Skip to content
Sealmetrics

Role · DPO and legal

One data inventory.
Fixed retention.
Nothing on the device.

A DPO reviewing an analytics vendor needs to know what is collected, where it is processed, for how long and by whom, and most vendors answer with a policy page. Sealmetrics gives the review a closed scope: an Article 28 DPA whose annexes list the data processed, the retention periods and the sub-processors, no storage on the visitor's device, no stored IP addresses, and visitor data processed in Dublin.

Article 28 DPA · retention by database TTL · no ISO 27001 or SOC 2 claimed · not legal advice

Quick answer

Reviewing web analytics as a DPO means documenting what the tool collects, where and by whom it is processed, how long it is kept and whether the consent requirement applies. Sealmetrics is built to give that review a fixed scope. It writes no cookie or other storage on the visitor's device and keeps no IP address; the country comes from the browser time zone, and a session identifier is pseudonymised server-side with a daily salt destroyed on rotation. Visitor data is processed in Dublin under an Article 28 DPA that lists the data processed, the retention periods and the sub-processors, the only non-EU one sending account emails with no visitor data. Event-level rows are deleted after one day and aggregates after 24 months. Whether a deployment is exempt from consent still depends on its configuration, its purposes and the national authority, and Sealmetrics holds no ISO 27001 or SOC 2 certification.

What the DPO has to document

Six entries in the record.
Six documented answers.

The questions below are the ones a record of processing and a vendor review need answered for any analytics tool. Each answer points to a document you can read.

What you documentWhat to ask any analytics vendorSealmetrics, as documentedWhere to verify
Data categoriesWhich fields are collected and which are never storedBrowsing and technical data, country from the browser time zone, a pseudonymised session identifier, UTMs and conversions; no IP, no user IDDPA Annex 1
Device accessIs anything stored on or read from the device?No cookies, localStorage or other device storageWhat we track
PurposesIs marketing attribution separate from audience measurement?Listed as separate purposes; attribution is optional and configured by youDPA
RetentionFixed or configurable, and who enforces it?Fixed TTLs: event rows 1 day, hourly aggregates 90 days, daily aggregates and conversions 24 monthsData location and retention
Location and transfersWhere is visitor data processed, and who processes it?Dublin, Ireland; the only non-EU sub-processor sends account emails and receives no visitor dataDPA Annex 3
AssuranceWhich certifications, audits and assistance?No ISO 27001 or SOC 2; audit rights and DPIA assistance in the DPA; TPSR packageDPA clauses 4.6 and 4.7 · security

The field list is public in what we track. How the architecture reads against the CNIL, DSK and AEPD criteria is set out regulator by regulator in GDPR analytics, and the security controls in security.

What an open-ended scope costs

A review without edges
never closes.

The effort of an analytics review is set by how much of the processing is left to interpretation.

01

Every new tag reopens the assessment

A new cookie, identifier or purpose changes the processing and the record. A fixed data inventory keeps the analytics entry stable while the rest of the stack changes.

03

Consent decides what marketing can see

A banner-dependent tool records only visitors who accept. On a Shopify store measured side by side for 48 days, GA4 did not record 29% of visits. The trade-off between compliance and data is argued in complete data.

The vendor review

Review the documents.
Then check the site.

Five steps a DPO can run on Sealmetrics or on any other analytics tool. The regulatory gap analysis applies the same questions to your current stack.

  1. Read the DPA and its annexes

    Check the data processed and never stored, the retention periods, the security measures and the sub-processors. For Sealmetrics that is the Article 28 DPA 2026-v2.0 and its annexes, published at /dpa.

  2. Check the live site

    Open the site with the browser's developer tools and confirm that the analytics script writes no cookie, localStorage or other storage, and that requests go to the expected domain.

  3. Audit what the site sends

    Custom properties, conversion values, URLs and campaign parameters are set by your own team. Confirm none of them carries names, emails, phone numbers or customer IDs; the Sealmetrics MCP prompt library includes an audit for this.

  4. Assess each purpose against your authority's criteria

    Audience measurement and marketing attribution are separate purposes. Read the conditions your national authority publishes, such as the CNIL, DSK or AEPD criteria, and decide how each purpose is covered.

