Last updated: 5 August 2026
1. General information
This Privacy Policy explains how OAKDYNE LIMITED collects, uses, stores, discloses, and protects personal data when you visit or use https://oakscribe.com or https://dynevox.com, create an account, request or purchase Services, upload Source Materials, communicate with us, or otherwise interact with the Platform.
OAKDYNE LIMITED is a company incorporated in England and Wales under company number 16913553, with its registered office at 22-28 Wood Street, Doncaster, England, DN1 3LW. In this Privacy Policy, OAKDYNE LIMITED is referred to as the "Company", "we", "us", or "our".
The terms "you" and "User" refer to any individual who visits either Website, creates or operates an account, submits information or Source Materials, places or manages an Order, makes a payment, contacts support, acts on behalf of a Client, or otherwise uses the Platform or Services.
For personal data processed in connection with the operation of the Websites, User accounts, Orders, payments, support, and provision of the Services, the Company generally acts as the data controller. In certain circumstances, particularly where a business Client submits personal data contained in Source Materials and determines the purposes for which that data is processed, the Client may act as the controller and the Company may process that data on the Client's behalf for the purpose of providing the Services.
Where the Company processes personal data on behalf of a business Client, requests relating to that data may need to be directed to the relevant Client as the controller. The Company will assist the Client where required by applicable data-protection law and the applicable contractual arrangements.
We process personal data to operate the Websites and Platform, create and administer User accounts, assess and manage Orders, provide written translation and content adaptation Services, coordinate work with independent Service Performers, process payments, arrange Delivery, provide customer support, respond to complaints and revision requests, maintain records, protect accounts and systems, prevent fraud and misuse, comply with legal obligations, and improve the operation and quality of the Services.
Depending on the relevant processing activity, we rely on one or more lawful bases, including performance of a contract or steps taken before entering into a contract, compliance with legal obligations, the legitimate interests of the Company or a third party, and consent where consent is required by applicable law.
We process personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, and other applicable data protection laws.
By using the Websites or Services, you acknowledge that personal data will be processed as described in this Privacy Policy. This acknowledgement does not replace consent where applicable law requires separate consent.
Terms defined in the Terms and Conditions have the same meaning in this Privacy Policy unless expressly stated otherwise.
The Company may update this Privacy Policy where necessary to reflect changes in the Websites, Services, processing activities, service providers, security measures, legal obligations, or business operations. The updated version will be published on the Websites with a revised "Last updated" date. Material changes may also be communicated by email, through the Platform, or by another reasonable method where appropriate.
2. Personal data we collect
Depending on how you use the Websites and Services, the Company may collect account and identity information, contact details, company and billing information, Order details, Source Materials and Translated Materials, project instructions, support communications, payment and transaction information, device and technical data, security and fraud-prevention information, cookie data, and translator application information.
Personal data may be collected directly from you, generated through your use of the Websites and Platform, included in Source Materials submitted by a Client, or received from payment providers, security providers, Service Performers, and other service providers supporting the Services.
Source Materials may contain personal data relating to the Client or other individuals. The categories of such data depend on the content submitted by the Client and may include names, contact details, professional information, identification information, financial information, health-related information, or other confidential data.
Source Materials may also contain special category personal data where the Client has a lawful basis and proper authority to submit it. The Company processes such data only where necessary to provide the relevant Services and where an applicable condition for processing is available under data-protection law.
The Company does not directly collect or store complete payment card numbers or card security codes.
3. Cookies and similar technologies
The Websites use cookies and similar technologies to operate the Platform, maintain secure User sessions, support account functions, process Orders, enable file uploads, remember preferences, protect the Websites against misuse, and understand how Users interact with Platform features.
Cookies are small data files stored on a User's device when a Website is accessed. Similar technologies may include local storage, pixels, tags, software development kits, or other technical identifiers used for comparable purposes.
Strictly necessary cookies may be placed without consent where they are required to provide functions requested by the User, maintain account security, authenticate sessions, process forms, support checkout, prevent fraudulent activity, or ensure the basic operation of the Websites.
Optional cookies, including analytics, functionality, marketing, or referral cookies, will be used only where permitted by applicable law and, where required, after the User has provided consent through the cookie preferences tool.
Cookies and similar technologies may be used to maintain login sessions, protect forms against unauthorised submissions, remember interface and language preferences, monitor Website performance, identify technical errors, understand navigation and use of Platform features, measure referral or campaign performance, and detect unusual or potentially fraudulent activity.
