Legal

Sub-processors

Version 1.0 · Effective from September 9, 2026

A sub-processor is a third party that MITRA engages to process personal data on behalf of its customer organisations in order to deliver the Service. This list is generated from the platform's configuration and identifies, for each sub-processor, the purpose, the categories of data involved, the location of processing and the safeguards in place.

1. How sub-processors are engaged

Every sub-processor is bound by a written data-processing agreement imposing confidentiality, security measures at least equivalent to ours, assistance with data-subject requests, deletion or return of the data at the end of the service, and the transfer safeguards described below. We remain responsible towards our customers for the performance of our sub-processors.

2. Current sub-processors

Entries marked optional are engaged only when your organisation actually uses the corresponding feature (there is no separate per-organisation switch: the sub-processor is reached the first time the feature is used).

Sub-processor Purpose Data categories Location Safeguards
Yousign SAS Electronic-signature ceremony, signer identification, one-time codes by SMS and e-mail, timestamping, certificate and audit-trail (evidence) files Signer identity and contact data, phone number, documents and their hashes, signature evidence (IP address, timestamps) France (European Union) Processing in the European Union; qualified trust service provider under eIDAS; data-processing agreement
Stripe Payments Europe, Limited
Optional — only when your organisation uses this feature
Collection of payments requested together with a signature, and refunds Amount and currency, payer e-mail address, payment identifiers and status (no card data reaches the platform) Ireland (European Union); transfers to the United States under Standard Contractual Clauses Stripe data-processing agreement; EU Standard Contractual Clauses for transfers to Stripe, Inc.; PCI-DSS certified
IT-Mitra Hosting of the application, the database, backups and file storage All platform data at rest Region France (EU) Hosting contract with data-processing terms; encryption in transit; access restricted to the operator
Resend Delivery of transactional e-mails (invitations, reminders, notifications, password resets) Recipient e-mail address and name, subject and content of the notification e-mails According to the provider's own disclosure Data-processing terms of the provider; TLS in transit
api.country.is
Optional — only when your organisation uses this feature
Resolving the country of a visitor's IP address so the geographic access rules of an organisation can be applied The IP address of the person connecting — an administrator signing in, or a signer opening a signature link — and nothing else According to the provider's own disclosure Lookup performed only for organisations that have an active geographic rule, cached to limit repeats; the operator removes this transfer entirely by installing the local MaxMind database (GEOIP_DB_PATH), after which no address leaves this installation

3. Changes and objections

We update this page, its version number and its effective date before adding or replacing a sub-processor. Customer administrators are asked to accept the new version; an organisation that objects on reasonable data-protection grounds may contact veeravel.pichaimuthu@it-mitra.com and, failing an acceptable solution, terminate the affected feature or the Service.

MITRA — pondy — veeravel.pichaimuthu@it-mitra.com

Version 1.0 · Effective from September 9, 2026