Sub-processors & Third-Party Services
Last updated: 18 September 2026
How to read this page
This page lists the third-party services that receive data when you use AdminLanding — the website, our mobile applications and the browser extension. We keep it as complete as we can. Where we could not verify something — a contracting entity, a hosting region, a certification — we say so on the card instead of asserting it.
These services do not all have the same legal role, so we do not describe them all as Article 28 processors acting on our instructions:
- Processors acting on our instructions — they handle your data only to run a feature for us: Google Cloud / Firebase, Cloudflare, Mistral AI, Google Cloud Translation and Text-to-Speech, Brevo, Sentry and Expo.
- Independent or joint controllers — they decide for themselves, at least in part, what they do with the data we or your browser send them: Microsoft (Clarity), Meta, Stripe for fraud prevention and its own regulatory duties, Apple and Google Play for in-app purchases, and Openapi for the signature evidence it retains.
- Public services we query — French and Swiss public bodies publishing open data. They are not our sub-processors: Légifrance (DILA), the French address registers and the Swiss federal geoportal.
Where a card shows a DPA link, that is the vendor's published data-processing agreement for the service. Cards with no DPA line run on the vendor's published standard terms; we do not claim a separate signed agreement for them here.
Infrastructure & Hosting
Google Cloud Platform / Firebase
Service Provider
Google LLC
Role: processor acting on our instructions, under the Google Cloud DPA
Data Location
🇪🇺 EU — Firestore: Europe multi-region (eur3, Belgium and Netherlands) · File storage: EU multi-region · Cloud Functions: europe-west3 (Frankfurt) · Firebase Authentication: region not pinned
Purpose
Database, authentication, file storage, hosting and Cloud Functions — and Google reCAPTCHA v3, which Firebase App Check runs to block automated abuse
Data Processed
User profiles, rental and tenant records, the documents you generate — which can contain sensitive details you enter, such as a social-security number or disability information — app data, and the risk signals reCAPTCHA collects
Note: Google reCAPTCHA v3 loads on the signed-in pages of the site without a cookie prompt. It is a security measure against automated abuse, not analytics or advertising, and it runs whatever your cookie choice is.
DPA: Google Cloud DPA
Certification: ISO 27001, SOC 2/3, as published by Google for Google Cloud
Privacy Policy: Firebase Privacy
Cloudflare
Service Provider
Cloudflare, Inc.
Role: processor acting on our instructions, under the Cloudflare Customer DPA
Data Location
🌍 Global edge network — requests are served from the nearest Cloudflare data centre, usually but not necessarily in the EU. We do not claim EU-only localisation for this traffic; transfers rely on Cloudflare's standard contractual clauses.
Purpose
CDN, DDoS protection, web application firewall, TLS, the edge worker that injects our content-security policy, Cloudflare Turnstile (the anti-bot check on sign-up, log-in and password reset) and Cloudflare Web Analytics
Data Processed
Web traffic data, IP addresses and request metadata. When you pass a Turnstile check, our own server sends your IP address to Cloudflare along with the challenge token in order to verify it — that transmission is ours, not just passing edge traffic.
Note: Cloudflare Web Analytics is injected by Cloudflare on our proxied pages and runs on every page view, including before you make any cookie choice. It is cookieless and gives us page-view and performance figures.
DPA: Cloudflare DPA
Certification: ISO 27001, SOC 2, as published by Cloudflare
Privacy Policy: Cloudflare Privacy Policy
AI & Machine Learning Providers
Mistral AI
Service Provider
Mistral AI (France)
Role: processor acting on our instructions. No separate DPA is linked on this page.
Data Location
🇫🇷 France (company establishment) — we call Mistral's api.mistral.ai endpoint and have not verified the region in which it processes requests
Purpose
All of our AI features: page assistance in the browser extension, fiscal explanations, the plain-language explanation of a situation you describe, legal explanations, the nightly drafting of our legal sheets, and the legal-intelligence and MCP endpoints
Data Processed
The question you type, exactly as written; the free-text description of your situation when a feature asks for one; and, when page assistance is on, the visible text of the government page you are viewing — headings and paragraphs, including those of a signed-in account
⚠️ Privacy Notice: What is excluded, and what is not. The values you have typed into a government form's fields are not sent — only the field labels and how we classify them. The page's visible text is sent, unredacted, so on a signed-in health or benefits account it can include your name and your reference numbers. Page assistance can be switched off in the extension popup, under Page assistance (AI); while it is on, the page text is sent automatically, without asking again.
