Jiminny is one of the stronger options on residency, and it is fair to say so. It is a UK company (Jiminny Holdings Limited), it publishes a current Article 28 DPA, and it documents a genuine EU environment hosted primarily in Ireland where, by its own words, all data is stored and processed. An EU controller can run it in that EU environment lawfully. The caveat: Jiminny is not US-free. Its Privacy Policy lists processing in the US, Ireland, the UK and other locations, its transfer basis includes the EU-US Data Privacy Framework, and its sub-processor list includes US AI vendors such as OpenAI. This piece quotes Jiminny's own current documents, retrieved 2026-07-26.
Is Jiminny GDPR compliant?
Jiminny is one of the stronger options on data residency in this category, and it is fair to say so up front. It is a UK company, it publishes a current Article 28 DPA, and it documents a genuine EU environment, hosted primarily in Ireland, where by its own words "all data is stored and processed." An EU controller can run Jiminny in that EU environment with a proper transfer basis.
The caveat is that Jiminny is not US-free. Its Privacy Policy states data is processed "in the United States of America, Ireland, the United Kingdom and other locations," its transfer basis leans on the EU-US Data Privacy Framework, and its sub-processor list includes US AI vendors such as OpenAI. So "EU residency is available" is accurate, while "no US processing" is not supported by Jiminny's own documents. The distinction is worth understanding before you rely on it.
Who Jiminny is and where it processes data
Jiminny's Privacy Policy names the entity and its regulator: "Jiminny Holdings Limited, Floor 2, 100 Fenchurch Street, London EC3M 5JD," registered "as a Data Controller with the Information Commissioner's Office (ICO) in the UK." That is a UK corporate home, which is a materially different starting point from the US-headquartered tools in this set.
On location, Jiminny documents two isolated environments. Its data-storage page states: "Our primary EU location is in Ireland, where all data is stored and processed," and separately, "Our primary US location is in Ohio, where all data is stored and processed." It adds that "Since the environments are completely isolated, data cannot pass between them." Meeting capture may use other regions within the same environment, for example Germany in the EU. That is a real EU-residency option, not a residency claim bolted onto a US backend.
Sources, retrieved 2026-07-26: jiminny.com/legal/privacy, help.jiminny.com data storage.
Jiminny's DPA and the transfer basis
Jiminny's DPA, last updated 1 July 2026, is a current Article 28 agreement. It states "Customer is the Controller and Jiminny is the Processor," binds Jiminny to process "only on behalf of and in accordance with Customer's lawful, documented instructions," and sets the transfer safeguard for restricted transfers.
On restricted transfers out of the EEA, Switzerland, and the UK, Jiminny's DPA provides that "the parties agree to comply with and enter into the EU SCCs and the UK Addendum," pointing to the EU Standard Contractual Clauses. Separately, Jiminny's Privacy Policy states it "complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework." So EU-to-US flows ride on SCCs plus the DPF, the same layered basis the US-headquartered tools use.
One housekeeping note for buyers doing diligence: an older Jiminny security brief still references the defunct EU-US Privacy Shield, which was invalidated in 2020. The current Privacy Policy uses the DPF, so treat the Privacy Shield mention as a stale page rather than the live position, and confirm the current basis in the DPA and Privacy Policy.
Sources, retrieved 2026-07-26: jiminny.com/legal/dpa, jiminny.com/legal/privacy.
Jiminny's sub-processors: where the AI runs
Even with an EU storage environment, the sub-processor list decides where the AI and transcription steps actually run. Jiminny's list (last updated 25 June 2025) mixes EU and US vendors, and the AI layer is not EU-exclusive.
- Amazon Web Services, Inc. (US) hosts the infrastructure, "such as servers, storage, and streaming of media."
- OpenAI (US) powers "responses to Ask Jiminny on a Call, as well as diarization for some mono conversations," and Google Cloud (US) powers some Ask Jiminny responses.
- AssemblyAI (US/EU) and Gladia (EU) "transcribe your calls into text," so transcription can run through a US-linked vendor or an EU one depending on routing.
- Recall (US/EU) captures meeting recordings via a bot, and backup generative-AI vendors Fireworks AI and Together (both US/EU) sit behind Ask Jiminny.
The list itself does not guarantee EU-only routing for these AI and transcription vendors. So the strength of Jiminny's EU environment for storage is real, while the AI layer still touches US-linked processors unless region routing is contractually pinned. Confirm with Jiminny which vendors serve your EU environment and where.
Sources, retrieved 2026-07-26: help.jiminny.com subprocessors.
Residency, sovereignty, and the CLOUD Act
Jiminny shows why residency and sovereignty are different questions. Storage residency in Ireland is documented and genuine. Sovereignty is about which jurisdiction can compel the data, and that is decided by corporate ownership and the sub-processors in the chain, not only by where the database sits.
With US sub-processors such as OpenAI in the AI path and a transfer basis that includes the DPF, a share of processing remains reachable by US law even when primary storage is in the EU. The US CLOUD Act can compel a US company to produce data in its control regardless of where servers sit, and that reach extends to a US sub-processor handling your call content. For the wider mechanics, see our explainer on the CLOUD Act and EU data sovereignty for AI.
Where Jiminny is genuinely solid
Jiminny earns real credit here, and a fair comparison says so.
- A genuine EU data-residency option. Unlike the US-only tools in this set, Jiminny documents a fully isolated EU environment with primary storage and processing in Ireland and hard isolation from the US environment.
- A current, well-structured DPA (updated July 2026) with proper controller and processor roles, instruction-bound processing, and SCCs plus a UK Addendum for restricted transfers.
- Encryption in transit and at rest, stated as 256-bit in transit.
- SOC 2 and infrastructure assurance, with external auditors and reliance on AWS certifications. Note that the ISO 27001 referenced is AWS's, not stated as Jiminny's own, and the SOC 2 type is not specified in the fetched page.
The honest read is that Jiminny sits a step ahead of the US-only tools on residency and a step behind a fully EU-native, US-vendor-free stack on sovereignty. Where you land depends on whether an EU storage region is enough for your risk assessment, or whether you need the AI layer to be US-vendor-free as well.
The EU-native alternative
If an EU storage region is not enough and you need the AI and transcription layers to be US-vendor-free as well, that is the gap to close. The structural answer is a provider with no US hosting and no US AI provider in the analysis loop. Numi is a sovereign meeting assistant built on that principle: EU data residency, self-hosted open-source transcription, no US AI provider in the loop, and a GDPR Article 28 processor agreement (Auftragsverarbeitungsvertrag) behind it. For the full field of EU-native options, see our guide to Gong alternatives for the DACH region in 2026, and compare the data practices of the major tools on our compliance comparison hub.