Skip to content
AdminLanding

Sub-processors & Third-Party Services

Last updated: 18 September 2026

How to read this page

This page lists the third-party services that receive data when you use AdminLanding — the website, our mobile applications and the browser extension. We keep it as complete as we can. Where we could not verify something — a contracting entity, a hosting region, a certification — we say so on the card instead of asserting it.

These services do not all have the same legal role, so we do not describe them all as Article 28 processors acting on our instructions:

  • Processors acting on our instructions — they handle your data only to run a feature for us: Google Cloud / Firebase, Cloudflare, Mistral AI, Google Cloud Translation and Text-to-Speech, Brevo, Sentry and Expo.
  • Independent or joint controllers — they decide for themselves, at least in part, what they do with the data we or your browser send them: Microsoft (Clarity), Meta, Stripe for fraud prevention and its own regulatory duties, Apple and Google Play for in-app purchases, and Openapi for the signature evidence it retains.
  • Public services we query — French and Swiss public bodies publishing open data. They are not our sub-processors: Légifrance (DILA), the French address registers and the Swiss federal geoportal.

Where a card shows a DPA link, that is the vendor's published data-processing agreement for the service. Cards with no DPA line run on the vendor's published standard terms; we do not claim a separate signed agreement for them here.

Infrastructure & Hosting

Google Cloud Platform / Firebase

Service Provider

Google LLC

Role: processor acting on our instructions, under the Google Cloud DPA

Data Location

🇪🇺 EU — Firestore: Europe multi-region (eur3, Belgium and Netherlands) · File storage: EU multi-region · Cloud Functions: europe-west3 (Frankfurt) · Firebase Authentication: region not pinned

Purpose

Database, authentication, file storage, hosting and Cloud Functions — and Google reCAPTCHA v3, which Firebase App Check runs to block automated abuse

Data Processed

User profiles, rental and tenant records, the documents you generate — which can contain sensitive details you enter, such as a social-security number or disability information — app data, and the risk signals reCAPTCHA collects

Note: Google reCAPTCHA v3 loads on the signed-in pages of the site without a cookie prompt. It is a security measure against automated abuse, not analytics or advertising, and it runs whatever your cookie choice is.

DPA: Google Cloud DPA

Certification: ISO 27001, SOC 2/3, as published by Google for Google Cloud

Privacy Policy: Firebase Privacy

Cloudflare

Service Provider

Cloudflare, Inc.

Role: processor acting on our instructions, under the Cloudflare Customer DPA

Data Location

🌍 Global edge network — requests are served from the nearest Cloudflare data centre, usually but not necessarily in the EU. We do not claim EU-only localisation for this traffic; transfers rely on Cloudflare's standard contractual clauses.

Purpose

CDN, DDoS protection, web application firewall, TLS, the edge worker that injects our content-security policy, Cloudflare Turnstile (the anti-bot check on sign-up, log-in and password reset) and Cloudflare Web Analytics

Data Processed

Web traffic data, IP addresses and request metadata. When you pass a Turnstile check, our own server sends your IP address to Cloudflare along with the challenge token in order to verify it — that transmission is ours, not just passing edge traffic.

Note: Cloudflare Web Analytics is injected by Cloudflare on our proxied pages and runs on every page view, including before you make any cookie choice. It is cookieless and gives us page-view and performance figures.

DPA: Cloudflare DPA

Certification: ISO 27001, SOC 2, as published by Cloudflare

Privacy Policy: Cloudflare Privacy Policy

AI & Machine Learning Providers

Mistral AI

Service Provider

Mistral AI (France)

Role: processor acting on our instructions. No separate DPA is linked on this page.

Data Location

🇫🇷 France (company establishment) — we call Mistral's api.mistral.ai endpoint and have not verified the region in which it processes requests

Purpose

All of our AI features: page assistance in the browser extension, fiscal explanations, the plain-language explanation of a situation you describe, legal explanations, the nightly drafting of our legal sheets, and the legal-intelligence and MCP endpoints

Data Processed

The question you type, exactly as written; the free-text description of your situation when a feature asks for one; and, when page assistance is on, the visible text of the government page you are viewing — headings and paragraphs, including those of a signed-in account

⚠️ Privacy Notice: What is excluded, and what is not. The values you have typed into a government form's fields are not sent — only the field labels and how we classify them. The page's visible text is sent, unredacted, so on a signed-in health or benefits account it can include your name and your reference numbers. Page assistance can be switched off in the extension popup, under Page assistance (AI); while it is on, the page text is sent automatically, without asking again.

