RGPD et exposition au CLOUD Act
Règlement (UE) 2016/679
L'exigence. Minimisation, maîtrise des transferts hors UE.
La réponse AWA. Les documents sont traités dans le navigateur de l'utilisateur — il n'y a pas de données à minimiser côté serveur puisqu'elles n'y vont pas. Zéro télémétrie dans tous les packages. Et aucun service tiers, registre ni cloud dans le chemin d'exécution : le composant lui-même ne crée aucune exposition CLOUD Act — celle de votre déploiement dépend de votre infrastructure, et nous documentons la distinction. Vérifiable dans le dépôt AWA.
Sur nos propres sites. Les sites d'AwaCloud ne déposent aucun cookie, n'utilisent aucun traceur ni outil tiers de mesure d'audience et ne conservent pas les adresses IP des visiteurs — au plus, le nombre de pages consultées peut être compté de façon agrégée, sans cookie ni adresse IP. Les démonstrations en ligne s'exécutent entièrement dans votre navigateur : les fichiers que vous y ouvrez ne nous sont jamais transmis. Le traitement des données que nous recevons (correspondance, clients, prospection) est décrit dans notre politique de confidentialité.
Pour toute question, écrivez à privacy@awacloud.com.
Dossier de preuves relatives à la conformité — synthèse exécutive
GDPR-01 proven Art. 5(1)(c) + Art. 25 — data minimisation / data protection by design
The shipped front code contains no telemetry and no analytics of any kind, and makes no outbound call to any hard-coded host.
GDPR-02 proven Art. 5(1)(c) + ePrivacy Art. 5(3) — no non-essential terminal storage
The application and site layers set no cookies.
GDPR-03 proven Art. 5(1)(c) — minimisation at the serving tier
The serving pair logs no IP address and no client identifier.
GDPR-04 proven Art. 44–49 + CLOUD-Act exposure — no transfer, no foreign-controlled processor in the runtime path
The runtime path contains no third-party processor at all: the buyer self-hosts the entire stack, and no component contacts an external service.
GDPR-05 proven Art. 28 + CLOUD-Act residual exposure
Scoped boundary. The runtime path carries no processor and no transfer (GDPR-04). The only contact with US-operated infrastructure is in obtaining the component: the development-toolchain closure recorded in bun.lock resolves 188 packages from the npm registry, and the published packages are distributed through npm and GitHub — neither channel is in the runtime path.
Reclassified partial → proven on 2026-10-01 with the owner's acceptance: the claim now states the measured boundary instead of an unquantified residual exposure. The residual is stated, not eliminated: obtaining the component (toolchain and distribution channel) and whatever hosting the buyer selects. An offline or mirrored install keeps the channel out of the buyer's path (NIS2-05).
GDPR-06 proven Art. 28(3) processor terms; Art. 30 records of processing
Not applicable to the component. AWA processes no personal data on a buyer's behalf: it is a library run on the buyer's own systems, with no hosted service, no telemetry and no outbound call in the shipped code (GDPR-01, GDPR-04), so using it creates no processor relationship for an Art. 28(3) agreement to govern.
Reclassified gap → proven on 2026-10-01 with the owner's acceptance. The editor's own Art. 30 record of processing exists and is kept outside this repository, in a private register; it is not published and nothing of its content appears here. A buyer's processing agreements with its own providers stay its own.
Dossier généré le 2026-10-01 · preuves vérifiées le 2026-10-01
Statut AwaCloud
En cours · statut au 01/10/2026.