GDPR-compliant analytics
Web analytics that is GDPR compliant by design.
GDPR-compliant analytics measures your traffic without storing personal data, so the regulation’s consent and transparency obligations are satisfied by the tool itself rather than by a cookie banner and a legal workaround. MetriXs is a cookieless, EU-hosted analytics tool with a signed DPA. Free plan, paid plans from €6/month.
What the GDPR asks of your analytics tool
The GDPR applies to any tool that processes personal data on behalf of your business. A conventional analytics tool does that in three ways: it sets cookies (personal data under the ePrivacy Directive), it stores IP addresses (personal data under the GDPR), and it may send that data outside the EU. Each of those triggers obligations: a cookie banner with valid consent, a lawful basis, transparency, and a Data Processing Agreement.
The cleanest way to be GDPR compliant is to not process personal data in the first place. That is what cookieless analytics does. When no personal data is stored, the consent requirement falls away, the lawful-basis question simplifies, and the privacy risk to your visitors is close to zero. You still need a DPA (MetriXs provides one), but the underlying processing is minimal.
“GDPR-compliant” with cookies is not the same thing
Many analytics tools market themselves as GDPR compliant while still setting cookies. They are compliant only if you deploy a consent banner, get valid opt-in before the script loads, honour rejections, and maintain a record of consent. That is a configuration and legal burden you carry on every page, and a rejected-consent visitor is invisible to your numbers. A cookieless tool removes that entire surface. Compliance is a property of the architecture, not a task on your checklist.
What to look for in a GDPR analytics tool
No cookies, no consent banner
If the tool sets cookies, you need a banner and valid consent before it loads. A cookieless tool needs neither. This is the single biggest compliance simplification.
No IP addresses stored
The IP address is personal data. A GDPR analytics tool should hash it with a rotating salt and discard the original, never store it in a raw column.
EU data residency
Visitor data should be processed and stored in the EU, with no US edge or CDN provider in the path. This keeps the data outside the reach of US surveillance laws.
A signed DPA (Article 28)
Your analytics provider is a processor. You need a signed DPA in place. If the provider does not offer one, that is a red flag.
A clear subprocessor list
The provider should publish who processes data on its behalf, where they are, and what they touch. MetriXs lists every subprocessor on /subprocessors.
Retention limits and deletion
Data should not be kept forever. Look for configurable retention and the ability to delete a site's data on request. MetriXs deletes data past your plan's retention window automatically.
Compliance you do not have to maintain
Cookieless, EU-hosted, with a signed DPA and a public subprocessor list. Free plan, paid from €6/month.
Start free trial →Frequently asked questions
- Is MetriXs GDPR compliant?
- Yes, by design. MetriXs sets no cookies, stores no IP addresses (only a daily-salted hash), is hosted in Germany, and never sends data outside the EU. A signed Data Processing Agreement (DPA) is available on the /dpa page.
- Do I need a cookie banner with a GDPR-compliant analytics tool?
- Only if the tool sets cookies or stores personal data. A truly cookieless analytics tool like MetriXs stores no personal data, so the ePrivacy consent requirement does not apply and no banner is needed. A "GDPR-compliant" cookie-based tool still needs a banner and valid consent before it loads.
- What is a DPA and do I need one?
- A Data Processing Agreement (DPA) is the Article 28 contract between you (the controller) and your analytics provider (the processor). You need one for any processor that handles visitor data on your behalf. MetriXs provides a signed DPA you can download from /dpa.pdf.
- Where is visitor data stored?
- On Hetzner servers in Germany. No CDN, no US edge provider, and no subprocessor outside the EU sees visitor data. The full subprocessor list is on /subprocessors.
- How long is visitor data retained?
- Retention is set by your plan: 1 month on Free, 1 year on Basic and Team, 2 years on Pro. Data older than your retention window is automatically deleted. You can also delete a site's data at any time from the dashboard.
- How are data subject requests handled?
- Because MetriXs stores no personal data (no cookies, no IP, only a daily-rotating hash that cannot be traced back to a person), there is no personal data to return or erase in response to a subject access or erasure request. The privacy policy on /privacy explains this in detail.