Privacy Policy: Mistral AI Privacy
Google Cloud Translation
Service Provider
Google LLC
Role: processor acting on our instructions, under the Google Cloud DPA
Data Location
🌍 Google's global translation endpoint — we have not pinned it to a region
Purpose
The Translate to French button offered next to free-text fields in the rental, letter and home-employment document forms
Data Processed
The contents of the field you choose to translate, up to 2,000 characters per request — whatever you have written there, including anything personal
DPA: Google Cloud DPA
Privacy Policy: Google Cloud Privacy Notice
Google Cloud Text-to-Speech
Service Provider
Google LLC
Role: processor acting on our instructions, under the Google Cloud DPA
Data Location
🌍 Google's global speech-synthesis endpoint — we have not pinned it to a region
Purpose
The Read aloud button in the browser extension, which speaks the assistance text shown on screen
Data Processed
The text to be spoken and the language requested
DPA: Google Cloud DPA
Privacy Policy: Google Cloud Privacy Notice
Payment Processing
Stripe
Service Provider
Stripe, Inc.
Role: processor for the payment operations we instruct; Stripe's own terms describe it as an independent controller for fraud prevention and for its regulatory obligations
Data Location
🌍 Global — Stripe describes international processing; we have not confirmed an EU-only residency setting on our account
Purpose
Checkout, subscription billing and payment processing on the web. In-app purchases do not go through Stripe — see Apple App Store / Google Play below.
Data Processed
Payment and billing details and transaction history, plus what we attach to a checkout session: the property address for rental packs, Google Analytics client and session identifiers with campaign (UTM) parameters, and, for home-employment packs, the gross salary figures used to price the pack
🔒 Security: Stripe is PCI DSS Level 1 certified. AdminLanding never stores your credit card details: card entry happens on Stripe's own pages, and no card field exists anywhere in our code.
DPA: Stripe DPA
Privacy Policy: Stripe Privacy Policy
Electronic Signature
Openapi Srl (Italy)
Service Provider
Openapi Srl (Italy) — electronic signature service
Role: processor for sending the document and collecting the signature; controller for the signature evidence it keeps under its own responsibility
Data Location
🇮🇹 Italy (company establishment) — we have not verified where the signature service itself is hosted
Purpose
Electronic signature of rental contracts, cross-border presence and leaver attestations, and home-employment documents
Data Processed
Signer names and e-mail addresses, and the PDF to be signed with everything in it. For a cross-border attestation this includes the name and e-mail address of your Swiss employer's signatory.
Compliance: Simple electronic signature (SES) under eIDAS Regulation (EU) No 910/2014. Authentication is by e-mail: it shows control of the mailbox used, not the identity of the signer. An SES does not carry the legal effect of a qualified electronic signature, and it is not a registered letter (LRAR).
Terms & privacy: openapi.com — the vendor's website. We do not link a separate data-processing agreement or privacy policy for this service.
Email & Communications
Brevo (formerly Sendinblue)
Service Provider
Brevo (France)
Role: processor acting on our instructions
Data Location
🇫🇷 France (company establishment) — we have not verified where Brevo's own sub-processors operate
Purpose
All the e-mail we send: account verification and password reset, purchase confirmations, monthly digests, lifecycle and re-engagement messages, review requests, rent, obligation, lease-expiry and follow-up reminders, tenant messages, home-employment invitations, vault share links, and occasional messages we send to users from our admin panel
Data Processed
Your e-mail address, your name, and the content of the message — including any document link it carries
⚠️ Privacy Notice: Two things are worth stating plainly. A vault share e-mail contains a link whose fragment carries the document's decryption key, so Brevo is technically able to open the document that link points to; for automatic rent receipts our server is the one that generates that key, and that message does not carry the header that asks Brevo not to rewrite links. Separately, bulk messages sent from our admin panel do not apply per-user e-mail preferences and carry no unsubscribe link.
DPA: Brevo DPA
Privacy Policy: Brevo Privacy Policy
Certification: ISO 27001, as published by Brevo
Observability & Error Tracking
Sentry
Service Provider
Functional Software, Inc. (Sentry)
Role: processor acting on our instructions
Data Location
🇪🇺 EU region (Germany) — the browser security reports go to Sentry's German ingest host
Purpose
Error tracking and debugging, plus the content-security-policy violation reports your browser sends directly
Data Processed
Error stack traces, browser and device information, page URLs, IP address, masked session replays, CSP violation reports, and error and performance reports from our servers (never the content of a request since 18 September 2026)
🔒 Privacy Notice: Without analytics consent, Sentry records errors only: browsing breadcrumbs, request context and session tracking are switched off. With consent, session replays mask all text input and block media. URL fragments and key or token query values are stripped before an event is sent, so a vault share link cannot reach Sentry from your browser. Our servers send their own reports, which no longer include the content of a request. Between 22 August and 18 September 2026 about one server request in ten produced a performance report that did; our logs show no deposit-return letter, MDPH application or e-mailed share link in that period, and Sentry deletes those reports within 90 days. Noisy and development errors are filtered by our own code before transmission — but CSP violation reports are sent by your browser straight to Sentry, so those are neither filtered by us nor consent-gated.
