Constaia
Concepts

Data residency & compliance

Where Constaia processes and stores documents, the sovereign and standard processing profiles, the upcoming US region, and how GDPR, CCPA and DPPA apply to your integration.

Constaia processes documents in the European Union today. This page explains where your data goes, what Constaia keeps, and how the main privacy laws for EU and US customers apply to an integration.

Not legal advice

This page describes how Constaia works so you can assess it. It is not legal advice. Check your obligations with your counsel.

Where documents are processed

StepWhereDetails
APIapi.constaia.comAll uploads and downloads go through the API; there are no direct storage URLs.
Local readers (MRZ, PDF417 barcode, PDF text and signature)Constaia's servers in the EUNo third party, no cost.
AI reading (OCR, classification, extraction)AI providers in EU regions, depending on the profileA European or Constaia-hosted model and Mistral OCR (Paris) with sovereign; also Claude on AWS Bedrock (Frankfurt, eu-central-1) or Gemini on Vertex AI (EU) with standard.
File storage (only when needed)Cloudflare R2 with EU jurisdictionAccessed only server-side. Files are encrypted by Constaia before they are stored.

Being honest about providers: AWS and Google are US companies, and so is Cloudflare. Even when they process or store data in EU regions, they are not EU-headquartered and may be subject to US law (such as the CLOUD Act). Stored files are encrypted by Constaia at application level, so the storage provider only holds ciphertext.

Processing profiles

You choose, per request with the processing option, which kind of AI providers may read a document. If you don't send it, your account's default profile applies (sovereign when a sovereign provider is available). If you ask for a profile that is not available, the API answers 422 processing_unavailable.

ProfileAI providers
sovereignOnly providers headquartered and operated in the EU: a European model (IONOS, Scaleway, OVHcloud) or one hosted by Constaia, and Mistral OCR (Paris).
standardThe above, plus Claude on AWS Bedrock (Frankfurt, eu-central-1) and Gemini on Google Vertex AI (EU region).

The local readers (MRZ, PDF417, PDF text and signatures) are used with both profiles.

Request
{ "expect": "passport", "processing": "sovereign" }

Each analysis tells you exactly which profile, region and providers handled the document:

Response fragment
"processing": {
  "profile": "sovereign",
  "region": "eu",
  "mode": "vlm",
  "providers": [
    { "name": "tesseract", "region": "local", "role": "local", "model": "mrz" },
    { "name": "openai_compat", "region": "de-fra", "role": "llm", "model": "mistral-small-3.2" }
  ]
}

Store this object next to your decision if you need to prove where each document was processed. The account default cannot be changed from the dashboard yet: send processing on each request or write to hola@constaia.com.

US region

Coming soon

A US processing region is planned, with no date yet. Until it is available, documents from US customers are processed and stored in the EU as described above, and processing.region is always eu. Watch the changelog.

What Constaia keeps

  • Zero retention by default. With storage: "none" a synchronous analysis is processed in memory and the file is never written to storage; with async or batches it is stored encrypted only until the analysis finishes. storage.file_deleted_at tells you when it was deleted.
  • Your choice beyond that. temporary deletes the file after ttl_hours (1–720); persistent keeps it until you call DELETE /v1/analyses/{id}.
  • Results. Extracted fields are kept by default so you can call GET /v1/analyses/{id}. With keep_results: false only billing metadata remains (pages, credits, type).
  • Encryption. Files are encrypted with AES-256-GCM using a per-account key derived from a master key before they reach storage. Webhook secrets are stored encrypted; API keys are stored hashed.
  • Exports expire after 24 hours.
  • Audit log of sensitive actions: who did it, from which IP and what.

Details in Storage & privacy and Security.

GDPR

For documents you send, you are the controller and Constaia acts as your processor. The Data Processing Agreement (DPA) covers the processing terms and lists the subprocessors: see /en/legal/dpa. The subprocessors depend on the processing profile described above; the DPA has the complete, current list.

Useful defaults for data minimisation: storage: "none", keep_results: false when you don't need to fetch results again, and metadata with your own internal ids only, never personal data.

CCPA / CPRA (California)

If you are subject to the CCPA, you are the business that collects the personal information, and Constaia acts as your service provider / processor under the DPA: it processes documents only to provide the service to you.

  • Minimise. Collect only the documents you need and use storage: "none" and keep_results: false where you can.
  • Deletion requests. When a consumer asks you to delete their data, delete the related analyses with DELETE /v1/analyses/{id} (it removes the file, results and exports). Tag analyses with your own customer id in metadata so you can find them.
curl "https://api.constaia.com/v1/analyses?metadata[customer_id]=cus_123&limit=100" \
  -H "Authorization: Bearer $CONSTAIA_API_KEY"

curl -X DELETE https://api.constaia.com/v1/analyses/an_01J... \
  -H "Authorization: Bearer $CONSTAIA_API_KEY"

Listing only returns analyses of the key's mode (test or live), so run it with your live key for production data. Analyses sent with keep_results: false hold no extracted data to delete.

Driver's licenses and the DPPA

The US Driver's Privacy Protection Act restricts how personal information from state motor vehicle records is obtained and disclosed. In a typical Constaia flow the license image is supplied by the person themselves, but it is still sensitive: collect it for a clear purpose, minimise what you keep and check with your counsel how the DPPA and state laws apply. See Verify a US driver's license.

What Constaia is not

  • Not biometric. Constaia reads documents. It does not compare faces, match selfies or do any biometric processing.
  • Not a consumer reporting agency. Constaia does not assemble reports on consumers for third parties and does not make eligibility decisions (credit, tenancy, employment, insurance). Your rules and your reviewers decide.
  • Not a government lookup. It does not query DMVs, the IRS, E-Verify or any other government database. Signals such as edited_suspected are prompts for review, not proof of fraud.

Next steps

On this page