Metricward

Legal

Compliance posture

What is actually in place, what backs each claim, and a plainly labelled list of what is not there yet.

Roles under GDPR

You are the controller.

You decide why your visitors are measured, what your privacy notice says, and what legal basis applies. Metricward does not make that decision for you and will not tell you that installing it satisfies it.

Metricward is the processor.

We process visitor data on your instructions, expressed through your project settings. We are a controller only for our own account data, meaning your colleagues' names, emails and billing details, not your visitors'.

The full commitment list and the mechanism behind each one is on the processor terms page. The signable data processing agreement itself is not published, that page says so directly rather than offering a generated document that looks executable.

What is in place

Data residency

Sweden by default for every project, with a second EU country available as an explicit setting for customers with a national preference. This is one deployment of the same stack rather than a per-request routing decision, so it applies for a project's lifetime.

Retention controls

Retention is a per-project setting, enforced by a nightly job rather than a policy nobody runs, and the real computed cutoff is shown in the product rather than only in a document.

Subject access and deletion

A DSAR flow exports or erases everything held for a visitor hash or a user id, then re-counts the affected rows and writes a deletion receipt with a job id, so a customer asking for proof gets one rather than a reassurance.

Subprocessors

Every company that could touch data processed through Metricward is named, with its purpose, its location and whether it is actually wired up yet, on a page that updates itself from the underlying list.

Audit logging

Subject access requests and project setting changes are recorded with the actor and the time, readable in the product. This is enforced at the application layer today, a change that could bypass the logging function and write to the table directly would not be stopped by the database itself yet.

Break-glass and support access

There is currently no supported route for Metricward staff to view a customer's analytics at all. A customer-granted, time-limited support access flow and a break-glass path requiring a second approver are both specified and not built, so today the honest answer is that nobody has a way in, rather than that access is loosely controlled.

Not in place

Being straight about these is the point of this page, not an afterthought at the bottom of it.

  • !No SOC 2 report, Type I or Type II, and no CPA firm has been engaged to produce one.
  • !No ISO 27001 certification.
  • !No external penetration test yet. One is planned before general availability.
  • !No completed, documented risk assessment, distinct from the engineering threat model on the security page.
  • !No written information security policy set, covering acceptable use, access control, incident response and vendor management, approved and communicated to anyone.
  • !No security awareness training programme, so there is no record of anyone having completed one.
  • !No background-check programme for anyone with a path to production access.
  • !No incident response drill has ever happened, because there is no production traffic yet to drill against.
  • !Postgres row-level security is written, migrated and tested against a restricted database role, but the application does not yet connect as that role, so the policies are currently inert in the running system. Until that switch is made, tenant isolation on the control plane rests on application code, not on the database.

None of the above is an oversight we are hoping nobody asks about. A SOC 2 or ISO 27001 report is an opinion issued by an external firm after a real audit, and until one is engaged there is no report to be close to, only engineering readiness. The technical controls listed above are real and would hold up to an auditor's questions; the organisational and infrastructure work that has to exist alongside them has not started yet.

Related: processor terms, subprocessors, data policy, security.

Nothing on this page is legal advice, and it is not a substitute for your own due diligence.

Compliance