then 10 yearsAligned to the longest applicable contractual limitation period across our operating jurisdictions. Indiana allows 10 years to bring an action on a written contract; Ireland allows 6.
Vendor and linguist recordsDuration of engagement, then 7 yearsCovers tax record-keeping in both jurisdictions and the window for a payment or performance dispute.
Invoicing and financial records7 yearsIrish Revenue requires tax records for 6 years. In the US the IRS assessment window is normally 3 years, extending to 6 where income is substantially understated and 7 for claims relating to bad debts or worthless securities.
Enquiries that do not become projects2 years from last contactLong enough to recognise a returning enquirer and honour prior requests.
Business contacts from third-party sources2 years from last meaningful contact, or until you objectData that has gone stale has no legitimate interest justifying its retention.
Marketing and newsletter contactsUntil you unsubscribe, plus a minimal suppression recordThe suppression record holds only what is needed to ensure we do not contact you again.
Job applicants — unsuccessful12 months from decisionAllows us to respond to queries and consider you for similar roles.
Website analytics14 monthsNo business reason to retain longer.
Visitor identification records12 months from the visitNo business reason to retain longer.
Project content containing third-party dataPer client contract and DPAThe client is controller. We delete or return on their instruction and at end of engagement.

Where a legal hold, dispute, investigation, or regulatory requirement applies, we retain the relevant data until that matter concludes.

When a retention period ends, data is deleted or irreversibly anonymised.

11. Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle: role-based and project-scoped access controls, encryption in transit and at rest, secure file exchange, restrictions on bulk download of client content, confidentiality agreements binding all staff and linguists, and access revocation when an engagement ends.

Our full controls are described in our Data Protection policy. Additional technical documentation and completed due-diligence responses are available to institutional buyers on request.

Breach notification

If a personal data breach occurs that is likely to result in a risk to individuals' rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware, and inform affected individuals without undue delay where the risk is high.

12. Children

Our services and websites are directed at organizations and professionals, not children. We do not knowingly collect personal data from children. Where project material concerns minors — in asylum, humanitarian, or family law contexts — we process it as a processor on our client's instructions, under enhanced confidentiality controls.

13. Changes to this notice

We review this notice at least annually and whenever our processing changes materially. The date at the top shows when it was last updated. Material changes are communicated to clients and vendors directly, and re-trigger the cookie consent prompt where they affect cookie categories.

14. Contact

admin@maven-international.com

Let's start a conversation

Tell us what you need and we'll map the right approach with you.

Contact us