JENTIS vs Stormly

Compare JENTIS and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: JENTIS

JENTIS

Austria· Web Analytics

Needs review

Shortlist when you need managed server-side / first-party capture with EU-entity hosting and multi-destination activation (ads + analytics). Skip when you only want lightweight privacy analytics or free self-hosted tagging—consider Piwik PRO or etracker for EU analytics-first stacks, or Google sGTM if you will operate a Google-centric pipeline yourself.

EU-operated (Austria)Server-side tag managerEU/EEA hosting (claimed)ISO 27001 (claimed)Managed SaaSNot open source
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
JENTIS vs Stormly: Snapshot
FeatureLogo: JENTISJENTISLogo: StormlyStormly
Country of originAustriaNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersAustriaNetherlands
Legal entityJENTIS GmbHMonon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawAustria / EU GDPRNetherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct: default EU/EEA-only processing on ISO 27001-certified cloud; docs cite IONOS cloud (Germany/EU). Exact host/region named in customer DPA. Optional non-EU instances may add non-EU subprocessors if selected. Marketing website separately uses Host Europe (DE) and US SaaS (HubSpot, Salesforce, Google) for corporate CRM/ads—not the Twin Server product path.Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Austrian managed server-side data capture and hybrid tag manager: first-party Twin Server collection, consent-aware routing, and ad activation for multi-tool MarTech stacks.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: JENTIS vs Stormly
At a glanceLogo: JENTISJENTISLogo: StormlyStormly
HQVienna, AustriaNot listed
Legal entityJENTIS GmbH (FN 529675i)Not listed
Founded2020Not listed
Product typeManaged server-side data capture / hybrid tag managerNot listed
Hosting modelManaged SaaS; EU/EEA by default (IONOS cited in docs)Not listed
Open sourceNoNo
Self-hosted productNo (managed hosting)Not listed
Commercial modelSales-led SaaS (demo / consultation)Free tier + monthly plan + custom; trial path on paid
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Self-hostNot listedNo
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: JENTIS vs Stormly
Key capabilitiesLogo: JENTISJENTISLogo: StormlyStormly
EU-operated (Austria)YesNot listed
Server-side tag managerYesNot listed
EU/EEA hosting (claimed)YesNot listed
ISO 27001 (claimed)YesNot listed
Managed SaaSYesNot listed
Not open sourceYesNot listed
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes
SaaS (not self-host)Not listedYes

JENTIS

  • Hybrid server-side tag management

    One container for client- and server-side tags with first-party DNS; migrate data-layer logic and debug from browser hit to server dispatch without running your own sGTM fleet.

  • Twin Server capture and transforms

    Server-side session mirror that can pseudonymize, anonymize, enrich, and time-frame parameters before forwarding—usable as a CNIL-style proxy pattern when configured carefully.

  • Essential Mode for non-consent traffic

    Configurable minimized/anonymized capture when marketing consent is refused so sessions and conversions are not fully invisible—subject to DPO/legal sign-off per jurisdiction.

  • Synthetic Users for ad activation

    Models trained on consented first-party data produce synthetic conversion signals for Google, Meta, TikTok, and other ad APIs; measure impact with holdouts—legal basis is configuration-specific.

  • Managed EU connectors and raw export

    Vendor-maintained connectors across analytics, ads, and MarTech plus raw data export/API-style control; not a self-hosted open-source stack.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: JENTIS vs Stormly
Assurance & complianceLogo: JENTISJENTISLogo: StormlyStormly
Independent security / no-logs audit
Not found

No public independent no-logs or third-party security audit PDF located; ISO is the main public assurance claim.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Vendor claimed

Vendor states ISO 27001 / ISO 27001:2013 certification on site footer and privacy docs; certificate not independently verified in this draft.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found on marketing or privacy docs.

Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

Austrian controller entity; product marketed as privacy-by-design processor with EU hosting, CMP hooks, and transform functions. Not legal advice—confirm config and DPA.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: AT entity and no known US parent; product hosting claimed EU-only (e.g. IONOS). Residual exposure via customer-chosen US destinations and any non-EU instance option. Not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Sample DPA via Customer Legal Hub; required for SaaS processing. Confirm signed version and subprocessor annex.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Core product is tag/data capture; Synthetic Users is ML-assisted but product is not marketed as a general-purpose AI system. Revisit if Synthetic Users becomes a primary regulated AI offering.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: JENTIS vs Stormly
Considerations & known limitationsLogo: JENTISJENTISLogo: StormlyStormly
Consent modes need legal sign-off
High

Essential Mode and Synthetic Users can re-open measurement when users refuse cookies; legality depends on jurisdiction, configuration, and DPO assessment—not automatic compliance.

Not listed
Downstream US ad/analytics tools
Medium

Even with EU capture, enabling Google/Meta/TikTok connectors can transfer personal data to US providers; use transforms/proxy patterns and transfer tools as required.

Not listed
ISO claimed; limited public audits
Medium

ISO 27001 is vendor-asserted; no independent public security/no-logs audit found. Request certificate, pen-test summaries, and full subprocessor list under NDA if needed.

Not listed
Managed SaaS, not self-host
Medium

No open-source self-host product path; ops simplicity trades for vendor dependency, sales-led pricing, and migration cost if you later leave.

Not listed
Implementation and data-layer effort
Low

Migration from client-side tags still needs DNS, data layer, CMP mapping, and QA—vendor connectors reduce but do not eliminate engineering work.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

JENTIS

Best fit when

  • E-commerce and multi-brand sites that lose conversion data to blockers, ITP, and consent drop-off
  • Performance marketing teams activating into Google, Meta, TikTok, and other ad APIs from first-party events
  • Analytics/DPO pairs that need data-point-level governance, CMP sync, and pseudonymization before third-country tools
  • Organizations preferring a managed EU capture layer over self-operated server-side GTM
  • Stacks that feed both EU analytics (e.g. Piwik PRO) and global ad platforms from one collection path

Poor fit when

  • Teams seeking free, open-source, or fully self-hosted analytics only
  • Lightweight privacy page analytics without ad activation or hybrid tag management
  • Buyers who cannot run sales-led procurement, data-layer work, and legal review of consent modes
  • Use cases that need a full CDP/BI product rather than capture and routing

Consider instead when

  • When: You primarily need EU privacy-focused web analytics (and optional self-host), not multi-destination ad activation

    Consider: Piwik PRO or etracker

    JENTIS can still sit in front of Piwik PRO; choose the analytics product when capture is not the bottleneck.

  • When: You are Google-only and will operate server-side GTM yourself

    Consider: Google Tag Manager (server-side) + GA4

    Lower cash cost; higher ops burden and different transfer/jurisdiction posture.

  • When: You need a full customer data platform or enterprise analytics suite

    Consider: Adobe Analytics or a dedicated CDP (e.g. Tealium)

    JENTIS is capture/routing at the start of the chain, not a CDP replacement.

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

JENTIS

  • What is the exact production cloud provider, region, and subprocessor list on the current DPA annex?
  • Can the vendor produce a current ISO 27001 certificate and any independent penetration-test summary?
  • Has legal counsel approved Essential Mode and Synthetic Users for your markets (ePrivacy/GDPR basis)?
  • Which destinations will receive personal data vs pseudonymized/synthetic signals only?
  • What SLA, raw data retention, and exit/export terms apply to your tier?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?