Protecting Your Personal Information and Confidential Documents
At The Native Translator, we place great importance on protecting personal information and maintaining the confidentiality of documents entrusted to us by our clients.
When you use our professional translation services, you should be able to trust that your information is handled responsibly, from your initial quotation request through to the delivery of your completed translation.
We provide professional translation services for legal documents, medical records, financial reports, corporate documentation, technical materials and personal documents.
We recognise that documents submitted to us may contain sensitive personal information, commercially confidential information, trade secrets and other materials requiring careful protection.
The Native Translator holds certification to ISO/IEC 27001, the internationally recognised standard for information security management systems. This certification demonstrates the implementation of a structured management system designed to identify, assess and manage information security risks.
We process personal information in accordance with applicable data protection legislation, including South Africa's Protection of Personal Information Act, 2013 (POPIA), the European Union's General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).
Where applicable, we also take account of relevant provisions of South Africa's Electronic Communications and Transactions Act, 2002 (ECTA), and other legislation governing electronic communications and privacy.
This Privacy Policy explains what personal information we collect, why we process it, how we protect it, how long we retain it and the rights available to you under applicable law.
Responsible Party and Contact Information
Under POPIA, a responsible party is a public or private body or other person that determines the purpose of and means for processing personal information.
For the processing activities described in this policy, the responsible party is:
The Native Translator
Prologic GmbH
Dorfstrasse 29
CH-6390 Engelberg
Switzerland
Data Protection and Information Security:
dataprotection(at)prologic-corp.ch
General Enquiries:
office(at)the-native-translator.com
Where required by applicable legislation, we will make available the contact details of any designated Information Officer, representative or other relevant data protection contact.
What Personal Information Do We Collect?
We collect and process personal information only where necessary to provide our services, comply with legal obligations or pursue other lawful purposes.
Depending on how you use our services, we may process the following categories of information:
-
Contact information: Your name, surname, email address, telephone number, company name and postal address.
-
Translation project information: Quotation requests, language combinations, project descriptions, orders, instructions and correspondence.
-
Documents submitted for translation: Files and supporting materials, including any personal information contained within them.
-
Billing and payment information: Information required to administer transactions, issue invoices and maintain financial records.
-
Technical information: IP addresses, browser details, device information and website usage data.
-
Additional information: Any other information you voluntarily provide when contacting our customer service team or submitting an enquiry.
Documents submitted for translation may contain special personal information within the meaning of POPIA, including information concerning health, religious or philosophical beliefs, race or ethnic origin, or other categories protected by the legislation.
Documents may also contain personal information relating to children.
We process such information only where the relevant legal requirements are satisfied.
We recommend that clients provide only the personal information necessary for the relevant translation assignment.
Why Do We Process Your Personal Information?
We process personal information to provide, organise, perform and administer our professional translation services.
Our principal purposes include:
-
Receiving and responding to quotation requests.
-
Reviewing documents and assessing translation requirements.
-
Preparing, managing and completing translation projects.
-
Communicating with clients about ongoing and completed assignments.
-
Delivering completed translations.
-
Managing payments, invoicing and accounting.
-
Protecting our IT systems and preventing unauthorised access, fraud and security incidents.
-
Complying with applicable legal obligations.
-
Operating, maintaining and improving our website and services.
-
Analysing website usage where permitted by applicable law.
We do not use documents submitted for translation for unrelated purposes without an appropriate lawful basis.
Lawful Processing of Personal Information Under POPIA
Where POPIA applies, we process personal information in accordance with the conditions for lawful processing established by the Act.
These include accountability, processing limitation, purpose specification, further processing limitation, information quality, openness, security safeguards and data subject participation.
Depending on the circumstances, processing may be justified where:
Consent Has Been Obtained
The data subject has provided valid consent to the processing.
Processing Is Necessary for a Contract
Processing is necessary to carry out actions for the conclusion or performance of a contract to which the data subject is a party.
Processing Is Required by Law
Processing complies with an obligation imposed by law on the responsible party.
