FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. CloudCannon

CloudCannon

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does CloudCannon do?

CloudCannon is a Git, based headless CMS for static sites built with Jekyll, Hugo, Eleventy, Astro, or Next.js. Editors work in a visual interface that commits changes to a Git repository, and the generated static site is served from a Cloudflare, backed CDN. Because the public output is plain HTML with no default tracking, the visitor, facing privacy footprint is minimal.

What is CloudCannon?

CloudCannon is a Git, based headless CMS founded in 2014 in New Zealand and now headquartered in the United States. It targets static site generators such as Jekyll, Hugo, Eleventy, Astro, and Next.js. Editors author content in a visual web interface that commits Markdown, YAML, JSON, or TOML files to a Git repository (GitHub, GitLab, Bitbucket, Azure DevOps). CloudCannon then triggers a build and either hosts the generated site on its own Cloudflare, fronted CDN or pushes the build artifact to an external provider. Because the public, facing output is plain HTML, CSS, and JavaScript with no embedded CloudCannon scripts, the privacy footprint visible to end visitors is essentially zero.

Cookies and data processed by CloudCannon

On a public CloudCannon, hosted page, the only cookies you typically see come from Cloudflare itself: __cf_bm (bot management) and cf_clearance (CAPTCHA / challenge), both first, party and short, lived. There are no analytics cookies, no advertising cookies, and no fingerprinting scripts injected by CloudCannon. Inside the editorial application (app.cloudcannon.com), CloudCannon sets functional session cookies to keep editors authenticated, plus a CSRF token cookie. CloudCannon also collects the standard editor account data: name, email, organisation, IP address at login, and a basic activity log used for audit and version history.

GDPR and ePrivacy implications

For end visitors, a CloudCannon, hosted static site is one of the lowest, friction architectures from a GDPR perspective. The Cloudflare bot management cookie qualifies as strictly necessary under EDPB and CNIL guidance, so no consent banner is required for the public site unless you add third, party scripts (analytics, embeds, fonts loaded from external CDNs). For the editorial side, CloudCannon acts as a processor under Article 28 GDPR. The relationship with editors is governed by contract performance, and CloudCannon publishes a Data Processing Addendum that customers can sign to formalise the relationship.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

No consent is required to deliver a static site through CloudCannon Hosting. The Cloudflare functional cookies fall under the strictly necessary exemption of the ePrivacy Directive, in line with EDPB Opinion 4/2012 and CNIL guidelines. If you add third, party services on top (Google Analytics, YouTube embeds, Calendly), those services keep their own consent obligations and you should gate them with a CMP. Inside the CMS, editors operate under their employment or contractor relationship and do not need a website, style consent banner.

International data transfers

CloudCannon Pty Ltd processes editorial data on AWS in the United States and uses Cloudflare as its public CDN. Cloudflare automatically routes traffic to the nearest edge, so requests from European visitors are normally terminated at EU edge nodes, but origin requests, build artifacts, and CMS metadata transit through US infrastructure. Both AWS and Cloudflare are certified under the EU, US Data Privacy Framework, and CloudCannon signs Standard Contractual Clauses with customers. A Transfer Impact Assessment is recommended when relying on the DPF, although the practical risk for editorial metadata is low.

Practical compliance steps

Sign a DPA with CloudCannon Pty Ltd and add it to your record of processing activities as a sub, processor for content management. List Cloudflare as a sub, processor in the privacy policy and explain that the website is delivered via a CDN. Restrict editor access using SSO or two, factor authentication, set a sensible password policy, and review the audit log periodically. If you embed external scripts in the static site, gate them through a CMP. Otherwise, the site can be served without a consent banner, which is one of the main reasons teams pick CloudCannon for European audiences.

GDPR consent category

Other

Websites using CloudCannon must obtain user consent under GDPR regulations.

Legal basisContract performance (GDPR Article 6(1)(b)) for editor accounts and content management. Legitimate Interest (Article 6(1)(f)) for CDN security and operational logs. No consent is required for end visitors of a static site generated by CloudCannon, as the public output does not embed CloudCannon tracking by default.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, CCPA, EU, US Data Privacy Framework

DPIA considerations

A DPIA is generally not required for using CloudCannon as a CMS because the public static site does not embed user tracking by default. The editorial backend processes only editor account data (email, login timestamp) which falls under standard contract performance. A DPIA becomes relevant only if you connect CloudCannon to data, sources or webhooks that pull personal data of end users into editor previews. Document the AWS sub, processor, the Cloudflare CDN, the data retention for backups, and the access controls of the editorial team.

Sample consent text

Our website is built with CloudCannon and served as static HTML through a CDN. CloudCannon does not set any tracking cookies on visitors. For the editorial team, CloudCannon uses functional cookies to keep editors logged in. Do you accept the strictly necessary cookies required for the editorial interface?

