Jumbo Privacy and GDPR
CertReports found no public GDPR evidence for Jumbo Privacy as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 27 Mar 2020
- Scope
- 2121 Atelier owns and operates an iOS and Android application entitled "Jumbo Privacy" which enables users to simply manage their privacy online. Any personal data that might be processed by 2121 Atelier (or any subprocessor) from European residents with regards to this activity is: - the data received when such users are contacting the support services with their enquiries. In such event, 2121 Atelier will receive the email addresses of the users, IPs and, sometimes, their names. This information is deleted within 30 days after reception. - analytic data (IP address) when navigating on 2121 Atelier's websites available at the following URL addresses: www.withjumbo.com and blog.withjumbo.com. This is only used for statistics purposes, and the data is destroyed after 24 hours. - 2121 Atelier allows users to store information related to account login directly on their device. This information does not leave the device and can be deleted at any time by the user.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Jumbo Privacy: Inactive | Live pagesha256 1710d9c1e7 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Jumbo Privacy GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.