Vannus / Catalog / DeepL

DeepL

Vannus has not established which model this vendor runs, and does not infer one. Every finding below is quoted to the vendor’s own document, or marked not disclosed where the vendor publishes nothing.

Determination
Contracts with DeepL SE (Germany), governed by the law of England and Wales.
Vannus has not established whether a US parent controls this entity, so US reach is not established either way. The LEI record reports no consolidating parent filed (NO_KNOWN_PERSON, [2026-09-12]).
deepl.com · read 2026-09-26
read from terms of service

Translation and writing AI (DeepL Translator, DeepL Write, API) from DeepL SE, a German company.

AI, writing, productivity
What the vendor's own documentation says
We built it on a specialized LLM architecture and years of proprietary translation data.
deepl.com ↗ Vendor-sourcedQuote re-checked 14 Sep 2026
Who controls it
Data jurisdictionEuropean Economic Area · a privacy notice ↗
US corporate controlNot established — the vendor's own terms name no US contracting entity, and no source establishes its parent either way
Contracting entityDeepL SE
Governing lawGoverned by the law of England and Wales
Trains on your dataYes, by default — on the vendor's default plan
On a paid or enterprise planDoes not train on your data — its words, on retention: “DeepL will only temporarily store Content or Processed Content to the extent technically required to provide its Services.”

This page gives the finding and links the document it comes from. The AI Subprocessor Jurisdiction Report ($299) quotes the exact clause for every vendor in your stack, dated, in one document you can hand to an auditor.

Applies to: DeepL Pro

From the DeepL Pro page FAQ (“How does DeepL secure my data as a Pro subscriber?”), which names Pro subscribers and not API Pro or Write Pro separately: “For Pro subscribers, DeepL temporarily stores both original content and processed results only as technically needed to provide its services and deletes it afterward unless otherwise specified. Additionally, it's never used to train DeepL's AI models.” deepl.com ↗

On retention, from the DeepL Pro Terms (Last update: August 2026), §3.1.2: “DeepL will only temporarily store Content or Processed Content to the extent technically required to provide its Services.” deepl.com ↗

Training and retention posture varies by plan. The default-plan row above describes the vendor’s free or standard tier; the paid-plan row is quoted from the document linked beside it. A negotiated contract can override either. Check your own agreement before relying on this.

On U.S. CLOUD Act reach specifically: the statute reaches a provider subject to U.S. jurisdiction over data in its possession, custody or control. Corporate control is a strong indicator of that and it is what we can evidence from published documents — but it is not the whole test. A company founded outside the U.S. can still contract through a U.S. entity or run substantial U.S. operations. Treat this as a starting point for your own review, not a legal determination, and take advice on anything that matters.

Signals on file
Origin
Germany · data in European Economic Area
Zero data retention
Yes — states it retains no prompt data

The vendor's published or catalog-recorded posture — the concrete facts this entry is built from. A full audit verifies each against the vendor's current documentation.

Compliance the vendor states
SOC 2GDPR

Taken from the vendor’s own published material. Vannus does not hold these reports and has not reviewed their scope or dates — ask the vendor for the current report before relying on any of them.

How this entry is set

Vannus records, from the vendor's own published documents, the legal entity a customer contracts with, the country that entity sits in, and the governing law of its terms — and whether the vendor runs its own model or resells someone else's. Each finding is quoted to its source and dated, or marked not disclosed where the vendor publishes nothing. No paid placements — affiliate status is walled off from the record, enforced by a test in the build. See the methodology →

Related tools we record
Visit DeepL ↗ Check your whole stack →