DPA: Sentry DPA
Certification: ISO 27001, SOC 2 Type II, as published by Sentry
Privacy Policy: Sentry Privacy Policy
Website Analytics & Session Recording (web)
Google Analytics 4 / Tag Manager (web)
Service Provider
Google Ireland Ltd / Google LLC
Role: processor for Google Analytics under Google's Analytics terms; Google acts under its own responsibility for any advertising use of the data
Data Location
🌍 Global (Google LLC, US)
Purpose
Website audience analytics and tag management. Neither Tag Manager nor GA4 is requested until you accept analytics or marketing cookies — measured on 17 September 2026.
Data Processed
Online identifiers (cookie / client ID), pages viewed, approximate location, device and browser information and, when you are signed in, your AdminLanding account identifier — which makes this data pseudonymous, not anonymous
Transfers: Any transfer to the United States relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCCs). We do not use Google Analytics data for advertising targeting ourselves; we have not verified whether Google signals is enabled on the property, and our content-security policy still allows the host GA4 uses when it is. The same Tag Manager container also delivers the Meta pixel — listed under Advertising Measurement below, marketing consent only — and a second Microsoft Clarity project, described in the next card.
Privacy Policy: Google Privacy
Microsoft Clarity
Service Provider
Microsoft Corporation
Role: independent controller — Microsoft states that it acts as a data controller for Clarity, so this is not a sub-processing relationship
Data Location
🌍 Global (Microsoft) — we have not verified where Clarity stores the recordings
Purpose
Heat maps and session recordings of the public website, so we can see where pages confuse or fail visitors
Data Processed
Pages viewed, clicks, scrolling and mouse movement, device and browser information, approximate location, and a recording of the page as it was rendered. The signed-in app shells and the authentication screens (log in, sign up, verify e-mail, delete account) are marked so their content is not uploaded; public marketing pages are recorded as they appear. Clarity is never started on a /share/ link, and is stopped if you navigate to one.
One project, consent-gated: Project yjsp6pi7pj is loaded by this site's own code only after you accept analytics cookies, and withdrawing consent stops the recorder and expires its cookies. A second project (yjsye0z228) used to be injected by our Google Tag Manager container, outside those controls; that integration was disconnected on 17 September 2026 and the container no longer carries any Clarity tag.
Linked to Google Analytics: this Clarity project is connected to our Google Analytics property, so a recorded session can be matched with the corresponding Google Analytics data. That link is a choice we made and can undo; it means the two services see related data about the same visit.
Privacy Policy: Microsoft Privacy Statement
Mobile Applications
Firebase Analytics & Crashlytics (Google)
Service Provider
Google LLC
Role: processor acting on our instructions, under the Google Cloud / Firebase terms
Data Location
🌍 EU / Global (Google)
Purpose
Usage analytics and crash diagnostics in our three mobile apps: Guide: Démarches en France, Rent — Bail & Courte Durée, and Net Frontalier
Data Processed
App-usage identifier, your AdminLanding account identifier where the app has accounts, device and OS information, the Android advertising ID, and crash logs
Note: No advertising is shown inside our applications. Three things this card should not leave out: in the Rent app, the same switch that turns on analytics and crash reporting also starts Meta's measurement SDK (see Advertising Measurement below); the Rent app also reads the Google Play install referrer; and crash reports are additionally written to our own database, independently of that switch. Net Frontalier has no accounts, so its signals are tied to device-level identifiers only.
Privacy Policy: Firebase Privacy
Expo — over-the-air updates & push notifications
Service Provider
Expo, Inc. (US)
Role: processor acting on our instructions. No separate DPA is linked on this page.
Data Location
🌍 United States — we have not verified the transfer mechanism Expo relies on
Purpose
Over-the-air updates for all three apps — each app contacts Expo at launch to check for one — and delivery of the push notifications you enable in the Rent app. Guide's reminders are scheduled on the device and do not pass through Expo.
Data Processed
On every update check: device and runtime information and your IP address, before any consent choice and whether or not you use notifications. For push: the device push token and the notification body, which can contain a tenant's name, a property address, a lease end date or an arrears amount — never the contents of your documents.
Privacy Policy: Expo Privacy
Apple App Store / Google Play
Service Provider
Apple Inc. / Google LLC
Role: Apple and Google sell in-app purchases as merchants of record, under their own responsibility. They are not our processors for the sale.
