Data Processing Agreement and Subprocessors — GoTranslate
Status: August 23, 2026
Version: 1.0
The German version is the operative text. This English page is a summary provided for convenience. The binding data processing agreement pursuant to Art. 28 GDPR is the German text at gotranslate.app/dpa (Part A). In the event of any discrepancy, the German version prevails.
Processor: AP10 Studios UG (haftungsbeschränkt), Peter-Henlein-Straße 13, 89312 Günzburg, Germany, represented by its Managing Director Andreas Paulheim, registered with Amtsgericht Memmingen, commercial register B, HRB 21190, VAT identification number DE370237913, email support@gotranslate.app.
Data processing agreement — summary
Roles. The merchant operating the Shopify store is the controller. The provider of the GoTranslate app is the processor with respect to store content it reads, stores, translates and writes back. For its own billing and operational records the provider acts as an independent controller; the DPA does not cover those.
Subject matter. Automated translation of the merchant's Shopify store content into additional languages, for the duration of the subscription.
Data processed. Source texts and translations of products, collections, pages, blogs, navigation, store and legal texts, shipping and payment methods, theme texts, metaobjects and metafields, plus content digests and merchant glossary entries. Personal data occurs only where the merchant itself writes personal details into store content.
Data explicitly not processed. Customer records, orders, payment data and any other Shopify protected customer data. The app does not request the corresponding access scopes and technically skips content belonging to protected resources.
Instructions. The provider processes data only on the merchant's documented instructions, which comprise the DPA, the terms of service, the settings the merchant configures in the app, and the jobs the merchant triggers. The provider does not use the data for its own purposes and does not use it to train models.
Subprocessors. General written authorisation under Art. 28(2) GDPR. Current
subprocessors: Mistral AI (machine translation; established in Paris,
France), Supabase (database hosting; contracting entity Supabase Pte. Ltd.,
Singapore, parent company in Delaware, USA; data held in the Ireland region,
eu-west-1) and Fly.io, Inc. (application hosting; established in the USA;
application instances run in the Frankfurt region, Germany). Shopify is the
merchant's own counterparty and is not listed as a subprocessor. The provider notifies the
merchant at least 30 days before adding or replacing a
subprocessor; the merchant may object on substantiated data protection grounds,
in which case either party may terminate.
Location of processing. The actual processing of store content takes place
within the European Union: application instances run in the Frankfurt region
(Germany), the database is held in the Ireland region (eu-west-1), and the
translation service is a company established in France. In short: EU data space
— app servers in Germany, database in Ireland. This describes where processing
takes place; it is not an assurance that all administrative, support and logging
functions of the providers used remain inside the European Union.
Security. Access tokens encrypted at rest with AES-256-GCM; TLS in transit; row level security enabled and forced on all tables with no policies defined, so that access is possible only through the application's privileged service role; per-store data separation including a per-store translation cache; HMAC verification of all inbound webhooks; least-privilege access scopes.
Deletion. On uninstall, sessions are deleted and the store is marked as
uninstalled. On Shopify's shop/redact webhook, all data belonging to that
store is deleted, cascading across every table. Translation cache entries are
deleted automatically after 12 months without use. Only the webhook processing
log is retained as evidence of deletion; it contains no store content.
Assistance. The provider assists the merchant with data subject requests (Art. 15–22 GDPR), security (Art. 32), breach notification (Art. 33–34) and data protection impact assessments (Art. 35–36). Data subject requests received directly by the provider are forwarded to the merchant and not answered independently.
Audit. The provider makes available the information necessary to demonstrate compliance with Art. 28 GDPR and permits audits on reasonable prior notice, subject to confidentiality.
Subprocessors
List as at: August 23, 2026
| Provider | Contracting entity and seat | Purpose | Data processed | Place of processing | Website |
|---|---|---|---|---|---|
| Mistral AI | Mistral AI, 15 rue des Halles, 75001 Paris, France (RCS 952 418 325) | Machine translation of source texts via an API | Source texts, source and target language, glossary entries | France / European Union; no specific server location has been publicly guaranteed | https://mistral.ai · DPA: https://legal.mistral.ai/terms/data-processing-addendum |
| Supabase | Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513; parent company Supabase, Inc., Delaware, USA | Operation of the PostgreSQL database in which all app data is stored | All data listed in Section 2 of Part A | Data held in the AWS Ireland region (eu-west-1); administration, support and logging functions may extend beyond it |
https://supabase.com · DPA: https://supabase.com/legal/dpa |
| Fly.io | Fly.io, Inc., USA | Operation of the application servers and background workers | All data listed in Section 2 of Part A while being processed in memory; no permanent storage of store content; application logs | Application instances in the Frankfurt region (fra), Germany; the provider states that it stores and processes the information it collects in the United States |
https://fly.io · Subprocessors: https://fly.io/legal/sub-processors/ |
Not listed as a subprocessor
| Provider | Reason |
|---|---|
| Shopify | Shopify is the merchant's own counterparty and is the source and destination of the content processed. It is not a service provider engaged by the processor. |
| Lovable | The chat application serves the provider's own support towards the merchant. The provider processes this data under its own responsibility (Art. 4(7) GDPR), not on the controller's instructions; no store content is processed there. See Sections 3 and 8 of the privacy policy. |
Notification of changes
The processor notifies the controller at least 30 days before a change to this list takes effect, by a notice inside the app and by updating this list at https://app.gotranslate.app/dpa. The controller may object in accordance with Section 6(4) of Part A.
Change history
| Date | Change |
|---|---|
| August 23, 2026 | First version (version 1.0) |
| September 8, 2026 | Support chat (Lovable Labs AB, Sweden) added as the provider's own processing — not a subprocessor |
Status: August 23, 2026 · Version: 1.0