Security & Compliance
European infrastructure, built for trust
DocuSearch AI is built and hosted entirely within the European Union. Your documents, embeddings, and personal data never leave EU borders.
Infrastructure
France (EU)
Azure France Central
Application, Database, Storage
France (EU)
Mistral AI
OCR, Embeddings, AI Chat
France (EU)
Qdrant
Vector Database
Data Flow
All document processing stays within the EU. No transatlantic data transfers for core operations.
Your Browser
→
Azure France Central
→
Mistral AI (Paris)
→
Qdrant (France)
Encryption & Access Control
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption at rest (Azure managed keys)
- Bcrypt password hashing with per-user salt
- JWT authentication with 72-hour token expiry
- Optional TOTP-based two-factor authentication
- Per-user data isolation at the application layer
- API keys stored as environment variables, never in code
GDPR Compliance
- We act as Data Controller under the General Data Protection Regulation
- Full data subject rights: access, rectification, erasure, portability, restriction, objection
- Data Processing Agreements (DPAs) with all sub-processors
- 30-day response commitment for all data subject requests
- Data minimization: only essential data collected and processed
- Right to lodge complaint with your local supervisory authority
- Account data export available at any time (Settings → Export)
- Full account deletion cascade removes all data including embeddings and files
Sub-Processors
| Service | Purpose | Location | Safeguards |
| Microsoft Azure | Application hosting, database, storage | France Central (EU) | EU Data Boundary |
| Mistral AI | OCR, text embeddings, AI chat | France (EU) | EU company |
| Qdrant | Vector database for document search | France Central (EU) | EU-hosted |
| Stripe | Payment processing | EU processing | PCI DSS Level 1, SCCs |
| Resend | Transactional email delivery | US | Standard Contractual Clauses |
| Dropbox | File import (optional, user-initiated) | US | SCCs, user-initiated only |
| Google | Sign-in (optional, only via “Continue with Google”) | US | SCCs, user-initiated only |
Data Retention
- Account data: Retained while account is active + 30 days after deletion
- Documents & OCR results: Stored until you delete them or close your account
- Document embeddings: Removed when you delete the file or folder
- Usage logs: 12 months (for billing and support purposes)
- Server logs: 90 days
- Chat conversations: Saved to your account until you delete the conversation or close your account; included in your data export and erased on account deletion
Security Questions?
Security inquiries: security@docusearch.eu
Privacy requests: privacy@docusearch.eu
General support: support@docusearch.eu