Privacy Policy: Mistral AI Privacy

Google Cloud Translation

Service Provider

Google LLC

Role: processor acting on our instructions, under the Google Cloud DPA

Data Location

🌍 Google's global translation endpoint — we have not pinned it to a region

Purpose

The Translate to French button offered next to free-text fields in the rental, letter and home-employment document forms

Data Processed

The contents of the field you choose to translate, up to 2,000 characters per request — whatever you have written there, including anything personal

Google Cloud Text-to-Speech

Service Provider

Google LLC

Role: processor acting on our instructions, under the Google Cloud DPA

Data Location

🌍 Google's global speech-synthesis endpoint — we have not pinned it to a region

Purpose

The Read aloud button in the browser extension, which speaks the assistance text shown on screen

Data Processed

The text to be spoken and the language requested

Payment Processing

Stripe

Service Provider

Stripe, Inc.

Role: processor for the payment operations we instruct; Stripe's own terms describe it as an independent controller for fraud prevention and for its regulatory obligations

Data Location

🌍 Global — Stripe describes international processing; we have not confirmed an EU-only residency setting on our account

Purpose

Checkout, subscription billing and payment processing on the web. In-app purchases do not go through Stripe — see Apple App Store / Google Play below.

Data Processed

Payment and billing details and transaction history, plus what we attach to a checkout session: the property address for rental packs, Google Analytics client and session identifiers with campaign (UTM) parameters, and, for home-employment packs, the gross salary figures used to price the pack

🔒 Security: Stripe is PCI DSS Level 1 certified. AdminLanding never stores your credit card details: card entry happens on Stripe's own pages, and no card field exists anywhere in our code.

DPA: Stripe DPA

Privacy Policy: Stripe Privacy Policy

Electronic Signature

Openapi Srl (Italy)

Service Provider

Openapi Srl (Italy) — electronic signature service

Role: processor for sending the document and collecting the signature; controller for the signature evidence it keeps under its own responsibility

Data Location

🇮🇹 Italy (company establishment) — we have not verified where the signature service itself is hosted

Purpose

Electronic signature of rental contracts, cross-border presence and leaver attestations, and home-employment documents

Data Processed

Signer names and e-mail addresses, and the PDF to be signed with everything in it. For a cross-border attestation this includes the name and e-mail address of your Swiss employer's signatory.

Compliance: Simple electronic signature (SES) under eIDAS Regulation (EU) No 910/2014. Authentication is by e-mail: it shows control of the mailbox used, not the identity of the signer. An SES does not carry the legal effect of a qualified electronic signature, and it is not a registered letter (LRAR).

Terms & privacy: openapi.com — the vendor's website. We do not link a separate data-processing agreement or privacy policy for this service.

Email & Communications

Brevo (formerly Sendinblue)

Service Provider

Brevo (France)

Role: processor acting on our instructions

Data Location

🇫🇷 France (company establishment) — we have not verified where Brevo's own sub-processors operate

Purpose

All the e-mail we send: account verification and password reset, purchase confirmations, monthly digests, lifecycle and re-engagement messages, review requests, rent, obligation, lease-expiry and follow-up reminders, tenant messages, home-employment invitations, vault share links, and occasional messages we send to users from our admin panel

Data Processed

Your e-mail address, your name, and the content of the message — including any document link it carries

⚠️ Privacy Notice: Two things are worth stating plainly. A vault share e-mail contains a link whose fragment carries the document's decryption key, so Brevo is technically able to open the document that link points to; for automatic rent receipts our server is the one that generates that key, and that message does not carry the header that asks Brevo not to rewrite links. Separately, bulk messages sent from our admin panel do not apply per-user e-mail preferences and carry no unsubscribe link.

DPA: Brevo DPA

Privacy Policy: Brevo Privacy Policy

Certification: ISO 27001, as published by Brevo

Observability & Error Tracking

Sentry

Service Provider

Functional Software, Inc. (Sentry)

Role: processor acting on our instructions

Data Location

🇪🇺 EU region (Germany) — the browser security reports go to Sentry's German ingest host

Purpose

Error tracking and debugging, plus the content-security-policy violation reports your browser sends directly

Data Processed

Error stack traces, browser and device information, page URLs, IP address, masked session replays, CSP violation reports, and error and performance reports from our servers (never the content of a request since 18 September 2026)

🔒 Privacy Notice: Without analytics consent, Sentry records errors only: browsing breadcrumbs, request context and session tracking are switched off. With consent, session replays mask all text input and block media. URL fragments and key or token query values are stripped before an event is sent, so a vault share link cannot reach Sentry from your browser. Our servers send their own reports, which no longer include the content of a request. Between 22 August and 18 September 2026 about one server request in ten produced a performance report that did; our logs show no deposit-return letter, MDPH application or e-mailed share link in that period, and Sentry deletes those reports within 90 days. Noisy and development errors are filtered by our own code before transmission — but CSP violation reports are sent by your browser straight to Sentry, so those are neither filtered by us nor consent-gated.

