{
  "schema_version": 1,
  "lang": "en",
  "page_type": "guide",
  "source_file": "lovable-cloud-rgpd-belgique-en.html",
  "context_url": "https://hebora.be/contexts/lovable-cloud-rgpd-belgique-en.en.json",
  "url": "https://hebora.be/lovable-cloud-rgpd-belgique-en.html",
  "title": "Lovable Cloud and GDPR in Belgium: responsibilities | Hebora",
  "meta_description": "Lovable Cloud and GDPR in Belgium: DPA, roles, hosting, data, security and a practical audit of a Lovable application Check the practical steps.",
  "h1": "Lovable Cloud and GDPR: who is responsible for what in Belgium?",
  "lead_paragraph": "Lovable publishes security measures and a DPA. That frames the platform; it does not automatically validate the choices, integrations and data in your application.",
  "structured_data_types": [
    "Article",
    "Organization",
    "ImageObject",
    "WebPage",
    "CreativeWork",
    "BreadcrumbList",
    "ListItem"
  ],
  "entities_mentioned": [
    {
      "name": "Hebora",
      "type": "Organization"
    },
    {
      "name": "Lovable",
      "type": "Organization"
    },
    {
      "name": "European Union",
      "type": "Organization"
    }
  ],
  "headings": [
    {
      "level": 2,
      "text": "Lovable secures a platform; the customer remains responsible for the app"
    },
    {
      "level": 2,
      "text": "The responsibility boundary that matters"
    },
    {
      "level": 2,
      "text": "Technical controls that create substance"
    },
    {
      "level": 2,
      "text": "DPA, region and processors: the evidence to gather"
    },
    {
      "level": 2,
      "text": "Verified official sources"
    },
    {
      "level": 2,
      "text": "Audit my Lovable application"
    },
    {
      "level": 2,
      "text": "Continue the review"
    },
    {
      "level": 3,
      "text": "AI-built website: what still needs checking in Belgium"
    },
    {
      "level": 3,
      "text": "Cookie banner in Belgium: what must be blocked before consent"
    },
    {
      "level": 3,
      "text": "AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026?"
    }
  ],
  "sections": [
    {
      "heading": "Lovable secures a platform; the customer remains responsible for the app",
      "intro": "Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights."
    },
    {
      "heading": "The responsibility boundary that matters",
      "intro": "The official logo only identifies the platform discussed. Hebora is not a Lovable partner and is not certified or endorsed by Lovable."
    },
    {
      "heading": "Technical controls that create substance",
      "intro": "An audit opens the published application, configuration and flows. It checks public routes, roles, table and file access rules, secrets, server functions, logs, test environments and third-party integrations."
    },
    {
      "heading": "DPA, region and processors: the evidence to gather",
      "intro": "Keep the applicable DPA version, check the required plan, and document the selected region, data categories, individuals, retention and added processors or APIs. Lovable’s privacy policy also covers Lovable’s own processing; it does not replace yours."
    },
    {
      "heading": "Verified official sources",
      "intro": "Sources checked on 15 August 2026."
    },
    {
      "heading": "Audit my Lovable application",
      "intro": "Hebora tests roles, tables, files, functions, secrets and integrations in the published app, then documents corrections and residual risks."
    },
    {
      "heading": "Continue the review",
      "intro": "The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you."
    }
  ],
  "proof_points": [
    {
      "label": "Available within the framework described by Lovable, including Business and Enterprise.",
      "value": "DPA"
    },
    {
      "label": "Customer as controller; Lovable as processor under the DPA.",
      "value": "2 roles"
    },
    {
      "label": "Interface, authentication, data and functions/integrations.",
      "value": "4 layers"
    },
    {
      "label": "The actual published application must be tested.",
      "value": "No magic badge"
    }
  ],
  "internal_links": [
    {
      "label": "Home",
      "url": "https://hebora.be/en.html"
    },
    {
      "label": "SEO & GEO in Belgium",
      "url": "https://hebora.be/seo-bruxelles-en.html"
    },
    {
      "label": "Test my application",
      "url": "https://hebora.be/diagnostic-en.html"
    },
    {
      "label": "AI-built website: what still needs checking in Belgium The website owner must still check business disclosures, legal grounds, notices to individuals, cookies, security, supplier contracts and — when applicable — e-commerce and accessibility rules. The platform helps build; it does not make those decisions for you.",
      "url": "https://hebora.be/conformite-site-ia-belgique-en.html"
    },
    {
      "label": "Cookie banner in Belgium: what must be blocked before consent The Belgian Data Protection Authority requires prior consent for cookies that are not strictly necessary, a genuine choice, refusal as accessible as acceptance and easy withdrawal. Necessary cookies may operate without consent, but they must genuinely be necessary.",
      "url": "https://hebora.be/banniere-cookies-rgpd-belgique-en.html"
    },
    {
      "label": "AI chatbot on a Belgian website: what must you disclose and check since 2 August 2026? Article 50 of the AI Act requires providers to design direct-interaction systems so people are informed that they are interacting with AI, unless that is obvious. The website owner must also check its own duties as deployer and data controller.",
      "url": "https://hebora.be/transparence-chatbot-ia-belgique-en.html"
    }
  ],
  "open_graph_image": "https://hebora.be/images/legal/responsabilites-site-lovable-og.png",
  "images": [
    {
      "src": "https://hebora.be/images/legal/responsabilites-site-lovable-1536.webp",
      "alt": "Founder and adviser mapping data flows in a Lovable application"
    },
    {
      "src": "https://hebora.be/images/brands/lovable-official-logomark.png",
      "alt": "Official Lovable logo"
    }
  ],
  "answer_summary": "Lovable’s DPA generally describes the customer as controller and Lovable as processor for data handled on the customer’s behalf. The customer still configures the app, informs users, chooses data and integrations, and handles requests to exercise data rights.",
  "services_provided": "Hebora tests roles, tables, files, functions, secrets and integrations in the published app, then documents corrections and residual risks.",
  "source_urls": [
    "https://lovable.dev/data-processing-agreement",
    "https://lovable.dev/security",
    "https://docs.lovable.dev/integrations/cloud",
    "https://lovable.dev/privacy/",
    "https://lovable.dev/brand",
    "https://eur-lex.europa.eu/eli/reg/2016/679/oj"
  ],
  "last_verified": "2026-08-15",
  "legal_boundary": "Hebora performs technical audits and corrections. This content is not legal advice, does not certify compliance and does not replace a lawyer or DPO when your situation needs legal interpretation.",
  "brand_asset": {
    "organization": "Lovable",
    "source_page": "https://lovable.dev/brand",
    "source_asset": "https://lovablebrand.lovable.app/assets/logomark-color-2x-BboAsRf2.png",
    "use": "Editorial identification of the platform discussed",
    "non_affiliation": "The official logo only identifies the platform discussed. Hebora is not a Lovable partner and is not certified or endorsed by Lovable."
  }
}
