Skip to content

Data processing agreement

Last updated

Scope and instructions

This Data Processing Agreement forms part of Jori's Terms of service between the customer and Vedin Labs AB, organisation number 556512-5449, Braxenvägen 12, 181 30 Lidingö, Sweden. Contact support@usejori.com. It applies where we process personal data on your behalf under the GDPR. You are the controller, or a processor authorised by your controller. We are your processor or subprocessor. This agreement takes priority for that processing.

Your use of Jori, settings and authorised requests are your documented instructions. We process personal data only on those instructions, including for transfers, unless applicable EU or member-state law requires otherwise. We will inform you of such a requirement before processing unless the law prohibits that notice. We will tell you if an instruction appears to infringe data protection law and may pause the affected processing while it is resolved.

You determine the purpose of your workspace, provide required notices and have a lawful basis for the data and instructions you provide. We do not use that data for our own advertising or general-purpose model training.

Processing details

  • Purpose and subject matter: providing Jori's AI workspace and carrying out your tasks, including authorised actions in connected services.
  • Operations: collecting, storing, organising, retrieving, analysing, generating, transmitting and deleting content as instructed.
  • People: workspace users and people mentioned in customer content, such as staff, customers, suppliers and correspondents.
  • Data: names, contact details, messages, files, calendar entries, code, task instructions, outputs, access credentials and associated usage records. Actual categories depend on what you provide and connect.
  • Duration: the service term and the return or deletion period below. Intentional sensitive-data repositories require our prior written agreement under the Terms; this agreement does not authorise unsupported regulated uses.

Security and confidentiality

We apply measures appropriate to the risk under GDPR Article 32. These include access controls for workspaces and service credentials, encrypted transport, provider encryption at rest, separate regional execution and storage configuration, isolated sandbox execution and limited operational access. We maintain incident handling, recovery and security review procedures and test relevant changes. Measures may evolve without reducing overall protection.

People authorised to process customer data must be bound by confidentiality obligations and access only what they need for their work. Google API data also remains subject to Google's Limited Use requirements described in our Privacy Policy.

Assistance and incidents

We assist you, taking account of the nature of processing and information available to us, with data-subject requests, security obligations, breach notifications, impact assessments and consultation with supervisory authorities. We forward requests concerning your workspace to you and do not answer on your behalf unless instructed or legally required.

We notify you without undue delay after becoming aware of a personal data breach affecting your data. We provide available information about the breach, affected data and people, likely consequences, mitigation and a contact for follow-up. We provide further information as it becomes available and cooperate with your response. You remain responsible for your own regulatory notifications.

Subprocessors and transfers

You give general written authorisation for subprocessors used to provide Jori. The providers below describe the current service chain. We require subprocessors to undertake data protection obligations equivalent to those in this agreement for their processing and remain responsible for their performance.

We give at least 30 days' notice before adding or replacing a subprocessor, allowing you to object on reasonable data protection grounds. We work with you to address the objection. If we cannot, you may end the affected service before the change and receive a refund of unused prepaid service and purchased credits.

Your workspace region governs the regional configuration described in our Privacy Policy. It is not a promise that every provider operation occurs there. Transfers outside the EEA require an applicable lawful mechanism, such as adequacy or standard contractual clauses with necessary safeguards. This agreement is not itself an international-transfer mechanism.

Return, deletion and verification

On ending the service, you may choose return or deletion of your personal data. Contact support for an export or earlier deletion. Without other instructions, we retain workspace content for 90 days after cancellation takes effect or the trial expires, give advance notice, then delete it. We delete existing copies unless EU or member-state law requires storage. Backup copies remain protected until overwritten through the applicable deletion cycle and are not restored to ordinary use. We can confirm completion on request.

We provide information needed to demonstrate compliance with this agreement and allow and contribute to audits, including inspections, by you or your mandated auditor. We may agree reasonable scheduling, confidentiality and security arrangements, but these must not prevent necessary verification or regulatory access.

Providers

The location column describes Jori's configuration, not the location of every provider's support, telemetry or administrative operation. Customer-connected applications and chosen recipients also process data under their own terms.

ProviderWhat it receives and doesConfiguration
ConvexWorkspace records, files and credentials; database, storage and backendSeparate EU and US deployments
VercelWeb requests and related operational data; website and application hostingRegional application configuration; global edge and platform operations
BlaxelTask files, commands and outputs; isolated code executionFrankfurt for EU, North Virginia for US
OpenRouter and its model hostsRelevant prompts, task context and outputs; AI inferenceRegional endpoints with no-training and zero-retention routing requirements
Google CloudImage instructions, inputs and outputs; image generationRegional endpoints; separate safety-monitoring rules
ParallelSearch queries, page URLs and extracted content; search and fetchingEU search endpoint for EU workspaces; global page fetching
BirdRecipient addresses and service messages; email deliveryRegional account configuration; recipient mail systems are separate
PostHogConsented page analytics and browser identifiersRegional projects; no chat or file content
StripeBilling identity, payment and transaction detailsGlobal processing; also acts as an independent controller for some purposes
ZohoSupport correspondence sent to JoriEU mail account; send only content needed for support

OpenRouter's downstream hosts depend on the selected model and route. Contact support for the current applicable host list and transfer information. Analytics, billing and support also involve processing for which Jori or the provider is an independent controller, as explained in the Privacy Policy.