Pulse · GDPR-compliant analytics
GDPR-compliant web analytics
Most analytics tools can be made GDPR-compliant with enough configuration, consent management and legal review. Pulse starts there: it collects no personal data, so compliance is structural rather than a setting you have to get right.
01 · The legal basis
No personal data, no consent required
The GDPR governs the processing of personal data — any information relating to an identified or identifiable person (Article 4). The consent obligation that puts a banner on so many sites actually comes from the ePrivacy Directive, which requires opt-in before storing or reading information on a user’s device, such as a cookie.
Pulse is built to sit outside both triggers. It sets no cookies and stores nothing identifying on the device — the current tab’s sessionStorage holds only a five-second guard against double-counting a refresh, never an identifier — so the ePrivacy consent requirement does not apply. And it collects no personal data: IP addresses are used only to resolve a country at request time and are then discarded, visit and visitor keys are server-derived hashes that rotate daily and monthly, and no visitor can be singled out or tracked across sites. With no personal data and no identifying device access, there is no lawful-basis question to answer and no consent to collect.
This is a different posture from “GDPR-ready”. You are not relying on a correctly-configured consent tool, a data-processing addendum and a region setting to stay compliant — the data that would create the obligation is simply never gathered.
02 · Beyond the checkbox
Compliant by architecture, operated in the EU
Data minimisation is a GDPR principle, not just a nicety: you should collect only what you need. Pulse takes that literally. No name, no email, no account, no cross-site identity, and no identifier that outlives a calendar month — so there is nothing in a breach that could identify a visitor, and a data-subject request about one cannot be answered because the data has never been linkable to a person in the first place. Visitor-level views group a month’s pageviews under a pseudonym that is re-minted every month; they are off by default and switched on per site by its owner.
Jurisdiction matters too. Pulse is operated by Ciphera BV, a Belgian company, with data held on Swiss and EU infrastructure. Your analytics provider is inside the EU and subject to EU law, rather than a foreign company whose home jurisdiction can reach into the data. And because the dashboard and tracking client are open source, your data protection officer can verify what is collected instead of trusting a marketing claim.
FAQ
Frequently asked questions
Is Pulse GDPR compliant?
Yes, by design. Pulse collects no personal data as defined by GDPR Article 4 — no cookies, no persistent identifiers, no fingerprinting, and no storage of raw IP addresses. Because there is no personal data and no cookie access, the processing does not require consent under the GDPR or the ePrivacy Directive. Compliance is a property of the architecture rather than something you configure.
Do I need a Data Processing Agreement (DPA) with Pulse?
A DPA governs a processor handling personal data on your behalf. Because Pulse is designed not to collect personal data, the surface a DPA would cover is minimal — but Ciphera BV is an EU company subject to the GDPR, and account and billing data is of course handled under EU law. Review your own regulatory obligations and, where required, put the appropriate agreements in place.
Where is the analytics data stored?
On Swiss and EU infrastructure. Data is not transferred to the United States, and Pulse does not depend on US-jurisdiction cloud providers in the processing path — which sidesteps the EU-to-US transfer problems that led several data-protection authorities to rule Google Analytics unlawful.
Keep reading
Related
Get started
GDPR-compliant analytics, out of the box
No cookies, no consent, no personal data. Start free on the Hobby tier, or open the live demo to see exactly what Pulse measures on real traffic.
Cookie-free · Open-source client · GDPR compliant
