TypeSafe Jev and Canadian Privacy: US Processing, PIPEDA, Law 25 and Human Review
Jev is processed in the US on every channel, and its DPA doesn't mention Canada. What PIPEDA and Law 25 raise, what we design for, and what to ask your lawyer.
— Craig Major
Short answer: TypeSafe Jev is not processed in Canada on any channel checked. A Canadian organisation must examine the US data path, its contracts, notices and any Quebec privacy impact assessment. Duties depend on the data and workflow. This is general information, not legal advice. Check with your own lawyer about your data and your obligations.

For the model’s capabilities, see the TypeSafe Jev explainer. This page stays with the privacy questions a controller, owner or privacy lead should resolve before putting real records into a pilot. The provider details below were checked for the September 26, 2026 research and should be confirmed again before publication and procurement.
The facts about Jev and your data
The first question is where processing occurs, not where your browser, automation account or gateway is located. TypeSafe’s privacy policy says its services are hosted in the United States. The researched routes through TypeSafe, OpenRouter, Cloudflare, DigitalOcean and Vercel did not provide a Canadian Jev processing option. DigitalOcean’s model details indicate Jev calls are passed to TypeSafe; selecting a Toronto DigitalOcean region would not by itself move Jev processing there. OpenRouter’s in-region routing covers EU and US choices, not Canada. Cloudflare’s regional-services documentation does not cover Workers AI. The research infers from Cloudflare’s third-party label that it passes the request to TypeSafe; confirm that exact path with Cloudflare rather than treating the inference as a contractual fact.
| Topic | What the cited public material says | What to check before a pilot |
|---|---|---|
| Processing by channel | Every Jev channel reviewed points to US processing; none offers a confirmed Canadian region. | Ask each gateway and TypeSafe for the actual processing path for your account and model version. |
| Subprocessors | TypeSafe’s trust centre lists AWS, Modal, Nebius, CoreWeave, Slack and Google Workspace, all in the US in the checked list. | Obtain the current list, roles, locations and change-notice terms. |
| DPA transfer scope | The public data processing addendum has EU SCC and UK Addendum transfer language and a general applicable-law clause. The checked text does not name Canada, PIPEDA, Quebec or Law 25. | Ask for written terms that address your Canadian and Quebec transfer needs; have counsel review them. |
| Privacy policy | The policy, dated November 19, 2025, says the service is US-hosted and does not name Canada in the checked research. | Read the current policy and compare it with the DPA and your own notice. |
| SOC 2 | The trust centre lists a “SOC 2 Type II – 2026” report behind a request-access step. The cited public page does not show an auditor or report date. | Request and review the report and scope; do not infer its contents from a badge. |
| Training on inputs | TypeSafe says it does not train or fine-tune on prompts or other input; its model notes say Jev is not trained on customer requests or responses. | Confirm the wording, exceptions and contract version applicable to your route. |
| Retention by channel | The research found zero-data-retention options on the direct enterprise API and Cloudflare, OpenRouter endpoint metadata indicating no retention, and conflicting Vercel status and changelog information. | Get written channel-specific retention and deletion terms. Do not treat a gateway label as proof of end-to-end zero retention. |
“Does not train on inputs” and “zero retention” answer different questions. Training addresses whether customer material changes a model. Retention addresses what request content, logs and metadata may remain, for how long and with whom. A buyer needs both, plus access controls and incident terms. A no-retention setting at one gateway does not automatically describe TypeSafe’s handling or the logs in your own workflow.
PIPEDA in plain English
The Office of the Privacy Commissioner of Canada says PIPEDA does not generally prohibit a Canadian organisation from transferring personal information to a processor outside Canada. Its guidance also says the organisation remains accountable for the information in the processor’s hands. That is why “the vendor is in the US” is the start of the review, not a final answer about whether a particular use is permissible.
Principle 4.1.3 calls for contractual or other means to provide a comparable level of protection while a third party processes the information. The OPC describes a contract as the main practical way to do that. A team should know the purposes for which information is sent, the processors involved, access and security measures, and what happens when the work ends. The right evidence depends on the information and the outsourcing arrangement.
The OPC also tells organisations to be open with individuals about foreign processing and possible access under the law of that jurisdiction. A privacy notice that says only “we use AI” would not answer where a person’s information may travel. Review the notices and the real data flow together. PIPEDA guidance is general; it does not approve a particular Jev deployment. Check with your own lawyer about your data and your obligations.
Quebec Law 25 in plain English
Quebec’s private-sector privacy statute adds questions that a Quebec organisation must address for its own system and data. A gateway account opened in Canada does not, by itself, answer whether information is communicated outside Quebec. Review the full path and the business decision that uses the answer. The comments below describe the cited provisions in general terms; check with your own lawyer about your data and your obligations.
Section 17: information leaving Quebec
Section 17 calls for a privacy impact assessment before personal information is communicated outside Quebec and a written agreement that takes the assessment into account. The assessment considers the information’s sensitivity, the purpose, safeguards and the destination’s legal framework. The public TypeSafe DPA checked for this review addresses EU and UK mechanisms but does not name Quebec. Ask TypeSafe for written Canadian and Quebec terms, map every gateway and subprocessor, and have your lawyer review the arrangement before a pilot with personal information. Do not treat the absence of a Quebec clause as a legal conclusion on its own.
Section 3.3: a new or overhauled system
Section 3.3 calls for a privacy impact assessment for a project to acquire, develop or overhaul an information system or electronic service delivery system involving personal information. An AI sorting step may sit inside a larger project, so describe the actual system: source records, categories, access, review, downstream action, retention and deletion. The assessment should cover both the model call and the surrounding automation. Your lawyer and privacy lead can determine how this provision applies to your project.
