Commanders Act vs Piwik PRO

Compare Commanders Act and Piwik PRO on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Adobe Analytics, Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: Piwik PRO

Piwik PRO

Poland· Web Analytics

Needs review

Shortlist Piwik PRO when you need a managed European analytics controller with integrated consent, tagging, and real-time data activation—and you can accept cloud residency on Azure and/or Elastx. Skip when you require open-source self-hosting (consider Matomo or Friendly Analytics) or only need a minimal cookieless counter (Plausible, Simple Analytics).

EU HQ (Poland)Analytics + tags + consentData activationEU hosting optionsISO 27001 / SOC 2 (claimed)HIPAA BAA (Enterprise)
Commanders Act vs Piwik PRO: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: Piwik PROPiwik PRO
Country of originFrancePoland
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersFrancePoland
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisPiwik PRO SA (Wrocław); affiliates Piwik PRO LLC (New York), Piwik PRO GmbH (Berlin)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Customer-selectable regions: Microsoft Azure public cloud (US, Netherlands, Germany, Hong Kong) and Elastx (Sweden, EU-operated). Enterprise private cloud: 60+ Azure regions plus Elastx. Business plan marketing highlights Swedish EU-operated hosting. No classic customer self-host.
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

Polish privacy-first analytics suite combining web and mobile analytics, tag management, consent management, and real-time data activation for regulated teams.

Tags
At a glance: Commanders Act vs Piwik PRO
At a glanceLogo: Commanders ActCommanders ActLogo: Piwik PROPiwik PRO
HQParis, France (Fjord Technologies SAS)Wrocław, Poland (Piwik PRO SA)
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)Not listed
DeploymentManaged SaaS (not self-hosted)Not listed
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Business subscription + trial; Enterprise custom
Product typeNot listedCommercial analytics suite (SaaS / private cloud)
Open sourceNot listedNo (closed source since split from Matomo lineage)
Self-hostNot listedNo classic on-prem; public or private cloud only
Hosting (public)Not listedAzure US/NL/DE/HK; Elastx Sweden
ModulesNot listedAnalytics, Tag Manager, Consent Manager, Data Activation
Key capabilities: Commanders Act vs Piwik PRO
Key capabilitiesLogo: Commanders ActCommanders ActLogo: Piwik PROPiwik PRO
EU-operated (FR)YesNot listed
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesNot listed
EU HQ (Poland)Not listedYes
Analytics + tags + consentNot listedYes
Data activationNot listedYes
EU hosting optionsNot listedYes
ISO 27001 / SOC 2 (claimed)Not listedYes
HIPAA BAA (Enterprise)Not listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

Piwik PRO

  • ClickHouse-backed web & mobile analytics

    Session-level web and app analytics with custom reports, funnels, user flows, multi-channel attribution, and calculated metrics. Vendor positions unsampled collection by default with optional sampling for extreme volumes, plus raw export via API, files, and BigQuery—aimed at teams that outgrew pre-aggregated MySQL-style tools.

  • Anonymous tracking when cookies are declined

    Collect privacy-safe behavioral signals without identifiers when visitors refuse cookies or when you configure limited measurement modes. Marketing can still see channels and journeys; personal identifiers and full attribution wait for a valid lawful basis—useful under GDPR/ePrivacy friction.

  • Integrated Consent Manager and Tag Manager

    Capture and store consent, drive tag firing from preferences, and handle visitor data requests in-product. Optional Cookie Information CMP and server-side tagging paths reduce the usual glue code between a separate CMP, GTM, and analytics.

  • Data Activation for real-time personalization

    Segment audiences from live behavior and trigger on-site or outbound actions without exporting every event to a second CDP first. Suited to regulated marketers who want activation on first-party data they control.

  • Selectable cloud residency (Azure + Elastx)

    Public cloud regions include Azure US, NL, DE, and HK plus Elastx Sweden; Enterprise private cloud spans 60+ Azure regions and Elastx. Business plan marketing highlights EU-operated Swedish hosting—pick region in procurement, not after go-live.

  • Regulated-industry packaging (GDPR tooling, HIPAA BAA path)

    DPA available on Business signup; Enterprise adds private cloud, higher action volumes, SLAs, and HIPAA Business Associate Agreements for healthcare marketing analytics. Vendor also claims ISO 27001 and SOC 2—request current certificates in diligence.

