Skip to content

GDPR (+ CLOUD-Act exposure)

Regulation (EU) 2016/679

The requirement. Minimisation, control of transfers outside the EU.

The AWA answer. Documents are processed in the user's browser — there is no data to minimise server-side since it never goes there. Zero telemetry in every package. And no third-party service, registry or cloud in the execution path: the component itself creates no CLOUD Act exposure — your deployment's exposure depends on your infrastructure, and we document the distinction. Verifiable like everything else: it is a single repository, search it.

On our own sites. AwaCloud's sites set no cookie, use no tracker and no third-party audience-measurement tool, and do not retain visitors' IP addresses — at most, pages viewed may be counted in aggregate, without cookie or IP address. The online demos run entirely in your browser: the files you open are never sent to us. How we handle the personal data we do receive (correspondence, customers, prospecting) is set out in our privacy policy; write to privacy@awacloud.com.

Compliance evidence pack — executive summary

6 proven
0 partial
0 gap

GDPR-01 proven Art. 5(1)(c) + Art. 25 — data minimisation / data protection by design

The shipped front code contains no telemetry and no analytics of any kind, and makes no outbound call to any hard-coded host.

snapshot 2026-10-01

GDPR-02 proven Art. 5(1)(c) + ePrivacy Art. 5(3) — no non-essential terminal storage

The application and site layers set no cookies.

snapshot 2026-10-01

GDPR-03 proven Art. 5(1)(c) — minimisation at the serving tier

The serving pair logs no IP address and no client identifier.

snapshot 2026-10-01

GDPR-04 proven Art. 44–49 + CLOUD-Act exposure — no transfer, no foreign-controlled processor in the runtime path

The runtime path contains no third-party processor at all: the buyer self-hosts the entire stack, and no component contacts an external service.

snapshot 2026-10-01

GDPR-05 proven Art. 28 + CLOUD-Act residual exposure

Scoped boundary. The runtime path carries no processor and no transfer (GDPR-04). The only contact with US-operated infrastructure is in obtaining the component: the development-toolchain closure recorded in bun.lock resolves 188 packages from the npm registry, and the published packages are distributed through npm and GitHub — neither channel is in the runtime path.

Reclassified partial → proven on 2026-10-01 with the owner's acceptance: the claim now states the measured boundary instead of an unquantified residual exposure. The residual is stated, not eliminated: obtaining the component (toolchain and distribution channel) and whatever hosting the buyer selects. An offline or mirrored install keeps the channel out of the buyer's path (NIS2-05).

snapshot 2026-10-01

GDPR-06 proven Art. 28(3) processor terms; Art. 30 records of processing

Not applicable to the component. AWA processes no personal data on a buyer's behalf: it is a library run on the buyer's own systems, with no hosted service, no telemetry and no outbound call in the shipped code (GDPR-01, GDPR-04), so using it creates no processor relationship for an Art. 28(3) agreement to govern.

Reclassified gap → proven on 2026-10-01 with the owner's acceptance. The editor's own Art. 30 record of processing exists and is kept outside this repository, in a private register; it is not published and nothing of its content appears here. A buyer's processing agreements with its own providers stay its own.

snapshot 2026-10-01

Pack generatedEvidence verified
2026-10-012026-10-01

AwaCloud status

In progress · status as of 2026-10-01.