GDPR Compliance
Jaapi AB is an EU-based company committed to protecting your privacy. We maintain GDPR compliance through EU data residency, minimal data collection, and full respect for your data rights.
View Trust CenterGDPR FAQs
Is Jaapi GDPR compliant? +
Yes. Jaapi AB is a Swedish company fully compliant with the EU General Data Protection Regulation (GDPR). We maintain EU data residency, process data under valid legal bases, and uphold all data subject rights. Our ISO 27001:2022 certification further demonstrates our commitment to data protection.
Where is my data stored? +
Your data is stored in the European Union, primarily in Frankfurt, Germany. As an EU-based company, we maintain strict EU data residency. For services requiring US-based providers (customer support, team communication), we ensure GDPR compliance through EU Standard Contractual Clauses.
What personal data does Jaapi collect? +
We collect only essential data: account information (name, email), shipping addresses for orders, and order history. We do not store credit card numbers, government IDs, health information, or biometric data. Payment processing is handled by Stripe—card details never touch our systems.
What are my data rights under GDPR? +
You have the right to access your data, correct inaccuracies, request deletion, receive your data in a portable format, object to processing, and restrict how we use your data. To exercise any right, contact lynn@jaapi.store. We respond within one month as required by GDPR.
Who are Jaapi's sub-processors? +
Our primary sub-processors are: AWS (database hosting, Frankfurt), Vercel (application hosting, Frankfurt), Stripe (payments, Ireland), MailerSend (email, Belgium), Pylon (support tickets, US with EU SCCs), and Slack (team communication, US with EU SCCs). A complete list is available at trust.jaapi.com/vendors.
How long does Jaapi retain my data? +
Account and order data is retained during your service period. System logs are automatically deleted after 30 days. Upon account deletion request, we remove personal data except where legally required (e.g., tax records retained 7+ years). Session data expires automatically.
Who is Jaapi's Data Protection contact? +
For privacy questions, data subject requests, or GDPR inquiries, contact Lynn Smeria at lynn@jaapi.store. We respond to all data protection requests within one month. For detailed compliance documentation, visit trust.jaapi.com.
Ready to unite your global team with hassle-free swag?
Connect your worldwide employees and customers with quality branded items—made on demand and delivered locally. No warehousing headaches. No customs delay.
Get a demo