Skip to main content

Legal FAQ

This page answers the most common legal and compliance questions related to Sealmetrics, privacy regulations, audits, and data protection.


Compliance Validation

How can I validate Sealmetrics' compliance claims?

Sealmetrics publishes detailed, criterion-by-criterion self-assessments against the published frameworks of European regulators, so your DPO can verify every claim directly:

👉 CNIL (France) · ICO PECR (UK) · TDDDG (Germany) · Garante (Italy) · FADP (Switzerland)

Technical claims (what is collected, what is never stored) are documented in What We Track and can be verified from the browser: every request the tracker sends is visible in your own DevTools.


How does Sealmetrics process customer data?

You can review our full Privacy Notice for our role as a B2B Data Controller here:

👉 Sealmetrics Privacy Notice

For our role as Data Processor:
👉 Data Processing Agreement (DPA) · Subprocessors


Where can I access Sealmetrics' DPIA?

We provide a completed DPIA (Data Protection Impact Assessment) for all customers.
You can request access directly from our team.


All legal documentation is available in the footer of our website, including:

  • Privacy Notice
  • Data Processing Agreement (DPA)
  • Terms of Service
  • Customer DPIA availability

Privacy by Design & Company Structure

Why is Sealmetrics a true privacy-by-design solution?

Because every metric that appears in the Sealmetrics platform must be validated and approved by our Legal Department before being allowed into the product.

No exceptions.


What kind of company is Sealmetrics?

Sealmetrics is a bootstrapped European company with no external investors on the board.


Data Collection & Calculation

What data does Sealmetrics collect?

We only collect four essential, non-personal variables per hit:

  • Current URL (including UTM parameters)
  • Referral URL
  • Timestamp
  • User Agent (used for anonymous device classification; event detail purged after 1 day, aggregated categories kept 24 months; never linked to a person)

Plus a short-lived session context marker used to tell a second pageview apart from a new entrance. See What We Track vs What We Don't for the full breakdown.

All data is anonymous and isolated.


What data does Sealmetrics calculate?

We compute:

  • Source ID (_adin): Used for attribution
  • Session context marker: a short-lived identifier scoped to a single browsing session (~2-hour inactivity window). It is not stored in the browser, does not persist across sessions, and cannot recognize a returning visitor.

Does Sealmetrics use IP addresses for calculation?

Never for analytics, and never stored in the analytics database.

  • No metric in Sealmetrics is calculated from IP addresses. Visitor country comes from the browser timezone, not from the IP.
  • The visitor's IP is used transiently on the server for security and anti-bot protection (checking the request against curated bot/datacenter blocklists before it is accepted). As with any web service, IPs may also appear transiently in operational logs with limited retention; those logs are separate from analytics data and are never available to clients.
  • The IP is never written to the analytics database — there is no IP column in our event storage — and it is never linked to any hit, session, or metric.
  • No GeoIP lookup is performed on the IP. One was designed for the optional Agent Analytics bot detector, but that feature is not live and cannot be enabled on any account, so it runs nowhere today.

This transient security use is processed under legitimate interest (GDPR Art. 6(1)(f), Recital 49 — network and information security). What keeps Sealmetrics consentless is that the IP is never stored with analytics data, never used for identification or tracking, and never used to compute analytics.


Bot Filtering

How does Sealmetrics block bots?

We use several layers, none of which stores personal data:

  • Bot user-agent signature lists (known crawlers, headless browsers, automation tools)
  • Curated IP/CIDR blocklists of known bots and datacenters, checked in memory at request time — the IP is used only for this transient check and never stored with analytics data
  • Request-header consistency checks (A fourth layer — Agent Analytics, using environmental and behavioral signals to classify traffic as human vs. automated — is designed but not live, and collects nothing on any account today.)

See How Sealmetrics Blocks Bot Traffic for the full picture.


Cookies & Storage

Does Sealmetrics use cookies?

No.
Sealmetrics does not use:

  • cookies
  • session storage
  • local storage
  • fingerprinting
  • cross-site IDs

Data Retention

How many months does Sealmetrics store my data?

We store data for a maximum of 24 months.
This stays inside the 25-month ceiling that CNIL guidance sets for consent-exempt analytics — Sealmetrics deliberately applies the stricter 24-month limit.