JENTIS vs Matomo by Stackhero

Compare JENTIS and Matomo by Stackhero on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: JENTIS

JENTIS

Austria· Web Analytics

Needs review

Shortlist when you need managed server-side / first-party capture with EU-entity hosting and multi-destination activation (ads + analytics). Skip when you only want lightweight privacy analytics or free self-hosted tagging—consider Piwik PRO or etracker for EU analytics-first stacks, or Google sGTM if you will operate a Google-centric pipeline yourself.

EU-operated (Austria)Server-side tag managerEU/EEA hosting (claimed)ISO 27001 (claimed)Managed SaaSNot open source
Logo: Matomo by Stackhero

Matomo by Stackhero

France· Web Analytics

Needs review

Shortlist when you want full Matomo on a dedicated French-operated bare-metal instance with one-click updates and hourly billing—especially if you prefer unlimited site/seat product framing over hit-metered multi-tenant SaaS. Skip when you need EU-only with no US region option, root/SSH access, or a minimal cookieless counter—consider self-hosted Matomo, Friendly Analytics, or Plausible instead.

Managed MatomoDedicated instanceFrench PaaS operatorISO 27001 (claimed)Automatic DPAEU or US region
JENTIS vs Matomo by Stackhero: Snapshot
FeatureLogo: JENTISJENTISLogo: Matomo by StackheroMatomo by Stackhero
Country of originAustriaFrance
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoNo
HeadquartersAustriaFrance
Legal entityJENTIS GmbHStackhero (RCS Paris 512 366 378, VAT FR92512366378), 1 rue de Stockholm, 75008 Paris, France
Governing lawAustria / EU GDPRFrench law; courts at registered head office (per Terms of service)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct: default EU/EEA-only processing on ISO 27001-certified cloud; docs cite IONOS cloud (Germany/EU). Exact host/region named in customer DPA. Optional non-EU instances may add non-EU subprocessors if selected. Marketing website separately uses Host Europe (DE) and US SaaS (HubSpot, Salesforce, Google) for corporate CRM/ads—not the Twin Server product path.Primary compute: Stackhero bare-metal cloud, customer-chosen region EU (France) or USA. Backups: stored in the EU per Matomo FAQ; encrypted atomic images retained up to ~3 months. Not built on AWS/GCP/Azure as the stated compute substrate. Payment processor (unnamed) handles card data; privacy policy mentions third-party messaging/stats tools without a full named subprocessor table.
Summary

Austrian managed server-side data capture and hybrid tag manager: first-party Twin Server collection, consent-aware routing, and ad activation for multi-tool MarTech stacks.

French PaaS-managed Matomo on dedicated bare-metal instances: unlimited sites until capacity, one-click updates, EU or US region choice, with hourly billing and an automatic DPA.

Tags
At a glance: JENTIS vs Matomo by Stackhero
At a glanceLogo: JENTISJENTISLogo: Matomo by StackheroMatomo by Stackhero
HQVienna, AustriaParis, France (1 rue de Stockholm, 75008)
Legal entityJENTIS GmbH (FN 529675i)Stackhero — RCS Paris 512 366 378
Founded2020Not listed
Product typeManaged server-side data capture / hybrid tag managerNot listed
Hosting modelManaged SaaS; EU/EEA by default (IONOS cited in docs)Not listed
Open sourceNoNot listed
Self-hosted productNo (managed hosting)Not listed
Commercial modelSales-led SaaS (demo / consultation)Hourly instance billing; free trial; no standard commitment
StackNot listedOpen-source Matomo on dedicated Stackhero VM
Hosting regionsNot listedEU (France) or USA; backups in EU (vendor FAQ)
CertificationsNot listedISO 27001:2022 claimed (BAB #254338)
Key capabilities: JENTIS vs Matomo by Stackhero
Key capabilitiesLogo: JENTISJENTISLogo: Matomo by StackheroMatomo by Stackhero
EU-operated (Austria)YesNot listed
Server-side tag managerYesNot listed
EU/EEA hosting (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Managed SaaSYesNot listed
Not open sourceYesNot listed
Managed MatomoNot listedYes
Dedicated instanceNot listedYes
French PaaS operatorNot listedYes
ISO 27001 (claimed)Not listedYes
Automatic DPANot listedYes
EU or US regionNot listedYes

