Data Subject Rights (DSAR) and SealMetrics
If you use SealMetrics on your website, sooner or later your DPO will receive a data subject access request (DSAR) and need to answer a simple question: "What does our analytics tool hold about this person?"
With SealMetrics, the answer is structurally simple — and this page explains why, what it means in practice, and where data subject rights do fully apply (your dashboard account).
Two very different data categories
| Category | Who it concerns | Contains personal data? | Rights requests |
|---|---|---|---|
| Visitor analytics data | Visitors to your website | No — no identifiers by design | Cannot be linked to any individual (see below) |
| Account data | You and your team (dashboard users) | Yes — email, name, billing details | Fully applicable, standard process |
Visitor rights requests: no data to link to
Why requests cannot be matched to records
SealMetrics stores no personal data and no identifiers for website visitors:
- No IP addresses stored (used ephemerally in memory for anti-bot protection, never persisted)
- No cookies or terminal storage
- No user IDs, device IDs, or fingerprints
- No cross-session identifiers — the short-lived session marker (~2h) expires and cannot recognize a returning visitor
- Country derived from the browser timezone, not from the IP
- User agent stored as a category signal, never joined to any identity
Because no record in the analytics database relates to an identified or identifiable person, there is no key by which a rights request could be matched to any stored record. If a visitor asks "show me my data" or "delete my data", there is no technical means — for SealMetrics or for you — to determine which rows (if any) were generated by that person's visits.
The legal frame: GDPR Article 11
GDPR anticipates exactly this situation. Article 11 (processing which does not require identification) provides that where a controller's purposes do not require the identification of a data subject, the controller is not obliged to acquire additional information just to identify the data subject for the purpose of complying with the Regulation. Where the controller can demonstrate it is not in a position to identify the data subject, Articles 15–20 (access, rectification, erasure, restriction, portability) do not apply — unless the data subject themselves provides additional information enabling identification, which with SealMetrics is not possible because no identifier exists to match it against.
This is not a workaround to avoid answering DSARs. It is the direct consequence of not collecting personal data in the first place: data minimization taken to its logical conclusion. The best DSAR response is having nothing to search.
What this means in practice for your DPO
When a visitor rights request mentions your website analytics:
- You can respond substantively — explain that your analytics tool (SealMetrics) stores no personal data or identifiers about visitors, so no stored record can be attributed to the requester.
- You do not need to ask SealMetrics to search — there is nothing to search by: no email, no IP, no ID exists in the analytics data.
- Document the reasoning — reference your records of processing (ROPA) entry for SealMetrics, which should describe the tool as processing anonymous, aggregate statistics. This page and What We Track vs What We Don't can be attached as supporting documentation.
- Remember Article 12(2) — you must still facilitate rights requests in general; the point is that for this specific processing, identification is impossible and Article 11(2) applies.
This analysis holds for SealMetrics as designed. If your implementation passes personal data into custom event properties (for example, an email address in a conversion property), you have introduced personal data into the system against our configuration guidance, and your DSAR analysis changes. Never send PII in custom properties.
Account-holder rights: fully applicable
Data subject rights apply in full to account data — the personal data of you and your team as SealMetrics dashboard users (email address, name, password hash, billing information, audit logs).
What you can do yourself
| Right | How |
|---|---|
| Access / portability | Export your data from the dashboard (CSV) or via the API |
| Rectification | Edit your profile and account details in the dashboard |
| Erasure | Close your account — all data deleted within 30 days, backups purged within 90 days |
How to submit a rights request
For anything you cannot do self-service, or to exercise any GDPR right formally:
- Email: privacy@sealmetrics.com
- DPO contact: dpo@sealmetrics.com
Include the email address associated with your SealMetrics account so we can verify your identity. We respond within the timelines required by GDPR Article 12(3) (one month, extendable in complex cases with notice).
Roles under the DPA
For visitor analytics data, you (the website operator) are the controller and SealMetrics is your processor under the SealMetrics DPA. For account data (your dashboard login, billing), SealMetrics acts as a controller in its own right. Rights requests for account data go directly to us at the addresses above.
Quick reference for DPOs
| Scenario | Answer |
|---|---|
| Visitor asks your company for their analytics data | No record can be attributed to them — no identifiers exist (GDPR Art. 11) |
| Visitor asks for erasure of their analytics data | Same — no record can be located; nothing identifiable is stored |
| Visitor objects to processing | No individual-level processing occurs; visitors can additionally block the script via browser settings or ad blockers |
| Dashboard user asks for their account data | Standard DSAR — self-service export or privacy@sealmetrics.com |
| Regulator asks where analytics data is stored | Dublin, Ireland (EU), 24-month retention — see Data Location & Retention |
Related documentation
- What We Track vs What We Don't — the full inventory of what is (and is not) collected
- Subprocessors — who touches what data, and where
- Data Location & Retention — storage location and deletion schedules
- Why Sealmetrics Can Measure Without Consent — the consent-free model behind this analysis
- CNIL Self-Assessment — configuration rules that keep PII out of the system