Processing Protects a Legitimate Interest of the Data Subject
Processing protects a legitimate interest of the individual concerned.
Processing Is Necessary for a Public Law Duty
Processing is necessary for the proper performance of a public law duty by a public body, where applicable.
Processing Pursues a Legitimate Interest
Processing is necessary for pursuing the legitimate interests of the responsible party or a third party to whom the information is supplied, subject to the requirements of POPIA.
Where we process special personal information or personal information relating to children, the additional restrictions and applicable authorisations under POPIA must also be satisfied.
Where the GDPR applies, processing is additionally assessed against the lawful bases set out in Article 6 and, where relevant, the conditions in Article 9.
Depending on the nature of an assignment, The Native Translator may act as an operator under POPIA or as a processor under the GDPR on behalf of a client who determines the purposes and means of processing.
In such cases, processing is governed by the relevant contractual arrangements and applicable legal requirements.
ISO/IEC 27001 – Certified Information Security Management
The Native Translator holds certification to ISO/IEC 27001.
ISO/IEC 27001 is an internationally recognised standard specifying requirements for establishing, implementing, maintaining and continually improving an information security management system.
The standard provides a structured approach to identifying information security risks and selecting appropriate measures to manage them.
Our information security management system is based on three fundamental principles.
Confidentiality: Protecting information against unauthorised access or disclosure.
Integrity: Protecting information against unauthorised or accidental alteration.
Availability: Ensuring that authorised individuals can access information when required.
Our management system incorporates technical and organisational safeguards appropriate to the risks associated with our activities.
ISO/IEC 27001 certification demonstrates that our information security management system meets the requirements of an internationally recognised standard.
However, certification does not mean that all security risks can be eliminated, nor does it independently guarantee compliance with every applicable data protection requirement.
How Do We Protect Your Documents and Personal Information?
Protecting confidential client information is an essential part of our professional translation services.
We implement technical and organisational measures designed to protect personal information and documents against unauthorised access, loss, improper alteration and unlawful disclosure.
These measures include:
-
Access controls based on assigned permissions.
-
Secure client and supplier portals for transferring files.
-
Encrypted data transmission using HTTPS/TLS when accessing our web portals.
-
Contractual confidentiality obligations for translators, revisers and project managers.
-
Procedures for identifying and managing information security risks.
-
Technical and organisational safeguards designed to prevent unauthorised access and other security incidents.
Where POPIA applies, we take account of the security safeguards required under section 19 of the Act.
The specific measures applied are proportionate to the nature of the processing and the associated risks.
Confidentiality Obligations for Translators and Project Managers
Many of our clients entrust us with documents containing confidential business or personal information.
Our translators, linguistic revisers and project managers are subject to contractual confidentiality obligations.
Information accessed during an assignment must not be used for unauthorised purposes or disclosed to third parties without appropriate authorisation.
Access to documents is limited to activities necessary to perform the assignment and any other processing permitted by law.
We follow the principle that only individuals with a legitimate professional need should have access to the relevant information.
Do We Share Your Personal Information with Third Parties?
We do not sell your personal information to third parties.
However, providing our services may require us to share certain information with selected recipients, including:
-
Translators, revisers and project managers involved in your assignment.
-
Providers of IT systems, hosting, data storage and technical support.
-
Payment service providers.
-
Administrative service providers, where necessary.
-
Public authorities or other authorised recipients where disclosure is required by law.
Where external service providers process personal information on our behalf, we implement the contractual and organisational safeguards required by applicable legislation.
In particular, where POPIA applies, arrangements with operators must satisfy the relevant requirements of section 21, including appropriate security and confidentiality obligations.
We limit disclosures to the information necessary for the relevant purpose.
International Transfers of Personal Information
The Native Translator works with an international network of qualified translators and other service providers.
Consequently, certain assignments may involve personal information being processed by recipients in different countries, including countries outside South Africa, the European Union, the European Economic Area and Switzerland.
Where POPIA applies, international transfers of personal information are subject to section 72 of the Act.