JENTIS

  • Hybrid server-side tag management

    One container for client- and server-side tags with first-party DNS; migrate data-layer logic and debug from browser hit to server dispatch without running your own sGTM fleet.

  • Twin Server capture and transforms

    Server-side session mirror that can pseudonymize, anonymize, enrich, and time-frame parameters before forwarding—usable as a CNIL-style proxy pattern when configured carefully.

  • Essential Mode for non-consent traffic

    Configurable minimized/anonymized capture when marketing consent is refused so sessions and conversions are not fully invisible—subject to DPO/legal sign-off per jurisdiction.

  • Synthetic Users for ad activation

    Models trained on consented first-party data produce synthetic conversion signals for Google, Meta, TikTok, and other ad APIs; measure impact with holdouts—legal basis is configuration-specific.

  • Managed EU connectors and raw export

    Vendor-maintained connectors across analytics, ads, and MarTech plus raw data export/API-style control; not a self-hosted open-source stack.

Matomo by Stackhero

  • Dedicated bare-metal Matomo instance

    Each customer gets an isolated VM on Stackhero’s own bare-metal cloud (Stackhero DC OS), not shared multi-tenant Matomo. Local disks and included Redis are positioned for high IOPS and heavy traffic—fit teams that outgrow noisy-neighbor shared analytics clouds.

  • Unlimited sites, members, segments, and goals until capacity

    Stackhero does not meter websites, team seats, segments, or goals as product SKUs; you scale by instance size (published up to 16 vCPUs / 64 GB RAM). Retention is limited by disk, not a fixed product TTL—plan storage for long history.

  • One-click Matomo updates and managed ops (no SSH)

    Stackhero delivers Matomo updates for dashboard application; firewall IP rules are customer-configurable. SSH is intentionally unavailable on the managed service—good for reduced surface area, poor fit if you need custom OS packages.

  • Custom domain, GeoIP2, and dedicated notification email

    Point matomo.yourdomain.com with TLS 1.3/ECDSA, ship visitor location via bundled GeoIP2, and send unlimited Matomo reports/alerts through a per-instance email path—reduces glue work after first deploy.

  • Atomic encrypted daily backups (EU vault)

    24-hour atomic image backups (plus event-driven backups on upgrades) are validated, then encrypted (OpenPGP ECDH/Curve25519) and retained up to three months. Vendor FAQ states backups are stored in the EU even when regions differ—confirm dual-region implications for US instances.

  • Hourly billing with EU or US region choice

    Spin services up/down with hourly charging and a single monthly invoice; free trial without payment method. Choose European (France) or USA placement at create time—region is a first-class control for residency, not a hidden default.

Assurance & compliance: JENTIS vs Matomo by Stackhero
Assurance & complianceLogo: JENTISJENTISLogo: Matomo by StackheroMatomo by Stackhero
Independent security / no-logs audit
Not found

No public independent no-logs or third-party security audit PDF located; ISO is the main public assurance claim.

Not found

ISO 27001 and bug-bounty openness claimed; no public independent no-logs audit report specific to analytics found.

ISO 27001
Vendor claimed

Vendor states ISO 27001 / ISO 27001:2013 certification on site footer and privacy docs; certificate not independently verified in this draft.

Vendor claimed

Vendor publishes ISO/IEC 27001:2022 certificate #254338 from the British Assessment Bureau (PDF). Not re-verified against the issuer’s public register in this draft.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found on marketing or privacy docs.

