As part of its overall global privacy compliance efforts, Glyph Language Services complies with both the US/EU Safe Harbor Framework and the US/Swiss Safe Harbor Framework (self-certification currently pending) concerning the transfer of personal identifiable data from the European Union and Switzerland to the United States of America. We follow the Safe Harbor Privacy Principles as set out by the United States Department of Commerce. This statement outlines our general policies and practices for implementing the Principles of Safe Harbor, including the type of data we collect and how we process it.
The term “processing” of personal data includes any operation or set of operations performed upon personal data such as collecting, storing, retrieving, consulting, using, disclosing, disseminating, and otherwise making available the personal data.
Glyph Language Services’ privacy practices are self-certified (pending as of 03/21/2014), but have been reviewed by legal counsel experienced with Safe Harbor Compliance.
For more information about the Safe Harbor program and to view Glyph Language Services’ certification, please go to : http://www.export.gov/safeharbor/
Glyph Language Services treats all material sent to us from our clients, vendors, and employees (collectively, “CVEs”) as confidential in accordance with its current confidentiality undertakings with CVEs. Confidentiality provisions are required as part of all of our contracts with all of our clients vendors and employees; each separate entity must sign a confidentiality agreement prior to becoming affiliated or working with Glyph Language Services.
Glyph Language Services maintains Personal Data regarding CVEs on secure systems. This information is collected to aid Glyph Language Services in conducting business operations. In addition to the Personal Data itself, the information that Glyph Language Services protects includes contact details, billing/invoicing/payment information, services provided to our clients, and information within source and reference files sent to perform translation projects, consulting and other linguistic services. In regards to our employees and vendors, this information may also include contact details, payment information, professional qualifications, financial information, and information provided by the employee or vendor in its resume or curriculum vitae (“CV”). When requested by a client and permitted under applicable law, Glyph Language Services may also cause criminal background checks to be conducted on all employees as well as seek such information concerning key vendors or consultants who may be retained by them. If criminal background checks are needed by clients for our vendors, Glyph Language Services may accommodate this request if permitted under local law and for an additional fee. Please discuss with your Client Services Representative if needed.
Glyph Language Services does not rent, sell, loan or otherwise make available Personal Data to any third party unless required by law or in the scope of a registrar, regulatory, or financial audit.
When any clients visit Glyph Language Services’ website, Glyph Language Services does not track Personal Data, names or email addresses. Instead, Glyph Language Services may track only which Internet Service Provider has accessed the site as well as statistics that show the number of site visitors, those requests received and the country origin of those requests. This information is used to improve our site in order to better serve our clients, but this information does not constitute Personal Data.
All emails sent to Glyph Language Services (globally) are routed through a third party SPAM filter (Google Gmail), that is located in the United States. This means all email correspondence originated outside of the United States with an end destination other than the United States still must travel through the United States before arrival at the desired location.
Glyph Language Services utilizes a network of over 400 freelance vendors to assist in the process of translation, localization and other related services. They may receive, as part of the assignment, the name of the client they are working on but no Personal Data about that client, unless such contact information is needed to perform the assignment (such as the cases of onsite document review, etc.). These freelance vendors may also have access to any Personal Data within the source documents and reference material sent to them for translation. However, in all cases, the freelance vendors will be subject to confidentiality undertakings in which such freelance vendors undertake to keep such information confidential and only use such information in accordance with their projects.
All vendors are required to sign a Nondisclosure Agreement/EU Data Protection Agreement prior to working with Glyph Language Services. This document addresses common requirements concerning Notice, Choice, Onward Transfer, Access, Security, Data Integrity and Enforcement of the Personal Data. Any vendor has the right to terminate its working relationship with Glyph Language Services and request the deletion of Personal Data pertaining to them. However, Glyph Language Services will continue to maintain its historical business records in such a way so that Glyph Language Services may retain its historical knowledge and relationships concerning any legal or regulatory inquiries which may later arise. This practice is in the best interest of both parties so that identifying information relating to a particular matter is accessible but sufficiently discrete so that Glyph Language Services does not accidentally contact them for projects in the future.
Glyph Language Services’ clients have the choice concerning what Personal Data is accessed, used or retained. In order to conduct business with our clients it is necessary to maintain contact information and specific billing information, but the extent of the information stored can always be discussed with a Glyph Language Services Client Services Representative. Additionally, if there is a specific concern about the Personal Data found in the information provided to process a language services project (such as source, reference material, etc.), we recommend redacting this information prior to sending it to Glyph Language Services or discussing alternative solutions with your Glyph Language Services Client Services Representative.
In order to better serve our clients’ needs and provide further information concerning services, Glyph Language Services may, from time-to-time, send information on additional services we provide. Should any client decide that this information is not desirable, a client may opt-out of receiving this information by informing their Client Services Representative or by contacting the Glyph Language Services Privacy Officer.
Glyph Language Services employees have a choice concerning what information is shared with other employees, affiliates and third parties (such as clients). Such information will only be provided pursuant to such employees written consent and not used for any other purpose.
Any individual CVE may request a copy of the Personal Data Glyph Language Services has collected from Glyph Language Services’ Privacy Officer in accordance with applicable law, in addition to receiving confirmation of the contents of any Personal Data relating to the individual. Under applicable law, such individual CVE then has the right to correct, amend or delete information when it is inaccurate.
Clients may do so by contacting their Client Services Representative or by contacting the Glyph Language Services Privacy Officer.
Vendors can do so by contacting firstname.lastname@example.org, a dedicated e-mail address to which such inquiries can be sent directly.
Employees can do so by contacting the Glyph Corporate Services department or the Glyph Privacy Officer.
Glyph Language Services is dedicated to ensuring that all data maintained is accurate, updated, and relevant for the use contemplated by the CVE and will take all required steps to ensure the data is accurate, complete and current. This process is accomplished by regular email and written correspondence with CVEs; however, it is highly recommended that CVEs continue to monitor the information provided to Glyph Language Services and remain proactive with requesting access to any Personal Data and advising Glyph Language Services of the need for corrections as needed.
Glyph Language Services has strict physical and logical security procedures to ensure that all digital and paper records are secured (such policy is available for dissemination to clients upon written request to the Glyph Language Services Privacy Officer). These records are accessible only by approved staff. All critical systems (such as servers, back-up devices, etc.) are accessible only by a small number of authorized staff. Glyph Language Services’ information security is managed internally and is routinely audited to ensure conformity with Glyph Language Services procedures and recommended industry standards.