Zum Inhalt springen
Unabhängig verifiziert · Quartalsweises Re-Audit
EU VETTED

Matomo

VERIFIZIERT
Web-Analyse · New Zealand
Gegründet 2007 · matomo.org ↗

Open-source web analytics (NZ-incorporated InnoCraft) with EU-hosted Matomo Cloud on AWS and full self-hosted option.

Kurzfassung

Matomo aus der Kategorie Web-Analyse bietet EU-Hosting mit Germany als Hosting-Standort, doch ein US-Mutterkonzern oder Unterauftragsverarbeiter hinterlässt ein materielles CLOUD-Act-Risiko.

Bewertungsnotizen

Open-source veteran with ISO 27001:2022 and customer Cloud data 100% stored in Europe, but the controlling legal entity is InnoCraft Limited in New Zealand and Matomo Cloud runs on AWS — meaning customer data at rest sits with a US-owned hyperscaler in the EU region; NZ holds an EU adequacy decision so transfers are legally clean, but the AWS dependency is material CLOUD Act exposure for procurement-grade buyers despite the strong open-source / on-premise alternative.

CLOUD ACT
OWNERSHIP
SUB-PROCS
3 · 1 US
CLOUD Act je nach Betrieb

Die Exposition hängt davon ab, wie Sie dieses Produkt betreiben.

Gehostetes SaaS (Standard)

Anbieterbetrieben — die unten genannten Unterauftragsverarbeiter gelten.

Selbst gehostet (Open Source)

Auf eigener EU-Infrastruktur betreiben — Sie kontrollieren Hosting und jeden Unterauftragsverarbeiter.

Geprüfte Signale
Jurisdiktion
  • EU-/Angemessenheits-Hosting
  • EU-/Angemessenheits-Betreiber
  • Keine US-CLOUD-Act-Exposition
Transparenz
  • Öffentlicher AVV
  • Unterauftragsverarbeiter offengelegt
  • Open-Source-Clients
  • Zertifizierung durch Dritte
JUMP TO
OVERVIEW

Über Matomo

Matomo (formerly Piwik, renamed in 2018) is a long-running open-source web analytics platform operated by InnoCraft Limited, a New Zealand company at 7 Waterloo Quay, Wellington (NZBN 6106769). It is one of the only Schrems-friendly Google Analytics alternatives that ships in two clearly separated forms: Matomo On-Premise — fully free and self-hostable on the customer's own infrastructure with unlimited hits, websites, and team members — and Matomo Cloud, the managed SaaS offering. The product reports more than one million tracked websites across 190+ countries, including the European Commission and the United Nations.

For EU buyers the operational story has two sides. On the positive side: the company is ISO 27001:2022 certified, the privacy policy is public, the GDPR Manager built into Matomo helps with Art. 30 records and consent capture, and Matomo Cloud commits that 100% of customer Cloud data and backups are stored in Europe rather than in the US. On the strict-CLOUD-Act side: InnoCraft is New Zealand–incorporated (NZ has an EU adequacy decision, so transfers are legally clean), and Matomo Cloud is operated on Amazon Web Services — meaning customer analytics data at rest sits with a US-owned hyperscaler even when the AWS region is European. Per our parent-jurisdiction stance (Schrems II, Microsoft Ireland v US), this counts as material CLOUD Act exposure regardless of region for the Cloud product. Buyers who self-host the on-premise edition on EU infrastructure (e.g. Hetzner) sidestep this entirely.

Pricing for Matomo Cloud Business starts at €29/month (€348/year, 50,000 hits/month, 30 sites, 30 users) with a 21-day free trial. Anthropic Claude and OpenAI are used to analyse aggregated, non-PII Matomo data for product features; Cognism is used for B2B marketing data enrichment on the matomo.org site. Best fit: organisations who want a long-running open-source GA alternative with a credible European-data-residency Cloud offering, or who can run the open-source build on their own EU-hosted infrastructure for a fully sovereign posture with no CLOUD Act exposure.

SUB-PROCESSORS

Unterauftragsverarbeiter-Karte · 3

Quelle ↗
  • Amazon Web Services EMEA SARL US
    Luxembourg

    Hosting (servers, databases, logs; Frankfurt with Dublin backups) and CDN for JavaScript files

  • Oblivion Cloud Control B.V. (Xebia Group B.V.) EU
    Netherlands

    AWS solution provider: infrastructure management, IT consulting and support

  • Tideways GmbH EU
    Germany

    Application performance monitoring (APM)

1 von 3 Unterauftragsverarbeitern sind in den USA registriert. CLOUD-Act-Risiko anwendbar.
CERTIFICATIONS

Rahmenwerke & Zertifizierungen

ISO/IEC 27001
AKTIV
FEATURES

Funktionsmatrix

Cookielos Ja
Self-Hosting Ja
Eigene Events Ja
Funnels Ja
Session-Replay Ja
GA-Import Ja
Statistik-API Ja
INTEGRATION & ZUGRIFF
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Preise & Tarife

FREEMIUM
ab €29/Monat
Preisseite ansehen ↗
PUBLIC DOCUMENTS

Öffentliche Dokumente

  • Auftragsverarbeitungsvertrag (AVV)
    matomo.org/matomo-cloud-dpa…
    Öffnen ↗
  • Liste der Unterauftragsverarbeiter
    matomo.org/privacy-policy…
    Öffnen ↗
  • Nutzungsbedingungen
    matomo.org/terms…
    Öffnen ↗
ALTERNATIVES

Alternativen in dieser Kategorie

GoatCounter
Ireland · Gegründet 2019
EU-SOUVERäN

Solo-developer open-source web analytics on Hetzner DE/FI; no IP storage, no trackers, free for personal use, MIT-style source on GitHub.

Öffentl. AVV Subprozessoren Open Source
FROM
CLOUD ACT
NONE
Pirsch Analytics
Germany · Gegründet 2020
EU-SOUVERäN

German cookieless server-side web analytics on Hetzner Gunzenhausen with bilingual public DPA and Schrems II-aligned posture.

Öffentl. AVV Subprozessoren Open Source
FROM
€6/Mt.
CLOUD ACT
NONE
Plausible Analytics
Estonia · Gegründet 2018
EU-SOUVERäN

Estonian-incorporated privacy-first Google Analytics alternative, bootstrapped, hosted on Hetzner Falkenstein, open source.

Öffentl. AVV Subprozessoren Open Source
FROM
€8/Mt.
CLOUD ACT
NONE