Glyphex
Partially CompliantFinnish cookieless analytics on a sub-1KB script, hosted on Hetzner in Germany. No DPA is published, which is a problem for hosted use.

GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | Finland |
| Ownership | European-owned |
| Foreign Disclosure Exposure | Not yet verified |
| Data Hosting Location | European UnionāAll data is stored on servers in the European Union. We use: Hetzner Cloud (Germany) for database storage and application hosting. No data transfers to non-EU countries.ā |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | Low Risk |
| SCCs in Place | |
| Notes | Finnish origin is recorded on the information of this directory's owner, not from vendor documents: Glyphex publishes no imprint, legal entity, company registration or terms of service, and its footer reads only 'Ā© 2026 glyphex'. Treat ownership as attested rather than evidenced until an imprint appears. The technical privacy design is documented at /docs/privacy and is genuinely strong: no cookies, IP addresses used for geo-lookup then discarded, visitors counted via a SHA-256 hash of IP and User-Agent with a salt that rotates every 24 hours, and 'All data is stored on servers in the European Union ... Hetzner Cloud (Germany) ... No data transfers to non-EU countries'. What does not exist is a Data Processing Agreement. Whether that is a problem depends on a contested question: Glyphex's position is that it processes no personal data at all, and if that holds then it is not a processor, GDPR does not engage and no DPA is required. Plausible Analytics takes the same position and some supervisory authorities have accepted it. The opposing reading is that a salted hash of IP and User-Agent remains pseudonymised personal data, in which case Article 28(3) requires a written contract and none is available. That page is documentation rather than a legal document: it names no controller, no retention period, no sub-processors, no security measures, no breach procedure and no data subject rights process. Practically, many procurement and DPO processes require a signed DPA regardless of the legal argument, so buyers who need one should ask before committing. Recorded as PARTIAL to reflect the unresolved position, not as a compliance failure. |
About Glyphex
Glyphex is a lightweight cookieless analytics tool built as a direct Google Analytics replacement, with a tracking script under 1 KB and no consent banner required. It identifies visitors by hashing IP and User-Agent with a daily-rotating salt, so nothing persistent is stored, and it reports traffic arriving from AI assistants. Data is stored on Hetzner Cloud in Germany.
Key Features
Pros & Cons
Categories
Glyphex GDPR & data protection: common questions
Is Glyphex GDPR compliant?
Partly. Glyphex meets some of the requirements, with caveats worth reading before you commit. Glyphex is a European company headquartered in Finland, data is hosted within the European Union.
Where does Glyphex store data?
Glyphex states: "All data is stored on servers in the European Union. We use: Hetzner Cloud (Germany) for database storage and application hosting. No data transfers to non-EU countries.". Data is hosted within the European Union.
Does Glyphex offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for Glyphex. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover āIs Glyphex a European company?
Yes. Glyphex is headquartered in Finland and, as far as we can establish, European-owned.
Related Tools

Plausible Analytics
Lightweight, open-source, cookie-free web analytics. Fully GDPR compliant with EU data hosting.

Matomo
Leading open-source web analytics. Self-host in the EU or use cloud with EU hosting.

Mouseflow
Heatmaps, session replay, and behavior analytics. Danish company with EU-only data processing.
Spot an error in the compliance data? Get in touch