Not found

No SOC 2/3 claim found on certifications/privacy/GDPR pages reviewed.

GDPR / EU data protection
Vendor claimed

Austrian controller entity; product marketed as privacy-by-design processor with EU hosting, CMP hooks, and transform functions. Not legal advice—confirm config and DPA.

Vendor claimed

French entity; public GDPR & DPA page; customer controller / Stackhero processor model; EU region option for service data.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: AT entity and no known US parent; product hosting claimed EU-only (e.g. IONOS). Residual exposure via customer-chosen US destinations and any non-EU instance option. Not legal advice.

Partial

French entity, no known US parent, non-hyperscaler bare-metal hosting claimed. Medium/partial because USA is a first-class hosting region; EU-only only when the customer creates the service in Europe. Backups stated as EU-stored. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Sample DPA via Customer Legal Hub; required for SaaS processing. Confirm signed version and subprocessor annex.

Vendor claimed

DPA applies automatically with Terms of service; PDF downloadable from the GDPR & DPA page.

EU AI Act
Not applicable

Core product is tag/data capture; Synthetic Users is ML-assisted but product is not marketed as a general-purpose AI system. Revisit if Synthetic Users becomes a primary regulated AI offering.

Not applicable

Web analytics hosting; not positioned as an AI system product.

Considerations & known limitations: JENTIS vs Matomo by Stackhero
Considerations & known limitationsLogo: JENTISJENTISLogo: Matomo by StackheroMatomo by Stackhero
Consent modes need legal sign-off
High

Essential Mode and Synthetic Users can re-open measurement when users refuse cookies; legality depends on jurisdiction, configuration, and DPO assessment—not automatic compliance.

Not listed
Downstream US ad/analytics tools
Medium

Even with EU capture, enabling Google/Meta/TikTok connectors can transfer personal data to US providers; use transforms/proxy patterns and transfer tools as required.

Not listed
ISO claimed; limited public audits
Medium

ISO 27001 is vendor-asserted; no independent public security/no-logs audit found. Request certificate, pen-test summaries, and full subprocessor list under NDA if needed.

Not listed
Managed SaaS, not self-host
Medium

No open-source self-host product path; ops simplicity trades for vendor dependency, sales-led pricing, and migration cost if you later leave.

Not listed
Implementation and data-layer effort
Low

Migration from client-side tags still needs DNS, data layer, CMP mapping, and QA—vendor connectors reduce but do not eliminate engineering work.

Not listed
Optional US hosting regionNot listed
Medium

Platform offers USA placement alongside France/EU. Mis-selected region or unclear contract language can put visitor analytics outside the EU. Procurements that require EU-only must pin region at create time and in the order form.

EU backups when primary is USNot listed
Medium

FAQ states backups are stored in the EU. If an instance runs in the USA, confirm whether visitor data is dual-homed (US primary + EU backup) and how that affects DPIA and transfer tools.

No SSH / managed-only hostNot listed
Low

Cannot install arbitrary system software or agents; support hours stated as CET office hours for basic platform support—not full Matomo application consulting.

Limited named subprocessor listNot listed
Medium

Privacy policy mentions third-party tools and a payment processor without a detailed public subprocessor register. Request the annex in diligence if procurement requires named processors.

ISO certificate vendor-publishedNot listed
Low

ISO 27001:2022 is claimed with a public PDF and BAB certificate number; validate scope, sites, and validity dates with the certification body before treating it as verified.

Matomo privacy configuration is yoursNot listed
Low

Hosting in the EU does not auto-configure consent, IP anonymization, or cookieless modes. Controllers remain responsible for Matomo GDPR tooling and site policy.

