Solutions · GDPR and EU residency

Monitoring your DPO
will not fight you over.

Most monitoring SaaS asks Europe to compromise: US clouds, vague subprocessors, agents that upload more than they admit. Wakora is built and hosted in the EU, engineered so the sensitive data never leaves your servers in the first place — and the paperwork is published before you ask.

EU
Built and hosted in the EU. Telemetry stays in the region, encrypted at rest, retention by plan.
Local secrets
Database and SNMP credentials are encrypted on your host, machine-bound. The platform cannot read them.
No visitor IPs
RUM resolves geography at ingest and drops the address. No cookies, no fingerprinting.
Public DPA
The Article 28 DPA and subprocessor register are published, signed, in the trust pack.

Data minimization as architecture, not policy

The strongest GDPR position is not collecting the data at all. Service credentials are resolved locally on your host and never uploaded — the platform authenticates the agent, not your databases. Log lines are filtered and redacted on the agent before transmission: credential-shaped content never leaves the machine, and log collection levels are yours to control per service. Visitor analytics keep no IP addresses. What the platform stores is operational telemetry, not people.

Everything a review asks for, already public

The trust pack holds the security model, data-flow description, threat model, SBOM, reproducible-build attestation, incident-response summary, the Article 28 DPA and the complete subprocessor register — signed, versioned, regenerated with every release. Nothing is gated behind a sales call, because a compliance answer you have to request is a compliance answer you cannot verify. The agent's full source is public, and its builds are reproducible byte for byte, so "what exactly runs on our servers" has a checkable answer.

Accountability inside the product

The console keeps an append-only, hash-chained audit log of actions that matter: who acknowledged, who changed a threshold, who exported what — including actions performed by AI agents through MCP, which act under scoped tokens and land in the same audit trail. Personal data of console users is erasable on request with history integrity preserved. Retention is explicit, per plan, enforced at the storage layer.

For regulated clients

Finance-grade design rules — signed checks, least privilege, no shell execution, staged changes — documented in the trust pack your auditor can keep.

For agencies with EU clients

White-label monitoring that inherits the same residency and DPA story — your clients' compliance questions arrive pre-answered.

Leaving is one command

No lock-in theater: uninstall removes the agent and its data from the host, and account deletion honors the retention you chose. The exit is documented too.

Frequently asked

Where is monitoring data stored?
In the EU, encrypted at rest, with retention set by your plan. Data residency is a region choice, EU at launch, and telemetry does not leave the region that owns it.
Do you sign a DPA?
Yes, and you can read it before you ever talk to us: the standard-form GDPR Article 28 DPA and the full subprocessor register are published, signed, in the public trust pack. Business and Agency customers receive countersigned execution copies.
Does Real User Monitoring store my visitors' personal data?
Visitor IP addresses are not stored: geography is resolved at ingest and the address is dropped. The RUM snippet sets no cookies and does not fingerprint. What remains is performance timings, error signatures and coarse geography — operational data, kept lean by design.

Send the trust pack to your DPO first.

Then start free on three hosts. The paperwork will already be approved by the time discovery finishes.