Enterprise-ready cookieless analytics: Scalable, performant, and fully GDPR compliant.
GDPR
ISO 27001:2022

NIS2

DORA

DSA
CCPA / CPRA

nFADP
Exclusively hosted in Germany (Hetzner Online)
ISO 27001 certified data centers (Nuremberg)
Zero US Cloud Act exposure (German legal entity)
View infrastructure details in TOMs
OS Hardening & automated security patching
Containerized architecture (Docker/K8s)
Strict Content Security Policy (CSP)
View product security controls
100% Data Residency in Germany
IP Anonymization before processing
No data transfer to US hyperscalers
View privacy controls
Multi-Factor Authentication (MFA) enforced
Strict VPN/SSH key access control for servers
Confidentiality agreements (NDAs) for staff
View organizational policies
Encrypted offsite backups (Daily)
Formal Incident Response Plan established
Strict offboarding checklist for employees
View internal procedures
Professional email address & account details
Anonymized website visitor IPs
Aggregated usage events & pageviews
Device & browser information (User Agent)
Hetzner Online GmbH • Core Infrastructure & Database
Stripe Payments Europe • Payment Processing & Billing
Loops Inc. • Transactional Emails & Onboarding
Exclusively in Germany. We use Hetzner Online GmbH as our infrastructure provider with data centers in Nuremberg and Falkenstein. Unlike many competitors, we do not rely on US hyperscalers (AWS/Google/Azure) for our core data processing, ensuring maximum data sovereignty and immunity to the US Cloud Act.
No, never. Your data belongs 100% to you. bchic Analytics acts strictly as a data processor. We do not sell data to advertising networks, nor do we use your customer data. Your data is logically isolated and only accessible to you and your team.
bchic is a German legal entity (UG) and falls under strict EU regulations.
- Infrastructure: We host strictly within the EU (Germany).
- Contract: We provide a comprehensive Data Processing Agreement (DPA) incorporating standard contractual clauses.
- Features: Our software includes privacy-by-design features like automatic IP anonymization and data retention controls to help you stay compliant.
- Subprocessors: We maintain a strict vetting process for all subprocessors to ensure adequate data protection levels.
No. bchic Analytics is specifically engineered to function without cookie banners. We do not use cookies, local storage, or fingerprinting to track individual users. Our platform strictly collects aggregated data only, with no technical option to enable personal tracking. This privacy-first design ensures compliance with GDPR and ePrivacy regulations without requiring end-user consent.
By default, no. We enforce strict access controls. Our engineers do not have standing access to customer production data. Access is granted only temporarily and strictly for support purposes (e.g., if you explicitly request help with a technical issue), and all access logs are audited.
Hetzner Online GmbH • Core Infrastructure & Database
Stripe Payments Europe • Payment Processing & Billing
Loops Inc. • Transactional Emails & Onboarding
Exclusively in Germany. We use Hetzner Online GmbH as our infrastructure provider with data centers in Nuremberg and Falkenstein. Unlike many competitors, we do not rely on US hyperscalers (AWS/Google/Azure) for our core data processing, ensuring maximum data sovereignty and immunity to the US Cloud Act.
No, never. Your data belongs 100% to you. bchic Analytics acts strictly as a data processor. We do not sell data to advertising networks, nor do we use your customer data. Your data is logically isolated and only accessible to you and your team.
bchic is a German legal entity (UG) and falls under strict EU regulations.
- Infrastructure: We host strictly within the EU (Germany).
- Contract: We provide a comprehensive Data Processing Agreement (DPA) incorporating standard contractual clauses.
- Features: Our software includes privacy-by-design features like automatic IP anonymization and data retention controls to help you stay compliant.
- Subprocessors: We maintain a strict vetting process for all subprocessors to ensure adequate data protection levels.
No. bchic Analytics is specifically engineered to function without cookie banners. We do not use cookies, local storage, or fingerprinting to track individual users. Our platform strictly collects aggregated data only, with no technical option to enable personal tracking. This privacy-first design ensures compliance with GDPR and ePrivacy regulations without requiring end-user consent.
By default, no. We enforce strict access controls. Our engineers do not have standing access to customer production data. Access is granted only temporarily and strictly for support purposes (e.g., if you explicitly request help with a technical issue), and all access logs are audited.
We help our clients (both EU and globally) comply with GDPR.
We support our clients in complying with CCPA and CPRA. As a 'Service Provider,' we process data exclusively on behalf of our clients and do not sell personal information. Our security standards and data processes are optimized to fully meet the requirements of Californian privacy law.
As a hosting provider, we support the objectives of the EU Digital Services Act (DSA) for a safer digital environment. Since we exclusively process analytics data on behalf of our clients and do not host public content, our compliance focuses on transparent reporting channels and protection against the illegal use of our infrastructure. We strictly adhere to the notice-and-action requirements of Articles 14 ff. DSA.
As we host your data in Germany and maintain strict incident reporting processes, we fulfill the requirements for supply chain security in accordance with NIS2.
Full compliance with the Swiss Federal Act on Data Protection (nFADP). Data storage takes place in the EU/Germany (adequate level of protection).
Specially for financial institutions, we offer a DORA Addendum covering the security of ICT services and third-party risk management.
bchic Analytics DORA Addendum.pdf