Two levels need distinguishing. Blueprint Maker, the vendor, processes your account data in line with the GDPR: hosting within the European Union (OVH, France), sub-processors bound by standard contractual clauses, a right to data portability. The GENERATED application, on the other hand, is a tool you operate: you become the data controller for the data YOUR users enter into it — the platform makes that role easier (EU hosting available, a database you own, no lock-in), it doesn't take it on for you.
What Blueprint Maker guarantees as the vendor
The controller for your Blueprint Maker account data (credentials, submitted content, billing) is BEAM Consulting, the service's publisher. The Service is hosted at OVH, in France, within the European Union. The sub-processors involved — AI model providers used for generation, payment provider, authentication providers, transactional email — are listed in the privacy policy; those outside the EU (notably the AI model providers) are bound by the European Commission's standard contractual clauses.
Your account data is never sold, and you have rights of access, rectification, deletion and portability — the latter explicitly guaranteed by the GDPR, regardless of which vendor's service you use.
What stays your responsibility, on the generated application
Once generated and in use, the application collects whatever data YOU have it collect — clients, members, case files, based on what you described. Toward those people, YOU are the data controller, exactly as if your own team had built the tool: informing data subjects, the legal basis for processing, retention periods, responding to rights requests.
Blueprint Maker makes that role easier without replacing it. The database is yours and can be hosted within the European Union (the included URL is served from France; self-hosting with a provider of your choice remains available at any time). Since the code is standard, exportable Next.js + Prisma, a developer can add whatever GDPR mechanisms your business needs — exporting or deleting one person's data on request, for instance — if they aren't already covered by what you described.
A distinction worth keeping
No generation tool can promise an application "is GDPR compliant" in the abstract: compliance depends on USE — which data, for what purpose, with what disclosures. What Blueprint Maker can guarantee is the absence of technical obstacles: no proprietary lock-in, no forced data transfer outside the EU for hosting, code you own and can audit or have audited.