Sub-processors
Last changed 16 September 2026. These are all of them. Three companies, not a category like "our hosting partners" that could mean anyone.
Under clause 5 of the data processing agreement we tell account holders before this list changes, so you have time to object before a new company receives anything.
Cloudflare, Inc.
- Used for
- Hosting, file storage, the database, email routing and sending, bot protection on card entry, and website analytics.
- What reaches it
- Uploaded documents and the data extracted from them, account and session data, and the IP address of anyone entering a card.
- Where it is processed
- Files are held in an EU-only storage bucket and the database is EU-constrained. The website itself, bot checks and the fallback extraction model described below run on Cloudflare's global network, which includes locations outside the UK and EEA.
- Transfer mechanism
- Cloudflare's customer data processing addendum, incorporating the EU standard contractual clauses and the UK International Data Transfer Addendum (version B1.0).
Mistral AI SAS
- Used for
- Reading the text out of your documents, and structuring it into the columns you agreed.
- What reaches it
- The contents of the documents you submit, and the instructions describing the columns you want.
- Where it is processed
- Mistral is a French company and stores data in the European Union by default. We call their standard endpoint, for which Mistral do not commit to a specific inference location, so a request may be processed outside the EEA.
- Transfer mechanism
- Mistral's data processing addendum, incorporating the EU standard contractual clauses.
Stripe, Inc. and Stripe Payments Europe, Ltd.
- Used for
- Taking payment and holding the card details we never see.
- What reaches it
- Your email address, billing details and subscription status. No document ever reaches Stripe.
- Where it is processed
- Ireland and the United States.
- Transfer mechanism
- Stripe's data processing agreement and data transfers addendum, relying on the EU-US and UK-US Data Privacy Framework, the EU standard contractual clauses and the UK International Data Transfer Addendum.
- Their terms
- https://stripe.com/legal/dpa
Two things worth reading twice
We call Mistral's standard endpoint, and Mistral state that they do not commit to a specific inference location for it. Separately, when Mistral is unavailable we fall back to Cloudflare Workers AI, which runs across a global network and cannot be restricted to a region. Both of those mean a document may be processed outside the UK and EEA, under the transfer mechanisms named above.
Most services in this category do the same thing and describe it as "EU hosting". We would rather you found this here than in a questionnaire six months after signing.
What is not on this list
No advertising network, no analytics company beyond Cloudflare's cookieless counter, no data broker, no offshore labelling or review team, and no accounting integration. Nobody looks at your documents to improve anything. If you configure a webhook, extracted data also goes to the URL you nominate, but you chose that one so it is yours rather than ours.
Datanem is a product of DATANEM LIMITED, a company registered in England and Wales, number 16870006. Registered office: 8 Court View, Clowne, Chesterfield, England, S43 4BU. Registered with the Information Commissioner's Office, reference ZC053711.