Trust
Security, hosting, and GDPR compliance
HeyMetrix is developed in Germany by Franco Consulting GmbH and hosted in EU data centers (Hetzner, Germany). It is fully GDPR compliant, accesses ad platforms exclusively through revocable OAuth connections, and never places tags or scripts on your or your clients' websites.
Agencies handle client data, so where a tool runs and what it can touch is a due-diligence question, not a footnote. Here are the facts.
- Hosted at Hetzner, Germany (EU)
- GDPR / DSGVO compliant
- OAuth-only, revocable anytime
- No tags or scripts on client sites
Last updated:
Where does HeyMetrix run and store data?
The entire platform (application, API, databases, and file storage) runs in EU data centers operated by Hetzner in Germany. There is no data processing in non-EU regions for the core product. Development and operations sit with Franco Consulting GmbH in Burgau, Germany.
What access does HeyMetrix get to ad accounts?
All platform connections are OAuth-based: you (or your client) authorize Google Ads, Meta Ads, Google Analytics 4, or Trello through the platform's own consent screen. HeyMetrix never sees passwords, and there are no tags, pixels, or scripts to install anywhere.
- Access is scoped to what the integration needs; Trello, for example, is connected read-only.
- Connections can be revoked anytime, on the platform side or in HeyMetrix; reconnect flows handle restored access.
- Connected accounts can be scheduled for deletion, removing their synced data.
How is client access separated?
External viewers (your clients) get their own account type with read-only access limited to exactly the resources shared with them: filtered fields, no ad-account access, no visibility into other clients. Internally, roles (Owner, Admin, Editor, Viewer) apply per organization and per resource, so every project, report, and portal has its own access list.
What do the AI agents do with my data?
Agents read the data you can see (project metrics, campaign drafts, reports) to do their work, and they ground every number in the platform APIs rather than generating it. Agent actions are approval-first and logged; automation executions record pre- and post-state per platform mutation. Agent memory is stored per project within your organization.
Which third-party services are involved?
Transactional email is delivered via Mailgun; product analytics run on PostHog; consent management on the marketing site uses Usercentrics. The authoritative, always-current list of processors and legal bases lives in the privacy policy.
A note on certifications
HeyMetrix is in early access and does not yet hold formal certifications like ISO 27001 or SOC 2. The statements on this page describe the actual architecture; for contractual details (DPA/AVV), contact us.
Frequently asked questions about security & GDPR
Is HeyMetrix GDPR compliant?
Yes. HeyMetrix is developed in Germany, hosted exclusively in EU data centers (Hetzner), and built for GDPR/DSGVO compliance, including viewer access separation and revocable OAuth connections.
Does HeyMetrix require scripts or tags on my clients' websites?
No. All data comes through the official platform APIs via OAuth. There is nothing to install on any website.
Can I get a data processing agreement (DPA/AVV)?
Yes. Contact us and we'll provide the current data processing agreement as part of early access onboarding.
What happens to synced data when I disconnect an account?
Connections can be revoked anytime, and connected accounts can be scheduled for deletion, which removes their synced data from HeyMetrix.
Where can I read the full privacy details?
In the privacy policy on this site. It lists all processors, legal bases, and data categories, and is kept current as the authoritative document.
Questions your DPO wants answered?
Get early access and we'll walk through data handling and the DPA together.
Get Early Access