Security & Privacy
Sealmetrics measures websites without collecting personal data: four non-identifying variables per hit, nothing written to the visitor's device, no identifier carried across sessions, and all customer analytics data stored in Dublin, Ireland. Because there is no personal data, the consent requirements of GDPR and the ePrivacy Directive are not triggered — the reasoning is set out in full in What is Consentless Analytics?.
Sealmetrics holds no third-party security certification (no ISO 27001, no SOC 2), and no supervisory authority certifies analytics tools. The pages under compliance are our own self-assessments against published criteria. A Data Processing Agreement is included and ready to sign at sealmetrics.com/dpa; Annex 3 of that DPA is the authoritative subprocessor list.
Start here
- What is Consentless Analytics? — the concept, the legal basis under GDPR and ePrivacy, and what the model can and cannot measure
- What We Track vs What We Don't — the field-by-field list, with retention for each field
The consentless model
- How Consentless Tracking Works — the technical mechanics, step by step
- Why Sealmetrics Can Measure Without Consent — the short answer on consent
- Benefits of Consentless Tracking — what complete data changes in practice
- How Attribution Works Without a User-ID — last-click attribution without identifiers
Privacy practice
- How Sealmetrics Protects User Privacy — the concrete protections
- Privacy by Design Principles — the seven principles mapped to architecture
- How Sealmetrics determines the country without using IP addresses — timezone-based geolocation
Data, hosting and quality
- Data Location & Retention — EU hosting, retention schedule, encryption, deletion and export
- Bot Detection & Traffic Quality — how automated traffic is filtered out of reports
- Why Sealmetrics Is Not Blocked by AdBlockers — first-party delivery and why filter lists do not match
Account security
Auditing someone else's tags
- What Is This Domain in My Cookie Audit? — lookup table of external analytics domains
- What Is demdex.net? — Adobe's Experience Cloud ID cookies
- What Is omtrdc.net? — Adobe Analytics' collection domain
Related documentation
- Compliance self-assessments — GDPR, ePrivacy, CNIL, AEPD, PECR analysed one by one
- Data Subject Rights (DSAR) — how access and erasure requests work
- Privacy and security FAQ — common questions in Q&A form