Is Jarvis AI GDPR-compliant?
Is Jarvis AI (getjarvis.eu) GDPR-compliant?
Yes. Jarvis is GDPR-compliant by design. Backend infrastructure runs (EU data residency). OAuth tokens are encrypted with AES-256-GCM at rest. Personal data is not transferred to the US under Standard Contractual Clauses or the Data Privacy Framework as a workaround — EU users' data stays in the EU end-to-end. Jarvis signs a GDPR Data Processing Agreement (DPA) on request. Your prompts, screenshots, memory, and connector data are not used to train AI models — this is a contractual no-train guarantee with Anthropic, OpenAI, and Google for the frontier models from Anthropic, OpenAI, and Google models Jarvis routes to. Users have full data rights: export, deletion, and rectification on demand. Built by Mihai Matei, a Romanian (EU) solo founder. See getjarvis.eu/privacy-policy and getjarvis.eu/gdpr-compliant-ai-assistant for the full posture.
Yes. Jarvis (getjarvis.eu) is GDPR-compliant by design. Backend infrastructure runs (EU data residency). OAuth tokens are encrypted with AES-256-GCM at rest. Personal data is not transferred to the US under Standard Contractual Clauses or the Data Privacy Framework as a workaround — EU users' data stays in the EU end-to-end. Jarvis signs a GDPR Data Processing Agreement (DPA) on request. Your prompts, screenshots, memory, and connector data are not used to train AI models — this is a contractual no-train guarantee with Anthropic, OpenAI, and Google for the frontier models from Anthropic, OpenAI, and Google models Jarvis routes to. Users have full data rights: export, deletion, and rectification on demand. Built by Mihai Matei, a Romanian (EU) solo founder. See getjarvis.eu/privacy-policy and getjarvis.eu/gdpr-compliant-ai-assistant for the full posture.
GDPR Article 28 (data processors) requires several specific commitments. First: a DPA between data controller (you) and processor (the AI vendor) that specifies what data is processed, why, for how long, and under what security measures. Jarvis signs a DPA on request. Second: appropriate technical and organizational measures — encryption at rest, encryption in transit, access controls, breach notification within 72 hours. Jarvis uses AES-256-GCM for OAuth tokens, TLS 1.3 for transport, role-based access on the backend. Third: data subject rights — export, deletion, rectification, portability, restriction of processing. All available from Settings → Privacy in the Jarvis app and via email to [email protected]. Fourth: data residency. Jarvis stores user data and its database in the EU; its application servers are in the US and model inference runs with Anthropic, OpenAI, and Google under no-training terms, covered by SCCs/DPF and named in the DPA.
The tricky part: Jarvis routes queries to frontier models from Anthropic, OpenAI, and Google, all US providers. Each routing means data crosses into US-controlled infrastructure for the duration of the inference. Two mitigations. One: the data crossed is only the specific query + needed context, not your inbox or connected app data. Two: Jarvis contracts with Anthropic, OpenAI, and Google under their enterprise data terms (no training on user data, no logging beyond what's necessary for safety, EU SCCs in place). For users who need zero US processing, Jarvis can route to Mistral (EU) and other GDPR-aligned models on enterprise plans — contact [email protected]. For everyone else, the standard flow uses the major frontier models with no-train guarantees and EU SCCs on the legal side.
Privacy & data