Such transfers must satisfy an applicable legal condition.
Depending on the circumstances, this may include appropriate legal protections in the recipient country or under a binding agreement, consent of the data subject, or another permitted ground under section 72.
Where the GDPR or Swiss data protection legislation applies, international transfers are carried out in accordance with the relevant legal requirements.
For transfers subject to the GDPR, we assess whether the destination is covered by an applicable adequacy decision.
Where an appropriate adequacy arrangement is unavailable, suitable safeguards may be required.
These may include the European Commission's Standard Contractual Clauses and supplementary protective measures, where necessary.
The appropriate safeguards depend on the destination country, the nature of the information and the circumstances of the transfer.
Payments and Protection of Payment Information
For payment of our translation services, we may use external payment service providers such as PayPal or Saferpay, where these payment options are offered during the ordering process.
These providers may collect and process information necessary to complete transactions, prevent fraud and comply with their legal obligations.
We may receive certain payment-related information, including transaction status, payment references and billing details.
For further information about how payment service providers process personal information, please consult their respective privacy policies.
How Long Do We Retain Personal Information and Translation Documents?
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, unless legal obligations or other lawful reasons justify a longer retention period.
As a general rule, documents submitted for translation are retained for 90 days following completion of the assignment.
After this period, the documents are deleted from our active systems unless a legal obligation or another lawful reason requires continued retention.
Different retention periods may apply to certain categories of information, including:
-
Invoices and accounting records subject to statutory retention requirements.
-
Information necessary to manage ongoing matters.
-
Documentation required for the establishment, exercise or defence of legal claims.
-
Information that must be retained under other applicable legal provisions.
Backup systems may be subject to separate technical deletion cycles.
Where POPIA applies, we take account of section 14, which governs the retention and restriction of records.
When information is no longer required and there is no lawful basis for continued retention, we delete, destroy or de-identify it in accordance with applicable requirements and procedures.
Cookies and Similar Technologies
Our website may use cookies and similar technologies to support essential functions, remember user preferences and understand how visitors interact with our website.
Cookies are small text files stored on your device when you visit a website.
Cookies may be classified according to how long they remain on your device.
Session Cookies: These are generally used during a single browsing session and expire when that session ends.
Persistent Cookies: These remain on your device for a defined period or until you delete them.
Cookies may also be categorised according to their purpose.
Strictly Necessary Cookies: These support essential website functions or enable services explicitly requested by the user.
Analytics Cookies: These may help us understand website usage and improve our content and functionality.
Third-Party and Other Cookies: These may support additional website features or services provided by external organisations.
Where applicable law requires consent, we use non-essential cookies and similar technologies only after obtaining the necessary consent.
For personal information processing subject to POPIA, the applicable lawful processing conditions must be satisfied, including any relevant transparency and consent requirements.
You may withdraw your consent where processing is based on consent, subject to applicable legal requirements.
Analytics Tools and Third-Party Cookies
Our website may use analytics tools such as Google Analytics or Matomo to understand website usage and performance.
Depending on their technical configuration, these tools may process information such as IP addresses, device details and pages visited.
We use analytics tools in accordance with applicable legislation and any relevant consent requirements.
Information about the tools actually deployed, the cookies used and their retention periods should reflect the website's current technical configuration and be made available to visitors.
How Can You Manage or Delete Cookies?
You can manage cookies through your web browser settings.
Most browsers allow you to block cookies, delete previously stored cookies or set preferences for particular websites.
Please note that blocking strictly necessary cookies may affect the operation of certain website features.
Further information is available from the following browser support pages:
Google Chrome:
https://support.google.com/chrome/answer/95647?hl=en
Mozilla Firefox:
https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
Safari:
https://support.apple.com/en-za/guide/safari/sfri11471/mac
Microsoft Edge:
https://support.microsoft.com/microsoft-edge
Where our website provides a cookie preference management tool, you may also use it to change your selections or withdraw previously given consent.
Your Rights Under POPIA
Where POPIA applies, you may exercise the rights provided by the Act, subject to applicable conditions and limitations.