DPA: Sentry DPA

Certification: ISO 27001, SOC 2 Type II, as published by Sentry

Privacy Policy: Sentry Privacy Policy

Website Analytics & Session Recording (web)

Google Analytics 4 / Tag Manager (web)

Service Provider

Google Ireland Ltd / Google LLC

Role: processor for Google Analytics under Google's Analytics terms; Google acts under its own responsibility for any advertising use of the data

Data Location

🌍 Global (Google LLC, US)

Purpose

Website audience analytics and tag management. Neither Tag Manager nor GA4 is requested until you accept analytics or marketing cookies — measured on 17 September 2026.

Data Processed

Online identifiers (cookie / client ID), pages viewed, approximate location, device and browser information and, when you are signed in, your AdminLanding account identifier — which makes this data pseudonymous, not anonymous

Transfers: Any transfer to the United States relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs). We do not use Google Analytics data for advertising targeting ourselves; we have not verified whether Google signals is enabled on the property, and our content-security policy still allows the host GA4 uses when it is. The same Tag Manager container also delivers the Meta pixel — listed under Advertising Measurement below, marketing consent only — and a second Microsoft Clarity project, described in the next card.

Privacy Policy: Google Privacy

Microsoft Clarity

Service Provider

Microsoft Corporation

Role: independent controller — Microsoft states that it acts as a data controller for Clarity, so this is not a sub-processing relationship

Data Location

🌍 Global (Microsoft) — we have not verified where Clarity stores the recordings

Purpose

Heat maps and session recordings of the public website, so we can see where pages confuse or fail visitors

Data Processed

Pages viewed, clicks, scrolling and mouse movement, device and browser information, approximate location, and a recording of the page as it was rendered. The signed-in app shells and the authentication screens (log in, sign up, verify e-mail, delete account) are marked so their content is not uploaded; public marketing pages are recorded as they appear. Clarity is never started on a /share/ link, and is stopped if you navigate to one.

One project, consent-gated: Project yjsp6pi7pj is loaded by this site's own code only after you accept analytics cookies, and withdrawing consent stops the recorder and expires its cookies. A second project (yjsye0z228) used to be injected by our Google Tag Manager container, outside those controls; that integration was disconnected on 17 September 2026 and the container no longer carries any Clarity tag.

Linked to Google Analytics: this Clarity project is connected to our Google Analytics property, so a recorded session can be matched with the corresponding Google Analytics data. That link is a choice we made and can undo; it means the two services see related data about the same visit.

Privacy Policy: Microsoft Privacy Statement

Mobile Applications

Firebase Analytics & Crashlytics (Google)

Service Provider

Google LLC

Role: processor acting on our instructions, under the Google Cloud / Firebase terms

Data Location

🌍 EU / Global (Google)

Purpose

Usage analytics and crash diagnostics in our three mobile apps: Guide: Démarches en France, Rent — Bail & Courte Durée, and Net Frontalier

Data Processed

App-usage identifier, your AdminLanding account identifier where the app has accounts, device and OS information, the Android advertising ID, and crash logs

Note: No advertising is shown inside our applications. Three things this card should not leave out: in the Rent app, the same switch that turns on analytics and crash reporting also starts Meta's measurement SDK (see Advertising Measurement below); the Rent app also reads the Google Play install referrer; and crash reports are additionally written to our own database, independently of that switch. Net Frontalier has no accounts, so its signals are tied to device-level identifiers only.

Privacy Policy: Firebase Privacy

Expo — over-the-air updates & push notifications

Service Provider

Expo, Inc. (US)

Role: processor acting on our instructions. No separate DPA is linked on this page.

Data Location

🌍 United States — we have not verified the transfer mechanism Expo relies on

Purpose

Over-the-air updates for all three apps — each app contacts Expo at launch to check for one — and delivery of the push notifications you enable in the Rent app. Guide's reminders are scheduled on the device and do not pass through Expo.

Data Processed

On every update check: device and runtime information and your IP address, before any consent choice and whether or not you use notifications. For push: the device push token and the notification body, which can contain a tenant's name, a property address, a lease end date or an arrears amount — never the contents of your documents.

Privacy Policy: Expo Privacy

Apple App Store / Google Play

Service Provider

Apple Inc. / Google LLC

Role: Apple and Google sell in-app purchases as merchants of record, under their own responsibility. They are not our processors for the sale.

