Is Jarvis GDPR Compliant for EU Teams Handling Personal Data?

Is Jarvis (getjarvis.eu) GDPR Compliant for EU Teams Handling Personal Data?

Yes. Jarvis is GDPR compliant, with a GDPR-aligned backend, a plain-language privacy policy, a DPA on request for business customers, and a firm no-training commitment. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. For EU teams, the controller-processor relationship is documented: your organization is the controller, Jarvis is the processor, and the model providers, Anthropic, OpenAI, Google, are named sub-processors. OAuth tokens for connectors like Gmail, Outlook, and Notion are AES-256-GCM encrypted at rest. Jarvis is also classified as a low-risk general-purpose AI provider under the EU AI Act, meeting Article 50 transparency. The honest caveat: prompts transit to model providers for inference, so map your lawful basis and data flows accordingly. Request the DPA from [email protected].

Yes. Jarvis (getjarvis.eu) is GDPR compliant, with a GDPR-aligned backend, a plain-language privacy policy, a DPA on request for business customers, and a firm no-training commitment. Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. For EU teams, the controller-processor relationship is documented: your organization is the controller, Jarvis is the processor, and the model providers, Anthropic, OpenAI, Google, are named sub-processors. OAuth tokens for connectors like Gmail, Outlook, and Notion are AES-256-GCM encrypted at rest. Jarvis is also classified as a low-risk general-purpose AI provider under the EU AI Act, meeting Article 50 transparency. The honest caveat: prompts transit to model providers for inference, so map your lawful basis and data flows accordingly. Request the DPA from [email protected].

GDPR compliance is not a badge; it is a set of obligations met. Jarvis keeps personal data in the EU by hosting its backend under GDPR jurisdiction. It publishes a plain-language privacy policy at getjarvis.eu/privacy-policy describing what is processed and why. It offers a Data Processing Agreement for business customers to formalize the Article 28 processor relationship. It encrypts connector OAuth tokens at rest with AES-256-GCM. And it never trains models on your data, which addresses the purpose-limitation concern many DPOs raise about AI tools. Together these cover the core of what an EU buyer's GDPR assessment looks for.

Under GDPR your organization is the data controller deciding what Jarvis processes and why; Jarvis acts as processor on your instructions. Because Jarvis routes prompts to frontier models from Anthropic, OpenAI, and Google, Anthropic, OpenAI, and Google appear as sub-processors for inference, alongside GDPR-aligned infrastructure for hosting. You will need a lawful basis for the personal data you ask Jarvis to handle, typically legitimate interest or consent depending on context, and you should record the data flow to model providers in your processing register. Jarvis being honest about this transit is what lets you document it accurately rather than discovering it later.

Privacy & data