GDPR (+ CLOUD-Act exposure)
Regulation (EU) 2016/679
The requirement. Minimisation, control of transfers outside the EU.
The AWA answer. Documents are processed in the user's browser — there is no data to minimise server-side since it never goes there. Zero telemetry in every package. And no third-party service, registry or cloud in the execution path: the component itself creates no CLOUD Act exposure — your deployment's exposure depends on your infrastructure, and we document the distinction. Verifiable like everything else: it is a single repository, search it.
On our own sites. AwaCloud's sites set no cookie, use no tracker and no third-party audience-measurement tool, and do not retain visitors' IP addresses — at most, pages viewed may be counted in aggregate, without cookie or IP address. The online demos run entirely in your browser: the files you open are never sent to us. How we handle the personal data we do receive (correspondence, customers, prospecting) is set out in our privacy policy; write to privacy@awacloud.com.
Compliance evidence pack — executive summary
GDPR-01 proven Art. 5(1)(c) + Art. 25 — data minimisation / data protection by design
The shipped front code contains no telemetry and no analytics of any kind, and makes no outbound call to any hard-coded host.
GDPR-02 proven Art. 5(1)(c) + ePrivacy Art. 5(3) — no non-essential terminal storage
The application and site layers set no cookies.
GDPR-03 proven Art. 5(1)(c) — minimisation at the serving tier
The serving pair logs no IP address and no client identifier.
GDPR-04 proven Art. 44–49 + CLOUD-Act exposure — no transfer, no foreign-controlled processor in the runtime path
The runtime path contains no third-party processor at all: the buyer self-hosts the entire stack, and no component contacts an external service.
GDPR-05 proven Art. 28 + CLOUD-Act residual exposure
Scoped boundary. The runtime path carries no processor and no transfer (GDPR-04). The only contact with US-operated infrastructure is in obtaining the component: the development-toolchain closure recorded in bun.lock resolves 188 packages from the npm registry, and the published packages are distributed through npm and GitHub — neither channel is in the runtime path.
Reclassified partial → proven on 2026-10-01 with the owner's acceptance: the claim now states the measured boundary instead of an unquantified residual exposure. The residual is stated, not eliminated: obtaining the component (toolchain and distribution channel) and whatever hosting the buyer selects. An offline or mirrored install keeps the channel out of the buyer's path (NIS2-05).
GDPR-06 proven Art. 28(3) processor terms; Art. 30 records of processing
Not applicable to the component. AWA processes no personal data on a buyer's behalf: it is a library run on the buyer's own systems, with no hosted service, no telemetry and no outbound call in the shipped code (GDPR-01, GDPR-04), so using it creates no processor relationship for an Art. 28(3) agreement to govern.
Reclassified gap → proven on 2026-10-01 with the owner's acceptance. The editor's own Art. 30 record of processing exists and is kept outside this repository, in a private register; it is not published and nothing of its content appears here. A buyer's processing agreements with its own providers stay its own.
| Pack generated | Evidence verified |
|---|---|
| 2026-10-01 | 2026-10-01 |
AwaCloud status
In progress · status as of 2026-10-01.