These include:
-
Right to Be Notified: The right to be informed when your personal information is collected and when relevant security compromises occur, as provided by law.
-
Right of Access: The right to request confirmation of whether your personal information is held and to request access to it.
-
Right to Correction or Deletion: The right to request correction, deletion or destruction of personal information in circumstances provided for by POPIA.
-
Right to Object: The right to object to certain processing activities on reasonable grounds relating to your particular situation.
-
Right to Withdraw Consent: The right to withdraw consent where processing is based on consent, subject to applicable conditions.
-
Rights Relating to Direct Marketing: The right to object to direct marketing and to exercise the protections provided by POPIA.
-
Rights Relating to Automated Decision-Making: The right to the protections provided by POPIA concerning certain decisions based solely on automated processing.
-
Right to Complain: The right to submit a complaint to the Information Regulator.
-
Right to Seek Legal Remedies: The right to pursue remedies where available under applicable legislation.
These rights are subject to statutory conditions and exceptions.
For example, a request for deletion may not always be fulfilled in full where certain information must be retained to comply with a legal obligation.
Your Rights Under the GDPR and Swiss Data Protection Law
Where the GDPR applies, you may also exercise the rights provided by that legislation.
These may include:
-
The right of access under Article 15.
-
The right to rectification under Article 16.
-
The right to erasure under Article 17.
-
The right to restriction of processing under Article 18.
-
The right to data portability under Article 20.
-
The right to object under Article 21.
-
The right to withdraw consent where processing is based on consent.
-
Rights concerning certain automated individual decisions under Article 22.
-
The right to lodge a complaint with a competent supervisory authority.
Swiss data protection legislation also provides individuals with certain rights, including rights of access and, subject to legal conditions, rectification and other remedies.
We assess each request in accordance with the legislation applicable to the relevant processing activity.
Your Right to Object to Processing
Where POPIA applies, you may object to certain processing activities on reasonable grounds relating to your particular situation, in accordance with section 11(3), subject to the relevant legal requirements.
Where the GDPR applies and we process personal data on the basis of legitimate interests under Article 6(1)(f), you may object to that processing on grounds relating to your particular situation in accordance with Article 21.
Following a valid GDPR objection, we will cease the relevant processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.
Personal Information Security Compromises
We take information security incidents seriously.
Where we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, we assess the incident and our notification obligations under applicable law.
Where POPIA applies, section 22 requires notification to the Information Regulator and affected data subjects in accordance with its requirements, subject to any legally permitted delay or exception.
We will also take appropriate steps to investigate the incident, limit its effects and implement relevant remedial measures.
Right to Complain to the Information Regulator of South Africa
If you believe that your personal information has been processed in breach of applicable data protection law, you are welcome to contact us so that we can investigate your concerns.
Where POPIA applies, you may also lodge a complaint with the Information Regulator of South Africa.
Information Regulator (South Africa)
Official website:
https://inforegulator.org.za
The Information Regulator is the independent authority responsible for overseeing compliance with POPIA and exercising the functions assigned to it by South African law.
Where the GDPR applies, you may also have the right to lodge a complaint with a competent European data protection supervisory authority.
In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) is the relevant federal supervisory authority within the scope of Swiss data protection legislation.
Official website:
https://www.edoeb.admin.ch
Changes to This Privacy Policy
We may update this Privacy Policy when our services, technical systems, internal procedures or applicable legal requirements change.
The latest version will be published on our website.
Where significant changes occur, we will provide additional information to affected individuals when legally required or otherwise appropriate.
Contact Us About Personal Information Protection and Information Security
If you have questions about how your personal information is processed, wish to exercise your rights or need to report a potential data protection or information security incident, please contact us.
Data Protection and Information Security:
dataprotection(at)prologic-corp.ch
General Enquiries:
office(at)the-native-translator.com
At The Native Translator, we provide professional translation services where linguistic quality, confidentiality and information security are integral to every assignment.














