The page for people who want the detail. How we measure without cookies, where your data lives, what we do not do, and how we fit GDPR, NIS2, DORA and the CRA.
For the legal version, see our privacy policy and the data processing agreement.
The trick, if it even is one, is that we never make identification persistent. We compute a daily rotating, hashed identifier from the IP address and User-Agent. It is valid for one calendar day (UTC) and useless after that.
/ivisitor_id (UInt64)daily_salt is destroyed, so the hash can never be reconstructedNo cookies, no localStorage, no fingerprinting, no IP storage.
All Tracera components run on dedicated hardware in a Belgian data centre. No replication, no backup, no CDN cache outside the EU. No US sub-processors in the data path.
Want the exact sub-processors? They are in the data processing agreement. Request it via legal@tracera.eu and we send it within one business day.
Under the GDPR the roles are clear. This is who is what.
Your website collects data from your visitors, for your purpose. You decide where and how Tracera processes it.
Tracera (GoTrust BV) processes only on your instruction. No secondary use, no AI training on customer data, no resale.
Disputes fall under the courts of Ghent. No complex holding structures in third countries.
A standard DPA template (EN and NL) is available on request via legal@tracera.eu.
Just as important as what we do. We list it explicitly so there is no room for interpretation.
What each regulation requires and how Tracera helps. We do not claim certifications we do not hold (we are not ISO 27001 certified today). We are honest about which reporting we can provide.
DPA template included, clear processor role, Article 30 RoPA input on request, transparent sub-processor list. Privacy by design through cookieless measurement.
Evidence of EU data location, sub-processor control, incident-response procedure, audit log per sensitive action.
Tracera qualifies as a third-party ICT provider. We provide what you need for ICT-risk registration and sub-contractor mapping.
Evidence of Belgian processing, no US cloud, audit log for changes, for entities using the CyFun framework.
Vulnerability disclosure policy, security-update procedure, SBOM on request for the tracker.
No AI training on customer data, no automated decision-making in the pipeline, full data provenance on request.
Specific regulatory question (for example "can we use Tracera as a bank under DORA?")? Write to legal@tracera.eu and we send a mapping document per control requirement.
For deeper technical questions, a DPA review, or an audit conversation. We respond within one business day.
Get in touch → or read the DPA →