Matomo
VERIFIEDOpen-source web analytics (NZ-incorporated InnoCraft) with EU-hosted Matomo Cloud on AWS and full self-hosted option.
Why this score?
Open-source veteran with ISO 27001:2022 and customer Cloud data 100% stored in Europe, but the controlling legal entity is InnoCraft Limited in New Zealand and Matomo Cloud runs on AWS — meaning customer data at rest sits with a US-owned hyperscaler in the EU region; NZ holds an EU adequacy decision so transfers are legal, but the AWS dependency caps the score at 3/5 for procurement-grade buyers despite the strong open-source / on-premise alternative.
- SCORE
- 3.0/5
- CLOUD ACT
- CLOUD ACT EXPOSURE
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- OWNERSHIP
- OWNERSHIP
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
US-owned US-headquartered, or has a US parent company.
-
Other This listing Swiss, UK or another non-EU jurisdiction.
-
- SUB-PROCS
- 0 none disclosed
JUMP TO
About Matomo
Sub-processor map · none disclosed
Frameworks & certifications
Capability matrix
Pricing & tiers
Public documents
Alternatives in this category
Estonian-incorporated privacy-first Google Analytics alternative, bootstrapped, hosted on Hetzner Falkenstein, open source.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Solo-developer open-source web analytics on Hetzner DE/FI; no IP storage, no trackers, free for personal use, MIT-style source on GitHub.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
German cookieless server-side web analytics on Hetzner Gunzenhausen with bilingual public DPA and Schrems II-aligned posture.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.