The Company does not use cookies for the purpose of collecting special category personal data or creating advertising profiles based on sensitive personal information.
Where analytics or marketing providers receive information through cookies or similar technologies, they may process device information, browser details, IP address, approximate location, referral source, session activity, page interactions, and technical identifiers in accordance with their own privacy documentation and the instructions or settings applied by the Company.
You may accept, reject, or manage optional cookies through the cookie banner or preference centre made available on the Websites. You may also restrict or delete cookies through your browser settings.
Disabling strictly necessary cookies may prevent certain Platform functions from operating correctly, including secure login, account access, Order submission, file uploads, checkout, support forms, and access to Order status or delivered materials.
Your cookie preferences may be stored for a reasonable period so that the Websites can remember your selection. You may change or withdraw your consent to optional cookies at any time through the available cookie settings.
The categories, providers, purposes, and retention periods of cookies may change as the Websites, security measures, and technical integrations are updated. The Company will update the cookie information where material changes occur.
4. Cookie information
| Cookie or identifier | Purpose | Category | Retention |
|---|---|---|---|
| session_id | Maintains the User's active session and authentication status | Strictly necessary | Session |
| csrf_token | Protects forms and account functions against unauthorised cross-site requests | Strictly necessary / Security | Session |
| lang_pref | Remembers the User's selected Website or interface language | Functionality | Up to 6 months |
| device_id | Supports account security, fraud prevention, and detection of unusual activity | Security | Up to 12 months |
| _ga | Distinguishes Website Users for analytics and usage measurement | Analytics | Up to 2 years |
| _gid | Supports short-term analytics and session measurement | Analytics | Up to 24 hours |
| _gat | Limits the rate of requests sent to analytics services | Analytics / Performance | Up to 1 minute |
| marketing_id | Measures referral sources or marketing campaign performance | Marketing | Up to 12 months |
5. Use of personal data
The Company processes personal data only where necessary to operate the Websites and Platform, provide the Services, manage User accounts and Orders, communicate with Users, protect the Platform, prevent fraud and misuse, comply with legal obligations, and support the Company's legitimate business operations.
Depending on the processing activity, the Company may rely on performance of a contract, steps taken before entering into a contract, compliance with a legal obligation, legitimate interests, or consent where required by applicable law.
Contractual necessity generally applies to account administration, Order processing, payment coordination, Service performance, Delivery, support, and complaint handling. Legitimate interests may apply to Platform security, fraud prevention, service administration, record keeping, and the establishment or defence of legal claims. Legal obligation applies where processing is required for tax, accounting, regulatory, or other statutory purposes. Consent is used where required for optional cookies or marketing communications.
Personal data may be used to create, administer, verify, and secure User accounts. This includes registration, login, authentication, password recovery, account management, contact-detail updates, and detection of unusual or unauthorised account activity.
The Company processes personal data to assess quotation requests, review Source Materials, confirm project requirements, accept and manage Orders, process payments, coordinate work with independent Service Performers, conduct quality-control procedures, arrange Delivery, and provide revisions, refunds, or other remedies where applicable.
Source Materials may contain personal data relating to the Client or other individuals. Such data is processed only to the extent reasonably necessary to assess and perform the relevant Order, review the Translated Materials, provide support, resolve complaints, maintain security, and comply with legal obligations.
Where a business Client determines the purpose and means of processing personal data contained in Source Materials, the Client is responsible for ensuring that it has a lawful basis and the necessary authority to submit that data. In such circumstances, the Company may process the data on the Client's behalf for the purpose of providing the Services.
Personal data may be shared with independent Service Performers and quality reviewers only where access is reasonably necessary for the relevant Order. The Company seeks to limit access to the materials and information required for the assigned task.
The Company may use translation-management systems, terminology tools, formatting software, automated quality checks, and AI-assisted tools as supporting technologies. Where Client materials are processed through such tools, they are used only to assess, perform, review, secure, or deliver the relevant Order. Client materials are not used for unrelated advertising, public disclosure, or general model training without the Client's authorisation or another valid legal basis.
Personal data may also be processed to provide customer support and respond to questions concerning accounts, quotations, Orders, payments, file uploads, Delivery, revisions, refunds, complaints, or technical problems.
The Company may send essential operational and administrative communications, including account-verification messages, password-reset instructions, Order confirmations, payment notifications, requests for clarification, Delivery updates, security notices, support responses, and material changes to applicable policies or Services.
