Europe Alternatives
DeepL logo

DeepL

German AI translation, writing and voice products. Self-operated GPU clusters, ISO 27001 and SOC 2 Type II certified.

🇩🇪 Germany

Profile last updated: · View sources

About DeepL

DeepL is a German AI translation and writing company headquartered in Cologne. The product range spans the consumer Translator, the AI writing assistant DeepL Write, the real-time DeepL Voice and Voice for Meetings tools (with Microsoft Teams and Zoom integrations), and the developer-facing Pro API. DeepL operates two NVIDIA-built supercomputers it has named Mercury (H100-based) and Arion -- the latter described as the first NVIDIA DGX SuperPOD with DGX GB200 systems in Europe.

The contracting entity for customers worldwide, including in North America, is DeepL SE (HRB 104617 Köln). The privacy policy commits to processing Pro and API Pro translation payloads exclusively on DeepL infrastructure in the European Economic Area. In April 2026 DeepL announced AWS as a subprocessor for global scale and removed the EU-exclusive default; customers with strict residency requirements can opt back into EU-only processing on contract. DeepL holds ISO/IEC 27001 certification and completed its first SOC 2 Type II audit in February 2024 covering all five trust service principles. Official SDKs in five languages are published under MIT licence on github.com/DeepLcom.

Features

  • AI translation across 30+ Translator UI languages and 36 API target language codes (130+ in extended API support)
  • DeepL Write -- AI writing assistant for clarity, tone and grammar (EN, DE, FR, ES, IT, PT)
  • DeepL Voice and Voice for Meetings -- real-time voice and caption translation with Microsoft Teams and Zoom integrations
  • DeepL Pro API with MIT-licensed first-party SDKs in .NET, Python, PHP, Node.js and Java
  • Self-operated NVIDIA GPU clusters (Mercury H100, Arion DGX SuperPOD GB200) for translation inference
  • Glossary feature for term consistency across translations
  • Native apps on Windows, macOS, iOS and Android, plus Chrome, Firefox and Edge extensions
  • Productivity integrations: Microsoft Word, Microsoft 365, Google Workspace, Outlook
  • Pro and API Pro translation payloads processed on DeepL infrastructure in the EEA (AWS expansion announced April 2026 with EU-only opt-in)
  • ISO/IEC 27001 certified plus SOC 2 Type II attested (February 2024) and HIPAA safeguards

Sovereignty Scorecard

Procurement-grade signals on data sovereignty, ownership, and EU residency.

The SHIELD framework

We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.

S
Subprocessors

The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.

H
Headquarters & ownership

Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.

I
Infrastructure & residency

Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.

E
Exposure

Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.

L
Legal documents

Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.

D
Diligence

Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.

Ownership

Venture-backed

European majority control

Privately-held venture-backed German Societas Europaea (SE). Most recently disclosed round: $300M in May 2024 led by Index Ventures at $2B valuation (with ICONIQ Growth, Teachers' Venture Growth, IVP, Atomico, WiL). Founder and sole executive named in the Impressum is Dr. Jaroslaw Kutylowski. Share register is not publicly disclosed; Handelsregister Auszug for HRB 104617 Köln is the authoritative source.

Headquarters

🇩🇪 Cologne, Germany

DeepL SE

Subsidiaries
  • DeepL AI GmbH 🇩🇪 GermanyGerman sister entity at the same Cologne address as DeepL SE. Listed as a possible employer in the candidate privacy notice; specific operational purpose not disclosed on deepl.com.
  • DeepL UK Ltd 🇬🇧 United KingdomUK operational entity (6th Floor, One London Wall, London EC2Y 5EB).
  • DeepL NL B.V. 🇳🇱 NetherlandsNetherlands operational entity (Amsterdam).
  • DeepL PL Sp. z o.o. 🇵🇱 PolandPolish operational entity (Wrocław, Pegaz Building B).
  • DeepL US Inc. 🇺🇸 United StatesUS HR-only entity registered in Delaware (2093A Philadelphia Pike, Suite 539, Claymont, DE 19703). Disclosed in the candidate privacy notice; not named as a controller or processor of customer translation data in the customer-facing terms.
  • DeepL Japan G.K. JapanJapanese operational entity (DeepL Japan 合同会社, Toranomon 4-3-20 Kamiyacho MT Bldg 14F, Minato-ku, Tokyo). Representative director: Kiyomitsu Takayama.
Data residency
EEA

Region selectable

Pro and API Pro translation payloads are processed exclusively on DeepL-operated infrastructure in the European Economic Area per the live privacy policy. In April 2026 DeepL announced AWS as a global subprocessor and dropped the EU-exclusive default for translation; customers with strict residency requirements can opt back into EU-only processing on contract. The Voice for Meetings bot is hosted on AWS or Microsoft (Ireland) per the privacy policy.

