Legal
Sub-processors
Version 1.0 · Effective from September 9, 2026
A sub-processor is a third party that MITRA engages to process personal data on behalf of its customer organisations in order to deliver the Service. This list is generated from the platform's configuration and identifies, for each sub-processor, the purpose, the categories of data involved, the location of processing and the safeguards in place.
1. How sub-processors are engaged
Every sub-processor is bound by a written data-processing agreement imposing confidentiality, security measures at least equivalent to ours, assistance with data-subject requests, deletion or return of the data at the end of the service, and the transfer safeguards described below. We remain responsible towards our customers for the performance of our sub-processors.
2. Current sub-processors
Entries marked optional are engaged only when your organisation actually uses the corresponding feature (there is no separate per-organisation switch: the sub-processor is reached the first time the feature is used).
| Sub-processor | Purpose | Data categories | Location | Safeguards |
|---|---|---|---|---|
| Yousign SAS | Electronic-signature ceremony, signer identification, one-time codes by SMS and e-mail, timestamping, certificate and audit-trail (evidence) files | Signer identity and contact data, phone number, documents and their hashes, signature evidence (IP address, timestamps) | France (European Union) | Processing in the European Union; qualified trust service provider under eIDAS; data-processing agreement |
|
Stripe Payments Europe, Limited Optional — only when your organisation uses this feature |
Collection of payments requested together with a signature, and refunds | Amount and currency, payer e-mail address, payment identifiers and status (no card data reaches the platform) | Ireland (European Union); transfers to the United States under Standard Contractual Clauses | Stripe data-processing agreement; EU Standard Contractual Clauses for transfers to Stripe, Inc.; PCI-DSS certified |
| IT-Mitra | Hosting of the application, the database, backups and file storage | All platform data at rest | Region France (EU) | Hosting contract with data-processing terms; encryption in transit; access restricted to the operator |
| Resend | Delivery of transactional e-mails (invitations, reminders, notifications, password resets) | Recipient e-mail address and name, subject and content of the notification e-mails | According to the provider's own disclosure | Data-processing terms of the provider; TLS in transit |
|
api.country.is Optional — only when your organisation uses this feature |
Resolving the country of a visitor's IP address so the geographic access rules of an organisation can be applied | The IP address of the person connecting — an administrator signing in, or a signer opening a signature link — and nothing else | According to the provider's own disclosure | Lookup performed only for organisations that have an active geographic rule, cached to limit repeats; the operator removes this transfer entirely by installing the local MaxMind database (GEOIP_DB_PATH), after which no address leaves this installation |
3. Changes and objections
We update this page, its version number and its effective date before adding or replacing a sub-processor. Customer administrators are asked to accept the new version; an organisation that objects on reasonable data-protection grounds may contact veeravel.pichaimuthu@it-mitra.com and, failing an acceptable solution, terminate the affected feature or the Service.