Such communications are necessary for the operation of the Platform or performance of the Services and are not treated as marketing communications.
Where the Company sends promotional or marketing communications, it will do so only where permitted by applicable law. Users may withdraw consent or opt out of such communications using the method provided in the relevant message.
Personal data may be processed to detect and prevent fraud, unauthorised payments, account compromise, malicious files, abusive activity, chargebacks, misuse of refund or complaint procedures, attempts to bypass Platform controls, and other security or compliance risks.
The Company may also process personal data to maintain accounting and transaction records, establish or defend legal claims, enforce the Terms and Conditions and Acceptable Use Policy, respond to lawful requests, and comply with tax, regulatory, data-protection, sanctions, or other legal obligations.
In limited circumstances, personal data may be processed to protect vital interests where this is necessary to prevent serious harm, respond to an emergency, or address an urgent safety or security issue.
6. Sharing of personal data
The Company does not sell personal data.
The Company does not disclose personal data to third parties for their own unrelated advertising or commercial purposes.
Personal data may be shared only where reasonably necessary to operate the Websites and Platform, provide the Services, manage Orders and payments, maintain security, comply with legal obligations, or protect the rights and legitimate interests of the Company, Users, Service Performers, and third parties.
Recipients may include authorised Company personnel, independent Service Performers, quality reviewers, payment providers, acquiring institutions, banks, hosting and cloud providers, file-storage and file-processing providers, communication and email providers, account-authentication providers, analytics providers, security and fraud-prevention providers, technical support providers, professional advisers, insurers, auditors, and other processors or subcontractors supporting the Platform or Services.
Independent Service Performers receive access only to the information and Source Materials reasonably necessary for the relevant assignment. They are expected to comply with applicable confidentiality, security, and data-protection obligations.
Payment providers may receive billing details, transaction information, device information, authentication data, and fraud-prevention information necessary to process or review a payment. The Company does not directly store complete payment card numbers or card security codes.
Service providers processing personal data on the Company's behalf are expected to act under appropriate contractual, confidentiality, security, and data-protection requirements and to use the data only for the agreed purposes.
Personal data may be disclosed where required by applicable law, regulation, court order, legal process, or a lawful request from a competent authority.
The Company may also disclose personal data where reasonably necessary to investigate or prevent fraud, unauthorised activity, security incidents, payment disputes, chargebacks, unlawful conduct, or violations of the Terms and Conditions or Acceptable Use Policy.
Where reasonably necessary, personal data may be shared to establish, exercise, or defend legal claims, protect the rights, property, security, or legitimate interests of the Company or another person, or prevent serious harm.
In connection with a merger, acquisition, restructuring, financing, insolvency process, sale of assets, transfer of business, or similar corporate transaction, personal data may be disclosed to prospective or actual purchasers, advisers, financiers, or other relevant parties. Any such disclosure will remain subject to applicable confidentiality and data-protection requirements.
7. International data transfers
The Company operates from the United Kingdom, but personal data may be processed in other countries where independent Service Performers, cloud providers, hosting providers, payment providers, communication providers, analytics providers, security providers, or other service providers are located.
These countries may have data-protection laws that differ from those applicable in the United Kingdom or European Economic Area.
The Company transfers personal data internationally only where reasonably necessary to operate the Platform, provide the Services, manage Orders, process payments, maintain security, provide support, or comply with legal obligations.
Where personal data is transferred outside the United Kingdom, the Company will use a transfer mechanism recognised under applicable UK data-protection law. This may include transfer to a country covered by UK adequacy regulations, use of the UK International Data Transfer Agreement, use of the UK Addendum to approved standard contractual clauses, or another lawful safeguard.
Where personal data subject to the EU GDPR is transferred outside the European Economic Area, the Company may rely on an adequacy decision, standard contractual clauses approved by the European Commission, or another legally recognised transfer mechanism.
The Company may also apply supplementary technical, organisational, or contractual measures where reasonably necessary, taking into account the nature of the data, the destination country, and the risks associated with the transfer.
Access to personal data by Service Performers and service providers is limited to what is reasonably necessary for the relevant purpose.
The Company does not sell personal data as part of an international transfer.
Users may contact the Company using the details provided in this Privacy Policy to request further information about the safeguards applied to international transfers.
