Compliance at ConveyThis
Last updated: 25 August 2026.
This page describes our position on HIPAA, GDPR and where your data is stored. It is a factual statement of what we do — not a certification, and not a promise of any particular regulatory status. If you need something in writing for a procurement or vendor-review process, email [メールアドレス] and ask.
HIPAA
HIPAA (the Health Insurance Portability and Accountability Act) sets United States privacy and security standards protecting patients’ medical records and other health information held by health plans, doctors, hospitals and other health care providers.
ConveyThis is not a covered entity under HIPAA. If you are a covered entity, or a business associate of one, and your website contains protected health information (PHI) that will pass through our service, then we act as your business associate — and that relationship must be governed by a signed ビジネスアソシエイト契約(BAA).
We will sign a BAA on request. メール [メールアドレス] before you send any PHI through the service. Until a BAA is executed between us, you should not use ConveyThis to process PHI.
The controls below are the ones we operate. They are not, by themselves, a HIPAA certification — no such certification exists — but they are what a BAA would commit us to:
- Security incidents – We track unauthorized access attempts in order to reduce risk and exposure to outside network attacks and malware.
- Access management – Requests to and from our servers are made over HTTPS using TLS 1.2 or TLS 1.3, with modern cipher suites. Earlier protocol versions are not accepted.
- Encryption – Our infrastructure is a multitenant cloud solution with the ability to segregate data by tenant on a dedicated instance. User information is encrypted in the ConveyThis database.
- Key management – Our key management service uses Hardware Security Modules to protect key material.
- Logging and audit controls – HTTPS is the only form of communication accepted by the ConveyThis API, and the certificate can be validated in the client’s browser. Security incidents are escalated to senior technical staff and, where they are confirmed to be genuine, logged in our internal ticketing system for mitigation.
- Monitoring – We monitor the servers and network hardware the application runs on. Role-based access control can be used to restrict access to users who should not be able to see PHI.
- Incident notification – Security incidents are communicated to administrators by email, text or phone, and must be acknowledged to close; unacknowledged notifications escalate to additional administrators.
Our security programme is modelled on the control areas of ISO/IEC 27001 — personnel security, product security, cloud and network infrastructure security, continuous monitoring and vulnerability management, physical security, business continuity and disaster recovery, third-party security, and security compliance. We are not ISO 27001 certified and we do not hold a SOC 2 report. We would rather tell you that plainly than imply otherwise.
GDPR
The EU General Data Protection Regulation gives individuals rights over their personal data, and places obligations on the organisations that handle it. We apply those rights to everyone who uses ConveyThis, not only to users in the EU.
- 私たちの 個人情報保護方針 explains what we collect, why, and what we do with it.
- 私たちの クッキーポリシー explains the tracking technologies used on our website.
- You can update your communication preferences, or close your account entirely, from your dashboard at any time.
- To exercise a data-protection right — access, correction, deletion, portability, or objection — email [メールアドレス] and we will respond.
When ConveyThis translates your website, we are acting as a processor on your behalf, and you are the controller of your visitors’ personal data. If you need a Data Processing Agreement, a list of our sub-processors, or details of our transfer safeguards, email [メールアドレス].
Where your data is stored
ConveyThis runs on infrastructure in the United States, Canada and Germany. Our translation platform and dashboard are hosted in the United States; parts of our website delivery and proxy infrastructure run in Germany and Canada.
Translation itself is performed by machine-translation providers we call on your behalf — currently Google, Google Gemini, DeepL, Microsoft, Yandex and OpenAI, alongside our own in-house translation model. Those providers operate their own infrastructure in their own regions.
If your organisation has a data-residency requirement, tell us what it is before you sign up, at [メールアドレス] — we would rather establish whether we can meet it than have you discover later that we cannot.
質問
For anything about HIPAA, privacy, GDPR or compliance at ConveyThis, contact us directly at [メールアドレス].
