shll's comments

shll | 2 years ago | on: Show HN: Google Analytics alternative with the most generous free tier

Yes, you are right that there is another part of the definition about large scale, regular and "systematic monitoring" of individuals. Apologies for not including that in the answer above.

Quoting from WP 243 Annex provided by the EU:

"The notion of regular and systematic monitoring of data subjects is not defined in the GDPR, but clearly includes all forms of tracking and profiling on the internet, including for the purposes of behavioural advertising. However, the notion of monitoring is not restricted to the online environment."

The link is here

https://ec.europa.eu/information_society/newsroom/image/docu...

We anonymize and aggregate all data so can't track or profile any users, or do such monitoring offline.

shll | 2 years ago | on: Show HN: Google Analytics alternative with the most generous free tier

Thank you for your follow up.

1. Glad we're in agreement!

2. We agree it is not GDPR compliant to transmit IP address data to the US. This is why we salt and hash all PII data so no IP address data is sent to the US. Please see our data policy.

https://beamanalytics.io/data

3. Thank you for your suggestion. We have already consulted privacy professionals and have been assured no DPO is required.

Thank you for this conversation about GDPR. We appreciate your interest in Beam's work.

shll | 3 years ago | on: Show HN: Google Analytics alternative with the most generous free tier

Hi - this is the other co-founder of Beam. Thank you for your comments and questions.

1. We are incorporated in the UK. I could be wrong but I think the European Commission did indicate that the UK was an Adequate Country?

https://commission.europa.eu/law/law-topic/data-protection/i...

2. For the details that our privacy policy lacks, I think they can be found in our Data Policy. Any further issues, please let us know.

https://beamanalytics.io/data

3. On the Data Protection Officer, I think one is only needed if sensitive data on a large scale is processed.

https://commission.europa.eu/law/law-topic/data-protection/r...

The definition of sensitive data can be found on this EU site and Beam does not process any of this type of data.

https://commission.europa.eu/law/law-topic/data-protection/r...

page 1