atriqo
ProductScannerDemoDocsPricingContactBlog
EN ES
Log in Start for free
atriqo
Product Scanner Demo Docs Pricing Contact Blog
Language
EN ES
Log in Start for free

← Back to Atriqo

Atriqo — Privacy Policy

Last updated: 22 September 2026

1. Who we are

This Privacy Policy is issued by:

Iñigo Larrea Arina, trading as “Atriqo” (a trade name; Atriqo is not a separate legal entity), sole trader/self-employed professional under Spanish law.

  • NIF: 72813588G
  • Address: Calle Monasterio de la Oliva 31, entreplanta, 31011 Pamplona (Navarra), Spain
  • Email: hello@atriqo.com
  • Legal notice: Aviso Legal

Atriqo has not appointed a Data Protection Officer (DPO). Privacy and data-protection enquiries may be sent to hello@atriqo.com or to the postal address above.

2. Scope and our different roles

Atriqo provides a web-analytics service to businesses and professionals. Our role depends on whose data is being processed and why.

2.1 Visitors to a Customer’s website

If you visit a website operated by an Atriqo Customer and that website uses Atriqo analytics, the Customer normally determines the purposes and essential means of that analytics processing and acts as controller. Atriqo processes the analytics data on the Customer’s behalf as processor, under our Data Processing Agreement (DPA).

If the Customer itself acts as processor for another controller, Atriqo acts as subprocessor as described in the DPA.

For this processing, the Customer’s own privacy notice is the primary source of information about why the website uses analytics and the lawful basis relied on. Atriqo does not choose or guarantee the Customer’s lawful basis.

2.2 Visitors to atriqo.com and Atriqo account users

When you visit atriqo.com, create or use an Atriqo account, contact us, request a scanner result, or purchase the Service, Atriqo may act as controller for the personal data needed for those purposes. The sections below describe those controller activities.

3. Analytics data processed for Atriqo Customers

When a Customer website has installed the Atriqo tracker, Atriqo may process the following on that Customer’s behalf:

Data How it is handled
Pseudonymous visitor identifier (visitor_hash) Derived server-side using an HMAC based on a secret, the visitor IP address, User-Agent information and a daily salt. The salt changes daily. The identifier is treated as personal data, not anonymous data.
Raw IP address Used transiently to derive the pseudonymous identifier and country-level location, then discarded immediately. Atriqo does not store raw visitor IP addresses in analytics records.
Session identifier (session_hash) Derived from the visitor identifier and session logic. It is not stored in a browser cookie.
Page and event information URL/path information after the Service’s configured scrubbing rules, referrer information, UTM/campaign parameters, screen width, language, browser, operating system, device type, country and supported event metadata.
Custom events Event names and properties selected and sent by the Customer. Customers are instructed not to send special-category data, criminal-offence data or other unnecessary personal data.

Country-level geolocation uses a locally installed MaxMind database. Visitor IP addresses are not sent to MaxMind for these lookups.

The Atriqo tracker does not use cookies to identify visitors, does not track visitors across unrelated Customer sites and does not use device-fingerprinting techniques to re-identify visitors after the daily identifier changes.

Cookie-free does not necessarily mean outside ePrivacy rules. The tracker receives or derives information such as User-Agent/browser/device information, language and screen information, and applicable law may treat collection of terminal information as storage/access to terminal equipment even where no cookie is set. Whether prior terminal-device consent is required, or an audience-measurement or other exemption applies, depends on the Customer’s configuration and applicable law.

Atriqo applies technical scrubbing intended to reduce accidental personal data in URLs and diagnostics, but no automated classifier can guarantee that Customers will never send additional personal data. Customers remain responsible for the content they configure and transmit.

4. Analytics on Atriqo’s own website

Atriqo uses its own cookieless analytics on atriqo.com to understand aggregate website usage, diagnose the performance of our public website and improve how information about the Service is presented.

For this activity, Atriqo is the controller. The technical data processed is substantially the same privacy-minimised data described in Section 3: a daily-changing pseudonymous identifier, page/event metadata and country-level location; the raw IP address is used transiently and discarded after the privacy identifier and country are derived.

For GDPR purposes, Atriqo relies on its legitimate interest under Article 6(1)(f) GDPR in measuring and improving its own business website using a minimised analytics design. You may object to this processing as described in Section 12. That GDPR legal basis does not replace any separate ePrivacy/terminal-access requirement. We are migrating this measurement to a mode that retains only aggregated statistics.

