← Back to blog
System One AI ·

Can European Enterprises Use Jev? GDPR, Data Residency and EU Readiness Explained

Jev data flow between a European enterprise and a US-hosted System One AI service

Yes, European enterprises can use Jev, but using it lawfully is not the same as deploying a sovereign European AI system. TypeSafe provides contractual GDPR mechanisms and says customer inputs are not used to train its models. However, its public privacy documentation states that the service is hosted in the United States, and its standard terms do not promise EU-only processing or zero data retention.

For European technology and procurement teams, that distinction matters.

Jev is TypeSafe AI’s first System One model: a model designed to make fast, typed decisions that software can consume directly. Its architecture may be attractive for classification, routing, scoring, policy checks and agent guardrails. But model performance is only one part of enterprise readiness.

Before sending personal data, confidential records or regulated information to any external AI service, European organisations must also understand where the data is processed, how long it is retained, which subprocessors can access it, what contractual safeguards apply and whether the deployment fits their own risk requirements.

This article assesses Jev against those questions using TypeSafe’s publicly available documentation, most recently reviewed on 23 September 2026.

The short answer: can Jev be used in Europe?

There is no general rule that prevents a European company from using a US AI provider. A European organisation can use Jev if it has an appropriate lawful basis, conducts the necessary vendor and transfer assessments, enters into the required contractual arrangements and configures the service consistently with its GDPR obligations.

TypeSafe publishes a Data Processing Addendum and incorporates the European Commission’s Standard Contractual Clauses for transfers of personal data from the European Union. Its privacy policy also states that customer input is not used to train or fine-tune its AI models.

Those are meaningful enterprise controls.

However, TypeSafe’s privacy policy states that its services are hosted in the United States and that users from the EEA transfer personal data to the US for storage and processing. The public documents reviewed for this article do not promise EU-only data residency, customer-selectable European inference, on-premises deployment or zero data retention.

The accurate conclusion is therefore:

Jev can be evaluated and used by European organisations, but its standard public offering should not be described as EU-sovereign.

Whether it is appropriate for a particular workload depends on the data involved, the organisation’s risk tolerance and the contractual and technical controls available to that customer.

What does “European-ready” mean for an AI model?

“Available in Europe,” “GDPR-capable” and “European sovereign” describe different things.

Requirement What it means
Available in Europe European customers are allowed to access and purchase the service.
GDPR-capable The provider supplies mechanisms such as a DPA, processor commitments and safeguards for international transfers.
EU data residency Customer data is stored and processed within specified European regions.
Zero data retention Prompts and outputs are not retained after the processing required to return the result, subject to precisely defined exceptions.
European sovereignty Data, infrastructure, operational control and legal exposure remain within a European jurisdiction and control framework.
Enterprise-ready The service also meets the organisation’s security, reliability, access-control, audit, support and deployment requirements.

A provider may satisfy some of these requirements without satisfying all of them. A DPA can support GDPR compliance while the underlying processing still takes place in the United States. Similarly, EU-hosted infrastructure does not automatically create sovereignty if control, keys, support access or legal jurisdiction remain outside Europe.

What TypeSafe publicly provides

TypeSafe has already published several elements that European procurement teams would expect from an enterprise AI vendor.

A Data Processing Addendum

TypeSafe’s DPA identifies the customer as controller and TypeSafe as processor when TypeSafe processes customer personal data. It commits TypeSafe to process that data according to documented instructions and applicable data-protection obligations.

Standard Contractual Clauses

For transfers from the European Union, the DPA incorporates the European Commission’s Standard Contractual Clauses. It specifies the controller-to-processor module and, where relevant, the processor-to-subprocessor module.

SCCs are a recognised legal transfer mechanism. They do not create EU data residency: they are safeguards for transferring data outside the EEA.

No model training on customer input

TypeSafe’s privacy policy states that it will not train or fine-tune AI or machine-learning models on customer input. Its Master Customer Agreement similarly says customer data will not be included in a model-training dataset without the customer’s prior consent.

This is an important distinction for enterprises concerned about confidential data being reused to improve a shared model.

Subprocessor and security commitments

The DPA refers customers to TypeSafe’s Trust Center for its subprocessor list and security safeguards. It also provides advance notice of new subprocessors and allows customers to object on reasonable privacy or security grounds.

The DPA includes incident-notification commitments and a limited right to audit TypeSafe’s controls, subject to the conditions stated in the agreement.

These provisions make Jev more assessable for enterprise buyers. They should be reviewed together with the current Trust Center, order form and any customer-specific commercial terms.

Where the European sovereignty gap remains

The existence of a DPA does not answer every operational question.

The public service is hosted in the United States

TypeSafe’s privacy policy states that the services are hosted in the US. For EEA users, personal data is transferred outside Europe for storage and processing.

That does not automatically make the service unlawful. It does mean that organisations seeking EU-only processing or a sovereign European deployment need additional options that are not established in the public documents reviewed here.

Retention is not presented as zero

TypeSafe’s DPA says customer personal data is retained for as long as necessary in light of the purpose of processing and applicable law. Its Master Customer Agreement also permits certain processing of customer data for service delivery, billing, fraud prevention, legal compliance and the generation of telemetry.

This is not the same as a clearly defined zero-data-retention commitment for prompts and outputs.

An enterprise should therefore ask for the exact retention period for inputs, outputs, logs, backups and telemetry; the deletion process; and whether a stricter retention configuration is available contractually.

EU-only deployment is not publicly documented

The public materials reviewed for this article do not describe a customer-selectable EU inference region, a European private cloud deployment, a private VPC option or an on-premises version of Jev.

TypeSafe may offer customer-specific arrangements that are not public. Procurement teams should confirm them directly rather than assume that they exist.

