Is Mediapapa GDPR compliant?

Accueil » Documentation » Account & Billing » Is Mediapapa GDPR compliant?

1. Data Processing Agreement (DPA)

No self-service DPA document is currently available. We can provide a DPA on request to support procurement and compliance processes.

Contact: [email protected]

2. Data transmitted to Mediapapa servers

The plugin contacts our API (api.wp-mediapapa.eu) in two cases only, both requiring explicit administrator action:

  • Image compression: the image file is sent for processing and returned compressed. No file is retained after the response.
  • AI-assisted metadata generation and content tags: the image file is sent to generate alt text, title and caption suggestions. No file is retained after the response.

All other features run entirely within WordPress on the customer’s server: duplicate detection, unused media detection, usage index, Library Health scoring, and Deletion Warnings. File hashes for duplicate detection are computed locally and never leave the server.

3. Subprocessors and hosting locations

ServiceProviderLocation
DatabaseScalewayFR-PAR (Paris, France)
Image optimisationScalewayFR-PAR (Paris, France)
AI metadata (LLM)Scaleway hosted LLMsFR-PAR (Paris, France)

AI model in use: pixtral-12b-2409 (Scaleway hosted, runs locally on Scaleway infrastructure). No data is transferred outside the EU/EEA.

4. Data retention and deletion periods

Data typeRetentionNotes
Image files (compression)Deleted immediatelyServerless: purged when container finishes executing
Image files (AI metadata)Deleted immediatelyOnly base64 transmitted, nothing stored
API usage logs12 monthsAPI key and action performed only; no file content retained
Container execution logs7 days
Instance metrics31 days