Last updated: 15 January 2026
This notice explains how Maven International collects, uses, stores, and protects personal data, and what rights you have over that data. It applies to our websites, our client and vendor relationships, and our language service delivery.
It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable data protection law in the other jurisdictions in which we operate.
This notice covers personal data — information that identifies a living individual. It is separate from our Confidentiality Standards and our Data Protection policy, which describe how we protect client content and project material.
Maven International operates through separate legal entities. The entity responsible for your personal data — the “data controller” — depends on where you are and which office you deal with.
Maven International Language Solutions Limited
Registered in Ireland, company registration number 801072
Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, Co. Cork, T23 AT2P, Ireland
Controller for visitors to our websites from the EEA, UK and Switzerland, and for clients, vendors, and contacts managed through our Ireland office.
Maven International LLC
Registered in Indiana, USA, Business ID 202504091881444
12205 Sunrise Circle, #32, Fishers, Indiana 46038, USA
Controller for visitors from the United States and Canada, and for clients, vendors, and contacts managed through our US office.
Maven International Sdn Bhd — Registration number 201301001641, Unit 325, Level 3, Menara AIA Sentral, No. 30 Jalan Sultan Ismail, 50250 Kuala Lumpur, Malaysia
Maven International Solutions LLC — Licence number 2326469.01, Shams Business Center, Sharjah Media City Free Zone, Al Messaned, Sharjah, UAE, 515000
Contact admin@maven-international.com. We will confirm which entity is responsible and route your request. You do not need to work this out yourself.
If you fall into any of these categories, the rights in Section 7 apply to you.
Name, job title, employer, business email, business phone, postal address, billing and payment details, project correspondence, and records of services provided.
Name, contact details, language pairs and specializations, qualifications, professional history, rates, tax identifiers where legally required, banking details for payment, and records of assignments completed.
Technical data including IP address, browser type, device type, pages visited, and referring source. Where you consent, this may be used to identify the organization you are visiting from — see Section 9.3.
Whatever you provide — typically name, email, organization, and a description of your requirement.
Business contact information — name, job title, employer, business email or phone — obtained from third-party providers and public professional sources.
Name, contact details, CV, work history, qualifications, right-to-work information where legally required, and anything you provide in support of your application.
Documents we translate and proceedings we interpret frequently contain personal data about third parties. Where a client sends us such material, the client is the controller and Maven acts as a processor on their instructions, under a data processing agreement.
Where we contact you using data obtained from a third-party source, we tell you where we got it, as required by Art. 14. You may object or ask for deletion at any time — see Section 7.
You have the right to object to any processing based on legitimate interests.
We rely on consent for three things, each separately controlled and each off until you turn it on:
Withdrawing consent does not affect the lawfulness of processing before withdrawal, and does not restrict your use of our websites or services.
Project material may contain special category data — health information in medical translation, or data revealing racial or ethnic origin, political opinions, or religious beliefs in asylum and human rights work. We process such data as a processor on our client's instructions and under their lawful basis, subject to a data processing agreement and enhanced confidentiality controls.
We do not sell personal data. We share it only as follows:
Each processor is engaged under written contract requiring them to process data only on our instructions and maintain appropriate security.
If you are in the EEA or UK you have the rights below. We extend them, as a matter of policy, to everyone whose data we hold — regardless of location or category.
Email admin@maven-international.com. Tell us what you want and, if you can, which office you have dealt with.
We respond within one month. Complex requests may be extended by two further months, and we will tell you if so. No charge, unless a request is manifestly unfounded or excessive. We may ask you to verify your identity first.
If your data appears in a document we translated or a proceeding we interpreted, we are usually a processor for our client. We will direct your request to them as controller and support them in responding, and we will tell you when we do.
You may also complain to the authority where you live. We would ask that you raise it with us first so we can put it right.
We operate offices in Ireland, the United States, Malaysia, and the UAE, and work with linguists in many countries. Personal data may therefore be transferred outside the EEA, or accessed from outside it.
Personal data belonging to EEA and UK individuals, and client project content handled through our Ireland office, is hosted on servers located within the European Union.
Storing data in the EU does not remove the need for a transfer safeguard. Where a linguist, project manager, or office outside the EEA accesses that data, that access is a restricted transfer under the GDPR even though the data remains on an EU server. Safeguards apply to the access, not only the storage.
Transfers to Maven International LLC, and to US-based service providers including Apollo.io, are made under the Standard Contractual Clauses.
Request a copy of the safeguards applying to a transfer at admin@maven-international.com.
We use three categories. They are treated differently and you control two.
Required for the site to work. Set without consent, as permitted under the ePrivacy Directive.
| Cookie | Purpose | Retention |
|---|---|---|
| mvnCookieConsent | Records which categories you accepted, when, and against which version of this notice | 12 months |
| Webflow session and security cookies | Page delivery, form handling, abuse prevention | Session to 12 months |
These do not track you across sites and are not used for advertising.
