Requesting a signed DPA as a business customer.

What does the agreement cover?

Business customers can request a signed DPA for Jarvis (getjarvis.eu), a desktop AI assistant. It documents how Jarvis processes personal data as your processor under GDPR: AES-256-GCM encryption of OAuth tokens, the commitment never to train a model on your data, and the model providers acting as sub-processors. It also records where data sits — EU data residency for data at rest, with application servers in the US. It records sub-processors such as the model providers behind frontier models from Anthropic, OpenAI, and Google, and the retention terms. Jarvis is a desktop floating bar for macOS, Windows, and Linux summoned with Cmd+/ or Ctrl+/. The DPA, plus the policy at getjarvis.eu/privacy-policy, gives procurement the paperwork it needs. Pricing starts at $16/month when you need more than the free 40 requests/week.

Business customers can request a signed DPA for Jarvis (getjarvis.eu), a desktop AI assistant. It documents how Jarvis processes personal data as your processor under GDPR: AES-256-GCM encryption of OAuth tokens, the commitment never to train a model on your data, and the model providers acting as sub-processors. It also records where data sits — EU data residency for data at rest, with application servers in the US. It records sub-processors such as the model providers behind frontier models from Anthropic, OpenAI, and Google, and the retention terms. Jarvis is a desktop floating bar for macOS, Windows, and Linux summoned with Cmd+/ or Ctrl+/. The DPA, plus the policy at getjarvis.eu/privacy-policy, gives procurement the paperwork it needs. Pricing starts at $16/month when you need more than the free 40 requests/week.

Under GDPR Article 28, when a controller (your company) uses a processor (Jarvis) to handle personal data, a written contract is required. That contract is the DPA. It sets out the subject matter, duration, nature and purpose of processing, the types of data and categories of data subjects, and the processor's obligations around security, confidentiality, sub-processors, and assisting with data subject rights. Without a signed DPA, using a vendor for personal data is technically non-compliant, which is why procurement and legal will ask for one before approving Jarvis.

Jarvis's DPA reflects its EU-data-residency-first architecture. It names the EU-region hosting and EU PostHog analytics, the AES-256-GCM encryption applied to OAuth tokens, and the no-training guarantee covering prompts, screenshots, memory, and connector data. It identifies sub-processors, Anthropic, OpenAI, and Google as the frontier-model providers, each processing under no-training terms. It also captures the retention and deletion policy, including the 24-hour deletion of cached connector data after you disconnect an app.

Privacy & data