8. Data retention
The Company retains personal data only for as long as reasonably necessary for the purposes for which it was collected, including operating the Websites and Platform, providing the Services, administering User accounts and Orders, processing payments, arranging Delivery, providing support, resolving complaints, maintaining security, preventing fraud and misuse, and complying with legal obligations.
Source Materials, Translated Materials, project instructions, communications, and other data connected with a completed Order may generally be retained for up to twelve months after completion of the relevant Order.
A shorter period may apply where the data is no longer required. A longer period may apply where retention is reasonably necessary for legal or regulatory compliance, accounting and tax obligations, payment disputes, chargebacks, fraud prevention, security investigations, complaint handling, enforcement of agreements, legal claims, evidence preservation, or protection of the Company or third parties.
Account information may be retained while the account remains active and afterwards for the period reasonably necessary to maintain transaction and support records, prevent repeated misuse, resolve disputes, and comply with applicable accounting, tax, and legal obligations.
Payment and transaction records may be retained for the periods required by applicable accounting, tax, anti-fraud, payment-processing, and legal requirements. The Company does not directly retain complete payment card numbers or card security codes.
Technical, security, device, log, and usage data is retained only for as long as reasonably necessary to protect the Platform, investigate incidents, prevent fraud, maintain system performance, resolve technical issues, and comply with legal obligations.
Cookie and analytics data is retained in accordance with the periods described in the Cookies and Similar Technologies section and the settings of the relevant provider.
Where a Website allows individuals to apply as Service Performers, application information may be retained while the application is assessed and for a reasonable period afterwards for administration, fraud prevention, future project consideration, and legal compliance.
When personal data is no longer required, the Company will delete it, anonymise it, remove it from active systems, or place it into restricted archival storage, subject to applicable technical and legal requirements.
Backup copies may remain for a limited period until they are overwritten or securely deleted in accordance with the Company's backup procedures.
9. Security of personal data
The Company applies reasonable technical, organisational, and operational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, misuse, or other unlawful processing.
Security measures are selected with regard to the nature of the personal data, the purposes of processing, available technology, and the level of risk involved.
Such measures may include access controls, authentication requirements, account-security procedures, encryption where appropriate, secure communication and storage environments, system monitoring, logging, backups, malware protection, incident-management procedures, and confidentiality requirements.
Access to personal data is limited on a need-to-know basis to authorised Company personnel, independent Service Performers, quality reviewers, and service providers who reasonably require the relevant information for an Order, assignment, support request, or operational function.
Service Performers and service providers with access to personal data are expected to comply with applicable confidentiality, data-protection, and security obligations.
The Company reviews security measures and may update them in response to changes in technology, processing activities, legal requirements, identified risks, or security incidents.
No internet transmission, email service, cloud environment, electronic communication, or data-storage system can be guaranteed to be completely secure. Users should therefore avoid submitting information that is not reasonably necessary for the Services.
Users are responsible for keeping their account credentials, devices, authentication methods, and registered email accounts secure. Users must promptly notify the Company if they suspect unauthorised access, account compromise, loss of credentials, or unusual activity.
Security notifications relating to Oakscribe accounts should be sent to support@oakscribe.com. Security notifications relating to Dynevox accounts should be sent to support@dynevox.com.
Where the Company becomes aware of a personal data breach, it will assess the incident and take appropriate steps in accordance with applicable law. Where legally required, the Company will notify the relevant supervisory authority and affected individuals.
10. Your data protection rights
Depending on the applicable law and the circumstances of the processing, you may have rights in relation to your personal data.
You may request confirmation of whether the Company processes personal data relating to you and request access to that data, together with information about how it is processed.
You may request correction of personal data that is inaccurate or completion of personal data that is incomplete.
In certain circumstances, you may request deletion of your personal data. The right to deletion does not apply where continued processing is required for legal compliance, performance of an ongoing contract, fraud prevention, dispute resolution, legal claims, or another lawful purpose.
You may request restriction of processing in circumstances provided by applicable law, including while the accuracy of personal data or the lawfulness of processing is being reviewed.
You may object to processing based on the Company's legitimate interests. The Company may continue processing where it demonstrates compelling legitimate grounds or where processing is required for legal claims.
You have the right to object at any time to the use of personal data for direct marketing. The Company will stop such processing after receiving a valid objection.
Where applicable, you may request to receive personal data you provided to the Company in a structured, commonly used, and machine-readable format and may request its transmission to another controller where technically feasible.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out lawfully before consent was withdrawn.
You may request information about safeguards used for international transfers of your personal data.
