Skip to main content

Legal FAQ

Sealmetrics is a B2B data controller for account data and a data processor for analytics data; this page answers the legal and compliance questions that come up in audits and vendor reviews — DPA, DPIA, subprocessors, data hosting, IP handling, cookies and retention.


Compliance Validation​

How can I validate Sealmetrics' compliance claims?​

Sealmetrics publishes detailed, criterion-by-criterion self-assessments against the published frameworks of European regulators, so your DPO can verify every claim directly:

👉 CNIL (France) · ICO PECR (UK) · TDDDG (Germany) · Garante (Italy) · FADP (Switzerland)

Technical claims (what is collected, what is never stored) are documented in What We Track and can be verified from the browser: every request the tracker sends is visible in your own DevTools.


How does Sealmetrics process customer data?​

You can review our full Privacy Notice for our role as a B2B Data Controller here:

👉 Sealmetrics Privacy Notice

For our role as Data Processor:
👉 Data Processing Agreement (DPA) · Subprocessors


Where can I access Sealmetrics' DPIA?​

We provide a completed DPIA (Data Protection Impact Assessment) for all customers.
You can request access directly from our team.


All legal documentation is available in the footer of our website, including:

  • Privacy Notice
  • Data Processing Agreement (DPA)
  • Terms of Service
  • Customer DPIA availability

Privacy by Design & Company Structure​

Why is Sealmetrics a true privacy-by-design solution?​

Because every metric that appears in the Sealmetrics platform must be validated and approved by our Legal Department before being allowed into the product.

No exceptions.


What kind of company is Sealmetrics?​

Sealmetrics is a bootstrapped European company with no external investors on the board.


Data Collection & Calculation​

What data does Sealmetrics collect?​

We only collect a small set of non-identifying fields per hit:

  • Current URL (including UTM parameters)
  • Referral URL
  • Timestamp
  • User Agent (used in flight for device classification; the raw string is never written to storage, and only the derived categories are kept, in aggregates, for 24 months; never linked to a person)
  • Browser timezone (used to assign the country)
  • A session identifier used to tell a second pageview apart from a new entrance (see below)

See What We Track vs What We Don't for the full breakdown.

No stored field identifies a visitor, and each account's data is isolated.


What data does Sealmetrics calculate?​

We compute:

  • Source ID (_adin): Used for attribution
  • Session identifier: the tracker computes, in the browser, a hash of standard device characteristics (user agent, timezone, languages, screen resolution, colour depth, dark-mode and reduced-motion preferences, CPU core count, device memory) plus the site's account ID — a device fingerprint. It is never written to the device. On the server it is re-keyed with a server secret and a daily salt that is destroyed on rotation, so the stored identifier changes every day and cannot be linked across days — not even by Sealmetrics. The raw hash is never stored. The live session expires after 2 hours of inactivity; the daily pseudonym is purged after 1 day. It cannot recognize a returning visitor.

Does Sealmetrics use IP addresses for calculation?​

Never for analytics, and never stored in the analytics database.

  • No metric in Sealmetrics is calculated from IP addresses. Visitor country comes from the browser timezone, not from the IP.
  • The visitor's IP is used transiently on the server for security and anti-bot protection (checking the request against curated bot/datacenter blocklists before it is accepted). As with any web service, IPs may also appear transiently in operational logs with limited retention; those logs are separate from analytics data and are never available to clients.
  • The IP is never written to the analytics database — there is no IP column in our event storage — and it is never linked to any hit, session, or metric.
  • No GeoIP lookup is performed on the IP. One was designed for the optional Agent Analytics bot detector, but that feature is not live and cannot be enabled on any account, so it runs nowhere today.

This transient security use is processed under legitimate interest (GDPR Art. 6(1)(f), Recital 49 — network and information security). The visitor analytics data rests on the same basis: it holds no IP, no persistent identifier and nothing that identifies anyone, and its session identifier is pseudonymised data — processed under legitimate interest (Art. 6(1)(f)) and unrecoverable after the daily rotation, not even by Sealmetrics. Consent is not used as the legal basis; reports are always aggregated. What keeps Sealmetrics consentless is that the IP is never stored with analytics data, never used for identification or tracking, and never used to compute analytics.


Bot Filtering​

How does Sealmetrics block bots?​

We use several layers, none of which stores the IP or anything that identifies a visitor:

  • Bot user-agent signature lists (known crawlers, headless browsers, automation tools)
  • Curated IP/CIDR blocklists of known bots and datacenters, checked in memory at request time — the IP is used only for this transient check and never stored with analytics data
  • Request-header consistency checks (A fourth layer — Agent Analytics, using environmental and behavioral signals to classify traffic as human vs. automated — is designed but not live, and collects nothing on any account today.)

See How Sealmetrics Blocks Bot Traffic for the full picture.


Cookies & Storage​

Does Sealmetrics use cookies?​

No.
Sealmetrics does not use:

  • cookies
  • session storage
  • local storage
  • any stored or persistent fingerprint
  • cross-site IDs

Nothing is stored on the visitor's device. The tracker does read standard browser properties to compute the daily-re-keyed session identifier described above. That read is an "access" under ePrivacy Article 5(3), so our self-assessment that no consent is needed rests on the audience-measurement exemption criteria (own-site statistics only, no cross-site tracking, no reuse of the data) — see Analytics Cookies: Consent Exemption Requirements.


Data Retention​

How many months does Sealmetrics store my data?​

We store data for a maximum of 24 months.
This stays inside the 25-month ceiling that CNIL guidance sets for consent-exempt analytics — Sealmetrics deliberately applies the stricter 24-month limit.

In short
  • The DPA is at sealmetrics.com/dpa and the Privacy Notice at sealmetrics.com/privacy; a completed DPIA is available to customers on request.
  • Sealmetrics collects a small set of non-identifying fields per hit, stores nothing on the device (no cookies or browser storage), and never writes the IP address to the analytics database.
  • Data is stored for a maximum of 24 months, inside the 25-month ceiling in CNIL guidance.
Written and maintained by the Sealmetrics Team