Legal
List version: 1.1 — 19 August 2026
Extract API OÜ uses the following sub-processors to provide Extract API. This list supplements Annex III of our DPA.
Technical details of when document content is sent to each provider: Data processing documentation.
We notify API account holders by email at least 30 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within 14 days of that notice (see DPA §6).
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting, database, Redis (cache + queues), backups | All service data at rest: accounts, extraction requests, cached results, temporary PDF storage | European Union (EEA) |
Local processing on our servers (not a sub-processor): Poppler (pdftotext)
for digital PDF text extraction runs on the same infrastructure — no document content is sent externally
for documents with a sufficient embedded text layer.
These providers receive document content only when required by the extraction pipeline (typically scanned PDFs or configured structured/vision stages). Your operator controls this via environment flags — see docs.
| Sub-processor | Purpose | When triggered | Data sent | Location |
|---|---|---|---|---|
| Mistral AI | OCR; structured JSON extraction; optional VLM pass | MISTRAL_OCR_ENABLED, structured/VLM flags |
PDF file, extracted text, or image crops (TLS in transit) | EU / US — per Mistral DPA & SCCs |
| OpenAI | Structured extraction; vision follow-up | STRUCTURED_EXTRACTION_PROVIDER=openai and/or DOCUMENT_EXTRACTION_VISION_ENABLED |
Extracted text or page images (TLS in transit) | United States — SCCs |
We do not use third-party LLMs to write raw document text into application audit logs. Sub-processors process data according to their respective DPAs and our instructions (extraction only, no model training on customer documents unless separately agreed — confirm in your vendor contracts).
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Stripe, Inc. | Credit pack checkout, invoicing, fraud prevention | Email, company name, payment method metadata, billing address — never PDF documents | EU/US per Stripe |
| Sub-processor | Purpose | Data processed |
|---|---|---|
| Postmark / Resend | Transactional email (sub-processor change notices, account messages) | Account email address, message content |
Extraction results (field values, not PDF files) are cached in Redis on our hosting for up to 30 days, scoped per API account. This is not a separate sub-processor — it is part of our infrastructure listed in §1.
| Version | Date | Change |
|---|---|---|
| 1.0 | 19 Aug 2026 | Initial list |
| 1.1 | 19 Aug 2026 | Added trigger conditions, cache note, Poppler local processing clarification |