GDPR
Last updated June 20, 2026
OceanWave Analytics is privacy-first and cookieless, which makes GDPR compliance dramatically simpler. Here’s how we approach it.
Our GDPR commitment
OceanWave Analytics is designed to be GDPR-friendly out of the box. Because we are cookieless and do not collect personal data from your visitors, using OceanWave Analytics helps you stay compliant without the usual friction. This page explains our approach; it is provided for transparency and is not legal advice.
No cookie banner required
Our analytics script does not store or read cookies or other identifiers on a visitor’s device, and it does not collect personal data. As a result, in most cases you do not need a cookie consent banner to run OceanWave Analytics on your site. You remain responsible for your own overall compliance.
What we don’t collect
- No cookies and no persistent device identifiers.
- No names, emails, or other personal data about your visitors.
- No cross-site or cross-device tracking, and no fingerprinting.
- IP addresses are used transiently to derive country and are never stored.
Controller and processor roles
For the visitor analytics collected on your website, you are the data controller and we act as your data processor, processing data only on your instructions. For your own OceanWave Analytics account information (e.g. your email), we are the controller.
Lawful basis
Because our analytics are anonymous and aggregated, they generally fall outside the scope of personal-data processing. Where any limited processing applies, it is based on legitimate interests in understanding website performance in a privacy-preserving way.
Data subject rights
Data subjects have the rights to access, rectification, erasure, restriction, portability, and objection under the GDPR. Because we do not hold identifiable visitor data, most requests relate to OceanWave Analytics account holders. Email us to exercise any right and we will respond within one month.
Data Processing Agreement (DPA)
We make a Data Processing Agreement available to customers who need one. Contact us and we will provide our DPA for signature.
International transfers and sub-processors
Where data is processed outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses. We use a limited set of sub-processors — Supabase (database, authentication and email), Polar (billing) and Vercel (hosting) — each bound by data-protection terms; a current list is available on request.
Data breach
We maintain procedures to detect and respond to security incidents and will notify affected customers and authorities without undue delay where required by law.
© 2026 All rights reserved.