Atriqo’s own website analytics are configured for a maximum retention of 24 months, unless a shorter period is used. This retention period alone does not establish that an ePrivacy audience-measurement exemption applies.

5. Account, contracting and support data

If you register for or use Atriqo, we may process:

  • Email address and account identity data, used for account creation, passwordless login, service notices and support.
  • Account and site configuration, such as registered domains, display names, time zone, plan, quota and settings.
  • Authentication and security data, such as hashed session identifiers, one-time login challenges, rate-limit information and technical audit records.
  • Billing and subscription information, including plan, billing status, invoice-related information and payment-provider references. Atriqo does not store full payment-card numbers.
  • Support and business communications, including information you send to hello@atriqo.com.
  • Scanner/lead information, where you voluntarily provide contact information to receive a requested scanner result or separately opt in to marketing communications.

We normally receive this information directly from you, from the organisation you represent, from your use of the Service, or from service providers such as Stripe where needed to administer payment and subscriptions.

6. Purposes and legal bases when Atriqo is controller

6. Purposes and legal bases when Atriqo is controller
Purpose Legal basis
Create and administer an account for an individual professional contracting in their own name Article 6(1)(b) GDPR — performance of a contract or steps requested before entering into it
Administer accounts and business contacts of a company or other organisation Article 6(1)(f) GDPR — Atriqo’s and the Customer’s legitimate interests in administering the business relationship and authorised access to the Service
Provide authentication, prevent abuse and secure accounts and infrastructure Article 6(1)(f) GDPR — legitimate interests in security, fraud prevention and service integrity
Process subscriptions, payments, invoicing and accounting Article 6(1)(b) GDPR where necessary for a contract with the individual Customer; Article 6(1)(c) GDPR for legal tax/accounting obligations; and Article 6(1)(f) GDPR where necessary to administer a business Customer relationship
Respond to support and service communications Article 6(1)(b) GDPR where necessary to perform a contract, and/or Article 6(1)(f) GDPR for business relationship management and support
Measure use of atriqo.com using Atriqo’s own cookieless analytics Article 6(1)(f) GDPR — legitimate interests described in Section 4, without prejudice to any separate ePrivacy consent/exemption requirement
Send a scanner result or respond to a requested pre-contract/business enquiry Article 6(1)(b) GDPR where the request is a step taken at the individual’s request before contracting, and/or Article 6(1)(f) GDPR for proportionate B2B enquiry handling
Send marketing communications where you have expressly opted in Article 6(1)(a) GDPR — consent. You may withdraw consent at any time, and every marketing email must provide a simple means to stop marketing
Establish, exercise or defend legal claims and maintain accountability/security records Article 6(1)(f) GDPR and, where applicable, Article 6(1)(c) GDPR

Where Atriqo relies on legitimate interests, the processing is limited to what Atriqo considers necessary and proportionate for the stated purpose. You have the right to object under Article 21 GDPR, subject to the conditions of that Article.

7. Customer lawful bases for analytics are not determined by Atriqo

For analytics processed on a Customer’s behalf, the Customer determines the applicable GDPR lawful basis. Depending on the Customer’s circumstances, this may be legitimate interests or another lawful basis available under applicable law.

The fact that Atriqo does not set visitor-identification cookies does not by itself determine the Customer’s GDPR lawful basis or eliminate separate ePrivacy/terminal-access duties. In particular, audience-measurement exemptions are conditional and can depend on purpose, data fields, retention, aggregation, reuse and the Customer’s configuration. Atriqo does not represent that every plan or configuration qualifies for such an exemption. Customers remain responsible for their own assessment, privacy notice and any consent requirements that apply to their use case.

8. Data minimisation and accidental personal data

Atriqo’s analytics is designed to minimise personal data. In particular:

  • raw visitor IP addresses are discarded after transient processing;
  • URL query-string handling is restricted and unnecessary values are removed under the Service’s scrubbing rules;
  • technical filtering is used to reduce common personal-data patterns in fields where such filtering is supported; and
  • Sentry diagnostics are filtered before transmission to remove cookies, authorisation headers and URL query strings and to redact tokens embedded in paths.

These controls reduce risk but do not guarantee that Customers cannot send personal data in custom event properties, paths, referrers or other fields. Customers must avoid sending personal data that is unnecessary or that they are not authorised to process.