Data Location

🌍 Global

Purpose

In-app purchases: AI credit packs in the Guide app; rental packs, e-signature credit packs and the tenant portal in the Rent app

Data Processed

Store purchase receipt and transaction identifier

Payments for in-app purchases are handled by the app stores; we receive only the receipt needed to validate your purchase. Refunds and cancellations for those purchases are handled by the store, not by us.

Advertising Measurement

Meta Platforms (Facebook / Instagram)

Service Provider

Meta Platforms Ireland Limited

Role: Meta's Business Tools terms describe this measurement partly as joint controllership with us and partly as Meta's own controller processing — not plain sub-processing

Data Location

🌍 EU / US (EU-US Data Privacy Framework + SCCs)

Purpose

Measuring the performance of our own ad campaigns on Facebook and Instagram — website pixel, and app-install / conversion measurement for the Rent mobile app. No ads are shown inside our products.

Data Processed

Web: online identifiers (cookie) and conversion events — only after marketing consent. Mobile: app events (e.g. account created, pack purchased) — only after in-app analytics consent. iOS installs: aggregated, anonymous SKAdNetwork data only.

🔒 Privacy Notice: The website pixel loads only after you accept marketing cookies — measured on 17 September 2026 — and the app SDK only after you turn analytics on in the Rent app. Your documents, properties and tenant data are never shared with Meta. Note that deleting your AdminLanding account erases our own records and propagates to Stripe and Brevo, but it does not delete anything Meta holds: data held by Meta has to be dealt with through your Meta account settings. Our account deletion page covers AdminLanding only.

DPA: Meta Data Processing Terms

Privacy Policy: Meta Privacy Policy

Public Services We Query

These are public bodies publishing open data, not sub-processors acting for us. We list them because a request still leaves your browser or our servers and reaches them.

Légifrance / PISTE API (DILA)

Service Provider

DILA — French government legal-information service

Role: a French public administration publishing open data. It is not our sub-processor.

Data Location

🇫🇷 France

Purpose

Fetching the official text of the specific articles cited in our own content registry

Data Processed

The identifier of the article being fetched. The request is made by our server and carries nothing about you: no user-facing search sends your search terms to this API.

Address & postcode lookup (public registers)

Service Provider

api-adresse.data.gouv.fr · geo.api.gouv.fr · api3.geo.admin.ch

Role: French public open-data services and the Swiss federal geoportal (swisstopo). They are not our sub-processors.

Data Location

🇫🇷 France · 🇨🇭 Switzerland

Purpose

Address autocomplete and postcode-to-town lookup in our forms, including two public pages

Data Processed

The address text as you type it, sent from your browser directly to these services together with your IP address — no account identifier, and no cookie prompt beforehand. In the cross-border tools the Swiss lookup is made by our server rather than your browser.

What Loads, and When

Measured on the live site on 17 September 2026, with the cookie banner in each state:

  • Before you choose: nothing is requested from Google, from Meta, or from the Clarity project our page controls. Three things do run: Cloudflare's cookieless Web Analytics beacon, Google reCAPTCHA v3 on the signed-in pages (App Check, a security measure), and Sentry's bare error capture.
  • If you accept analytics cookies: Google Tag Manager and GA4 load, Clarity project yjsp6pi7pj starts, and Sentry additionally records browsing breadcrumbs and masked session replays.
  • If you accept marketing cookies: the Meta pixel loads, delivered by the Tag Manager container.

Changes to Sub-processors

This page is the record. When we add or replace a service, we update the cards above and add a dated entry to the change log below, so the page can be compared with what it said before. The date at the top of the page is the date of the last such change.

This page previously promised notice at least 30 days before adding or replacing a sub-processor, by e-mail and in Settings. Neither channel was ever built, and no such notice has ever been sent: Microsoft Clarity was added on 17 September 2026 and went live the same day. We have removed the promise rather than leave an unbacked one in place.

Change log

17 September 2026 — Added to this page: Microsoft Clarity (both projects), Google reCAPTCHA v3 via App Check, Cloudflare Turnstile and Cloudflare Web Analytics, Google Cloud Translation, Google Cloud Text-to-Speech, Expo over-the-air updates, the Net Frontalier app, and the French and Swiss public address registers. Corrected: the data locations, each service's role, and the described purpose of Expo, the app stores, Légifrance, Brevo, Mistral and Meta.

If you object to a service listed here, you can stop using the feature that relies on it, or close your account at any time from our account deletion page.

Contact

If you have questions about the services listed here, or about how we handle your data, write to our privacy contact:

Email: privacy@adminlanding.com

We aim to reply to data-protection requests within 48 hours.

Related Policies

Related policies:

Your data is handled with strict protection and EU hosting practices.