Views: 285 · Update Time: 2025-12-29 21:59:22

1. What kind of data is being processed?

To complete translation hosting and delivery, the system may process the following data:

1) Site and task-related data

  • Site identification information (such as domain name, site ID, binding credentials/verification information)

  • Task metadata (task time, language pair, task status, time taken, reason for failure)

2) Translation content data

  • XLIFF content from WPML (containing text fragments and structural information that need to be translated)

  • Translable text in HTML/rich text editors (extracted, translated, and then replaced back with the original structure).

3) Billing and auditing data

  • Engine/model information, input/output tokens

  • Expense and credit limit deduction records (for reconciliation and auditing)


2. How is data transmitted and used?

2.1 Translation Execution

The translated content will be sent to the selected translation engine for processing:

  • Machine Translation Engine (MT)

  • LLM Engine (charged per model)

  • Built-in API Key: Use your provided third-party key to call the corresponding service.

The system uses the method of "extracting translatable text/nodes" to minimize the transmission of invalid content, thereby reducing costs and exposure.

2.2 Automated Delivery

Once the translation is complete, the system writes the results back to the task and pushes them to WPML, allowing it to enter the subsequent WPML process.


3. Data storage and retention strategy

To support task tracking, reconciliation, and troubleshooting, the system may save:

  • Task status and log information

  • Transaction details (Tokens, Engine, Deduction records)

We recommend clearly stating your strategy on the page:

  • Task metadata and consumption details retention: e.g., 30 days/90 days

  • Translation content (XLIFF/text) retention: for example, processing only temporarily during task execution and not storing for a long time; or retaining the shortest possible period for retries.

  • Automatic cleanup and unrecoverable rules upon expiration


4. Boundary of responsibility between third-party services and built-in API keys

Platform built-in engine

When using the platform's built-in engine, the content will be sent to the corresponding supplier for translation processing. Third parties may handle requests and logs according to their policies.

Comes with API Key

When using the built-in API Key:

  • The request will be charged to your account and billing with the third-party service provider.

  • You need to ensure the key's permissions, limits, compliance, and access policies yourself.

  • In the event of data throttling, errors, regional restrictions, or billing disputes with third-party services, the third-party rules shall prevail.


5. Security Measures (Recommended "Minimum Necessary Disclosures")

The system typically takes the following measures to protect data security (retain/reduce based on your actual implementation):

  • Encrypted transmission (HTTPS/TLS)

  • The principle of least privilege: Access data only to the extent necessary for task execution and delivery.

  • Access control and auditing: restricting backend access and logging critical operations.

  • Sensitive information protection: Encrypt or mask the storage of bound credentials/keys.


6. User-friendly security best practices

  • Prioritize setting minimum permissions and limits for built-in API keys (to avoid misuse leading to high bills).

  • Rotate API keys regularly to avoid exposing them in public locations.

  • When a site enables security plugins/WAF, configure allow rules for callbacks and delivery interfaces (to avoid accidental blocking).

  • For page content containing sensitive information, it is recommended to use a more stringent internal review process before publishing.


7. Contact and Request

If needed:

  • Query data retention range

  • Request to export task records/consumption details

  • Report security issues or suspected leaks

Please submit your request through the support channel xiaoxiggnet@gmail.com, and provide the site identifier and time range for location assistance.

Email
info@savantlook.com
Wechat
xxxiaoxiyy