Data Location
🌍 Global
Purpose
In-app purchases: AI credit packs in the Guide app; rental packs, e-signature credit packs and the tenant portal in the Rent app
Data Processed
Store purchase receipt and transaction identifier
Payments for in-app purchases are handled by the app stores; we receive only the receipt needed to validate your purchase. Refunds and cancellations for those purchases are handled by the store, not by us.
Advertising Measurement
Meta Platforms (Facebook / Instagram)
Service Provider
Meta Platforms Ireland Limited
Role: Meta's Business Tools terms describe this measurement partly as joint controllership with us and partly as Meta's own controller processing — not plain sub-processing
Data Location
🌍 EU / US (EU-US Data Privacy Framework + SCCs)
Purpose
Measuring the performance of our own ad campaigns on Facebook and Instagram — website pixel, and app-install / conversion measurement for the Rent mobile app. No ads are shown inside our products.
Data Processed
Web: online identifiers (cookie) and conversion events — only after marketing consent. Mobile: app events (e.g. account created, pack purchased) — only after in-app analytics consent. iOS installs: aggregated, anonymous SKAdNetwork data only.
🔒 Privacy Notice: The website pixel loads only after you accept marketing cookies — measured on 17 September 2026 — and the app SDK only after you turn analytics on in the Rent app. Your documents, properties and tenant data are never shared with Meta. Note that deleting your AdminLanding account erases our own records and propagates to Stripe and Brevo, but it does not delete anything Meta holds: data held by Meta has to be dealt with through your Meta account settings. Our account deletion page covers AdminLanding only.
DPA: Meta Data Processing Terms
Privacy Policy: Meta Privacy Policy
Public Services We Query
These are public bodies publishing open data, not sub-processors acting for us. We list them because a request still leaves your browser or our servers and reaches them.
Légifrance / PISTE API (DILA)
Service Provider
DILA — French government legal-information service
Role: a French public administration publishing open data. It is not our sub-processor.
Data Location
🇫🇷 France
Purpose
Fetching the official text of the specific articles cited in our own content registry
Data Processed
The identifier of the article being fetched. The request is made by our server and carries nothing about you: no user-facing search sends your search terms to this API.
Address & postcode lookup (public registers)
Service Provider
api-adresse.data.gouv.fr · geo.api.gouv.fr · api3.geo.admin.ch
Role: French public open-data services and the Swiss federal geoportal (swisstopo). They are not our sub-processors.
Data Location
🇫🇷 France · 🇨🇭 Switzerland
Purpose
Address autocomplete and postcode-to-town lookup in our forms, including two public pages
Data Processed
The address text as you type it, sent from your browser directly to these services together with your IP address — no account identifier, and no cookie prompt beforehand. In the cross-border tools the Swiss lookup is made by our server rather than your browser.
What Loads, and When
Measured on the live site on 17 September 2026, with the cookie banner in each state:
- Before you choose: nothing is requested from Google, from Meta, or from the Clarity project our page controls. Three things do run: Cloudflare's cookieless Web Analytics beacon, Google reCAPTCHA v3 on the signed-in pages (App Check, a security measure), and Sentry's bare error capture.
- If you accept analytics cookies: Google Tag Manager and GA4 load, Clarity project yjsp6pi7pj starts, and Sentry additionally records browsing breadcrumbs and masked session replays.
- If you accept marketing cookies: the Meta pixel loads, delivered by the Tag Manager container.
Changes to Sub-processors
This page is the record. When we add or replace a service, we update the cards above and add a dated entry to the change log below, so the page can be compared with what it said before. The date at the top of the page is the date of the last such change.
This page previously promised notice at least 30 days before adding or replacing a sub-processor, by e-mail and in Settings. Neither channel was ever built, and no such notice has ever been sent: Microsoft Clarity was added on 17 September 2026 and went live the same day. We have removed the promise rather than leave an unbacked one in place.
Change log
17 September 2026 — Added to this page: Microsoft Clarity (both projects), Google reCAPTCHA v3 via App Check, Cloudflare Turnstile and Cloudflare Web Analytics, Google Cloud Translation, Google Cloud Text-to-Speech, Expo over-the-air updates, the Net Frontalier app, and the French and Swiss public address registers. Corrected: the data locations, each service's role, and the described purpose of Expo, the app stores, Légifrance, Brevo, Mistral and Meta.
If you object to a service listed here, you can stop using the feature that relies on it, or close your account at any time from our account deletion page.
Contact
If you have questions about the services listed here, or about how we handle your data, write to our privacy contact:
Email: privacy@adminlanding.com
We aim to reply to data-protection requests within 48 hours.
Related Policies
Related policies:
Your data is handled with strict protection and EU hosting practices.

