GDPR
Compliant by architecture — no personal data collected.
EU-hosted in Dublin. Zero personal data collection. Zero sub-processors outside the EU. Your compliance team signs off in one meeting — not three.
Every framework your compliance team looks for — architectural, contractual and pre-documented for procurement review.
Compliant by architecture — no personal data collected.
No cookies, no localStorage — directive doesn't apply.
Zero transfers outside EU. No SCCs needed.
Single region. No failover to third countries.
Standard DPA with every plan. Custom DPA on Enterprise.
Vendor security questionnaire pre-built for procurement review.
Every byte of data stays within the EU. No third-country transfers, no sub-processors, no hidden dependencies.
Your domain. No cookies. No localStorage. No identifiers. Zero personal data on the device.
Direct-to-server with PFS. No third-party CDN for analytics traffic.
Dublin region. Isolated VPC. Anonymous event counting with no personal identifiers ever stored.
AES-256. Dublin region. 24-month retention. No third-country replication.
What DPOs, CISOs and procurement teams ask. If your team has something else, we'll answer it in the walkthrough.
Still have questions? Our team — including the founder — is one message away.
Talk to us →30 minutes with our compliance lead. Architecture, DPA, Schrems II stance, TPSR — walked through with your legal team.
Built by a founder · supported by a founder · EU-hosted by design