Hosting infrastructure

Website: Cloudflare (US-incorporated) in front of www.deepl.com (server: cloudflare, cf-ray and cf-cache-status headers confirmed)

Application: DeepL-owned NVIDIA GPU clusters at EcoDataCenter (Sweden) on DeepL-allocated AS60550 / 194.124.204.0/22 (RIPE org-record ORG-DS543-RIPE, DeepL SE Cologne)

Email: Google Workspace (MX terminator: smtp.google.com)

CDN: Cloudflare (marketing site); DeepL-operated 'acheron' ingress layer behind Cloudflare for the API

Subprocessors
NameCountryPurpose
Cloudflare, Inc.🇺🇸 United StatesWeb infrastructure, DNS and CDN in front of www.deepl.com
Amazon Web Services / Microsoft Ireland Operations Ltd.🇮🇪 IrelandCloud hosting for DeepL Voice for Meetings bot (per privacy policy); AWS expanding to global translation infrastructure announced April 2026
Stripe Payments Europe Ltd.🇮🇪 IrelandCard payment processing; may transfer billing metadata to Stripe, Inc. (United States)
Salesforce Germany GmbH🇩🇪 GermanyCRM and customer data, stored on EU servers (Munich)
Riskified Ltd. IsraelFraud prevention; may transfer to the United States
Zendesk, Inc.🇺🇸 United StatesCustomer support ticketing
HubSpot, Inc.🇺🇸 United StatesMarketing automation and CRM
Salesloft, Inc.🇺🇸 United StatesSales call recording and transcription
Zoom Video Communications, Inc.🇺🇸 United StatesWebinars and virtual events
Bettermode Inc. CanadaCommunity platform (EU to Canada under Commission adequacy decision)
Certifications
iso-27001
Certified

ISO/IEC 27001 certification confirmed on the DeepL Pro data security page and Write product page. Certificate body, scope and validity dates available on request via the SafeBase trust portal.

soc-2-type-2
Certified

First SOC 2 Type II report completed February 2024, covering all five trust service principles (security, availability, processing integrity, confidentiality, privacy). Full report available on sales request only.

hipaa
Self-assessed

HIPAA safeguards self-attested for healthcare customers; announced July 2025. Not a third-party certification.

US CLOUD Act exposure
Partial, via US subprocessors
Open source
Has open components
View source

Questions & Answers

6 questions

Who owns DeepL?

DeepL SE is a privately-held venture-backed German company. The most recently disclosed round was a $300 million raise in May 2024 led by Index Ventures at a $2 billion valuation, with participation from ICONIQ Growth, Teachers' Venture Growth, IVP, Atomico and WiL. A prior round in January 2023 valued the company at €1 billion (IVP, Bessemer Venture Partners, Atomico and WiL named on DeepL's own blog). DeepL does not publish its share register; the German Handelsregister Auszug for HRB 104617 (Amtsgericht Köln) is the authoritative source for the current ownership breakdown.

Where will my translation data be stored?

DeepL's privacy policy commits to processing Pro and API Pro translation payloads exclusively on DeepL-operated infrastructure in the European Economic Area. The translation models themselves run on DeepL-owned NVIDIA GPU clusters at the EcoDataCenter facility in Sweden, on a DeepL-allocated /22 IPv4 block on AS60550. In April 2026 DeepL announced AWS as a global subprocessor and dropped the EU-exclusive default; customers with strict residency requirements can request EU-only processing on contract. Ancillary flows -- billing, support, marketing analytics -- use US-incorporated subprocessors and may transfer related metadata outside the EEA under DPAs.

Is DeepL subject to the US CLOUD Act?

DeepL SE is the contracting entity for customers worldwide, including in North America. It is a German Societas Europaea registered as HRB 104617 in Cologne. DeepL operates a US subsidiary, DeepL US Inc. (Claymont, Delaware), but per the privacy policy this entity functions as an HR employer rather than as a controller or processor for customer translation data. Several DeepL subprocessors are US-incorporated and handle adjacent flows: Cloudflare for web infrastructure, Stripe for billing, HubSpot and Zendesk for marketing and support, and Zoom for webinars. Customer translation payload contracts with the German entity and is policy-promised to stay in the EEA on Pro and API Pro plans.

