# Webflow

## Kurzbeschreibung
**“Create custom, responsive websites with the power of code — visually.”**


Webflow is a visual platform for creating, managing, and hosting websites and web-based experiences.


Its features include, among other things, a visual builder, CMS, hosting, collaboration, APIs, localization, Analyze/Optimize, as well as Webflow AI for site generation, copy, CMS content, and SEO/AEO support. For classification as an “AI tool,” it is important to note: AI is a growing part of the product, but not its sole core.

## Claim
Build, manage, optimize — all with Webflow AI

## Geeignet für
- API Integration
- Automation / Workflows
- Design / Graphics
- Marketing & Advertising
- no Code App
- SEO / GEO Optimization
- Texts / Content
- Websites / Landing Pages

## Kernfunktionen
- E-Commerce Optimization
- SEO
- Text Generation
- UI Design
- Website Creation

## Preismodell
- **free:** Free entry point for building and testing Webflow projects with a Webflow subdomain.
- **subscription:** **Basic **For simple websites with their own domain and no CMS focus.


**CMS** For blogs, content websites, and dynamic content with CMS features.


**Business** For larger marketing and business websites with higher capacity and more traffic.


**Standard / Plus / Advanced** For online stores with increasing e-commerce features and capacities.


**Starter / Core / Growth / Freelancer / Agency **Workspace plans for individuals, teams, freelancers, and agencies with collaboration, roles, and client access.
- **other:** **Enterprise** Custom Enterprise offering with advanced security, support, governance, and scalability features.


**Webflow AI** AI Site Builder and AI Assistant for website creation, pages, CMS Collection Items, SEO/AEO, and help in the Editor.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-Prem / local hosting: indirect / not available**

No on-premise or local self-hosting deployment for Webflow was found on the website. Webflow describes itself as a platform/SaaS and refers to its own or cloud-based infrastructure; deployment on customer-owned hardware is not stated on the website.

**Private cloud / data center: partial**

The Trust Center mentions a 'Webflow Custom Hosting (WCH) Pentest Report', which indicates a special hosting offering. However, no specific statements were found in the website content indicating that customers can choose a dedicated private cloud or a clearly defined EU/EEA data center.

**EU SaaS / managed: partial**

Webflow clearly offers a managed SaaS service. However, for EU/EEA requirements, there is no explicit commitment to EU data residency or EU/EEA hosting, and the Privacy FAQs explicitly mention the storage of customer and end-user data in the USA.

**Hybrid: indirect / not available**

A hybrid operating model with partly internal/local processing and partly external processing was not described on the website. A combination of local model usage and the Webflow cloud is also not stated.

**DPA / DPA: covered**

A DPA is available on the website and, according to the Privacy FAQs, is available to all customers regardless of plan and is incorporated into the terms of use by default. According to the website, the DPA also contains the EU Standard Contractual Clauses and other data protection contractual mechanisms.

**No training: covered**

On its AI page, Webflow explicitly states that customer data is not used to train generative AI models and that third-party providers are also contractually prevented from using customer data to train their models. This means that an opt-out is not merely implicit; rather, the no-training approach itself is documented.

**Open source / transparency path: partial**

No open-source or self-hostable core was found on the website. However, there is a certain transparency path via the Trust Center, security documentation, subprocessor list, and contractual documents. Nothing specific is stated on the website regarding open-source components in the sense of a sovereign operating path.

**Data processing**

The website describes Webflow as a managed cloud service. According to the Privacy FAQs, Webflow stores customer and end-user data in the USA. According to the DPA, the infrastructure is operated via ISO 27001-certified AWS data centers in multiple regions and availability zones. Webflow publishes a subprocessor list with the locations of subcontracted processors and states that it has concluded data processing agreements with each of them, including a valid transfer mechanism. For AI features, Webflow states that customer data is not used to train generative models.

