Privacy & Sovereignty

Sovereignty is not a marketing term.

The page for people who want the detail. How we measure without cookies, where your data lives, what we do not do, and how we fit GDPR, NIS2, DORA and the CRA.

For the legal version, see our privacy policy and the data processing agreement.

01 · Cookieless

How we measure without cookies.

The trick, if it even is one, is that we never make identification persistent. We compute a daily rotating, hashed identifier from the IP address and User-Agent. It is valid for one calendar day (UTC) and useless after that.

1.A visitor arrives; the tracker sends an HTTP POST to /i
2.The server computes SHA256( daily_salt + IP + User-Agent + property_id )
3.The first 64 bits become the visitor_id (UInt64)
4.The IP is used in memory only for a country lookup, then discarded
5.At midnight UTC the daily_salt is destroyed, so the hash can never be reconstructed

No cookies, no localStorage, no fingerprinting, no IP storage.

02 · Data location

Where your data lives.

All Tracera components run on dedicated hardware in a Belgian data centre. No replication, no backup, no CDN cache outside the EU. No US sub-processors in the data path.

Ingest layer, query layer and dashboard, all in Belgium
Database (PostgreSQL) and analytics store (ClickHouse) in the same location
Email delivery via Canvos, Belgian SMTP infrastructure
No Amazon, no Google Cloud, no Microsoft Azure
No Cloudflare in the data path; static assets are deliberately separated

Want the exact sub-processors? They are in the data processing agreement. Request it via legal@tracera.eu and we send it within one business day.

03 · Legal

The legal framework.

Under the GDPR the roles are clear. This is who is what.

You are the controller

Your website collects data from your visitors, for your purpose. You decide where and how Tracera processes it.

We are the processor

Tracera (GoTrust BV) processes only on your instruction. No secondary use, no AI training on customer data, no resale.

Subject to Belgian law

Disputes fall under the courts of Ghent. No complex holding structures in third countries.

A standard DPA template (EN and NL) is available on request via legal@tracera.eu.

04 · What we don't do

What we don't do.

Just as important as what we do. We list it explicitly so there is no room for interpretation.

05 · Compliance

How we fit compliance frameworks.

What each regulation requires and how Tracera helps. We do not claim certifications we do not hold (we are not ISO 27001 certified today). We are honest about which reporting we can provide.

GDPR

General Data Protection Regulation

DPA template included, clear processor role, Article 30 RoPA input on request, transparent sub-processor list. Privacy by design through cookieless measurement.

NIS2

Cybersecurity directive

Evidence of EU data location, sub-processor control, incident-response procedure, audit log per sensitive action.

DORA

Digital Operational Resilience Act

Tracera qualifies as a third-party ICT provider. We provide what you need for ICT-risk registration and sub-contractor mapping.

CyFun

Cyber Fundamentals (Belgium)

Evidence of Belgian processing, no US cloud, audit log for changes, for entities using the CyFun framework.

CRA

Cyber Resilience Act

Vulnerability disclosure policy, security-update procedure, SBOM on request for the tracker.

AI Act

EU AI Act

No AI training on customer data, no automated decision-making in the pipeline, full data provenance on request.

Specific regulatory question (for example "can we use Tracera as a bank under DORA?")? Write to legal@tracera.eu and we send a mapping document per control requirement.

Talk to our security lead.

For deeper technical questions, a DPA review, or an audit conversation. We respond within one business day.

Get in touch → or read the DPA →