Published August 20, 2026 in Inside Vibely·9 min read
GDPR, data residency, and the EU AI Act: what EU teams should ask an AI app builder

What "GDPR compliant AI app builder" actually means, how the EU AI Act treats a general-purpose tool like Vibely, and the specific facts on data residency, DPAs, and certifications every EU team should check before adopting one.
Every EU procurement conversation about an AI app builder now includes two questions that used to be niche: "is this GDPR compliant?" and, more recently, "does the EU AI Act apply to this?" Neither question has a one-word answer, and any vendor that gives you one is oversimplifying. Here is a straight, sourced answer for Vibely, plus the questions worth asking any tool in this category.
"GDPR compliant" is not a single certificate
There is no such thing as a "GDPR certification" a vendor can hold up and hand you. GDPR compliance for a SaaS vendor is a combination of things: a documented lawful basis for processing, a Data Processing Agreement (DPA) you can sign or review, contractual protection for cross-border transfers, and technical controls (encryption, access control, breach handling) that back it up. When you evaluate an AI app builder, ask for the DPA and the lawful basis, not a badge.
For Vibely specifically: our lawful basis for processing EEA and UK users' personal data is contract performance (to provide the service you signed up for), legitimate interests (to improve and secure the platform), and consent for optional communications. Our Article 28 Data Processing Agreement is published at /dpa and applies without signature. Full detail is in our privacy policy and security page.
Where is your data actually hosted?
This is the question that matters most in practice, and it deserves a direct answer rather than marketing language. Here is ours: Vibely does not offer a data-residency choice today. There is no region selector in the product, and we are not going to imply one exists. Vibely runs on managed cloud infrastructure, and the authoritative, current list of every provider that processes your data — hosting, database, AI inference, payments, observability, email — is public at /subprocessors. Read it, and check the jurisdiction of each entry against your own requirements. If your organization has a hard EU-data-residency requirement today, Vibely is not the right fit yet, and that is worth knowing up front rather than discovering during a security review.
For users accessing Vibely from the EEA or the UK, these transfers are made under Standard Contractual Clauses (SCCs) approved by the European Commission — the standard mechanism for lawfully moving personal data outside the EEA/UK under GDPR.
Is there a Data Processing Agreement?
Yes. Our GDPR DPA is published at /dpa, applies without signature, and covers the small, deliberate set of subprocessors Vibely uses (cloud hosting, AI inference, payments, observability, email) under their own data protection agreements. The current subprocessor list is public at /subprocessors; the DPA-backed schedule itself is shared under NDA on request.
What about SOC 2 and ISO 27001?
Here is where we would rather under-claim than over-claim. We hold no SOC 2 report and no ISO 27001 certificate, no audit against either framework is under way, and we are not naming a date for one. The controls themselves are described at /security and the live ones are re-run on every load at /trust, but none of it is externally attested, and we will say so here on the day we engage an auditor rather than before. If a competing AI app builder tells you it is "SOC 2 compliant" without specifying Type I vs Type II and without an audit date, ask to see the report — the distinction matters more than the acronym.
Does the EU AI Act apply to an AI app builder?
The EU AI Act's obligations for high-risk AI systems began enforcement on August 2, 2026, and this is the question we get asked most since. The short answer for a tool like Vibely: it is a general-purpose AI development tool, not a high-risk AI system under the Act. The apps you build with Vibely are your own products, and whether any specific app you ship falls under the AI Act's high-risk categories — and what obligations follow from that — is your own compliance responsibility as the deployer, not Vibely's. What Vibely does control is the platform itself, where we follow GDPR data protection practices as described above (lawful basis, DPA, encryption, subprocessor governance).
We are not claiming any EU AI Act certification here, because none applies to a general-purpose builder in the way it would to a deployed high-risk system. If you are building something that could plausibly qualify as high-risk under the Act — biometric identification, credit scoring, employment screening, and similar categories are the classic examples — that assessment belongs to you and your legal counsel for the app you ship, not to the tool you built it with.
Technical controls that back all of this up
- Encryption. TLS 1.3 in transit, AES-256 at rest.
- No training on your data. Vibely does not use customer prompts, code, or project data to train models. What each model vendor does under its own terms is a separate question, and the vendors we route to are named at /subprocessors so you can check theirs directly.
- Isolation. Vibely is multi-tenant with strict logical isolation between workspaces and projects, including row-level security on shared databases.
- Secrets. Encrypted at rest, scoped to specific environments, and never round-tripped through the model in plaintext.
FAQ
Is Vibely GDPR compliant?
Vibely supports GDPR with a documented lawful basis for EEA/UK processing, SCCs for the transfer, and an Article 28 Data Processing Agreement published at /dpa that applies without signature. We hold no SOC 2 report and no ISO 27001 certificate, and no audit against either is under way.
Is Vibely ready for the EU AI Act?
Vibely is a general-purpose AI development tool, not a high-risk AI system under the EU AI Act — the apps you build with it are your own products and your own compliance responsibility. Vibely follows GDPR data protection practices for the platform itself.
Where is my data stored if I build on Vibely from the EU?
There is no region selector in Vibely today, so you do not choose. Transfers outside the EEA/UK are made under SCCs, and the providers involved are listed at /subprocessors. We will update our privacy policy before changing where data is stored.
Can I get a signed DPA?
Yes — our GDPR Article 28 Data Processing Agreement is published at /dpa and applies without a signature, so there is nothing to countersign. If your procurement needs it executed, email [email protected].
The bottom line
"GDPR compliant" and "EU AI Act ready" are both claims worth interrogating rather than accepting at face value, for any vendor — including us. What we can tell you, sourced directly from our own security and privacy pages: no data-residency choice today, a public subprocessor list you can check line by line, a DPA published at /dpa that applies without signature, SCCs for EEA/UK transfers, and no SOC 2 report and no ISO 27001 certificate, with no audit against either under way. If those specifics work for where your project is today, start building on Vibely.