**Conclusion**

For a European tool directory, Webflow can only be rated **conditionally** positively from a data protection perspective: the contractual framework, subprocessor transparency, security certifications, and the documented exclusion of AI training with customer data speak in its favor. However, the explicitly stated storage in the USA and the lack of clearly documented EU data residency or an on-premise/self-hosting alternative on the website argue against a clear classification as fully uncomplicated GDPR-compliant.

**Sources**

- [https://webflow.com/legal/privacy](https://webflow.com/legal/privacy)
- [https://webflow.com/legal/privacy-faqs](https://webflow.com/legal/privacy-faqs)
- [https://webflow.com/legal/dpa](https://webflow.com/legal/dpa)
- [https://webflow.com/legal/subprocessors](https://webflow.com/legal/subprocessors)
- [https://webflow.com/ai/our-approach](https://webflow.com/ai/our-approach)
- [https://trust.webflow.com/](https://trust.webflow.com/)

Webflow documents several important building blocks for GDPR-compliant use for customers in the EU/EEA region: a privacy policy, a Data Processing Addendum as a data processing agreement, a subprocessor list, standard contractual clauses in the DPA, certifications, as well as statements that customer data is not used to train generative AI models. At the same time, Webflow explicitly states the storage of customer and end-user data in the USA and refers to data transfers to the USA or other countries. Explicit EU data residency or clearly documented EU/EEA hosting as a standard or simple option is not specified on the website. For the EU/EEA as a whole, use is therefore only viable under certain conditions and following the user's own legal review, not as clearly and comprehensively demonstrated standard compliance.

**Positive**

Positively documented are a DPA/data processing agreement, the inclusion of the EU Standard Contractual Clauses and the UK transfer mechanism in the DPA, a published subprocessor list, contractual obligations toward subprocessors, statements excluding AI training on customer data, as well as certifications such as SOC 2 Type II, ISO 27001, ISO 27017, and ISO 27018.

**Negative**

Negative from an EU/EEA perspective is above all that Webflow itself states that it stores customer and end-user data in the USA, and that the website does not indicate clear EU data residency, no exclusive EU/EEA data center for SaaS use, and no on-premise/self-hosting option. This means that a third-country transfer risk remains, and fully uncomplicated GDPR use is not demonstrated on the basis of the website.

**Server location**

The website states that Webflow stores customer and end-user data in the USA. The DPA additionally describes that the infrastructure is operated via ISO 27001-certified Amazon Web Services data centers in multiple regions and Availability Zones; however, specific EU/EEA server locations for customer data are not named. The subprocessor list lists the locations of individual subcontracted processors, including the USA, the United Kingdom, and Ireland.

## Hosting und Daten
- **On-Prem / lokales Hosting:** unknown
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** teilweise / indirekt
- **Hybrid:** unknown
- **AVV / DPA:** abgedeckt
- **Kein Training auf Kundendaten:** abgedeckt
- **Open-Source / Transparenz-Pfad:** teilweise / indirekt

## Standort
**Land:** USA

**Taxonomie:** USA

Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, USA

## Vorteile
- Very strong combination of visual design, CMS, and hosting from a single source.
- Suitable for marketing, content, and web teams with little dependency on developers.
- Strong AI extensions: Site Builder, copy, CMS generation, SEO/AEO support.
- Strong team and enterprise features such as roles, approvals, SSO/SCIM/audit options depending on the plan.
- Mature security/compliance signals through SOC 2 Type II and ISO certifications.

## Nachteile
- Problematic for strict EU data residency requirements, because Webflow is US-based and, according to its Privacy FAQ, stores customer/end-user data in the USA.
- A paid Site plan is required for live operation; Free is primarily suitable for prototyping/staging.
- The Basic Site plan does not include CMS features.
- Code export is only a partial workaround, as dynamic content/CMS pages cannot be exported.
- According to Webflow, Localization is not compatible with Ecommerce.
- 6) Several advanced features are add-ons or Enterprise-/sales-led.

## Quellen
- Offizielle Website: https://webflow.com/pricing

## Letzter Datenstand
2026-04-28

## Originalseite
https://kifox.ai/en/ki-tools/webflow-en/
