Paperless-ngx
Self-hosted document management, indexing and archiving. The server, backups and connected services must remain within the agreed deployment in the EU/EEA.
Understand which providers may be involved, what they do and which information each may process.
This requirement covers OCR, classification, extraction and auditing, including AWS Bedrock and self-hosted servers. Global routing is disabled. We only enable services after verifying their contracts, configuration and locations; active providers are specified for each project.
Only options with verified storage and processing within the EU/EEA are enabled. Providers and models are selected for each project; the residency requirement applies in every case.
Scroll the table to see all fields →
| Provider | Purpose | Data it may process | Location and conditions |
|---|---|---|---|
|
|
OCR, extraction, models and cloud resources. | Documents, text, results and metadata for the contracted service. |
Only EU Document Intelligence resources and Azure OpenAI deployments with processing restricted to
the EU and global routing disabled. Verification on a per-service basis. Provider information ↗ |
|
|
OCR, models and storage or processing. | Documents, model requests, results and metadata. |
Only EU regions and EU-restricted Bedrock inference profiles, with global routing disabled. Model,
storage and processing destinations verified before enabling the service. Provider information ↗ |
|
|
Reading, extraction, models and cloud services. | Submitted documents or excerpts and structured results. |
Document AI in the EU multi-region or a supported EU region. EU processing must be verified
separately for Vertex AI and other services. Provider information ↗ |
|
|
OCR, classification, extraction and checks. | Documents or text required for the contracted feature. |
Mistral OCR through Mistral's service; Mistral models through its API or AWS Bedrock. In both
cases, only deployments with verified storage and processing within the EU/EEA, with global
routing disabled. Provider information ↗ Mistral on AWS Bedrock ↗ |
|
|
Analysis and information extraction using OpenAI models. | Text, images or files included in requests. |
Azure OpenAI with a compatible EU regional deployment or OpenAI models available in AWS Bedrock
with an EU region or EU-restricted inference profile. Only verified storage and processing within
the EU/EEA, with global routing disabled. Each model and feature is verified. Provider information ↗ OpenAI on AWS Bedrock ↗ |
|
|
Analysis, classification and extraction using Claude models. | Text, images or files included in requests. |
Claude models through AWS Bedrock, only with an EU region or EU-restricted inference profile.
Storage and processing verified within the EU/EEA, with global routing disabled. Provider information ↗ Claude on AWS Bedrock ↗ |
|
|
Document parsing, structure and extraction. | Files, extracted content and processing metadata. |
LlamaParse/LlamaCloud's EU deployment, integrated with AWS Bedrock models in EU regions or
EU-restricted profiles. Document parsing and model processing remain within the EU/EEA, with
global routing disabled. Both services are verified separately. Provider information ↗ AWS Bedrock integration ↗ |
|
|
Usage analytics and diagnostics, if included in the project. | Technical events and analytics identifiers; captured content depends on configuration. |
Cloud EU instance in Frankfurt. Before enabling it, verify submitted data, capture settings,
integrations, access and EU processing. Provider information ↗ |
|
|
Hosting, connectivity or cloud services depending on scope. | Hosted data and technical metadata depending on the contracted service. |
Only services with facilities and processing within the agreed EU/EEA scope. The entity, product
and specific locations are confirmed by contract. Provider information ↗ |
The model developer and the service hosting it may be different. For example, using an OpenAI model through Azure or AWS Bedrock is different from contracting OpenAI’s direct API. Subprocessor chains are reviewed for the selected deployment.
These services are documented in the website’s privacy policy and configuration. Their role here is to support visits, enquiries and meetings; this does not make them subprocessors for your document processing.
The current website includes providers with international processing. This website directory is not covered by an EU/EEA-only residency assurance. Extending that requirement to all website services requires a separate configuration and contract review.
Scroll the table to see all fields →
| Provider | Purpose | Data it may process | Location and conditions |
|---|---|---|---|
|
|
Website hosting, page delivery and traffic protection. | IP address, technical browsing data and form requests. |
Global network; locations and safeguards depend on the contracted service. Provider information · Cloudflare ↗ |
|
|
Receipt and handling of communications. | Contact details, content and attachments supplied by email. |
According to the tenant region and applicable Microsoft 365 terms. Provider information · Microsoft 365 ↗ |
|
|
Checking availability and booking meetings. | Technical data and information supplied for the booking. |
May involve international transfers. Connects when the calendar is opened. Provider information · Calendly ↗ |
|
|
Website usage measurement when analytics cookies are accepted. | Browsing events and analytics identifiers. |
Under Google Analytics terms; activated only with consent. Provider information · Google Analytics ↗ |
Paperless-ngx, LiteParse, Docling and MinerU can run in an environment controlled by MestrIA or the customer, always within the EU/EEA, including backups and connected services. Using the software locally does not, by itself, make its developers recipients of the documents.
Self-hosted document management, indexing and archiving. The server, backups and connected services must remain within the agreed deployment in the EU/EEA.
Local PDF parsing, text extraction and optional OCR, without requiring a cloud service. Runs on MestrIA or customer-controlled servers within the agreed deployment in the EU/EEA.
Document reading and structuring in the selected environment. If external models or services are connected, their providers are identified too.
OCR and document conversion in the selected environment. Hosting, access and external connections depend on the deployment.
Infrastructure or support providers that have access to data must also be identified when the software runs on private servers.
When MestrIA processes data on behalf of a customer, subprocessor selection is governed by the data processing agreement and agreed instructions.
Identify the provider entity, purpose, necessary data, storage location and processing location.
Specify the processing agreement, access, retention, deletion and safeguards for any transfers.
The GDPR requires prior specific or general written authorisation; general authorisation requires notice of intended changes and an opportunity to object. Channels and timeframes are defined in the applicable agreement.