Skip to main content

Privacy by Design Principles

Privacy by Design is the framework GDPR Article 25 refers to as data protection by design and by default. Sealmetrics addresses it the blunt way: by keeping almost nothing — nothing stored on the device, no data that identifies anyone, and a session identifier that rotates daily and, once rotated, cannot be reconstructed, not even by Sealmetrics. The seven principles below map to specific architectural choices rather than to policies.

How does Sealmetrics map to the seven principles?​

PrincipleHow it shows up in Sealmetrics
1. Proactive, not reactivePrivacy constraints are structural. The system cannot start identifying visitors later without a redesign, because there is no persistent identifier to switch on.
2. Privacy as the defaultNon-identifying measurement from the first page load. Visitors do not opt in to anything, and there is no less-private mode to fall back to.
3. Full functionalityTraffic, attribution, conversions, revenue and aggregate engagement are all reported as aggregates, without identifying anyone. What is genuinely lost — unique visitors, session duration, cross-session journeys — is documented rather than worked around.
4. End-to-end securityEU-only storage in Dublin, Ireland; encryption in transit and at rest; role-based access control; short retention enforced by database TTLs. See Data Location & Retention.
5. Visibility and transparencyThe complete field list and its retention is published in What We Track. The tracker is client-side and inspectable.
6. Respect for user privacyNo cookies, no device storage, no stored or persistent fingerprint, no cross-day, cross-session or cross-site linking. The session identifier is a device-characteristics hash re-keyed on the server with a daily salt that is destroyed on rotation, and it incorporates the publisher account, so the same browser yields different identifiers on different sites.
7. Accommodate all legitimate interestsSite owners get the measurement they need for business decisions; visitors are not identified to provide it.

Is privacy by design a certification?​

Two claims worth keeping straight, because vendor reviews turn on them: privacy by design is an architectural property, not a certification. Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools. The pages under compliance are our own self-assessments against published criteria, and a Data Processing Agreement is included at sealmetrics.com/dpa.

In short
  • Sealmetrics addresses GDPR Article 25 (data protection by design and by default) by keeping only minimal, pseudonymised data that becomes unrecoverable daily, so each of the seven principles maps to an architectural choice.
  • Non-identifying measurement is the default and only mode: no cookies, no device storage, no stored or persistent fingerprint, EU-only storage in Dublin with short retention enforced by TTLs.
  • Privacy by design is an architectural property, not a certification — Sealmetrics holds no ISO 27001 or SOC 2 and no supervisory authority certifies analytics tools.
Written and maintained by the Sealmetrics Team