You may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The Company does not intend to make such decisions solely through automated processing in connection with ordinary provision of the Services.
These rights may be subject to legal conditions, exemptions, identity-verification requirements, and the rights of other individuals.
11. Exercising your rights
Requests concerning personal data processed through Oakscribe should be sent to support@oakscribe.com. Requests concerning personal data processed through Dynevox should be sent to support@dynevox.com.
The request should identify the relevant account or interaction and clearly describe the right the User wishes to exercise.
The Company may request additional information where reasonably necessary to confirm identity, prevent unauthorised disclosure, identify the relevant data, or verify that the requester is entitled to exercise the relevant right.
The Company will respond within the period required by applicable law. Under the UK GDPR, this will generally be within one month after receiving a valid request, although the period may be extended where permitted by law because of the complexity or number of requests.
Requests will generally be handled without charge. The Company may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, to the extent permitted by applicable law.
The Company may be unable to comply fully with a request where personal data must be retained or processed for legal obligations, ongoing Orders, accounting or tax requirements, fraud prevention, security, payment disputes, chargebacks, complaints, legal claims, or protection of the rights of others.
Where the Company refuses or limits a request, it will provide an explanation where required by applicable law.
12. Complaints to a supervisory authority
If you believe that the Company has processed your personal data in breach of applicable data-protection law, you may contact the Company using the relevant support address so that the matter can be reviewed.
You also have the right to lodge a complaint with a competent supervisory authority.
In the United Kingdom, the supervisory authority is the Information Commissioner's Office.
Where the EU GDPR applies, you may also be entitled to complain to the supervisory authority in the European Economic Area country where you reside, work, or believe an infringement occurred.
13. Age requirements
The Websites, Platform, and Services are intended only for individuals who are at least eighteen years old and who have the legal capacity required to enter into binding agreements.
The Company does not knowingly allow minors to create accounts, place Orders, make payments, or use the Services.
If the Company reasonably believes that an account is being used by a person under eighteen years of age, it may request verification, restrict access, cancel pending Orders, or close the account.
Source Materials submitted by a Client may contain personal data relating to minors where the Client has a lawful basis and proper authority to submit that information for translation. In such circumstances, the Client remains responsible for ensuring that the disclosure and processing are lawful and limited to what is necessary.
If a parent, guardian, or another person believes that a minor has directly provided personal data to the Company without a valid legal basis, they should contact support@oakscribe.com or support@dynevox.com, depending on the relevant Website.
Where the Company confirms that personal data relating to a minor was collected directly without a valid legal basis, it will take reasonable steps to delete, restrict, or otherwise lawfully address that data.
14. Legal disclosures
The Company may disclose personal data where required by applicable law, court order, regulatory requirement, or a lawful request from a competent authority.
The Company may also disclose personal data where reasonably necessary to investigate fraud or security incidents, enforce its legal rights, establish or defend legal claims, or protect the rights, property, or safety of the Company or another person.
Any disclosure will be limited to the personal data reasonably necessary for the relevant purpose and made in accordance with applicable data-protection law.
15. Changes to this Privacy Policy
The Company may update this Privacy Policy to reflect changes in the Websites, Platform functionality, Services, processing activities, service providers, security measures, legal obligations, regulatory requirements, or business operations.
The current version will be published on https://oakscribe.com and https://dynevox.com with an updated "Last updated" date.
Unless otherwise stated, changes will take effect from the date on which the revised Privacy Policy is published.
Where a change materially affects how personal data is collected, used, shared, retained, or otherwise processed, the Company may provide additional notice through the Platform, by email, through a Website notice, or by another reasonable method.
Where applicable law requires consent for a new processing activity, the Company will request that consent separately.
Continued use of the Websites or Services after an updated Privacy Policy takes effect constitutes acknowledgement of the revised notice. It does not constitute consent where applicable law requires separate and specific consent.
Contact information
Operator and data controller: OAKDYNE LIMITED
Company number: 16913553
Registered office: 22-28 Wood Street, Doncaster, England, DN1 3LW
Websites: https://oakscribe.com and https://dynevox.com
Oakscribe privacy and support enquiries: support@oakscribe.com
Dynevox privacy and support enquiries: support@dynevox.com
Phone: +44 7520 467294
Privacy requests should be sent to the address associated with the Website through which the relevant account, Order, or interaction occurred. Where the relevant Website cannot be identified, the request may be sent to either support address and will be routed internally.