9. Retention

9.1 Customer analytics data

Analytics events processed for Customers are retained according to the selected plan unless the Customer configures a shorter period:

Plan Maximum standard analytics retention
Free / Starter 24 months
Growth 36 months
Business 60 months

When a paid subscription lapses but the account remains open, it may move to the free plan and the applicable retention horizon changes accordingly. Termination, return, deletion and residual backup copies are governed by the DPA.

Customers can export analytics events in CSV on all plans and JSON on Growth and higher plans. The standard export excludes certain service-internal pseudonymous and technical identifiers. Where the DPA requires return of remaining Customer Personal Data on termination, the DPA governs that supplementary process.

9.2 Account and authentication data

  • login codes/challenges expire after approximately 15 minutes and are intended to be single-use;
  • Atriqo uses a session token to maintain authenticated access to the dashboard. By default, the session cookie is a browser-session cookie. If the user expressly selects “Keep me signed in for 30 days”, the cookie becomes persistent for 30 days from login, without automatic extension through use;
  • incomplete signup attempts with no continuing account relationship are deleted after approximately 30 days;
  • account configuration is kept while the account is active and afterwards only for as long as necessary for account closure, legal obligations, dispute handling, security and the establishment, exercise or defence of legal claims;
  • billing, tax and accounting records are retained for the periods required by applicable law; and
  • product/security audit-trail records may be retained for up to 7 years for security, accountability and dispute-management purposes.

9.3 Diagnostics and support

Ordinary Sentry error events are currently subject to the retention configured for Atriqo’s plan, generally 30 days for ordinary free-plan events; events ingested under a trial may have a longer provider-assigned period, up to 90 days. Residual provider backups may follow a separate deletion cycle. Atriqo applies the deletion obligations described in the DPA where diagnostics contain Customer Personal Data.

Support communications are retained for as long as reasonably necessary to handle the request and business relationship and, where needed, to establish, exercise or defend legal claims.

10. Service providers and recipients

Atriqo uses a limited number of service providers. Their role depends on the relevant processing:

  • Hetzner Online GmbH — hosting and storage in Falkenstein, Germany.
  • OVH HISPANO S.L.U. / OVHcloud — encrypted backup storage in Paris, France (EU-WEST-PAR).
  • Functional Software, Inc. (Sentry) — error diagnostics for the dashboard and analytics collection service, using Sentry’s EU region; filtered diagnostic data may still contain incidental personal data.
  • Scaleway SAS (Paris, France) — delivery of transactional emails: login codes and links, requested scanner reports and, for Customers who subscribe, analytics report emails.
  • Brevo / Sendinblue SAS (France) — storage of the contact details of people who opt in to communications in the scanner. Atriqo does not use Brevo to send email.
  • Stripe Payments Europe, Limited — payment and subscription processing. Stripe may process some information under its own legal obligations and privacy terms as well as provide payment-related services to Atriqo.
  • Cloudflare, Inc. — authoritative DNS only. Atriqo does not use Cloudflare’s HTTP reverse proxy or CDN for analytics traffic under the current configuration.

MaxMind is not used as a remote processor for visitor geolocation: Atriqo downloads and queries the relevant database locally and does not send visitor IP addresses to MaxMind for the lookup.

Atriqo may also disclose information where required by law, to establish or defend legal claims, or in connection with a permitted transfer of the business subject to applicable data-protection requirements.

11. International transfers

Atriqo’s primary analytics infrastructure and operational backup storage described above are located in the European Union. Some providers, notably Sentry and Cloudflare, are established in or may involve processing chains that include the United States or other countries outside the EEA even where EU-region storage is used.

Where Chapter V GDPR applies to a transfer, Atriqo uses an applicable lawful transfer mechanism. Depending on the recipient and transfer, this may include an applicable adequacy decision such as the EU–US Data Privacy Framework while it validly covers the recipient and data, or appropriate safeguards under Article 46 GDPR such as the European Commission’s Standard Contractual Clauses together with any required assessment and supplementary measures.

You may request further information about safeguards relevant to Atriqo’s own controller processing by contacting hello@atriqo.com. Transfers involving Customer Personal Data processed on behalf of Customers are described in more detail in the DPA.

