GDPR at UseJunction
Updated 2026-09-18
UseJunction's EU hosted region stores workspace data in the EU, disables Signals work extraction, shows developers a collection notice before the agent enrolls, and lets people export or erase their data. The customer remains the controller of employee telemetry and must handle employment-law notice and works councils.
What the agent collects
Usage, estimated cost, plan utilization, tool inventory, device health, and related metadata from local tool stores. It does not capture keystrokes, screenshots, clipboard, source code, or full chats.
A collection notice is shown in the product before an enrollment token is issued, and the agent records the same notice version on the device.
EU region
Choose the EU region at signup to use eu.usejunction.dev with an EU database. US and EU deployments do not mix customer telemetry.
Signals work extraction (titles, summaries, clipped asks) is off and cannot be enabled on the EU hosted region in this release.
Your team's responsibilities
You are the controller. Provide employees a notice, consult your works council or CSE/OR where required, and do not use the product for unlawful individual surveillance or automated performance decisions.
Templates for an employee notice and a works-council brief live in the open-source repo under docs/compliance.
Rights requests
Each developer can open My data, export a machine-readable bundle, and request erasure. Owners and admins can export or erase a member. Removal from the team schedules erasure after 30 days unless cancelled.
Privacy policy: /privacy. Processor terms: /dpa. Subprocessors: /subprocessors.
FAQ
- Is employee consent required?
- Usually no — and often invalid because of the employment power imbalance. Use a lawful basis such as legitimate interests that is proportionate, plus transparency. We still show a collection notice so people know what is uploaded.