Fit

JENTIS

Best fit when

  • E-commerce and multi-brand sites that lose conversion data to blockers, ITP, and consent drop-off
  • Performance marketing teams activating into Google, Meta, TikTok, and other ad APIs from first-party events
  • Analytics/DPO pairs that need data-point-level governance, CMP sync, and pseudonymization before third-country tools
  • Organizations preferring a managed EU capture layer over self-operated server-side GTM
  • Stacks that feed both EU analytics (e.g. Piwik PRO) and global ad platforms from one collection path

Poor fit when

  • Teams seeking free, open-source, or fully self-hosted analytics only
  • Lightweight privacy page analytics without ad activation or hybrid tag management
  • Buyers who cannot run sales-led procurement, data-layer work, and legal review of consent modes
  • Use cases that need a full CDP/BI product rather than capture and routing

Consider instead when

  • When: You primarily need EU privacy-focused web analytics (and optional self-host), not multi-destination ad activation

    Consider: Piwik PRO or etracker

    JENTIS can still sit in front of Piwik PRO; choose the analytics product when capture is not the bottleneck.

  • When: You are Google-only and will operate server-side GTM yourself

    Consider: Google Tag Manager (server-side) + GA4

    Lower cash cost; higher ops burden and different transfer/jurisdiction posture.

  • When: You need a full customer data platform or enterprise analytics suite

    Consider: Adobe Analytics or a dedicated CDP (e.g. Tealium)

    JENTIS is capture/routing at the start of the chain, not a CDP replacement.

Matomo by Stackhero

Best fit when

  • Teams that want Matomo’s full analytics/admin surface without running OS or Matomo upgrades themselves
  • Buyers who prefer a dedicated VM and capacity-based limits over multi-tenant hit metering
  • Orgs consolidating Matomo with other Stackhero-managed open-source services under one French operator
  • Projects that need hourly elasticity and the ability to stop billing with one click
  • Controllers who will configure Matomo privacy features themselves and want a signed/automatic DPA plus ISO 27001 claims

Poor fit when

  • Requirements that forbid any US hosting option or dual-region backup stories—platform publicly offers USA regions
  • Teams that need SSH, custom kernels, or non-Matomo system agents on the host
  • Buyers seeking only a lightweight cookieless pageview product (Plausible-class tools are simpler)
  • Organizations that must self-host inside their own cloud account with no third-party PaaS operator
  • Use cases needing a named public subprocessor register beyond Stackhero’s high-level privacy/GDPR pages

Consider instead when

  • When: You want Swiss Matomo-as-a-Service with cookieless defaults and CH product hosts

    Consider: Friendly Analytics

    Different operator, residency story, and privacy defaults; still Matomo-based.

  • When: You need enterprise analytics packaging beyond plain managed Matomo

    Consider: Piwik PRO

    Compare modules, contracts, and hosting regions independently.

  • When: You only need a minimal open-source-friendly counter with simple SaaS UX

    Consider: Plausible Analytics

    Far less Matomo depth; different product surface.

  • When: You require full root control and in-house residency guarantees

    Consider: Self-hosted Matomo on your own EU IaaS

    Maximum control; you own updates, backups, and hardening.

Open questions for due diligence

JENTIS

  • What is the exact production cloud provider, region, and subprocessor list on the current DPA annex?
  • Can the vendor produce a current ISO 27001 certificate and any independent penetration-test summary?
  • Has legal counsel approved Essential Mode and Synthetic Users for your markets (ePrivacy/GDPR basis)?
  • Which destinations will receive personal data vs pseudonymized/synthetic signals only?
  • What SLA, raw data retention, and exit/export terms apply to your tier?

Matomo by Stackhero

  • Will the order form and DPA annex permanently pin the Matomo instance to the EU (France) region with no US failover?
  • For US-region instances, what exact data is copied to EU backup vaults and under which transfer mechanism?
  • Who is the unnamed parent company referenced on the About page, and is there any US ownership or PE?
  • Can ISO 27001 certificate 254338 be validated on the British Assessment Bureau (or successor) public register for current scope/dates?
  • Which payment, support, and website analytics providers process Stackhero account data (named subprocessor list)?