12. Your rights when Atriqo is controller

Subject to the conditions and limits in the GDPR, you may have the right to:

  • access your personal data;
  • rectify inaccurate personal data;
  • request erasure;
  • request restriction of processing;
  • receive personal data in a portable format where Article 20 GDPR applies;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent, without affecting processing already lawfully carried out; and
  • lodge a complaint with a competent supervisory authority.

Atriqo does not make decisions about account users based solely on automated processing that produce legal effects or similarly significant effects within Article 22 GDPR.

To exercise rights concerning processing for which Atriqo is controller, contact:

Email: hello@atriqo.com
Postal address: Calle Monasterio de la Oliva 31, entreplanta, 31011 Pamplona (Navarra), Spain

We may request information reasonably necessary to verify identity and the scope of the request. We will respond within the periods required by the GDPR.

You may complain to the Agencia Española de Protección de Datos (AEPD) or another supervisory authority competent under Article 77 GDPR, including in the Member State of your habitual residence, place of work or the place of the alleged infringement.

13. Requests concerning a Customer’s website analytics

If your request concerns analytics collected through a Customer’s website, that Customer is normally the controller and should be your primary contact.

If you send such a request to Atriqo, we will not independently decide the outcome on the Customer’s behalf. We will route or assist with the request as appropriate under the DPA, taking account of the pseudonymous nature of the data and the information available to identify the relevant records.

14. Children

Atriqo accounts are offered only to business/professional users who are at least 18 years old. We do not knowingly permit minors to create Atriqo Customer accounts.

Atriqo’s analytics technology may technically receive pseudonymous analytics events when a minor visits a Customer website or atriqo.com. For Customer websites, the Customer remains responsible for determining whether its audience includes children and for meeting any additional legal requirements that apply to that processing.

15. Security

Atriqo applies technical and organisational measures proportionate to the processing and risk. Current measures include, among other things:

  • HTTPS/TLS for analytics endpoints and the Customer dashboard;
  • restricted administrative and database access;
  • key-based SSH administration over a private network rather than a publicly exposed administration port;
  • HMAC-based pseudonymisation with a daily-changing salt for visitor analytics;
  • encrypted backup archives before transfer to external backup repositories;
  • two operational external backup repositories in the EU under the current architecture;
  • documented recovery procedures and a completed full restoration test; and
  • diagnostic filtering before data is sent to Sentry.

Security measures evolve over time. The DPA contains the more detailed contractual description applicable to Customer Personal Data.

16. Cookies and similar technologies

The Atriqo tracker does not set cookies and does not write information to localStorage, sessionStorage or IndexedDB. It only reads the atriqo_opt_out key from localStorage to determine whether the user has chosen to opt out of analytics. If that key exists, the tracker stops collection and sends no analytics events. This read is used exclusively to honour the user's opt-out choice and is not used to identify the user, measure their activity or build profiles. It can nevertheless receive or derive terminal information, so the absence of cookies is not a statement that ePrivacy consent is never required. The Atriqo dashboard uses authentication/access cookies described in the Cookie Policy; by default they last only for the browser session.

17. Email tracking

Atriqo sends its transactional emails through Scaleway. Atriqo does not enable or use open or click tracking in these emails: they contain no tracking pixel, and their links point directly to Atriqo.

18. Changes to this Policy

Atriqo may update this Privacy Policy to reflect changes in the Service, providers, legal requirements or processing practices. The current version and its “Last updated” date will be published on this page.

Where a change materially affects how Atriqo processes account-holder or other personal data as controller, Atriqo may provide additional notice by email or through the Service where appropriate. Changes to contractual processor obligations are governed by the DPA rather than by unilateral amendment of this Privacy Policy.

19. Contact

Privacy questions and requests: hello@atriqo.com.

Postal address: Calle Monasterio de la Oliva 31, entreplanta, 31011 Pamplona (Navarra), Spain.

atriqo

Privacy-first web analytics, hosted in the EU. No cookies, no cross-site tracking, no fingerprinting.

Product

  • Product
  • Pricing
  • Demo
  • Cookie scanner
  • Docs

Legal

  • Privacy Policy
  • Terms of Service
  • DPA
  • Cookie Policy
  • Legal Notice

Connect

  • hello@atriqo.com
  • X · @larreaio
  • LinkedIn

Built in the EU. Privacy-first analytics — no cookies, no cross-site tracking, no fingerprinting.

© 2026 Atriqo