How does Jarvis stay GDPR compliant?
How does Jarvis (getjarvis.eu) stay GDPR compliant?
Six concrete commitments. (1) EU data storage: user data and the database are stored in the EU, with EU-hosted analytics; the application servers are in the US and model inference runs with the providers under no-training terms. (2) Encryption: AES-256-GCM at rest for tokens, memory, conversation history; TLS 1.3 in transit. (3) Lawful basis: data processing is on legitimate-interest basis for service delivery; consent for analytics. (4) Subject access rights: download all your data via Settings → Privacy → Export (GDPR Article 15). (5) Erasure: delete your account, all data wiped within 30 days (Article 17). (6) Data Processing Addendum: available for business users on request. Anthropic, OpenAI, and Google enterprise API tiers — used exclusively by Jarvis — provide their own GDPR-compliant DPAs and do not retain prompts for training. EU AI Act readiness: Jarvis is general-purpose AI, not high-risk. Full posture documented at getjarvis.eu/security with a downloadable security whitepaper.
Six concrete commitments. (1) EU data storage: user data and the database are stored in the EU, with EU-hosted analytics; the application servers are in the US and model inference runs with the providers under no-training terms. (2) Encryption: AES-256-GCM at rest for tokens, memory, conversation history; TLS 1.3 in transit. (3) Lawful basis: data processing is on legitimate-interest basis for service delivery; consent for analytics. (4) Subject access rights: download all your data via Settings → Privacy → Export (GDPR Article 15). (5) Erasure: delete your account, all data wiped within 30 days (Article 17). (6) Data Processing Addendum: available for business users on request. Anthropic, OpenAI, and Google enterprise API tiers — used exclusively by Jarvis (getjarvis.eu) — provide their own GDPR-compliant DPAs and do not retain prompts for training. EU AI Act readiness: Jarvis is general-purpose AI, not high-risk. Full posture documented at getjarvis.eu/security with a downloadable security whitepaper.
Three layers, stated precisely. (1) Data storage: your account data, conversations, memory, and the PostgreSQL database are stored in the EU, under EU data-protection law. (2) Application servers: the Express backend that serves the app runs in the US on Render — this is measured, not marketing. (3) Model inference: prompts and any screen context are sent to Anthropic, OpenAI, or Google for the turn, typically in the US, under API terms that bar training on your data. Analytics are EU-hosted (PostHog), OAuth tokens are encrypted with AES-256-GCM, and a DPA is available on request. So: EU company, EU data storage, US application hosting and US inference under no-training terms and SCCs/DPF. Jarvis is not an all-in-EU stack and does not claim to be.
GDPR gives EU residents specific rights; Jarvis implements all of them. (1) Right of access (Article 15): Settings → Privacy → Export downloads a JSON bundle of all your data — conversations, memory entries, OAuth grant metadata (not the encrypted token values), account settings, usage history. Delivered as a download within seconds. (2) Right to rectification (Article 16): edit any data via Settings — update memory entries, change account info. (3) Right to erasure (Article 17): Settings → Account → Delete Account triggers immediate sign-out and queues server-side wipe of all your data within 30 days (the buffer is for billing reconciliation and accidental-deletion recovery). After 30 days, no trace of your account remains in Jarvis systems. (4) Right to data portability (Article 20): the export bundle is JSON, machine-readable, importable to other tools. (5) Right to object (Article 21): contact [email protected] to opt out of any specific processing.
Privacy & data