Where your documents go, and who can compel them
Most EU-only claims describe where bytes sit and stop there. The harder question is whose courts can reach them. Both answers are on this page, including the parts that do not flatter us.
Last reviewed 2026-08-28 · reviewed again before launch
Two questions, not one
1 · Where is it processed?
Residency. Which racks, in which country. This is the question every vendor answers, because it is the easy one.
2 · Who controls the processor?
Jurisdiction. A US-incorporated company can be ordered under the CLOUD Act to produce data in its possession, custody or control — including data held by a foreign subsidiary.
A vendor can pass the first and fail the second. That is the failure mode worth watching, and it catches both providers below — which is why they are listed with their owners rather than just their addresses.
The chain, in full
Two providers touch documents. Both are EU-incorporated and both offer an Article 28 DPA. Neither is EU-controlled, and that distinction is the point of this table.
| Provider | Role | Incorporated | Processing | Controlled by |
|---|---|---|---|---|
| Contabo GmbH | Hosting and compute | Munich, DE | Germany | KKR & Co. Inc. — New York, majority since June 2022 |
| Mistral AI | Model inference for hard pages | Paris, FR | EU endpoint | Independent, France |
Mistral's own sub-processors, in scope for the API
Published because a chain is only as short as its longest link. Taken from Mistral's trust centre; they list 25 in total, of which these are scoped to the API path.
| Sub-processor | Role | Location | Note |
|---|---|---|---|
| Mistral Compute | Cloud infrastructure | France | — |
| CoreWeave Inc. | Inference provider | EEA | US-incorporated |
| Cloudflare Inc. | Traffic routing | Worldwide | US-incorporated, in the request path |
| CrowdStrike Inc. | Security | EEA, US | US-incorporated |
| Ory Corp. | Authentication | BE, DE | — |
| Sentry | Error handling | EEA | US-incorporated |
| Stripe Inc. | Billing | US | Billing metadata only |
| Twilio Inc. | Phone verification | US | Account data only |
Two entries deserve singling out. CoreWeave is the inference provider — US-incorporated, sitting at the most sensitive point in the pipeline. Cloudflare routes Mistral's traffic worldwide, so documents transit a US company the moment they leave our box for theirs. We refuse Cloudflare's proxy in front of our own server, which removes one hop we control; it does not remove that one.
What is kept, and for how long
Documents you send for parsing are deleted once parsing finishes. The caveat is the model provider: retention there is theirs, not ours, and the honest figure is on the right.
Four sentences you will not find on this site
Each of these is standard copy elsewhere in the category. None of them survives the two-question test above, so none of them is written anywhere on this site — including in the marketing.
| The claim | Why it does not hold |
|---|---|
| “Documents never leave EU jurisdiction.” | Contabo's majority owner and Mistral's inference provider are both US-incorporated. |
| “No CLOUD Act exposure.” | A US private-equity majority holder is a weaker route to compulsion than a US hyperscaler, but it is not none. |
| “Sub-processors: two companies, nothing else.” | Mistral's own chain adds eight more in the API path. The short list is not achievable. |
| “Documents deleted immediately after processing.” | True on our server. Not true of the model provider below their Scale plan. |
What is defensible: documents are processed in the EU by EU-incorporated contracting entities under Article 28 DPAs; no US hyperscaler holds them; the chain is short, fully disclosed, and materially shorter than Textract's or Document AI's. That is a real claim. It is just a narrower one than the category usually makes.
Found a hole in this?
Tell me. A compliance objection I have not thought of is worth more at this stage than a signup.