Skip to main content

Compliance Overview

Sealmetrics is designed to need no consent banner for its own analytics (our self-assessment; in Germany an open question — see Germany): nothing is stored on the device (no cookies, no localStorage), no IP addresses are stored, and the only identifier is an ephemeral session identifier that rotates daily and cannot be linked across days or across sites. Under ePrivacy our self-assessment rests on the audience-measurement exemption (own-site statistics only, no cross-site tracking, no reuse of the data); under the GDPR on the stored dataset not identifying anyone. This section explains how that architecture is designed to meet GDPR, ePrivacy and CNIL requirements while enabling consentless analytics. Self-assessed, not certified.

Our privacy-first approach is built on legal foundations, not technical workarounds. Learn how we ensure data accuracy through bot filtering, how we assess our tracking method against the rules of each EU jurisdiction, and get answers to common legal questions about implementing analytics without consent banners.

What does this section cover?​

In short
  • We store nothing on the device and no data that identifies anyone. The session identifier is ephemeral: it rotates daily and, once rotated, not even we can reconstruct it. Reports are always aggregated. That is how Sealmetrics is designed to meet GDPR, ePrivacy and CNIL requirements, on its own self-assessment.
  • Bot filtering keeps the consentless dataset accurate; the legal analysis sets out our self-assessment across EU jurisdictions.
  • The Legal FAQ answers the questions raised when implementing analytics without consent banners (DPA, DPIA, retention, hosting).
Written and maintained by the Sealmetrics Team