How do I obtain DeepL's DPA?

DeepL does not publish its DPA on a public URL. Per section 8.1.5 of the DeepL Pro Terms of Use, customers contract by emailing sales@deepl.com and signing the DeepL-provided agreement. DeepL also operates a Trust Center at trust.deepl.com (powered by SafeBase) that exposes the subprocessor list and security collateral after an NDA workflow.

What certifications and audits has DeepL completed?

DeepL is ISO/IEC 27001 certified and completed its first SOC 2 Type II audit in February 2024 covering all five trust service principles (security, availability, processing integrity, confidentiality, privacy). DeepL also implements HIPAA safeguards (self-attested, announced July 2025) for healthcare customers. GDPR compliance is claimed across the product. Certificate bodies, validity dates and the full report are available on request via the SafeBase trust portal under NDA.

How do I integrate DeepL?

DeepL publishes the official REST API documentation at developers.deepl.com and maintains MIT-licensed first-party SDKs on github.com/DeepLcom for .NET, Python, PHP, Node.js and Java, plus a command-line client (deepl-cli) and an MCP server (deepl-mcp-server). Two API endpoints exist: api-free.deepl.com for the free tier and api.deepl.com for paid Pro plans. Productivity integrations include Microsoft Word, Microsoft 365, Google Workspace, Outlook, and browser extensions for Chrome, Firefox and Edge.

Alternatives

Other European companies in the same category as DeepL.

Quick facts

Languages supported
Deutsch
English
Español
Français
Italiano
日本語
KO
Nederlands
Polski
Português
RU
TR
Українська
中文
Categories

Sources & verification

Every fact on this page is backed by a primary or independent source. Most recent verification: May 12, 2026.

Found an error? Report it

Citations

Profile content

Tagline
Description
Languages
  • primary · otherwww.deepl.com/en/translatorSite UI language switcher and translation-language enumeration on the marketing page
Features
Q&A
Integrations

Sovereignty (SHIELD)

SSubprocessors
  • primary · privacy-policywww.deepl.com/en/privacyFull subprocessor list disclosed inline in the privacy policy; complete enumeration also in the SafeBase trust portal after an NDA workflow
HHeadquarters
HOwnership
HSubsidiaries
IData residency
IHosting infrastructure
  • primary · http-headerswww.deepl.comcurl -I confirms Cloudflare via server: cloudflare, cf-ray and cf-cache-status headers; custom x-deepl-ingress-type: acheron header indicates internal ingress behind Cloudflare
  • primary · dns-recordswww.deepl.comdig api.deepl.com -> 194.124.204.71 in DeepL-allocated AS60550 / 194.124.204.0/22 (RIPE org DeepL SE, Cologne). MX records: smtp.google.com (Google Workspace)
  • primary · blogwww.deepl.com/en/blog/nvidia-gtc-story-continuesMercury (H100) and Arion (DGX SuperPOD GB200) hosted at EcoDataCenter
EUS CLOUD Act exposure
  • primary · impressumwww.deepl.com/en/publisherDeepL SE is the German contracting entity
  • primary · privacy-policywww.deepl.com/en/privacyMultiple US-incorporated subprocessors (Cloudflare, Stripe Inc., HubSpot, Zendesk, Zoom, UserTesting, Ethnio, Salesloft) handle ancillary flows -- basis for partial-via-subprocessors rather than none
  • primary · termswww.deepl.com/en/pro-license-enterprise-naEven the North America-specific terms still contract customers with DeepL SE (Cologne) -- no US legal entity acts as controller of customer translation data
LLegal documents
  • primary · impressumwww.deepl.com/en/publisherAll legal-doc URLs surfaced via the footer of deepl.com
  • primary · termswww.deepl.com/en/pro-licensePro Terms section 8.1.5 -- DPA URL is non-public; DPA obtained by emailing sales@deepl.com. Subprocessor list URL similarly non-public; full list behind the SafeBase NDA portal
DCertifications
DOpen source
  • primary · othergithub.com/DeepLcom35+ public repos; first-party SDKs MIT-licensed in .NET, Python, PHP, Node.js and Java