A US company remains subject to US jurisdiction

TypeSafe AI, Inc. is a US company, and its standard customer agreement is governed by California and US law. European organisations with strict sovereignty requirements may therefore consider not only where a server is located, but also which entity operates the service and which legal regimes can reach the provider.

Jev enterprise-readiness checklist for European buyers

Before deploying Jev with production data, a European enterprise should obtain clear answers to the following questions.

Area Question to verify
Data location In which countries are inputs, outputs, logs, backups and telemetry processed and stored?
Retention What is retained, for how long, and can zero retention be enforced contractually and technically?
Training Are inputs or outputs used for training, fine-tuning, evaluation or human review?
Transfers Which transfer mechanism applies, and has the organisation completed its transfer assessment?
Subprocessors Which infrastructure, security and support providers can access customer data?
Deployment Are EU region, single-tenant, private VPC or on-premises options available?
Security Which certifications, penetration tests, encryption controls and incident procedures can be evidenced?
Access control Are SSO, role-based permissions, service accounts and key rotation supported?
Auditability Can the organisation export decision logs, confidence values, policy outcomes and evidence?
Model risk How are accuracy, calibration, drift, failure modes and human escalation tested for the intended use case?

The answer may differ by workload. Routing an anonymous support request is not equivalent to processing patient data, employee records, financial information or customer identifiers.

GDPR compliance is not a feature a vendor can grant

No AI vendor can make a customer “GDPR compliant” merely by offering a DPA.

The customer remains responsible for questions such as:

  • the lawful basis for processing;
  • transparency to data subjects;
  • data minimisation and purpose limitation;
  • access controls and retention policies;
  • the need for a Data Protection Impact Assessment;
  • international transfer risk;
  • human oversight and contestability where decisions affect individuals.

Jev’s typed outputs and confidence estimates may make certain decisions easier to test and audit than free-form generated text. But structured output does not remove the legal and organisational obligations attached to the underlying data and use case.

Can Jev be made safer for European enterprise use?

Yes. An organisation can reduce exposure by controlling what reaches the model.

One architecture is to place a governance layer before the external API:

  1. detect personal, confidential or regulated information before transmission;
  2. replace sensitive values with reversible tokens or safe placeholders;
  3. send only the minimum necessary context to the model;
  4. restore authorised values locally when required;
  5. log the policy decision, model response and confidence for audit;
  6. block or escalate requests that cannot be processed safely.

This approach does not change the provider’s jurisdiction, but it can substantially reduce the amount of sensitive information exposed to an external service.

For some workloads, that may make a US-hosted model acceptable. For organisations requiring EU-only processing and control, the model itself must also be available inside an appropriate European deployment.

Why Colchix is building THEMIS

Jev demonstrates the value of fast, typed decisions for software. Colchix is developing THEMIS to bring that model category to European enterprise data protection and AI governance.

THEMIS begins with real-time detection of personal and sensitive information and bounded allow, mask, block or escalate decisions before data reaches an external AI system.

It is being designed around European data residency, zero data retention and flexible deployment, with a longer-term path toward a broader European System One model and specialised decision models for regulated use cases.

Starting with PII. Building Europe’s decision layer for enterprise AI.

THEMIS is currently under development. Deployment characteristics and performance objectives should be treated as product direction until Colchix publishes validated technical documentation and benchmark results.

Frequently asked questions

Can Jev legally be used in the European Union?

Yes, potentially. European organisations can use US-hosted AI services when they establish a lawful basis, meet their GDPR obligations and implement an appropriate mechanism for international data transfers. Suitability must be assessed for the specific data and use case.

Is Jev GDPR compliant?

GDPR compliance applies to a processing activity, not to a model in isolation. TypeSafe publishes a DPA and incorporates EU Standard Contractual Clauses, but each customer must assess its own lawful basis, data flows, risks and controls.

Is Jev hosted in Europe?

TypeSafe’s public privacy policy states that its services are hosted in the United States. The public documents reviewed for this article do not establish an EU-only inference or storage option.

Does TypeSafe train Jev on customer data?

TypeSafe’s privacy policy states that it does not train or fine-tune AI or machine-learning models on customer input. Its customer agreement also says customer data will not be included in a training dataset without prior consent.

Does Jev offer zero data retention?

The standard public documents reviewed for this article do not provide a clear zero-data-retention commitment for Jev inputs and outputs. Enterprises should confirm exact retention periods and any customer-specific zero-retention option directly with TypeSafe.

Is there a sovereign European alternative to Jev?

Colchix is developing THEMIS, its own sovereign, enterprise-ready System One model for real-time data protection and AI governance in Europe. It begins with PII detection and real-time protection decisions and is currently under development.

What Colchix is building

Colchix is developing THEMIS, its own sovereign System One model for real-time data protection and AI governance in Europe.

Starting with real-time PII detection and data protection, THEMIS is being designed to give European enterprises the speed and reliability of System One AI with European data residency, zero data retention and flexible deployment.

More details about THEMIS will be published as development progresses.

Sources and disclosure

This article is based on TypeSafe AI’s publicly available Master Customer Agreement, Data Processing Addendum, Privacy Policy, Jev documentation and Jev announcement, reviewed on 23 September 2026.

The article distinguishes between commitments stated in public documents and capabilities that were not publicly documented at the time of review. Absence from public documentation does not prove that a customer-specific option is unavailable.

Jev and TypeSafe AI are names belonging to their respective owner. Colchix is not affiliated with or endorsed by TypeSafe AI. This article is for general information and does not constitute legal advice. Organisations should verify current terms directly with the provider and obtain professional advice for their own processing activities.

Related: What Is Jev? System One Models vs LLMs Explained