Data transparency

List of sub-processors

Listar uses third-party providers to deliver Listar services. All are contractually committed to protecting the security and confidentiality of data.

Updated: February 24, 2025

Listar uses third-party entities to perform limited activities as part of Listar services. Under the GDPR, these providers are qualified as sub-processors. Listar contractually requires them to protect the security and confidentiality of personal data processed on its behalf. To be notified of changes: dpo@listar.fr

Payment

💳

Stripe

Secure card-payment processing, subscription and billing management.

Payment🌍 International (PCI-DSS certified)

Data processed: Billing information, card data (tokenized), payment history.

Stripe privacy policy →

Transactional email

✉️

Mailjet

Sending transactional emails: signup confirmation, password reset, invoices.

Email🌍 International

Data processed: Email address, user name.

Mailjet privacy policy →

Authentication

🔑

Google (Sign-In)

Login via Google Sign-In. Only the email address and name are transmitted during authentication.

Authentication🌍 International (DPF)

Data processed: Google email address, full name.

Google privacy policy →

Hosting

☁️

Amazon Web Services EMEA SARL

Hosting of Listar's technical infrastructure (servers, databases, storage).

Hosting🇪🇺 Luxembourg / EU

Data processed: All data processed via the Listar platform and API.

Address: 38 Av. John F. Kennedy, L-1855 Luxembourg — SIREN 831 001 334

AWS privacy policy →
ℹ️
Transfers outside the EUStripe, Mailjet and Google may transfer data outside the European Union. These transfers are covered by the European Commission's Standard Contractual Clauses, adequacy decisions, and/or the Data Privacy Framework (DPF) for transfers to the United States.
⚠️
Information to be completed
  • Data partners (enrichment providers): The data partners that power Listar's enrichment waterfall are not yet listed publicly (confidential list — see DPA Annex 3, Part B). They are subject to contractual safeguards equivalent to the DPA.
  • Analytics / monitoring tool: If a server-monitoring or product-analytics tool is used, it will be declared here.