  5. Record the decision and update the notice

    Add the processing to your record with Sealmetrics as processor under the DPA, and describe the analytics in your privacy notice. The documentation includes recommended notice text you can adapt.

Who signs off

One review,
four signatures.

A vendor review crosses several desks. Each one gets a document it can check rather than a claim.

DPO

A record of processing entry that does not change every quarter.

The DPA annexes: data processed, retention, sub-processors and the purposes listed separately.

Read the DPA

Legal counsel

The authority's criteria, not a vendor's conclusion.

Analyses against the CNIL, DSK and AEPD criteria, stated as guidance and not as legal advice.

GDPR analytics by country

CISO and security

Controls and their boundaries, without claimed certifications.

Encryption, isolation, retention by TTL and the Dublin operating boundary; no ISO 27001 or SOC 2.

Security overview

Marketing

To know what can be sent without reopening the review.

An audit of custom properties and campaign parameters for personal data, runnable from an AI assistant.

MCP prompt library

Documents, not badges

There is no approved client quote on compliance, so this page points to documents. Sealmetrics also says what it does not hold: no ISO 27001, no SOC 2, and no regulator certification, because authorities do not certify analytics tools.

1 day

retention of event-level rows before deletion; aggregates are kept 24 months

Security overviewOpen
4.6

the DPA clause committing Sealmetrics to assist with impact assessments and prior consultations

Data Processing AgreementOpen
14

CNIL technical criteria documented one by one in a public self-assessment

CNIL self-assessmentOpen

What a review still has to decide

Documents support a decision.
They do not take it.

These limits belong in the record as much as the answers. The CNIL self-assessment in the documentation shows the criteria it maps.

Not legal advice

These pages describe the product and published guidance. Your DPO or counsel decides for your deployment.

No certification

Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools.

Your configuration can change the answer

Properties, URLs or campaign parameters that carry personal data bring it into the dataset. Keep them out of what the site sends.

Attribution is its own purpose

Marketing attribution is listed separately from audience measurement in the DPA and has to be assessed on its own terms.

Other tools keep their obligations

Advertising pixels, A/B testing and chat widgets that store or read data on the device still need consent.

The notice is still yours

The site owner describes the analytics in its privacy notice; the documentation offers text to adapt, not a finished policy.

Questions DPOs ask

Before you sign
the vendor review.

What should a DPO ask a web analytics vendor?

Which data is collected and which is never stored, whether anything is stored on or read from the visitor's device, which purposes the data serves, how long each category is kept, where it is processed and by which sub-processors, and which audits, certifications and assistance the contract provides. Ask for the answers in the processing agreement, not on a marketing page.

Is Sealmetrics a processor or a controller?

Sealmetrics acts as processor for the customer's analytics under an Article 28 DPA; the customer remains controller of its website's processing. The DPA sets out the data processed, the purposes, the retention periods, the security measures and the sub-processors.

Do we need a DPIA for Sealmetrics?

That is your assessment to make, based on your processing as a whole. Under clause 4.6 of the DPA, Sealmetrics assists with impact assessments and prior consultations and keeps the technical documentation of the processing available: architecture, data inventory, retention and the AEPD assessment.

What should our privacy notice say about Sealmetrics?

That the site uses Sealmetrics for audience measurement, which data it processes and for which purposes, and how visitors can object. The documentation includes recommended text in its CNIL self-assessment that you can adapt to your notice and your national rules.

Can visitors opt out?

Sealmetrics builds no individual profile, so there is no personal history to opt out of. Visitors can block analytics through their browser's privacy settings or an ad blocker, and a site can add its own opt-out mechanism, as the CNIL self-assessment in the documentation describes.

Where is visitor data processed, and who are the sub-processors?

Visitor data is stored and processed in Dublin, Ireland. Annex 3 of the DPA lists the sub-processors: the only one outside the EU sends service emails to account users and receives no visitor data, and the managed AI inference for Private AI runs in Paris.

Which certifications does Sealmetrics hold?

None. Sealmetrics does not hold ISO 27001 or SOC 2 certification and does not claim either. The security measures are listed in the DPA, customers have audit rights under clause 4.7, and a TPSR package is available for procurement reviews.

Compliance walkthrough

Bring your review template.
We bring the documents.

Thirty minutes with the person responsible for the implementation: the DPA annexes, the retention periods, the sub-processors and the criteria of your national authority.