Legal

Privacy Policy

Effective 30 September 2026

Draft for legal review. This policy is grounded in Inteprit's actual product and operating regions, not template boilerplate, but privacy law is jurisdiction-specific, and this has not yet been reviewed by qualified counsel. It should be reviewed by a lawyer licensed in South Africa (and ideally EU/GDPR counsel) before being relied on.

This policy explains how Inteprit Language Solutions (Pty) Ltd T/A Inteprit Group (“Inteprit,” “we,” “us”) collects, uses, and protects personal information when you visit inteprit.com, submit an Ad Intent Audit request, or when we deliver content intelligence and transcreation services to a client.

Who we are, and what this policy covers

Inteprit Language Solutions (Pty) Ltd T/A Inteprit Group, headquartered at 27 Ballyclare Drive, Bryanston 2191, Johannesburg, South Africa, is the data controller for inteprit.com and for the content intelligence and transcreation services we deliver to performance marketing agencies scaling into Europe, the Gulf, LATAM, and APAC.

This policy covers two distinct things, and we're explicit about which is which throughout:

  1. Site visitor data: anyone browsing inteprit.com or submitting a Request a Complimentary Ad Intent Audit form. We're the controller here: we decide why and how this data is used.
  2. Client engagement data: the ad copy, keyword lists, campaign performance figures, and brand glossaries a client shares with us so we can generate, route, review, and deliver localized ad creative. For this data, we typically act as a processor on the client's behalf under a separate Data Processing Agreement (DPA); this policy describes our general handling practices, but the DPA governs.

If you're an individual named or referenced inside a client's ad copy or campaign materials (for example, in a testimonial or case study a client asks us to localize), the client, not Inteprit, is the controller for that data, and you should direct requests to them in the first instance.

What we collect, and why

Data categoryCollected viaPurposeLegal basisRetention
Name, work email, company, job titleAd Intent Audit form, contact form, sales callsRespond to the request, run the audit, follow upContract (pre-contractual steps) / legitimate interest24 months from last contact, or until deletion is requested
Submitted ad copy and campaign URLsAd Intent Audit formRun the diagnostic and show where CPA is leakingConsent12 months, unless you become a client (then per the DPA)
Site usage dataAnalytics on inteprit.comUnderstand what's working on the siteLegitimate interest / consent for non-essential cookies14 months
Billing and contract detailsClient onboardingInvoicing, contract administration, legal complianceContract / legal obligation7 years (statutory record-keeping)
Client-submitted ad copy, keyword lists, campaign data, brand glossariesClient engagement (Phrase TMS workflow)Generate, risk-route, review, and deliver localized creativeProcessor instruction under the client DPAPer the DPA: typically deleted or returned at contract end
Recruiting data (CV, portfolio)Careers page, freelancer applicationsAssess fit, onboard approved linguistsConsent / contract12 months if unsuccessful; contract duration + 3 years if engaged

We don't collect more than a category needs to do its job: the Ad Intent Audit form, for instance, asks for the ad copy and URL it needs to run the diagnostic, not a full campaign export.

Who we share it with

We don't sell personal information, ever. We do share it with a short list of processors who help us run the business and deliver the work:

Every processor operates under a written agreement that limits them to our instructions and to appropriate security safeguards; none of them can use your data for their own purposes.

International transfers. Because we operate across South Africa, the EU, the Gulf, LATAM, and APAC, personal information routinely crosses borders: most commonly, ad copy submitted from an EU-based client reaching an in-market linguist in Brazil or the UAE. Where a transfer leaves a jurisdiction with data protection laws (like the EU or UK), we rely on Standard Contractual Clauses (SCCs) or an equivalent recognized transfer mechanism, and we flow the same contractual protections down to our sub-processors.

Your rights, by region

We operate across enough regulatory regimes that a single generic rights paragraph would undersell what's actually available to you:

RegionGoverning lawRights availableHow to exercise
South Africa (home jurisdiction)POPIAAccess, correction, deletion, objection to processing, and the right to complain to the Information RegulatorEmail devon.bezuidenhout@inteprit.com
European Union / UKGDPR / UK GDPRAccess, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your local supervisory authorityEmail devon.bezuidenhout@inteprit.com; EU/UK requests handled within 30 days
Gulf & Middle EastVaries by market (e.g., UAE PDPL, Saudi PDPL)Access, correction, and deletion rights broadly comparable to GDPR, subject to local variationEmail devon.bezuidenhout@inteprit.com, noting your country
LATAM (Brazil)LGPDAccess, correction, anonymization, portability, deletion, and information about who we've shared your data withEmail devon.bezuidenhout@inteprit.com
APACVaries by market (e.g., Singapore PDPA)Access and correction rights, and the right to withdraw consent for direct marketingEmail devon.bezuidenhout@inteprit.com, noting your country

Regardless of region, we'll verify your identity before acting on a request, and we'll tell you within 5 business days that we've received it, even on the requests that take longer to fully resolve.

Security and retention

Access to client campaign data and translation memory inside Phrase TMS is role-scoped: a linguist assigned to Amber-tier German copy sees that copy, not the client's full account. Data in transit and at rest is encrypted, and access to production systems is logged and reviewed.

We keep personal information only as long as the table above sets out, or as long as the law requires. Client engagement data is handled per the DPA, which generally requires deletion or return at contract end.

If we experience a breach involving personal information, we'll notify affected individuals and the relevant regulator (the Information Regulator in South Africa, the appropriate supervisory authority under GDPR, and equivalent bodies elsewhere) within the timeframe each jurisdiction requires; GDPR's is 72 hours from when we become aware of it.

Cookies and site analytics

inteprit.com uses a small number of cookies:

You can block or delete cookies in your browser settings at any time; doing so may affect analytics but won't break core site functionality.

Changes to this policy, and how to reach us

We'll update this policy as our regions, sub-processors, or the law change, and we'll post the revised effective date at the top. For material changes (a new region, a new category of data, a new sub-processor with broad access), we'll flag it prominently on the site rather than let the date change quietly.

Privacy contact: devon.bezuidenhout@inteprit.com

Postal address: Inteprit Language Solutions (Pty) Ltd T/A Inteprit Group, 27 Ballyclare Drive, Bryanston 2191, Johannesburg, South Africa

If you're a client with questions about how we process your campaign or ad-copy data specifically, your Data Processing Agreement is the controlling document: reach out to your account lead, or to the privacy address above.