Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Kalix is a serverless Platform-as-a-Service (PaaS) by Lightbend, formerly known as Akka Serverless. It provides a cloud-native application platform for building stateful microservices and APIs without managing servers or databases. As pure backend infrastructure, Kalix does not set tracking cookies on end-user browsers. Under GDPR, its use as a hosting provider requires a Data Processing Agreement and attention to international data transfers to the US, but no end-user consent is required for the hosting function itself.
Kalix is a serverless Platform-as-a-Service (PaaS) developed by Lightbend, the company behind the Akka framework. Originally launched as Akka Serverless, Kalix provides a fully managed cloud-native application platform designed for building stateful microservices, event-driven APIs, and distributed backend systems. Developers can deploy production-grade services without provisioning or managing servers, databases, or messaging infrastructure. Kalix handles persistence, caching, service mesh, and API gateway capabilities natively, significantly reducing operational overhead.
Kalix is backend infrastructure and does not inject any client-side scripts, tracking pixels, or cookies into the browsers of visitors to your website. Unlike advertising networks or analytics platforms, Kalix operates entirely at the server layer. No JavaScript SDK is loaded in end-user browsers as part of using Kalix as a hosting provider. This means that integrating Kalix for your application backend has no direct impact on your cookie banner or ePrivacy consent flows for end users.
When you use Kalix to host an application that processes personal data of EU residents, Lightbend acts as a data processor on your behalf under GDPR Article 28. You must therefore enter into a Data Processing Agreement (DPA) with Lightbend before using Kalix for any processing involving personal data. The legal basis for the hosting itself is typically legitimate interest (Art. 6(1)(f)) or performance of a contract (Art. 6(1)(b)), depending on your service context. No end-user consent is required for the infrastructure hosting function.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Kalix infrastructure runs on cloud providers including Google Cloud Platform, which operates data centres in the United States and other countries outside the European Economic Area. This constitutes a third-country transfer under GDPR Chapter V. Lightbend relies on Standard Contractual Clauses (SCCs) as the transfer mechanism. As a data controller, you must document these transfers in your Records of Processing Activities (RoPA) and ensure that Lightbend''s SCCs are current and adequate. Review Lightbend''s privacy documentation and sub-processor list regularly.
The ePrivacy Directive (2002/58/EC) applies to the storage of information on, or access to information from, a user''s terminal equipment. Since Kalix does not place any cookies or similar technologies on end-user devices, the ePrivacy Directive is not directly triggered by the use of Kalix as a backend hosting platform. Your existing cookie policy and consent management does not need to list Kalix as a technology that interacts with end-user devices.
To comply with GDPR when using Kalix, complete the following steps: sign a Data Processing Agreement with Lightbend, document the Kalix relationship in your RoPA including the nature of data processed and the US transfer mechanism, verify that SCCs are in place and conduct a Transfer Impact Assessment if processing high-risk personal data, and review Lightbend''s sub-processor list periodically. Update your privacy policy to disclose that backend infrastructure is hosted on Kalix/Lightbend with data potentially processed in the US. No changes to your cookie banner are required specifically for Kalix.
Websites using Kalix must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is unlikely to be required for using Kalix as a backend PaaS provider, as it does not involve high-risk processing of end-user personal data through client-side tracking. However, if personal data of EU data subjects is processed on Kalix infrastructure (e.g. user records, logs), the controller must assess the risk. The transfer of data to the US under SCCs should be documented. Review Lightbend's Sub-processor list and DPA terms.
Third-party domains contacted
kalix.ioconsole.kalix.ioThis service may collect user data. Ensure GDPR compliance with FlowConsent.
No. Kalix is a serverless backend PaaS platform and does not deploy any client-side scripts or cookies. It operates entirely at the server layer, so no cookies are placed on your website visitors' devices as a result of using Kalix as your application infrastructure.
No end-user consent is required specifically for Kalix. Since Kalix does not set cookies or access end-user devices, the ePrivacy Directive consent requirement is not triggered. You do not need to add Kalix to your cookie banner or consent management platform.
The legal basis for using Kalix as a hosting provider is typically legitimate interest (Art. 6(1)(f) GDPR) or performance of a contract (Art. 6(1)(b) GDPR). You must also sign a Data Processing Agreement (DPA) with Lightbend under Art. 28 GDPR before processing any personal data on Kalix infrastructure.
Yes. Kalix infrastructure runs on cloud providers including Google Cloud Platform, which operates data centres in the United States outside the EEA. This constitutes a third-country transfer under GDPR Chapter V. Lightbend relies on Standard Contractual Clauses (SCCs) as the transfer safeguard. You must document this transfer in your Records of Processing Activities.
A DPIA is generally not required solely for using Kalix as a backend hosting provider, since no high-risk processing of end-user personal data occurs through client-side tracking. However, if your application hosted on Kalix processes special categories of data or large-scale personal data, you should assess whether a DPIA is needed for that processing activity specifically.
To comply with GDPR when using Kalix: sign a DPA with Lightbend, document Kalix in your Records of Processing Activities including the US data transfer and SCC details, conduct a Transfer Impact Assessment if handling sensitive data, review Lightbend's sub-processor list regularly, and update your privacy policy to disclose Kalix/Lightbend as a hosting sub-processor.
Yes. EU-based cloud and PaaS alternatives include OVHcloud (France), Scaleway (France), Hetzner Cloud (Germany) and IONOS (Germany). These providers offer data residency within the EU/EEA, which can simplify GDPR compliance by eliminating the need for third-country transfer mechanisms. The right choice depends on your technical requirements and workload.
No. Since Kalix does not set cookies or access end-user devices, it does not need to be listed in your cookie policy. You should, however, mention Lightbend/Kalix in your privacy policy as a data processor (hosting sub-processor) if personal data is processed on their infrastructure, disclosing the US transfer and SCC safeguards.