← All pages

1. What the document is: Mistral AI's Data Processing Addendum (DPA), a GDPR Article 28-style processor agreement defining Mistral's data-processing obligations toward Customer as a "Processor," including Subprocessor authorization, international-transfer safeguards, and explicit cross-references to AI training.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Le Chat – Data Processor Agreement

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Le Chat/Data Processor Agreement/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2026-03-12

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (gdpr, train AI/models, feedback). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.

Data-quality note: The 2025-12-15 and 2026-03-12 captures contain the entire DPA text twice within the same file (the same scraper/page-rendering artifact found in Le Chat’s Acceptable Use Policy) — quotes below are from the first occurrence only.


Overview

1. What the document is: Mistral AI’s Data Processing Addendum (DPA), a GDPR Article 28-style processor agreement defining Mistral’s data-processing obligations toward Customer as a “Processor,” including Subprocessor authorization, international-transfer safeguards, and explicit cross-references to AI training.

2. Input rights: The DPA carves out an AI-training purpose from Mistral’s ordinary duties as a data “Processor” (a company that only handles data on a customer’s instructions): “Training its artificial intelligence models in accordance with its Privacy Policy, unless (a) Customer opted-out of training or (b) uses a Mistral AI Product that is opted-out by default and has not opted-in.” Notably, for Feedback-derived training specifically, Mistral switches roles and acts “as Controller” — the party that decides how and why data is used, and bears the legal responsibility for that choice under GDPR — instead of Processor.

3. Output restrictions: Not separately addressed.

4. Non-explicit predatory clauses: An “aggregated/anonymized statistics” clause for product-improvement purposes exists across all versions; its wording was tightened on 2026-03-12 to explicitly state “Customer Data and Outputs will not be used to generate such data and statistics” and that such use “shall not include the training of Mistral AI’s models” — a clarifying, more protective rewrite (paralleling the removal of the analogous “Usage Data” clause from Le Chat’s Commercial Terms around the same date).

5. Regulatory references: GDPR explicitly defined and cited throughout — “Applicable Data Protection Law” is defined by reference to “Regulation (EU) 2016/679… (the ‘GDPR’)” and CCPA; “SCC” is defined by reference to the EU Commission’s 2021/914 Implementing Decision on Standard Contractual Clauses; “Restricted Country” is defined relative to EEA adequacy decisions. No EU AI Act reference found.

6. Regional variation: International Data Transfer / Restricted Country provisions are EEA-centric by design (any country outside the EEA without an adequacy decision triggers SCC safeguards).

7. Key risk to users: The Controller/Processor role-switch for Feedback-derived training data is the most legally significant finding — it means GDPR data-subject rights and liability allocation differ depending on how a customer’s data entered Mistral’s training pipeline (ordinary processing vs. Feedback-triggered), a distinction not found explicitly stated in any other provider’s DPA in this dataset.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Pandit et al. (2026), who directly studied Mistral/Le Chat’s terms, note that “all terms mentioned that inputs and outputs would also be used for other purposes beyond” the immediate service — this DPA’s Controller-role carve-out, under which Feedback-derived Input/Output is used “to train its artificial intelligence models, conduct research or improve the Mistral AI Products,” is a concrete legal mechanism for exactly that purpose-broadening. Applying Davidson et al.’s (2026) regulatory-gray-area framework by analogy (Mistral was not among the providers they directly studied), the Controller/Processor role-switch documented here — where GDPR liability allocation shifts depending on how a customer’s data entered the training pipeline — is itself a form of jurisdictional/legal-basis ambiguity of the kind their framework is built to identify.


Changes Summary

DateWhat changed
2025-11-11Baseline version (“Effective 27 May 2025”).
2025-11-28Cosmetic only: one Subprocessor added to the public list (CoreWeave, EEA-based inference provider).
2025-12-15Document re-issued under a new “Effective: November 28, 2025” date with updated URLs (legal.mistral.ai domain) and bolded defined terms; substance of the GDPR/SCC/training clauses unchanged from baseline.
2026-03-12Genuine tightening: the aggregated/anonymized statistics clause rewritten to explicitly exclude Customer Data/Outputs from statistics generation and to explicitly exclude model training from that use.

Version History

2025-11-11

Clause: gdpr

“Applicable Data Protection Law” means any applicable privacy, data security, or data protection law or regulation, including, to the extent applicable, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 applicable since 25 May 2018 (the “GDPR”) and the California Consumer Privacy Act of 2018, as amended, and associated regulations promulgated thereunder (“CCPA”).

Clause: train AI/models, feedback

Training its artificial intelligence models in accordance with its Privacy Policy, unless (a) Customer opted-out of training or (b) uses a Mistral AI Product that is opted-out by default and has not opted-in. Customer acknowledges that if Customer provides feedback to Mistral AI by using the in-app “thumbs up” or “thumbs down” features (the “Feedback”), Mistral will use such Feedback as well as the associated Input and Output, as Controller, to train its artificial intelligence models, conduct research or improve the Mistral AI Products.

Clause: aggregated statistics (not separately concept-tagged — tightened 2026-03-12)

Make anonymized and aggregated statistics regarding the use by Customer of the Mistral AI Products (example: number of web search requests on Le Chat), in order to improve the Mistral AI Products and for roadmap prioritization purposes.


2025-11-28

All flagged clauses unchanged from 2025-11-11 — this date’s only change was a Subprocessor-list addition (CoreWeave).


2025-12-15

gdpr/train AI/models/feedback unchanged from 2025-11-11 (re-issued under new URLs/dates with no substantive change).


2026-03-12

gdpr/train AI/models/feedback unchanged from 2025-11-11.

Clause: aggregated statistics (tightened)

Processing usage and operational data (such as product usage events, performance metrics, billing metrics, and Feedback) to produce aggregated or anonymized data or statistics in accordance with the Agreement. Customer Data and Outputs will not be used to generate such data and statistics. Such data or statistics will be used for Mistral AI’s business purposes, including conducting research, developing or improving Mistral AI Products, performance, functionality, and/or user experience, provided that such use shall not include the training of Mistral AI’s models.