Aller au contenu

RGPD et exposition au CLOUD Act

Règlement (UE) 2016/679

L'exigence. Minimisation, maîtrise des transferts hors UE.

La réponse AWA. Les documents sont traités dans le navigateur de l'utilisateur — il n'y a pas de données à minimiser côté serveur puisqu'elles n'y vont pas. Zéro télémétrie dans tous les packages. Et aucun service tiers, registre ni cloud dans le chemin d'exécution : le composant lui-même ne crée aucune exposition CLOUD Act — celle de votre déploiement dépend de votre infrastructure, et nous documentons la distinction. Vérifiable dans le dépôt AWA.

Sur nos propres sites. Les sites d'AwaCloud ne déposent aucun cookie, n'utilisent aucun traceur ni outil tiers de mesure d'audience et ne conservent pas les adresses IP des visiteurs — au plus, le nombre de pages consultées peut être compté de façon agrégée, sans cookie ni adresse IP. Les démonstrations en ligne s'exécutent entièrement dans votre navigateur : les fichiers que vous y ouvrez ne nous sont jamais transmis. Le traitement des données que nous recevons (correspondance, clients, prospection) est décrit dans notre politique de confidentialité.

Pour toute question, écrivez à privacy@awacloud.com.

Dossier de preuves relatives à la conformité — synthèse exécutive

6 proven
0 partial
0 gap

GDPR-01 proven Art. 5(1)(c) + Art. 25 — data minimisation / data protection by design

The shipped front code contains no telemetry and no analytics of any kind, and makes no outbound call to any hard-coded host.

snapshot 2026-10-01

GDPR-02 proven Art. 5(1)(c) + ePrivacy Art. 5(3) — no non-essential terminal storage

The application and site layers set no cookies.

snapshot 2026-10-01

GDPR-03 proven Art. 5(1)(c) — minimisation at the serving tier

The serving pair logs no IP address and no client identifier.

snapshot 2026-10-01

GDPR-04 proven Art. 44–49 + CLOUD-Act exposure — no transfer, no foreign-controlled processor in the runtime path

The runtime path contains no third-party processor at all: the buyer self-hosts the entire stack, and no component contacts an external service.

snapshot 2026-10-01

GDPR-05 proven Art. 28 + CLOUD-Act residual exposure

Scoped boundary. The runtime path carries no processor and no transfer (GDPR-04). The only contact with US-operated infrastructure is in obtaining the component: the development-toolchain closure recorded in bun.lock resolves 188 packages from the npm registry, and the published packages are distributed through npm and GitHub — neither channel is in the runtime path.

Reclassified partial → proven on 2026-10-01 with the owner's acceptance: the claim now states the measured boundary instead of an unquantified residual exposure. The residual is stated, not eliminated: obtaining the component (toolchain and distribution channel) and whatever hosting the buyer selects. An offline or mirrored install keeps the channel out of the buyer's path (NIS2-05).

snapshot 2026-10-01

GDPR-06 proven Art. 28(3) processor terms; Art. 30 records of processing

Not applicable to the component. AWA processes no personal data on a buyer's behalf: it is a library run on the buyer's own systems, with no hosted service, no telemetry and no outbound call in the shipped code (GDPR-01, GDPR-04), so using it creates no processor relationship for an Art. 28(3) agreement to govern.

Reclassified gap → proven on 2026-10-01 with the owner's acceptance. The editor's own Art. 30 record of processing exists and is kept outside this repository, in a private register; it is not published and nothing of its content appears here. A buyer's processing agreements with its own providers stay its own.

snapshot 2026-10-01

Dossier généré le 2026-10-01 · preuves vérifiées le 2026-10-01

Statut AwaCloud

En cours · statut au 01/10/2026.