This Privacy Notice explains how Acclaro collects, uses, shares, and protects Partner’s Personal Data in connection with the Framework Services Agreement (“FSA”) and forms an integral part of any associated contractual document between the parties, including the FSA. In this regard, Acclaro is considered a Data Controller.
Please note that this Privacy Notice applies only to Acclaro’s own systems and Platforms operated by Acclaro (including Acclaro’s Partner Database and WordsOnline). It does not apply to websites, tools, or platforms developed or operated by Acclaro’s Clients or other third parties. Partners are encouraged to review the privacy policies of any third-party systems they may be asked to use when providing Services.
For the purposes of this Privacy Notice, “Acclaro” or “Acclaro Group” means Acclaro Belgium and its Affiliates, including Acclaro US, as defined in the Framework Services Agreement.
“Data Protection Laws” means all applicable laws and regulations in any jurisdiction, as revised from time to time, related to data protection, data privacy and data security with regard to Personal Data Processed under or in connection with this Privacy Notice, including, but not limited to, the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the United Kingdom’s General Data Protection Regulation (“UK GDPR”), Switzerland’s Federal Act on Data Protection (“FADP”), the California Consumer Privacy Act of 2018 including its regulations and amendments made by the California Privacy Rights Act of 2020 (“CCPA”), the Virginia Consumer Data Protection Act (“VCDPA”), and the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Utah Consumer Privacy Act (“UCPA”), the Oregon Consumer Privacy Act (“OCPA”), the Texas Data Privacy and Security Act (“TXDPSA”), and the Montana Consumer Data Privacy Act (“MTCDPA”), the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and any applicable provincial privacy laws in Canada, and the Privacy Act 1988 (“Privacy Act”) and any relevant state laws in Australia.
“Personal Data” means “personal data”, “personal information” or any information relating to an identified or identifiable individual or device as defined under Data Protection Laws.
Personal data “processed automatically” includes information held on, or relating to use of, a computer, laptop, mobile phone or similar device. It covers data derived from systems or equipment such as access passes within a building, performance data relating to work activities and sound and image data such as CCTV and photographs (where applicable).
“Process” (and the related terms “Processes” and “Processing”) shall have the same meaning as defined under Data Protection Laws.
All other defined terms from Data Protection Laws that appear in this Privacy Notice such as “business,” “business purposes,” “commercial purposes,” “collect,” “consumer,” “data controller,” “data processor,” “de-identified data,” “sell,” “sensitive personal information,” “service provider,” “share,” and “special categories of personal data” shall have the same meaning ascribed to them in the relevant Data Protection Law.
We use the word “you” to refer to anyone within the scope of this Privacy Notice.
Capitalized terms used but not defined in this Privacy Notice shall have the meanings assigned to them in the FSA.
We process Personal Data on the following legal grounds, as defined under Data Protection Laws:
We do not intentionally collect or process sensitive Personal Data in our relationship with Partners unless:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as necessary:
The purposes for which we process your Personal Data, examples of the Personal Data that may be processed, and the grounds on which we process it, are set out in the table below.
The examples in the table are illustrative and not exhaustive.
Without your acknowledgment of consent, we may be unable to manage your engagement effectively which could impact payments and compliance with regulatory requirements.
If you have any concerns, please contact your Acclaro representative or dataprivacy@acclaro.com.
Currently, Acclaro does not use supplier Personal Data in connection with AI tools or services, including model training or performance analytics.
Should this change in the future, Acclaro will ensure that:
Most of the Personal Data we process is provided directly by you or your employer (our Partner), such as when entering into a contract, exchanging emails, or submitting documentation.
We may also collect data from:
Access to your Personal Data is limited to authorized personnel within Acclaro and, where applicable, its Affiliates, on a strict need-to-know basis in order to fulfil the purposes described above. This includes staff in departments such as Human Resources, Finance, Legal, Vendor Management, Project Management, and IT, who require access in order to manage our relationship with you and perform administrative or operational tasks.
Your Personal Data may be shared with Acclaro’s Affiliates, located in the European Union or the United States, where necessary for global business operations or to ensure compliance with applicable laws.
We only disclose your Personal Data outside the Acclaro Group where the disclosure is consistent with a valid legal basis for processing, and where it is lawful, fair, and proportionate.
We may share limited professional information (such as your name, language qualifications, or relevant experience) with Clients, when necessary to demonstrate your suitability for a specific project, and in line with our contractual obligations.
We may share your Personal Data with trusted third-party service providers who support our operations, such as communication platforms, accounting systems, payment processors, resourcing/vendor management platforms, IT infrastructure and security providers, or translation management systems. These providers act on our instructions, and we require them to implement appropriate security and confidentiality measures.
We may also disclose your Personal Data:
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, tax, accounting, or reporting obligations, to resolve disputes, or to enforce our agreements.
The specific retention period depends on the nature of the Personal Data and the context in which we collect it. In general:
Once your Personal Data is no longer required for these purposes, we will delete or anonymize it in a secure manner, in accordance with our internal procedures and applicable Data Protection Laws.
Because Acclaro operates globally, specific retention periods may vary depending on the Acclaro entity you engage with and the applicable legal requirements in that jurisdiction.
Because Acclaro operates globally, your Personal Data may be transferred to and processed in countries outside of your country of residence, including jurisdictions that may not provide the same level of data protection as your local laws.
This includes transfers:
Where such transfers involve Personal Data subject to the General Data Protection Regulation (GDPR), the UK GDPR, or other applicable Data Protection Laws, Acclaro ensures that appropriate safeguards are implemented in accordance with those laws.
These safeguards may include:
You can request further information on the safeguards we use for international transfers, including a copy of the applicable clauses, by contacting us at dataprivacy@acclaro.com.
You have certain rights in relation to your Personal Data, subject to applicable Data Protection Laws. These may include the right to:
To exercise your rights or request information about how we process your data, please contact us at dataprivacy@acclaro.com. We may need to verify your identity before responding.
If you have concerns about how your Personal Data is handled, we encourage you to contact us first at dataprivacy@acclaro.com. You also have the right to lodge a complaint with a data protection authority in your country or where you believe a breach of data protection law has occurred.