Helps us understand in aggregate which pages are used and where visitors have difficulty.
Provider: Google Analytics (Google Ireland Limited).
| Cookie | Purpose | Retention |
|---|---|---|
| _ga | Distinguishes visitors | 2 years |
| _ga_<ID> | Maintains session state | 2 years |
| _gid | Distinguishes visitors | 24 hours |
IP anonymisation is enabled. We do not use Google Analytics for advertising or remarketing. Analytics data is retained for a maximum of 14 months. If you decline, these scripts do not execute.
Disclosed separately because it does more than measure behaviour: it attempts to identify the organization, and potentially individuals, behind a visit.
Provider: Apollo.io (Apollo.io, Inc., United States).
What it does. Matches your visit — typically by IP address — against a commercial database to identify the organization you are visiting from, and may enrich that with business contact information about individuals at that organization.
What we use it for. Identifying organizations in the sectors we serve that have shown interest in our services, so our team can follow up in a professional capacity.
Lawful basis: consent. Off unless you turn it on. If you decline, the script does not execute and no identification takes place.
Where the data goes. Apollo.io is based in the United States. Transfers are made under Standard Contractual Clauses — see Section 8.
Your rights. Withdraw consent at any time via the Cookie preferences link in our footer. You may also ask what data we hold about you, or ask for deletion, at admin@maven-international.com — see Section 7.
We do not use advertising cookies, cross-site advertising tracking, or social media tracking pixels. We do not sell personal data and do not share it with advertising networks.
On your first visit you are asked to choose. Accept all and Reject all are equally prominent and both a single click — we do not make refusing harder than accepting. Manage preferences lets you set each category individually.
If you make no choice, only strictly necessary cookies are set. Silence is treated as refusal.
You can change your choice at any time via the Cookie preferences link in our footer. Turning a category off stops collection immediately and clears cookies already set by it.
Stored for 12 months, then we ask again. We also ask again whenever we change the categories or their purpose, so a preference is never carried over onto something different from what you agreed to.
You can block or delete cookies in your browser. Blocking strictly necessary cookies may break parts of the site. Blocking the other categories has no effect on functionality.
| Category | Retention period | Reason |
|---|---|---|
| Client contact and project records | Duration of relationship, then 10 years | Aligned to the longest applicable contractual limitation period across our operating jurisdictions. Indiana allows 10 years to bring an action on a written contract; Ireland allows 6. |
| Vendor and linguist records | Duration of engagement, then 7 years | Covers tax record-keeping in both jurisdictions and the window for a payment or performance dispute. |
| Invoicing and financial records | 7 years | Irish Revenue requires tax records for 6 years. In the US the IRS assessment window is normally 3 years, extending to 6 where income is substantially understated and 7 for claims relating to bad debts or worthless securities. |
| Enquiries that do not become projects | 2 years from last contact | Long enough to recognise a returning enquirer and honour prior requests. |
| Business contacts from third-party sources | 2 years from last meaningful contact, or until you object | Data that has gone stale has no legitimate interest justifying its retention. |
| Marketing and newsletter contacts | Until you unsubscribe, plus a minimal suppression record | The suppression record holds only what is needed to ensure we do not contact you again. |
| Job applicants — unsuccessful | 12 months from decision | Allows us to respond to queries and consider you for similar roles. |
| Website analytics | 14 months | No business reason to retain longer. |
| Visitor identification records | 12 months from the visit | No business reason to retain longer. |
| Project content containing third-party data | Per client contract and DPA | The client is controller. We delete or return on their instruction and at end of engagement. |
Where a legal hold, dispute, investigation, or regulatory requirement applies, we retain the relevant data until that matter concludes.
When a retention period ends, data is deleted or irreversibly anonymised.
We apply technical and organisational measures appropriate to the sensitivity of the data we handle: role-based and project-scoped access controls, encryption in transit and at rest, secure file exchange, restrictions on bulk download of client content, confidentiality agreements binding all staff and linguists, and access revocation when an engagement ends.
Our full controls are described in our Data Protection policy. Additional technical documentation and completed due-diligence responses are available to institutional buyers on request.
If a personal data breach occurs that is likely to result in a risk to individuals' rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware, and inform affected individuals without undue delay where the risk is high.
Our services and websites are directed at organizations and professionals, not children. We do not knowingly collect personal data from children. Where project material concerns minors — in asylum, humanitarian, or family law contexts — we process it as a processor on our client's instructions, under enhanced confidentiality controls.
We review this notice at least annually and whenever our processing changes materially. The date at the top shows when it was last updated. Material changes are communicated to clients and vendors directly, and re-trigger the cookie consent prompt where they affect cookie categories.
Tell us what you need and we'll map the right approach with you.
Contact us