Guides
EU compliance guides for app builders. Grounded in real code.
Practical explanations of GDPR architecture, EU data residency, DSAR portals, and tamper-evident audit logs — tied to real modules and infrastructure, not marketing copy.
EU Residency
EU data residency & GDPR architecture
What 'GDPR-compliant by construction' means, how EU data residency works at each infrastructure layer, and how Alleex Cloud enforces these properties as architectural defaults.
What does 'GDPR-compliant by construction' mean?
"GDPR-compliant by construction" means that every application produced by Alleex Cloud includes the required data-protection measures as a structural default — data residency in the EU, a tamper-evident audit log, DSAR self-serve, and cookie consent — before any custom code is written. The compliance properties are enforced at composition time, not retrofitted later. If the composition plan would produce a non-compliant data path, the engine rejects it.
Read guide →
EU data residency for web apps: what it requires and how to achieve it
EU data residency means that all personal data your web application collects and processes — including the database, server-side logic, and transactional email — remains physically located within the European Union. For a Next.js app, this requires choosing EU-region infrastructure for each layer: database (Postgres in Frankfurt or similar), compute (Cloudflare Workers EU zone or an EU server), auth, and email. Alleex Cloud provisions all of these in the EU by default, without a region toggle.
Read guide →
Data Subject Rights
DSAR & data subject rights
How to implement GDPR Articles 15, 17, and 20 — access, portability, and erasure — in a Next.js app. How the compliance-eu module automates request intake, verification, export, and erasure.
Audit Log
Tamper-evident audit log
How hash-chaining and Sigstore Rekor witnessing make an audit log verifiably tamper-evident. Why this matters for GDPR accountability and enterprise due diligence.
Comparison
Alleex Cloud vs other builders
Honest, factual comparisons with other app builders on EU compliance dimensions. Competitor claims are stated accurately — certifications, residency options, and architectural differences.
Every capability claim in these guides corresponds to a real module or feature in the Alleex Cloud registry. Competitor statements are checked for accuracy and updated when their products change. These guides are information, not legal advice — consult your DPO for your specific obligations.
Ready to build EU-compliant by default?
Free tier, no credit card. EU data residency, DSAR portal, and hash-chained audit log from the first deploy.