No raw visitor IP storage, no cookie-based Web identity and no cross-customer visitor profile.
Trust / regional readiness
Privacy controls that travel across borders.
Privacy law is regional; good data practice is portable. Abnio reduces the personal data required for useful analytics, documents the processing path and is being designed for explicit regional deployment—not a single global data bucket.
Built around durable privacy principles.
Major privacy frameworks differ in scope and obligations, but commonly value transparency, purpose limitation, data minimization, storage limitation, security and accountability. Abnio’s product choices support those principles while leaving legal-basis and notice decisions with the customer.
Customer analytics is processed to deliver the service—not sold or reused for third-party advertising.
The UA-free browser beacon and User-Agent-retaining server-log module are documented separately.
Tenant-scoped routes, site roles, required TOTP and audit trails reduce unauthorized access risk.
Analytics retention can follow the customer agreement and regional deployment requirements.
Region-coded ingest hosts allow additional collection and storage regions to be added explicitly.
Framework readiness
One product posture, regional implementation.
These are support areas, not blanket certifications or legal conclusions. Applicability depends on the customer, visitors, purpose, configuration and local rules.
EU & EEA
GDPR-aligned data practices
Data minimization, documented processor roles, appropriate safeguards, retention limits and support for verified data-subject requests can form part of a controller’s GDPR program.
United Kingdom
UK data protection readiness
The same privacy-by-design controls support UK GDPR and related obligations, while the customer remains responsible for its lawful basis and PECR analysis.
United States
State privacy requirements
Abnio does not sell customer analytics data or use it for cross-context behavioural advertising. Customer-specific disclosure and rights workflows remain part of onboarding.
Asia-Pacific
Regional notices and processing
Contract, consent, notice, localization and individual-right requirements vary. Deployment and subprocess expectations are reviewed for the customer’s target markets.
Shared responsibility
The platform helps. The context decides.
Secure the service, follow documented instructions, enforce boundaries and provide accurate processing information.
Choose a lawful basis, configure collection, publish notices and respond to people who exercise rights.
Define the laws, regulator guidance and transfer conditions that apply to the actual processing context.
Map data, modules, providers, retention and residency before production—not after a complaint.
Onboarding review
What we can document with you.
Early-access onboarding includes a practical data-path review so your public claims match the configuration that actually runs.
Enabled modules, fields, first-party proxying, external integrations and visitor regions.
Available ingest/storage placement, dashboard location and relevant subprocessors.
Suggested product disclosure, retention choices and operational contacts for rights requests.
Plan the real data path
Bring your regions and requirements.
Tell us where your visitors are, what modules you need and which restrictions matter. We’ll tell you what is available now and what belongs on the regional roadmap.