Technical details

Tracking methodCloudCannon is a Git-based headless CMS used in the editorial backend rather than embedded on public pages. The published front-end is generated by Jekyll, Hugo, Eleventy, Astro, or Next.js and served from CloudCannon Hosting (a Cloudflare-fronted CDN) or any external host. The visual editor and dashboard load from the CloudCannon application domain and may set first-party session cookies for editor authentication and CSRF protection.
Server locationEditorial application: hosted in the United States on AWS. Hosting CDN: Cloudflare global edge network. Build infrastructure: AWS US regions. Customers can host the generated static site anywhere (Netlify, AWS, Cloudflare Pages, OVH, Hetzner) since the front-end is just static files.
Cookieless tracking availableYes
Data transferred outside the EUYes. CloudCannon Pty Ltd processes editorial data on AWS infrastructure in the United States and uses Cloudflare as its public hosting CDN. Editor accounts and CMS content metadata transit through US infrastructure. SCCs (2021/914) plus the EU, US Data Privacy Framework cover the transfer for AWS and Cloudflare. End visitors of the published site are not normally exposed to CloudCannon analytics; the front-end output is plain HTML.

Third-party domains contacted

cloudcannon.comapp.cloudcannon.comcdn.cloudcannon.com*.cloudvent.net

Cookies placed

NameTypeDurationPurpose
__cf_bmfirst-party30 minutesCloudflare bot management cookie set on sites delivered through CloudCannon Hosting. Distinguishes humans from automated traffic to protect against bot abuse. Considered strictly necessary under the ePrivacy Directive.
cf_clearancefirst-party1 yearCloudflare CAPTCHA / managed challenge cookie. Records that the visitor has passed a security challenge so they are not re, prompted on subsequent requests. Strictly necessary for security purposes.
cloudcannon_sessionfirst-partySessionFunctional session cookie set inside the CloudCannon editorial application (app.cloudcannon.com) to keep editors authenticated. Not present on public sites.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does CloudCannon set?

On a publicly hosted CloudCannon site you typically only see Cloudflare's functional cookies (__cf_bm for bot management, around 30 minutes; cf_clearance for CAPTCHA challenges, up to 1 year). The editorial application sets short, lived session cookies for editor authentication and a CSRF token. CloudCannon does not inject analytics, advertising, or fingerprinting cookies into the public output by default.

Is consent required for a CloudCannon site?

No. The Cloudflare bot, management cookie qualifies as strictly necessary under the ePrivacy Directive, in line with EDPB Opinion 4/2012. As long as you do not add third, party scripts on top (Google Analytics, embeds, fonts loaded from external CDNs), the site can be served without a consent banner. The editorial application is used by employees or contractors and does not need a website, style consent prompt.

What is the legal basis for processing data with CloudCannon?

Contract performance (GDPR Article 6(1)(b)) for editor accounts, content versioning, and CMS operations. Legitimate Interest (Article 6(1)(f)) for CDN security, abuse prevention, and operational logs through Cloudflare and AWS. End visitors of the published static site are not subject to a separate legal basis since CloudCannon does not write tracking cookies on them.

Are data transferred to the United States?

Yes. CloudCannon Pty Ltd hosts the editorial application on AWS in the United States and serves the public site through Cloudflare's global edge. Cloudflare normally terminates traffic at EU edge nodes, but the origin and editorial metadata transit through US infrastructure. Both sub, processors are certified under the EU, US Data Privacy Framework, and CloudCannon signs Standard Contractual Clauses with EU customers.

Is a DPIA required for CloudCannon?

Not for a typical CMS use case. A DPIA is generally not required because the public site does not embed user tracking and the editorial backend processes only standard account data. It becomes relevant if you build editor previews on top of personal data sources, or if you store special categories of data in repositories that CloudCannon edits. Document the AWS sub, processor and editorial access controls in your record of processing activities.

How do I implement CloudCannon in a compliant way?

Sign a DPA with CloudCannon, list AWS and Cloudflare as sub, processors in your privacy policy, enforce SSO or 2FA for editors, and review the audit log. Keep the static output clean: load any third, party scripts (analytics, embeds, maps) only behind a CMP. With this setup, the public site can usually run without a consent banner while remaining fully GDPR, compliant.

Are there alternatives to CloudCannon?

Yes. Other Git, based or headless CMS options popular with European teams include Netlify CMS / Decap CMS (open source, self, hostable), Forestry (now sunset, succeeded by Tina), TinaCMS (open source visual editing), Strapi (EU, headquartered, self, hostable), Directus (self, hostable, EU options), and Sanity. The right choice depends on whether you need EU hosting, full self, hosting, or a managed Git, native experience.

How do I update the cookie policy for a CloudCannon site?

List Cloudflare as a sub, processor with the cookies __cf_bm and cf_clearance under the strictly necessary category. Mention CloudCannon as the CMS and AWS as a sub, processor for editorial data. Specify that no analytics or marketing cookies are set unless you have explicitly added third, party scripts. Include links to the privacy policies of CloudCannon, Cloudflare, and AWS.