Section 12.1: decisions based exclusively on automated processing
Quebec's Law 25 (s.12.1) sets duties for decisions 'based exclusively on automated processing'. The law doesn't list which systems count. Whether auto-routing a lead, a document or a call is covered depends on how your system works, for example whether a person looks at or can change the result before it takes effect. That's a question for your own lawyer. Either way, we design for it: a human review path, a log of each question, answer, probability, model version and threshold, and a way for anyone affected to reach a person.
What we design for
A privacy review should become an operating design, not a folder of policies. Our human-led system design guide starts with the person who remains responsible for the outcome.

- Send less. Redact names, identifiers or free text that the decision question does not require. Keep the original record in your controlled system when possible.
- Use a confidence gate and review queue. A low or missing probability, unfamiliar document or conflicting signal should stop automatic action. The review-queue guide covers the handoff.
- Log the factors. Record the question, selected answer, probability, model version, threshold, proposed action and any human override. Limit access to that log and set a retention rule.
- Keep a human path. Affected people and staff need a way to question or correct an outcome. The human-boundary guide explains the role of reviewers.
- Pin and retest the version. Where a channel allows it, record the exact model version. A change in the model or question can change the routing pattern and should trigger a fresh check.
- Know every processor. Map the gateway, TypeSafe, subprocessors and your own automation tools. Confirm which party receives what data and which agreement covers each step.
These are design controls to discuss with counsel and the people who operate the process. They are not a declaration that a workflow satisfies a statute.
Keeping a step in-house
A local classifier can be an in-house sorting step. If that step runs on your own machines, it removes the foreign transfer for that particular classification call. It does not erase transfers elsewhere in the workflow, such as OCR, storage, email or voice services. Nor does it remove the need to assess a new system, set safeguards, decide retention and explain decisions. Labelled training and test examples can themselves contain personal information.
Flowgrammer spot-checked one in-house sorting step and found English-only handling, French failure, 256-token truncation and an early version without server authentication. That small check is a reason to test carefully, not a verdict on all local tools. The local-options article records its limits. The only ways we found to keep a classification step in Canada are running it on your own machines or AWS Comprehend in the Canada (Central) region; other hosted options, including Jev, process in the US or do not confirm a region. The alternatives guide compares the decision methods; AWS pricing was not checked in the research.
An in-house route may change which transfer questions arise for that step. It does not make a system lawful by itself. Check the complete system with your own lawyer about your data and your obligations.
Pre-pilot checklist
Before using real personal information, put the answers in one reviewable record:
- What personal information appears in the input, including examples used for testing?
- Which Jev channel and model version will be used, and can the version be pinned?
- Where does each provider process, retain and log the request? What does the current subprocessor list show?
- Has the team read the TypeSafe DPA, including the fact that its checked transfer section does not name Canada?
- Has TypeSafe supplied the SOC 2 Type II report and written terms for Canadian or Quebec transfers where needed?
- If Quebec information is in scope, has the team planned the privacy impact assessment and written agreement for the actual transfer?
- Which decisions are automatic? What stops a wrong route, and how does an affected person reach a human?
- Are question, answer, probability, version, threshold, action and override logs enabled with controlled access?
- What are the retention and deletion rules for source material, prompts, responses, logs and labelled examples?
- Do notices to individuals describe the real processing path in plain language?
- Has your own lawyer reviewed the proposed use and agreements?
A blank answer is a reason to pause the pilot design until the team can answer it, rather than a reason to assume the provider has settled it.
FAQ
Is TypeSafe Jev hosted in Canada?
No Canadian Jev processing option was found on any channel checked for the September 26, 2026 research: TypeSafe, OpenRouter, Cloudflare, DigitalOcean or Vercel. TypeSafe’s policy says its services are hosted in the United States. A Canadian gateway region does not establish Canadian processing by TypeSafe. Confirm the current data path with each provider before sending real information.
Is Jev PIPEDA compliant?
A model cannot carry a blanket PIPEDA label for every customer use. The OPC says a Canadian organisation remains accountable for personal information sent to a processor outside Canada and should use contractual or other means for comparable protection. The answer depends on your data, contracts, safeguards and notices. This is general information, not legal advice. Check with your own lawyer.
Does TypeSafe’s DPA cover Canadian data transfers?
The public DPA checked for this review has EU and UK international-transfer mechanisms and a general applicable-law clause, but does not name Canada, PIPEDA, Quebec or Law 25. That observation does not decide whether its terms are sufficient for your use. Ask TypeSafe for written Canadian and Quebec terms, then have your own lawyer review the agreement and data path.
Can I send Quebec personal information to Jev?
Quebec’s section 17 generally calls for a privacy impact assessment and a written agreement before personal information is communicated outside Quebec. TypeSafe’s public terms checked here do not specifically address Quebec. Map the actual route, ask TypeSafe for written terms and have your lawyer review the planned transfer before a pilot. This is general information, not legal advice.
Is auto-routing with Jev an “automated decision” under Law 25?
Section 12.1 addresses decisions based exclusively on automated processing. Whether a particular lead, document or call route falls within it depends on how your system works and when a person can review or change the result. The statute does not list every possible workflow. Keep a human path and decision log, and ask your own lawyer to assess your design.
Does running AI locally make me Law 25 compliant?
No single hosting choice settles the legal duties for a system. Running a classification step on your own machines can remove that step’s foreign transfer, while privacy impact assessment, safeguards, retention, explanation and other data flows remain relevant. Training and test examples may contain personal information too. This is general information, not legal advice. Check with your own lawyer.
Next step
If a funded automation system needs an owner for the data path, review rules and ongoing operation, contact Flowgrammer about systems leadership.