GDPR & Compliance
MetriXs is built privacy-first, compliant with GDPR, CCPA, and PECR out of the box.
Why MetriXs needs no consent banner
Nothing placed on the device
The ePrivacy Directive (Art. 5(3)) requires consent before storing or accessing information on a visitor’s device, unless strictly necessary. MetriXs sets no cookies and uses no local storage, so this requirement is never triggered.
No personal data stored
GDPR applies to personal data. MetriXs discards the raw IP and User-Agent in memory and stores only a daily-salted, irreversible hash that resets every 24 hours. There is no persistent identifier to link to a person.
The controller / processor split
When you place MetriXs on your website, two legal roles apply. Understanding them is the key to GDPR-compliant analytics:
You = Controller
You decide to measure your traffic and remain responsible for having a lawful basis. Because MetriXs stores no personal data, that basis is legitimate interest, no consent needed.
MetriXs = Processor
MetriXs processes visitor data on your behalf, under your instructions, for the sole purpose of providing aggregate analytics. A DPA is available.
What this means for you
No cookie banner
Remove your consent popup. Higher opt-in rates, cleaner UX, less legal risk.
No DSAR flood
Because no personal visitor data is stored, there is nothing to access or delete on request.
Privacy by design
Meets GDPR Article 25, data minimisation and privacy-by-default are baked into the architecture.
EU-only data flow
All visitor data stays in the EU. No US edge provider in the path, no international transfer concerns.
CCPA & PECR
CCPA (California)
The CCPA’s obligations centre on personal information. Because MetriXs stores no personal data about your visitors, there is no personal information to sell, disclose, or delete on request.
PECR (UK)
The UK’s Privacy and Electronic Communications Regulations mirror the ePrivacy Directive on cookies. MetriXs places none, so PECR consent is not required.
Documentation
- Data Policy, exactly what the tracker collects and the daily-salt mechanism
- Privacy Policy, how we handle your account data and your rights
- Data Processing Agreement, available for procurement teams
- Subprocessors, the providers we rely on
- Security, how we protect your data
Last updated: July 2026