Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Matomo

VERIFIED
Web analytics · New Zealand
Founded 2007 · matomo.org ↗

Open-source web analytics (NZ-incorporated InnoCraft) with EU-hosted Matomo Cloud on AWS and full self-hosted option.

Why this score?

Open-source veteran with ISO 27001:2022 and customer Cloud data 100% stored in Europe, but the controlling legal entity is InnoCraft Limited in New Zealand and Matomo Cloud runs on AWS — meaning customer data at rest sits with a US-owned hyperscaler in the EU region; NZ holds an EU adequacy decision so transfers are legal, but the AWS dependency caps the score at 3/5 for procurement-grade buyers despite the strong open-source / on-premise alternative.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Matomo

Matomo (formerly Piwik, renamed in 2018) is a long-running open-source web analytics platform operated by InnoCraft Limited, a New Zealand company at 7 Waterloo Quay, Wellington (NZBN 6106769). It is one of the only Schrems-friendly Google Analytics alternatives that ships in two clearly separated forms: Matomo On-Premise — fully free and self-hostable on the customer's own infrastructure with unlimited hits, websites, and team members — and Matomo Cloud, the managed SaaS offering. The product reports more than one million tracked websites across 190+ countries, including the European Commission and the United Nations. For EU buyers the operational story has two sides. On the positive side: the company is ISO 27001:2022 certified, the privacy policy is public, the GDPR Manager built into Matomo helps with Art. 30 records and consent capture, and Matomo Cloud commits that 100% of customer Cloud data and backups are stored in Europe rather than in the US. On the strict-CLOUD-Act side: InnoCraft is New Zealand–incorporated (NZ has an EU adequacy decision, so transfers are legally clean), and Matomo Cloud is operated on Amazon Web Services — meaning customer analytics data at rest sits with a US-owned hyperscaler even when the AWS region is European. Per our parent-jurisdiction stance (Schrems II, Microsoft Ireland v US), this counts as material CLOUD Act exposure regardless of region; the score therefore caps at 3/5 for the Cloud product. Buyers who self-host the on-premise edition on EU infrastructure (e.g. Hetzner) sidestep this entirely. Pricing for Matomo Cloud Business starts at €29/month (€348/year, 50,000 hits/month, 30 sites, 30 users) with a 21-day free trial. Anthropic Claude and OpenAI are used to analyse aggregated, non-PII Matomo data for product features; Cognism is used for B2B marketing data enrichment on the matomo.org site. Best fit: organisations who want a long-running open-source GA alternative with a credible European-data-residency Cloud offering, or who can run the open-source build on their own infrastructure for a 5/5-equivalent posture.
SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
from €29/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    matomo.org/privacy-policy…
    Open ↗
  • Terms of Service
    matomo.org/terms…
    Open ↗
ALTERNATIVES

Alternatives in this category