Your Documents Stay Yours
Taia never uses your content to train AI models. Everything is encrypted in transit and at rest, processed exclusively in AWS Europe (Dublin, Ireland), and handled in line with GDPR. That is the whole promise. The rest of this page is the proof.
Does Taia Train AI on Your Data? No. Never.
Your content is never used to train, fine-tune, or improve any AI model. Not ours, not anyone's.
Here's the thing about pasting a contract into a free translation tool: you should always check the terms first to see what happens to that text afterwards. With Taia, you do not have to wonder. Taia does not use customer content, including source documents, translated outputs, translation memories, glossaries, or style guides, to train any AI or machine learning system made available to any third party.
This is a contractual commitment, not a settings toggle you have to find. Every AI provider Taia works with is contractually prohibited from using your content to train, fine-tune, or improve its models. The commitment is written into our Privacy Policy (section 4.1) and our Data Processing Agreement, so it is enforceable, not just marketing.
Your translation memory and glossary do make Taia's translations better over time, but only for you. They are isolated to your account and used solely to improve the quality of your own translations. Nothing you upload ever improves a model that someone else uses.
Contractual, Not Optional
Every AI provider we work with is bound by written no-training terms. There is no opt-out you need to hunt for. The default is the protection.
Your TM Stays Private
Translation memories and glossaries are scoped to your account only. They improve your translations, and nobody else's.
Nothing Lingers
AI-only translations are processed in transit and not retained in Taia's database after the translation is returned to you.
Is Taia GDPR Compliant? Yes.
Taia processes personal data in line with the EU GDPR and UK GDPR, with a published Privacy Policy and a signable Data Processing Agreement.
Taia Translations Ltd is a company incorporated in England and Wales (company number 12779985), registered at 71-75 Shelton Street, Covent Garden, London. When you upload content to translate, you stay the controller of that data and Taia acts as the processor. That means Taia processes your content only on your instructions, and the obligations that come with that role are spelled out in writing.
The paperwork a compliance team actually asks for is already public. The Privacy Policy covers what Taia collects and why, your rights (access, erasure, portability, and the rest), and how to exercise them. The Data Processing Agreement covers processing on behalf of business customers, security measures, breach notification within 72 hours, and audit rights.
Turns out most vendors make you chase a DPA through sales. Taia's DPA is incorporated into the Terms automatically for every customer, and a separately signed copy is available from legal@taia.io if your procurement process requires one. Where a transfer outside the UK or EEA is ever required, Standard Contractual Clauses apply.
Your Rights, In Practice
Access, rectification, erasure, restriction, portability, and objection. Email privacy@taia.io and Taia responds within the legally required timeframe, typically one month. Complaints can go to the ICO in the UK or your local EU supervisory authority.
Breach Notification in 72 Hours
If a personal data breach affects your data, Taia notifies you without undue delay and within 72 hours of becoming aware, including what happened, the likely consequences, and what is being done about it.
Where Is Your Data Stored? AWS Europe (Dublin, Ireland).
All production infrastructure runs exclusively in the AWS Europe (Ireland) region. No production data leaves the AWS network.
"Where does our data physically live?" is usually the second question a compliance team asks, right after the AI training one. The honest answer is short: Amazon Web Services, Europe (Ireland) region, Dublin. Compute, database, storage, all of it. Taia does not spread your content across regions or providers.
No production data leaves the AWS network. Backups are encrypted and retained on a rolling basis for disaster recovery, within the same environment. Production systems are isolated with network segmentation and firewalling, and regular vulnerability scanning and security monitoring run on top.
For teams in the EU and UK, this makes the data residency conversation simple. Your documents are processed inside the EU, by a UK company, under GDPR. That is one less workshop with your legal team.
Single EU Region
AWS Europe (Ireland) exclusively. One region, one provider, no surprises about where your content sits.
Nothing Leaves AWS
No production data leaves the AWS network. Backups stay encrypted inside the same environment.
Transfer Safeguards
If a restricted transfer outside the UK or EEA is ever required, Standard Contractual Clauses and supplementary measures apply, as set out in the DPA.
What Does ISO 17100 Certification Actually Mean?
ISO 17100:2015 is the international standard for translation service quality. Taia is certified, and here is what that buys you in plain language.
Most people don't realise translation has an ISO standard at all. ISO 17100:2015 sets requirements for how a professional translation service must run: who is qualified to translate, how projects are managed, and how quality is checked before delivery. It is the difference between "we have good translators, trust us" and a certified, auditable process.
In practice, it means Taia's professional translations are done by qualified, vetted native-speaking linguists working to a documented process. On the ISO 17100 workflow tiers, a second qualified linguist revises the translation before you receive it. Taia's Enhanced tier pairs a translator with a revisor under ISO 17100, and the Ultimate tier adds a third step with full translation, editing, and proofreading.
Why does this belong on a trust page? Because for regulated content, quality is a compliance question, not a taste question. A pharma leaflet, a contract, or a safety manual translated wrong is a liability. ISO 17100 certification means the process that protects you from that is independently defined, not improvised. See how the tiers compare on the pricing page.
Qualified Linguists
2,000+ vetted, native-speaking professional linguists, matched to your subject matter across 204 languages.
Second-Linguist Revision
On ISO 17100 tiers, a separate revisor checks the translation before delivery. Two sets of professional eyes, not one.
