Privacy Battles
Swetrix
Privacy Score
64
%
⚔️
Matomo
Privacy Score
94
%

Designated DPO or GDPR correspondent

Compliant
Partially Compliant
Not Compliant

Swetrix doesn't mention having a DPO or GDPR correspondent but has a privacy dedicated email contact available on its website: contact@swetrix.com.

Compliant
Partially Compliant
Not Compliant

DPO is external. It is ePrivacy GmbH who can be reached on privacy@matomo.org or by post.

Privacy Policy

Compliant
Partially Compliant
Not Compliant

Regarding website and cloud: https://swetrix.com/privacy

Compliant
Partially Compliant
Not Compliant

Country & Type of Data storage

Compliant
Partially Compliant
Not Compliant

Company Headquarters:

Ukraine

Storage Facilities:

Analytics data is stored in German by US cloud provider Cloudflare.

Compliant
Partially Compliant
Not Compliant

Company Headquarters:
New Zealand 🇳🇿

Storage Facilities:
Servers, databases and logs are hosted in Frankfurt, Germany (cloud provider is AWS New Zealand). Offsite backups are stored in Dublin, Ireland.

Possibility to host Matomo Analytics on client premises.

Data transfers outside the EU

Compliant
Partially Compliant
Not Compliant

Data is deemed not transferred outside the EU.

If ever, Swetrix commits only to transferring personal data outside the EU if adequate security controls are in place.

Compliant
Partially Compliant
Not Compliant

The adequate level of protection in New Zealand has been approved by the European Commission.

Every transfer of personal data by Matomo to a country which is not a member state of either the EU or the EEA is submitted to prior consent of the controller.

Legal tools for Subcontractors

Compliant
Partially Compliant
Not Compliant

Subcontractors are subjects to the same protection level as set out in Swetrix’s Privacy Policy: https://swetrix.com/privacy 

Swetrix has made public its list of subprocessors: https://swetrix.com/privacy 

Swetrix doesn’t specify if written contracts are signed with subcontractors, nor if they inform controllers about adding a new subcontractor to the analytics service.

Compliant
Partially Compliant
Not Compliant

Subcontractors are subjects to written agreements substantially similar to Matomo’s DPA: https://fr.matomo.org/matomo-cloud-dpa/

Matomo has made public its list of subprocessors: https://fr.matomo.org/matomo-cloud-privacy-policy/

Prior to modifying the list of subprocessors, the controller will be notified by email and is able to object.

Data Breach Notification

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t mention directly notifying controllers of a data breach in a determined delay, nor providing assistance to controllers to notify the breach to the Supervisory authority.

Compliant
Partially Compliant
Not Compliant

In case of data breach, Matomo will inform without undue delay the controller by email and provide a description of the incident as well as periodic updates, including the impact on the controller.

Right Requests Process

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t mention providing assistance to controllers in case of a data subject's right request.

Compliant
Partially Compliant
Not Compliant

Data request will be forwarded to the controller without delay.

Data Privacy Impact Assessment

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t specify having conducted DPIAs or providing assistance to controllers if needed.

Compliant
Partially Compliant
Not Compliant

Matomo will provide assistance to the controller for DPIAs.

Employee Trainings

Compliant
Partially Compliant
Not Compliant

Swetrix doesn't mention employee training or submission to NDAs.

Compliant
Partially Compliant
Not Compliant

All employees required to access the personal data are deemed informed of the confidential nature of the personal data.

Security Policy

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t mention having a security policy.

Compliant
Partially Compliant
Not Compliant

Matomo doesn’t mention having a security policy.

Organizational and Technical Security Measures

Compliant
Partially Compliant
Not Compliant

Server security:

Cloud security relying on Cloudflare.

Other measures:

Data pseudonymisation (salted hash), data backups, data encryption.

Compliant
Partially Compliant
Not Compliant

Matomo doesn’t mention having a security policy.

Data Encryption

Compliant
Partially Compliant
Not Compliant

Data is encrypted in transit (HTTPS).

Compliant
Partially Compliant
Not Compliant

Data is encrypted in transit (HTTPS) and at rest.

Restriction of access

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t mention any specific restrictions of access to personal data.

Compliant
Partially Compliant
Not Compliant

A subset of employees has access to the products and to personal data via controlled interfaces. Access is enabled through “just in time” requests for access; all such requests are logged.

Backend production environment is accessible by a dedicated group of Privileged Users approved by senior management. Privileged Users may only access backend production environment via a bastion host (2 factor authentication and SSH to log in).

Reuse of data

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t reuse personal data, nor sell it.

Compliant
Partially Compliant
Not Compliant

Matomo does not pursue its own purposes with this data processing.

Exemption of cookie consent

Compliant
Partially Compliant
Not Compliant

YES, Swetrix analytics script is fully cookieless.

Compliant
Partially Compliant
Not Compliant

YES, if controller disables « cross domain tracking » and « third party cookies » functionalities.

Submission to Cloud Act/FISA

Compliant
Partially Compliant
Not Compliant

NO, data is hashed and not stored on servers more than 30min.

Compliant
Partially Compliant
Not Compliant

NO, when data is stored on controller premise.

NO, if controller enables data anonymization when using the Cloud solution.