Privacy and GDPR
Why the default measurement needs no consent banner, and what still falls to you.
The measurement model is the compliance story: there is nothing to consent to because nothing is stored on the visitor’s device and nothing identifies them.
How a visitor is counted
Anonymous visitors are identified by a daily rotating fingerprint, computed on our servers from a global salt, a per-site salt, the day, the IP and the user agent.
- No cookie is read or written, and nothing is stored on the visitor’s device — so the consent requirement for terminal access does not apply.
- The IP is used to compute the hash and is never stored.
- The fingerprint rotates daily and is salted per site: no tracking across days, no correlation across sites, no way for us to re-identify anyone.
- What comes out is aggregated audience statistics and nothing else.
This matches the criteria French regulators apply to consent-exempt audience measurement: strictly necessary, no cross-site tracking, no resale, bounded retention.
Who is responsible for what
| Party | Role | Why |
|---|---|---|
| Your site | Controller | You decide to measure your audience, and for what purpose |
| causalIT | Processor | We process measurement data on your behalf, on your instructions |
What you still need to do
- Mention audience measurement by causalIT in your privacy policy, along with the cookieless model and your retention setting. No consent banner is required for the default measurement.
- Sign the data processing agreement — a written contract is required, not optional.
- If you use identified mode, establish a legal basis, tell your users, and handle their objections.
- If you load third-party services of your own — ads, embeds, other trackers — collecting consent for those remains yours. Our banner is a tool, not a transfer of liability.
Retention and erasure
Retention is configurable per site within your plan’s bounds, with a global ceiling as a backstop, and purges run automatically. Deleting a site purges its events. In identified mode, per-user deletion is supported.