Transparency in data processing

Providers and subprocessors

Understand which providers may be involved, what they do and which information each may process.

European Union flag
Service requirement Document processing: storage and processing exclusively within the EU/EEA, in accordance with the GDPR.

This requirement covers OCR, classification, extraction and auditing, including AWS Bedrock and self-hosted servers. Global routing is disabled. We only enable services after verifying their contracts, configuration and locations; active providers are specified for each project.

Document processing

01

Only options with verified storage and processing within the EU/EEA are enabled. Providers and models are selected for each project; the residency requirement applies in every case.

Scroll the table to see all fields →

Always EU/EEA · Services selected by project
Provider Purpose Data it may process Location and conditions
MicrosoftAzure · Document Intelligence · Azure OpenAIPer project OCR, extraction, models and cloud resources. Documents, text, results and metadata for the contracted service. Only EU Document Intelligence resources and Azure OpenAI deployments with processing restricted to the EU and global routing disabled. Verification on a per-service basis.
Provider information ↗
Amazon Web ServicesTextract · Bedrock · InfrastructurePer project OCR, models and storage or processing. Documents, model requests, results and metadata. Only EU regions and EU-restricted Bedrock inference profiles, with global routing disabled. Model, storage and processing destinations verified before enabling the service.
Provider information ↗
Google Cloud ServicesDocument AI · Vertex AIPer project Reading, extraction, models and cloud services. Submitted documents or excerpts and structured results. Document AI in the EU multi-region or a supported EU region. EU processing must be verified separately for Vertex AI and other services.
Provider information ↗
Mistral AIMistral OCR · ModelsPer project OCR, classification, extraction and checks. Documents or text required for the contracted feature. Mistral OCR through Mistral's service; Mistral models through its API or AWS Bedrock. In both cases, only deployments with verified storage and processing within the EU/EEA, with global routing disabled.
Provider information ↗
Mistral on AWS Bedrock ↗
OpenAIAzure OpenAI · AWS BedrockPer project Analysis and information extraction using OpenAI models. Text, images or files included in requests. Azure OpenAI with a compatible EU regional deployment or OpenAI models available in AWS Bedrock with an EU region or EU-restricted inference profile. Only verified storage and processing within the EU/EEA, with global routing disabled. Each model and feature is verified.
Provider information ↗
OpenAI on AWS Bedrock ↗
AnthropicClaude · AWS BedrockPer project Analysis, classification and extraction using Claude models. Text, images or files included in requests. Claude models through AWS Bedrock, only with an EU region or EU-restricted inference profile. Storage and processing verified within the EU/EEA, with global routing disabled.
Provider information ↗
Claude on AWS Bedrock ↗
LlamaIndexLlamaParse / LlamaCloud · Bedrock integrationPer project Document parsing, structure and extraction. Files, extracted content and processing metadata. LlamaParse/LlamaCloud's EU deployment, integrated with AWS Bedrock models in EU regions or EU-restricted profiles. Document parsing and model processing remain within the EU/EEA, with global routing disabled. Both services are verified separately.
Provider information ↗
AWS Bedrock integration ↗
PostHogPostHog Cloud EUPer project Usage analytics and diagnostics, if included in the project. Technical events and analytics identifiers; captured content depends on configuration. Cloud EU instance in Frankfurt. Before enabling it, verify submitted data, capture settings, integrations, access and EU processing.
Provider information ↗
TelefónicaInfrastructure and managed servicesPer project Hosting, connectivity or cloud services depending on scope. Hosted data and technical metadata depending on the contracted service. Only services with facilities and processing within the agreed EU/EEA scope. The entity, product and specific locations are confirmed by contract.
Provider information ↗

The model developer and the service hosting it may be different. For example, using an OpenAI model through Azure or AWS Bedrock is different from contracting OpenAI’s direct API. Subprocessor chains are reviewed for the selected deployment.

Website and communications

02

These services are documented in the website’s privacy policy and configuration. Their role here is to support visits, enquiries and meetings; this does not make them subprocessors for your document processing.

The current website includes providers with international processing. This website directory is not covered by an EU/EEA-only residency assurance. Extending that requirement to all website services requires a separate configuration and contract review.

Scroll the table to see all fields →

Website and communications providers
Provider Purpose Data it may process Location and conditions
CloudflarePages · CDNWebsite and contact Website hosting, page delivery and traffic protection. IP address, technical browsing data and form requests. Global network; locations and safeguards depend on the contracted service.
Provider information · Cloudflare ↗
Microsoft 365Business emailWebsite and contact Receipt and handling of communications. Contact details, content and attachments supplied by email. According to the tenant region and applicable Microsoft 365 terms.
Provider information · Microsoft 365 ↗
CalendlySchedulingWebsite and contact Checking availability and booking meetings. Technical data and information supplied for the booking. May involve international transfers. Connects when the calendar is opened.
Provider information · Calendly ↗
Google AnalyticsGA4Website and contact Website usage measurement when analytics cookies are accepted. Browsing events and analytics identifiers. Under Google Analytics terms; activated only with consent.
Provider information · Google Analytics ↗

Read the privacy policy →

Local processing

03

Paperless-ngx, LiteParse, Docling and MinerU can run in an environment controlled by MestrIA or the customer, always within the EU/EEA, including backups and connected services. Using the software locally does not, by itself, make its developers recipients of the documents.

Paperless-ngx

Self-hosted document management, indexing and archiving. The server, backups and connected services must remain within the agreed deployment in the EU/EEA.

Software documentation ↗

LlamaIndex

LiteParse Self-hosted

Local PDF parsing, text extraction and optional OCR, without requiring a cloud service. Runs on MestrIA or customer-controlled servers within the agreed deployment in the EU/EEA.

Software documentation ↗

Docling

Document reading and structuring in the selected environment. If external models or services are connected, their providers are identified too.

MinerU

OCR and document conversion in the selected environment. Hosting, access and external connections depend on the deployment.

Infrastructure or support providers that have access to data must also be identified when the software runs on private servers.

Selection and changes

04

When MestrIA processes data on behalf of a customer, subprocessor selection is governed by the data processing agreement and agreed instructions.

  1. Define the service

    Identify the provider entity, purpose, necessary data, storage location and processing location.

  2. Agree the conditions

    Specify the processing agreement, access, retention, deletion and safeguards for any transfers.

  3. Manage additions

    The GDPR requires prior specific or general written authorisation; general authorisation requires notice of intended changes and an opportunity to object. Channels and timeframes are defined in the applicable agreement.

Article 28 GDPR ↗