Skip to content
AdminLanding

Sub-processors & Third-Party Services

Last Updated: 12/08/2026

Our Commitment to Data Protection

AdminLanding is committed to protecting your data. This page lists all third-party sub-processors we use to deliver our service. Under GDPR Article 28, we ensure all sub-processors meet strict data protection standards and have appropriate Data Processing Agreements (DPAs) in place.

Infrastructure & Hosting

Google Cloud Platform / Firebase

Service Provider

Google LLC

Data Location

🇪🇺 EU Only (europe-west3, Frankfurt, Germany)

Purpose

Database, Authentication, Storage, Hosting

Data Processed

User profiles, rental & tenant records, documents, app data

DPA: Google Cloud DPA

Certification: ISO 27001, SOC 2/3, EU-based

Privacy Policy: Firebase Privacy

Cloudflare

Service Provider

Cloudflare, Inc.

Data Location

🌍 EU / Global (EU data localization, SCCs)

Purpose

CDN, DDoS protection, WAF, performance optimization, security

Data Processed

Web traffic data, IP addresses, request metadata

DPA: Cloudflare DPA

Certification: ISO 27001, SOC 2, GDPR-compliant

Privacy Policy: Cloudflare Privacy Policy

AI & Machine Learning Providers

Mistral AI

Service Provider

Mistral AI (France)

Data Location

🇪🇺 EU Only (France)

Purpose

AI-powered administrative guidance and form assistance

Data Processed

Typed queries + truncated page context (avoid personal data in queries)

⚠️ Privacy Notice: Questions you type are sent to Mistral AI as written, with truncated page context; sensitive fields are excluded and nothing is used for AI training. Avoid including personal data in your questions.

Privacy Policy: Mistral AI Privacy

Payment Processing

Stripe

Service Provider

Stripe, Inc.

Data Location

🇪🇺 EU Only

Purpose

Subscription billing, payment processing

Data Processed

Payment info, billing address, transaction history

🔒 Security: Stripe is PCI DSS Level 1 certified. AdminLanding never stores your credit card details.

DPA: Stripe DPA

Privacy Policy: Stripe Privacy Policy

Electronic Signature

Openapi Srl (Italy)

Service Provider

Openapi Srl (Italy) — eIDAS trust-service provider

Data Location

🇪🇺 EU Only (Italy)

Purpose

eIDAS-compliant electronic signatures for rental contracts

Data Processed

Signer names, email addresses, PDF documents to be signed

Compliance: EU-SES level electronic signatures under eIDAS Regulation (EU) No 910/2014. Signer identity verified via OTP email authentication. Documents are cryptographically sealed.

DPA: Openapi — Terms & Data Processing

Certification: eIDAS trust service (EU-SES), EU-based

Privacy Policy: Openapi Privacy Policy

Email & Communications

Brevo (formerly Sendinblue)

Service Provider

Brevo (France)

Data Location

🇪🇺 EU Only (France)

Purpose

Transactional emails (verification, password reset)

Data Processed

Email address, name, email content

DPA: Brevo DPA

Privacy Policy: Brevo Privacy Policy

Certification: ISO 27001, EU-based

Observability & Error Tracking

Sentry

Service Provider

Functional Software, Inc. (Sentry)

Data Location

🇪🇺 EU region (Germany)

Purpose

Error tracking, performance monitoring, debugging

Data Processed

Error stack traces, browser/device info, page URLs, IP address, masked session replays

🔒 Privacy Notice: Session replays mask all text input and block media. Noisy and development errors are filtered before transmission. Error reports may include technical context such as IP address and browser metadata.

DPA: Sentry DPA

Certification: ISO 27001, SOC 2 Type II

Privacy Policy: Sentry Privacy Policy

Mobile Applications

Firebase Analytics & Crashlytics (Google)

Service Provider

Google LLC

Data Location

🌍 EU / Global (Google)

Purpose

Mobile app usage analytics & crash diagnostics (Guide for French Procedures, Rent — Lease & Short-Term)

Data Processed

App-usage identifier, account identifier, device/OS info, advertising ID (Android), crash logs — never used for advertising

Note: No advertising is shown in our applications. These signals are used solely for analytics and stability.

Privacy Policy: Firebase Privacy

Google Analytics 4 / Tag Manager (web)

Service Provider

Google Ireland Ltd / Google LLC

Data Location

🌍 Global (Google LLC, US)

Purpose

Website audience analytics & tag management — strict consent gating: Google scripts do not load and no data reaches Google until you accept analytics or marketing cookies

Data Processed

Online identifiers (cookie/client ID), pages viewed, approximate location, device/browser info — GA4 data is used for analytics only

Transfers: Any transfer to the United States relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs). Installed via Google Tag Manager under strict consent gating: neither Tag Manager nor GA4 loads, and no data reaches Google, until you accept analytics or marketing cookies. Tag Manager also loads the Meta Pixel — listed under Advertising Measurement below — only after marketing consent.

Privacy Policy: Google Privacy

Expo Push Notifications (mobile app)

Service Provider

Expo, Inc. (US)

Data Location

🌍 United States (SCCs / DPF)

Purpose

Delivering the push notifications you enable in the Rent mobile app

Data Processed

Device push token and notification payloads (titles/summaries) — no document contents

Privacy Policy: Expo Privacy

Légifrance / PISTE API (DILA)

Service Provider

DILA — French government legal-information service

Data Location

🇫🇷 France

Purpose

Retrieving official legal texts for the legal-search feature

Data Processed

Your legal search terms (avoid including personal data)

Apple App Store / Google Play

Service Provider

Apple Inc. / Google LLC

Data Location

🌍 Global

Purpose

In-app purchases of AI credits (mobile)

Data Processed

Store purchase receipt & transaction identifier

Payments for in-app purchases are handled by the app stores; we receive only the receipt needed to validate your purchase.

Advertising Measurement

Meta Platforms (Facebook / Instagram)

Service Provider

Meta Platforms Ireland Limited

Data Location

🌍 EU / US (EU-US Data Privacy Framework + SCCs)

Purpose

Measuring the performance of our own ad campaigns on Facebook and Instagram — website pixel, and app-install / conversion measurement for the Rent mobile app. No ads are shown inside our products.

Data Processed

Web: online identifiers (cookie) and conversion events — only after marketing consent. Mobile: app events (e.g. account created, pack purchased) — only after in-app analytics consent. iOS installs: aggregated, anonymous SKAdNetwork data only.

🔒 Privacy Notice: Both surfaces are consent-gated and send nothing by default. Your documents, properties and tenant data are never shared with Meta. You can request deletion of data linked to your Meta account at any time via our data deletion page.

DPA: Meta Data Processing Terms

Privacy Policy: Meta Privacy Policy

Changes to Sub-processors

We will notify users at least 30 days in advance before adding or replacing any sub-processor. If you object to a new sub-processor, you may terminate your account before the change takes effect.

Notification method: Email to registered address + notice in Settings

Contact

If you have questions about our sub-processors or data processing practices, please contact our Data Protection Officer:

Email: privacy@adminlanding.com

Response time: Within 48 hours for GDPR-related inquiries

Related Policies

Related policies:

Your data is handled with strict protection and EU hosting practices.