Assurance & compliance: Commanders Act vs Piwik PRO
Assurance & complianceLogo: Commanders ActCommanders ActLogo: Piwik PROPiwik PRO
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Partial

Vendor states regular external security audits and SOC 2/ISO programs; no public third-party no-logs-style audit PDF reviewed for this draft. Request reports under NDA.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Vendor claimed

Asserted on privacy-security and platform pages; certificate not independently re-verified against a public registry for this entry.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Vendor claimed

Vendor claims SOC 2 (comparison content references type II) and SOC 2-certified infrastructure; obtain current report in diligence.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

EU legal entity, residency options, consent tooling, anonymization, and DPA. Compliance depends on customer configuration and purposes.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

No known US parent (Polish SA). Medium exposure due to Microsoft Azure as public/private cloud subprocessor and optional US region; Elastx Sweden is EU-operated alternative. Not legal advice.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Vendor claimed

Business DPA linked from Business plan signup (piwik.pro/business-dpa/); Enterprise contracts expand terms.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Analytics/activation platform; not marketed as an AI system provider. Customer AI use of exported data is out of product scope.

HIPAA / BAANot listed
Vendor claimed

HIPAA-oriented offering with BAA on Enterprise path per vendor; not available on all plan tiers.

Considerations & known limitations: Commanders Act vs Piwik PRO
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: Piwik PROPiwik PRO
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Not listed
ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
US-group cloud (Azure) in hosting pathNot listed
Medium

Even with EU region selection, Azure introduces US-group infrastructure risk. Pin region, review SCCs/subprocessors, and escalate if policy forbids US cloud groups entirely.

Closed source and no classic self-hostNot listed
Medium

Cannot independently audit full source or run fully air-gapped on customer iron. Private cloud still involves vendor-managed stack on Azure/Elastx.

Certifications not independently verified hereNot listed
Low

ISO 27001, SOC 2, and HIPAA are vendor-claimed. Request certificates/reports and BAA text before treating them as assured.

Paid plans only after Core sunsetNot listed
Low

Free Core has been discontinued; evaluation relies on trials and paid Business/Enterprise metering by actions/domains.

Compliance depends on configurationNot listed
Medium

Anonymous modes and CNIL exemption require correct setup and purpose limitation. Misconfiguration can recreate the same legal exposure teams left GA to avoid.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

Piwik PRO

Best fit when

  • Regulated marketing/analytics teams that want one suite for measurement, consent, tags, and activation under a Polish legal entity
  • Public sector and EU enterprises that need selectable EU residency (e.g. Elastx Sweden or Azure NL/DE) plus a formal B2B DPA
  • Healthcare digital teams evaluating HIPAA-aware analytics with a signed BAA on Enterprise
  • Organizations leaving GA4 primarily for residency, no vendor ad-network reuse, and anonymous pre-consent measurement options
  • Teams that need enterprise reporting depth (custom reports, funnels, flows, attribution) beyond lightweight privacy analytics

Poor fit when

  • Buyers who mandate fully self-hosted open-source analytics with no cloud hypervisor vendor
  • Sites that only need simple cookieless page analytics without tag management or activation
  • Teams that refuse any US-group infrastructure (Azure appears in public hosting options even when EU regions are chosen)
  • Orgs seeking a free forever analytics tier (Core plan sunset; paid Business/Enterprise only)

Consider instead when

  • When: You need open-source code and true on-premises control

    Consider: Matomo (self-host) or Friendly Analytics / Matomo by Stackhero for managed Matomo

    Piwik PRO is proprietary cloud/private-cloud only.

  • When: You want minimal, cookieless EU analytics without enterprise suite complexity

    Consider: Plausible Analytics or Simple Analytics

    Far smaller feature surface; no HIPAA/CDP-style activation packaging.

  • When: You need a German enterprise analytics vendor with long public-sector presence

    Consider: etracker

    Different product depth and packaging—compare consent tooling and activation needs.

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

Piwik PRO

  • What exact subprocessor list and backup/DR locations apply to the contracted region (Azure vs Elastx) today?
  • Can the vendor provide current ISO 27001 certificate scope and SOC 2 Type II report under NDA?
  • For healthcare: which plan tier, region, and BAA wording cover the intended PHI workflows?
  • Does the Business Swedish hosting path avoid Azure entirely for production data, or only for selected components?
  • What residual free/legacy Core accounts remain, and what is the migration deadline for this tenant?