Privacy Notice — Skriza Pulse

Last updated: 5. Juli 2026

Skriza Pulse is a privacy-first web analytics system (audience measurement). Site operators embed Pulse to see which pages are viewed and where visitors come from — without cookies, without recognising anyone across days, and without cross-site profiles. This notice describes what Pulse processes in visitors' browsers and on our servers. Operators may link to it or adopt the relevant sections into their own privacy policy.

1. Roles: controller and processor

The controller under the GDPR for data collected on an embedding website is the operator of that website. Skriza Pulse processes the data described below solely on the operator's behalf and acts as a processor (Art. 28 GDPR).

The provider of Skriza Pulse is:

Yusuf Senel, Von-Hünefeld-Str. 8, 40764 Langenfeld, Deutschland

Email (data protection): [email protected]

We do not analyse our customers' data for our own purposes, do not pool it across customers, and do not pass it on.

2. Nothing is stored on your device

Pulse stores nothing on visitors' devices and reads nothing from them: no cookies, no localStorage, no sessionStorage, no cache-based identifier. The rule in § 25 TDDDG (and Art. 5(3) ePrivacy) governs storing or accessing information on terminal equipment, and is therefore not triggered — which is why the processing described here needs no cookie banner.

We also build no device fingerprint: no canvas, font or WebGL hashing, no exact screen dimensions (they are rounded into coarse buckets), and no full User-Agent string.

3. How visitors are counted

To tell whether two pageviews belong to the same visit, we derive a non-reversible hash on the server from the IP address, the User-Agent and a random secret (a “salt”) that is specific to each website and regenerated every night at 00:00 UTC. The previous salt is destroyed.

Two things follow. The hash cannot be turned back into an IP address, and yesterday's identifier cannot be linked to today's — not even by us. Someone who visits on two days is therefore counted as two visitors. That imprecision is the price of having no persistent recognition, and we state it openly in the dashboard rather than hiding it.

A session ends after 30 minutes of inactivity, and in any case when the salt rotates at midnight.

4. Data processed

Per event we process only the following, already-reduced information:

  • The page path without query string or fragment (e.g. “/pricing”) — search terms, order ids or tokens in the URL never reach us.
  • The referrer as a hostname only (e.g. “chatgpt.com”), never the full referring URL; plus the five UTM campaign parameters where present.
  • IP address: used only to derive country and network operator (ASN) via our own internal WHOIS service, and to compute the daily hash described above. The raw IP address is not stored.
  • User-Agent: reduced to device type (mobile/tablet/desktop), operating system and browser family. The full string is discarded.
  • Browser language, reduced to language and region (e.g. “de-DE”).
  • Screen width and height, rounded to coarse buckets (e.g. 1280 rather than 1366).
  • Time on page and maximum scroll depth.
  • Operator-defined events (“goals”) with a name they choose and optionally a monetary value.
  • A classification of the request as human, bot, crawler or AI agent, so automated traffic can be kept out of the statistics.

5. What Pulse deliberately cannot do

The following are not switched off — they are absent. There is no interface in Pulse through which they could be produced:

  • No session replay, no heatmaps, no mouse or keystroke traces.
  • No reconstruction of an individual's path through the site, and no output of individual visitors or sessions — not in the dashboard and not through the API.
  • No cross-site recognition, no identifiers shared between customers, no benchmarking database.
  • No advertising audiences, no remarketing, no connection to any ad network.

6. Retention

Individual events are deleted after the window the operator configures — 30 days by default, 90 days at most. The daily aggregates derived from them (totals per page, country, source and so on) are deleted after 25 months. Deletion runs automatically as a daily job.

The salts and session identifiers used for counting live only in our Redis/Valkey service's memory and expire on their own (salt: 26 hours, session: 30 minutes).

7. Where processing takes place

Processing takes place exclusively on servers in the European Union. There is no transfer to third countries. Mapping IP addresses to country and network operator is likewise done by our own service rather than a non-EU vendor.

8. Legal basis

Because Pulse neither stores information on the device nor accesses information stored there, § 25 TDDDG does not apply. The remaining processing of the pseudonymous data listed above is typically based by the operator on their legitimate interest in operating and improving their website (Art. 6(1)(f) GDPR). The operator states the applicable legal basis in their own privacy policy.

9. Opting out

We honour your browser's “Do Not Track” (DNT) and “Global Privacy Control” (Sec-GPC) signals: if either is set, nothing is collected. Independently of that, you can object permanently using the button below. Doing so sets a single strictly necessary cookie (“skriza_pulse_optout”) whose only content is your objection.

10. Your rights

You have the rights set out in Art. 15 ff. GDPR. Please note that we cannot relate the data processed here to an identified person — the identifier is non-reversible and destroyed daily — so under Art. 11 GDPR we are unable to tie a record to a particular individual. For access and erasure please contact the operator of the website in question; for questions about Pulse itself, reach us at [email protected].

Measurement is active. You can opt out permanently here at any time.