JENTIS vs nilly

Compare JENTIS and nilly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Adobe Analytics, Google Analytics

Logo: JENTIS

JENTIS

Austria· Web Analytics

Needs review

Shortlist when you need managed server-side / first-party capture with EU-entity hosting and multi-destination activation (ads + analytics). Skip when you only want lightweight privacy analytics or free self-hosted tagging—consider Piwik PRO or etracker for EU analytics-first stacks, or Google sGTM if you will operate a Google-centric pipeline yourself.

EU-operated (Austria)Server-side tag managerEU/EEA hosting (claimed)ISO 27001 (claimed)Managed SaaSNot open source
Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
JENTIS vs nilly: Snapshot
FeatureLogo: JENTISJENTISLogo: nillynilly
Country of originAustriaSwitzerland
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersAustriaSwitzerland
Legal entityJENTIS GmbHLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)
Governing lawAustria / EU GDPRSwitzerland (terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct: default EU/EEA-only processing on ISO 27001-certified cloud; docs cite IONOS cloud (Germany/EU). Exact host/region named in customer DPA. Optional non-EU instances may add non-EU subprocessors if selected. Marketing website separately uses Host Europe (DE) and US SaaS (HubSpot, Salesforce, Google) for corporate CRM/ads—not the Twin Server product path.Vendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.
Summary

Austrian managed server-side data capture and hybrid tag manager: first-party Twin Server collection, consent-aware routing, and ad activation for multi-tool MarTech stacks.

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Tags
At a glance: JENTIS vs nilly
At a glanceLogo: JENTISJENTISLogo: nillynilly
HQVienna, AustriaZürich, Switzerland (Lyo GmbH)
Legal entityJENTIS GmbH (FN 529675i)Lyo GmbH (CHE-417.675.763)
Founded2020Not listed
Product typeManaged server-side data capture / hybrid tag managerNot listed
Hosting modelManaged SaaS; EU/EEA by default (IONOS cited in docs)Not listed
Open sourceNoNot listed
Self-hosted productNo (managed hosting)Not listed
Commercial modelSales-led SaaS (demo / consultation)Traffic-based plans; trial; no permanent free tier
Product modelNot listedSaaS web analytics (not self-hosted)
TrackingNot listedCookieless; no IP/fingerprint claims
Hosting (claimed)Not listedSwitzerland (multi-site)
Live site noteNot listedkandur.one (nilly branding; nilly.io DNS failed at research)
Key capabilities: JENTIS vs nilly
Key capabilitiesLogo: JENTISJENTISLogo: nillynilly
EU-operated (Austria)YesNot listed
Server-side tag managerYesNot listed
EU/EEA hosting (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Managed SaaSYesNot listed
Not open sourceYesNot listed
Cookieless trackingNot listedYes
Swiss-hosted (claimed)Not listedYes
Swiss entityNot listedYes
Sub-1 kB scriptNot listedYes
REST APINot listedYes
SaaS onlyNot listedYes

JENTIS

  • Hybrid server-side tag management

    One container for client- and server-side tags with first-party DNS; migrate data-layer logic and debug from browser hit to server dispatch without running your own sGTM fleet.

  • Twin Server capture and transforms

    Server-side session mirror that can pseudonymize, anonymize, enrich, and time-frame parameters before forwarding—usable as a CNIL-style proxy pattern when configured carefully.

  • Essential Mode for non-consent traffic

    Configurable minimized/anonymized capture when marketing consent is refused so sessions and conversions are not fully invisible—subject to DPO/legal sign-off per jurisdiction.

  • Synthetic Users for ad activation

    Models trained on consented first-party data produce synthetic conversion signals for Google, Meta, TikTok, and other ad APIs; measure impact with holdouts—legal basis is configuration-specific.

  • Managed EU connectors and raw export

    Vendor-maintained connectors across analytics, ads, and MarTech plus raw data export/API-style control; not a self-hosted open-source stack.

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Assurance & compliance: JENTIS vs nilly
Assurance & complianceLogo: JENTISJENTISLogo: nillynilly
Independent security / no-logs audit
Not found

No public independent no-logs or third-party security audit PDF located; ISO is the main public assurance claim.

Not found

No public third-party audit report found for tracking claims.

ISO 27001
Vendor claimed

Vendor states ISO 27001 / ISO 27001:2013 certification on site footer and privacy docs; certificate not independently verified in this draft.

Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found on marketing or privacy docs.

Not found
GDPR / EU data protection
Vendor claimed

Austrian controller entity; product marketed as privacy-by-design processor with EU hosting, CMP hooks, and transform functions. Not legal advice—confirm config and DPA.

Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: AT entity and no known US parent; product hosting claimed EU-only (e.g. IONOS). Residual exposure via customer-chosen US destinations and any non-EU instance option. Not legal advice.

Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Sample DPA via Customer Legal Hub; required for SaaS processing. Confirm signed version and subprocessor annex.

Not found

No public DPA download found; request from vendor.

EU AI Act
Not applicable

Core product is tag/data capture; Synthetic Users is ML-assisted but product is not marketed as a general-purpose AI system. Revisit if Synthetic Users becomes a primary regulated AI offering.

Not applicable

Web analytics product; not marketed as an AI system.

Swiss Made Software / Swiss Web labelsNot listed
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Considerations & known limitations: JENTIS vs nilly
Considerations & known limitationsLogo: JENTISJENTISLogo: nillynilly
Consent modes need legal sign-off
High

Essential Mode and Synthetic Users can re-open measurement when users refuse cookies; legality depends on jurisdiction, configuration, and DPO assessment—not automatic compliance.

Not listed
Downstream US ad/analytics tools
Medium

Even with EU capture, enabling Google/Meta/TikTok connectors can transfer personal data to US providers; use transforms/proxy patterns and transfer tools as required.

Not listed
ISO claimed; limited public audits
Medium

ISO 27001 is vendor-asserted; no independent public security/no-logs audit found. Request certificate, pen-test summaries, and full subprocessor list under NDA if needed.

Not listed
Managed SaaS, not self-host
Medium

No open-source self-host product path; ops simplicity trades for vendor dependency, sales-led pricing, and migration cost if you later leave.

Not listed
Implementation and data-layer effort
Low

Migration from client-side tags still needs DNS, data layer, CMP mapping, and QA—vendor connectors reduce but do not eliminate engineering work.

Not listed
Brand/domain transition (nilly.io vs kandur.one)Not listed
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

US SaaS on customer account pathNot listed
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Thin public assurance packNot listed
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

No self-host or open-source editionNot listed
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Small independent operatorNot listed
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Fit

JENTIS

Best fit when

  • E-commerce and multi-brand sites that lose conversion data to blockers, ITP, and consent drop-off
  • Performance marketing teams activating into Google, Meta, TikTok, and other ad APIs from first-party events
  • Analytics/DPO pairs that need data-point-level governance, CMP sync, and pseudonymization before third-country tools
  • Organizations preferring a managed EU capture layer over self-operated server-side GTM
  • Stacks that feed both EU analytics (e.g. Piwik PRO) and global ad platforms from one collection path

Poor fit when

  • Teams seeking free, open-source, or fully self-hosted analytics only
  • Lightweight privacy page analytics without ad activation or hybrid tag management
  • Buyers who cannot run sales-led procurement, data-layer work, and legal review of consent modes
  • Use cases that need a full CDP/BI product rather than capture and routing

Consider instead when

  • When: You primarily need EU privacy-focused web analytics (and optional self-host), not multi-destination ad activation

    Consider: Piwik PRO or etracker

    JENTIS can still sit in front of Piwik PRO; choose the analytics product when capture is not the bottleneck.

  • When: You are Google-only and will operate server-side GTM yourself

    Consider: Google Tag Manager (server-side) + GA4

    Lower cash cost; higher ops burden and different transfer/jurisdiction posture.

  • When: You need a full customer data platform or enterprise analytics suite

    Consider: Adobe Analytics or a dedicated CDP (e.g. Tealium)

    JENTIS is capture/routing at the start of the chain, not a CDP replacement.

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Open questions for due diligence

JENTIS

  • What is the exact production cloud provider, region, and subprocessor list on the current DPA annex?
  • Can the vendor produce a current ISO 27001 certificate and any independent penetration-test summary?
  • Has legal counsel approved Essential Mode and Synthetic Users for your markets (ePrivacy/GDPR basis)?
  • Which destinations will receive personal data vs pseudonymized/synthetic signals only?
  • What SLA, raw data retention, and exit/export terms apply to your tier?

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?