AI models
GDPR Mistral
In an indie stack, Mistral is used for Model inference via the API. Entity cited: Mistral AI, a French company registered in Paris under number 952 418 325, 15 rue des Halles, 75001 Paris. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Mistral
Yes. Public Data Processing Addendum.
Stated role
If the customer uses the products to process personal data in its activity, the customer is controller and Mistral AI is processor. Under the policy (users of the products), Mistral AI is controller. The DPA also allows Mistral AI to process certain data as controller for training and operational purposes described there.
Personal data
Civil-identity data (first name, last name), contractual data, payment data for a paid product, Input (prompts, content, or fine-tuning data), Output, technical data (IP address, network protocol), cookies, usage data.
Sub-processors of Mistral
Trust Center list.
Transfers outside the EU
Hosting / location
By default, data is hosted in the European Union. Explicit use of the US API endpoint hosts the data in the United States. Certain features may temporarily transfer data outside the EU to the places listed on the Trust Center sub-processor page.
EU–United States Data Privacy Framework
Official search for “Mistral” and “Mistral AI”: no participant. Not registered.
Cookies
When the site is visited, Mistral AI uses cookies. Data from non-essential cookies is retained only for as long as consent lasts.
Typical use, written by StackLégal and not by the vendor: Model inference via the API.
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Mistral a processor within the meaning of the GDPR?
If the customer uses the products to process personal data in its activity, the customer is controller and Mistral AI is processor. Under the policy (users of the products), Mistral AI is controller. The DPA also allows Mistral AI to process certain data as controller for training and operational purposes described there.
What DPA does Mistral publish?
Yes. Public Data Processing Addendum. https://legal.mistral.ai/terms/data-processing-addendum/
Which further sub-processors does Mistral publish?
Trust Center list. https://trust.mistral.ai/subprocessors
Where does Mistral state that it processes data, including outside the EU?
By default, data is hosted in the European Union. Explicit use of the US API endpoint hosts the data in the United States. Certain features may temporarily transfer data outside the EU to the places listed on the Trust Center sub-processor page.
Is Mistral registered under the EU–United States Data Privacy Framework?
Official search for “Mistral” and “Mistral AI”: no participant. Not registered.
Which personal data does Mistral mention?
Civil-identity data (first name, last name), contractual data, payment data for a paid product, Input (prompts, content, or fine-tuning data), Output, technical data (IP address, network protocol), cookies, usage data.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.