Confidentiality Built In
Linguists work inside Taia's secure online editor under written confidentiality and data protection obligations. Custom NDAs are available for enterprise clients.
How Does Taia Protect Your Data Day to Day?
Encryption everywhere, access on a need-to-know basis, and payments that never touch Taia's servers. All documented in the DPA, not just promised here.
Encryption in Transit and at Rest
All customer data in transit is encrypted with TLS 1.2 or higher. Data at rest is encrypted with AES-256 or equivalent, and backups are encrypted the same way. These measures are documented in Schedule 2 of the Data Processing Agreement.
Access Control That Defaults to No
Role-based access control is enforced across production systems, multi-factor authentication is required for administrative access, and access to customer data is limited to people who need it for their role, and logged. Your accounts, translation memories, and glossaries are logically isolated from other customers.
Payments Handled by Stripe
All payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. Taia never sees or stores your credit card information, and Stripe receives billing data only, never your translation content.
Tested, Monitored, Rehearsed
Regular vulnerability scanning and security monitoring, secure development practices with code review and security testing, documented incident response and disaster recovery procedures with regular backup testing, and ongoing staff security and privacy training.
You Own Your Data
Your translation memory, glossaries, and translations belong to you. Export them anytime and keep them forever, even if you cancel. After a subscription ends, you have a 30-day export window before content is deleted from production systems.
Enterprise Options
Enterprise plans add single sign-on (SSO), dedicated infrastructure, and custom data retention policies, plus custom NDAs on request. If your security review needs more, talk to us.
Who Else Touches Your Content? You Decide.
Content is only shared with an external AI provider when you explicitly select that provider for a specific job. The full sub-processor list is public.
Taia's platform is built around a simple principle: your content is only shared with an external AI provider when you explicitly choose that provider for a specific task. Pick Standard AI and your text goes to ModernMT, for that job only. Pick an Advanced AI model and it goes to the model you selected, such as OpenAI or Anthropic, for that job only. Nothing is shared in the background, and never for training.
Professional human translation is private by default. On the human tiers, no external AI provider receives your content at all. Your documents are handled by Taia and its vetted linguists inside the secure editor, under written confidentiality obligations.
The full list of sub-processors, what each one receives, and what triggers the sharing is published at taia.io/legal/sub-processors/. Taia gives at least 30 days notice before adding or replacing a sub-processor that performs a fundamentally new processing activity, and customers with a signed DPA can object on data protection grounds. No fine-print surprises.
Security Questions, Straight Answers
The questions compliance-minded buyers actually ask, answered the way we answer them on sales calls.
Does Taia use my data to train AI models?
No. Taia never uses your content, including source documents, translations, translation memories, glossaries, and style guides, to train, fine-tune, or improve any AI model made available to third parties. Every AI provider Taia works with is contractually prohibited from training on your content. This commitment is written into our Privacy Policy and Data Processing Agreement, not just this page.
Where is my data stored?
All customer content is stored and processed exclusively on Amazon Web Services in the AWS Europe (Ireland) region, in Dublin. No production data leaves the AWS network. Backups are encrypted and stay within the same environment.
Is Taia GDPR compliant?
Yes. Taia Translations Ltd is a UK company (company number 12779985) and processes personal data in line with the EU GDPR and UK GDPR. Our Privacy Policy explains what we collect and why, our Data Processing Agreement covers processing on behalf of business customers, and Standard Contractual Clauses cover any restricted transfers.
Can we sign a DPA with Taia?
Yes. The Data Processing Agreement is published at taia.io/legal/dpa/ and is incorporated into the Terms for every customer automatically. If your procurement process needs a separately signed copy, request one from legal@taia.io. The signed version is identical to the published one.
How is my data encrypted?
Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent. Backups are encrypted the same way. These measures are documented in Schedule 2 of our Data Processing Agreement.
How do I delete my data from Taia?
You can request deletion of your personal data at any time by emailing privacy@taia.io, and we respond within the legally required timeframe, typically one month. When a subscription ends, you get a 30-day window to export your content, after which it is deleted from production systems. On request, Taia provides written confirmation of deletion.
Which third parties receive my content?
Only the translation engine or AI model you select for a specific job, and only for that job. Professional human translation tiers involve no external AI provider at all unless you choose a machine translation post-editing option. The full sub-processor list, including ModernMT, OpenAI, Anthropic, OpenRouter, AWS, and Stripe, is published at taia.io/legal/sub-processors/ and we give at least 30 days notice before adding a sub-processor that performs a fundamentally new processing activity.
What happens if there is a data breach?
Taia notifies affected customers without undue delay and in any event within 72 hours of becoming aware of a personal data breach. The notification includes the nature of the breach, its likely consequences, and the measures taken to address it, as set out in clause 7 of our Data Processing Agreement.
Are payments on Taia secure?
Yes. All payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. Taia never sees or stores your credit card information, and Stripe receives billing data only, never any translation content.
Something your security review needs that is not covered here? Ask us directly at privacy@taia.io.
Contact UsTranslate Without Wondering Where Your Data Goes
Taia combines instant AI translation in 204 languages, a built-in editor, and ISO 17100-certified linguists. Your content stays encrypted, stays in the EU, and is never used to train AI models. Start with 5,000 free words per month.