Offen Fair Web Analytics vs Piwik PRO

Compare Offen Fair Web Analytics and Piwik PRO on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics, Matomo, Mixpanel

Logo: Offen Fair Web Analytics

Offen Fair Web Analytics

Germany· Web Analytics

Needs review

Shortlist when you want self-hosted, Apache-2.0 analytics that only measures after opt-in, encrypts events in the browser, and lets visitors open their own data in the Auditorium. Skip when you need cookieless full-coverage metrics, session replay/heatmaps, or zero-ops managed EU hosting—consider Plausible, Pirsch, or Friendly Analytics instead.

Opt-in onlyBrowser E2E encryptionSelf-hostedApache-2.0Visitor data accessBerlin-based project
Logo: Piwik PRO

Piwik PRO

Poland· Web Analytics

Needs review

Shortlist Piwik PRO when you need a managed European analytics controller with integrated consent, tagging, and real-time data activation—and you can accept cloud residency on Azure and/or Elastx. Skip when you require open-source self-hosting (consider Matomo or Friendly Analytics) or only need a minimal cookieless counter (Plausible, Simple Analytics).

EU HQ (Poland)Analytics + tags + consentData activationEU hosting optionsISO 27001 / SOC 2 (claimed)HIPAA BAA (Enterprise)
Offen Fair Web Analytics vs Piwik PRO: Snapshot
FeatureLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: Piwik PROPiwik PRO
Country of originGermanyPoland
CategoryWeb AnalyticsWeb Analytics
Open sourceYesNo
Self-hostedYesNo
HeadquartersGermanyPoland
Legal entityPublic legal notice lists Frederik Ring, Berlin (offen.software); product authors Frederik Ring and Hendrik Niefeld—no separate GmbH name verified on imprintPiwik PRO SA (Wrocław); affiliates Piwik PRO LLC (New York), Piwik PRO GmbH (Berlin)
Governing lawGermany (indicative from Berlin imprint)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct is operator self-hosted (your VPS/cloud/on-prem). No Offen multi-tenant analytics SaaS or vendor subprocessor list for visitor events. Related marketing site (offen.software) names Hetzner Online GmbH (Germany) as host—not the analytics data path. Optional community deploys include Heroku (operator choice).Customer-selectable regions: Microsoft Azure public cloud (US, Netherlands, Germany, Hong Kong) and Elastx (Sweden, EU-operated). Enterprise private cloud: 60+ Azure regions plus Elastx. Business plan marketing highlights Swedish EU-operated hosting. No classic customer self-host.
Summary

Open-source, self-hosted web analytics with opt-in consent, browser-side end-to-end encryption, and a shared Auditorium so visitors can see and control their own usage data.

Polish privacy-first analytics suite combining web and mobile analytics, tag management, consent management, and real-time data activation for regulated teams.

Tags
At a glance: Offen Fair Web Analytics vs Piwik PRO
At a glanceLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: Piwik PROPiwik PRO
HQ / authorsBerlin, Germany (Frederik Ring & Hendrik Niefeld)Not listed
LicenseApache-2.0 (code/docs); logo CC-BY-NC-ND-4.0Not listed
DeliverySelf-host only (binary, Docker, community deploys)Not listed
Consent modelOpt-in only; first-party cookiesNot listed
Default retention6 months (configurable shorter)Not listed
Funding noteNLnet NGI support (project-stated)Not listed
HQNot listedWrocław, Poland (Piwik PRO SA)
Product typeNot listedCommercial analytics suite (SaaS / private cloud)
Open sourceNot listedNo (closed source since split from Matomo lineage)
Self-hostNot listedNo classic on-prem; public or private cloud only
Hosting (public)Not listedAzure US/NL/DE/HK; Elastx Sweden
ModulesNot listedAnalytics, Tag Manager, Consent Manager, Data Activation
Commercial modelNot listedBusiness subscription + trial; Enterprise custom
Key capabilities: Offen Fair Web Analytics vs Piwik PRO
Key capabilitiesLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: Piwik PROPiwik PRO
Opt-in onlyYesNot listed
Browser E2E encryptionYesNot listed
Self-hostedYesNot listed
Apache-2.0YesNot listed
Visitor data accessYesNot listed
Berlin-based projectYesNot listed
EU HQ (Poland)Not listedYes
Analytics + tags + consentNot listedYes
Data activationNot listedYes
EU hosting optionsNot listedYes
ISO 27001 / SOC 2 (claimed)Not listedYes
HIPAA BAA (Enterprise)Not listedYes

Offen Fair Web Analytics

  • Opt-in only collection with first-party cookies

    No analytics events are recorded until the visitor actively consents. Cookies are first-party and the tracker is meant to run on a same-site subdomain so third-party cookie restrictions and cross-site tracking models do not apply. Visitors who never opt in leave no usage trail—expect lower absolute volumes than cookieless tools that measure by default.

  • Browser-side end-to-end encryption of usage events

    Clients encrypt usage data before it leaves the browser; the server stores ciphertext and cannot decrypt events alone. Only the visitor (via their cookie) and the matching operator account can open that visitor's data in the Auditorium. Practical impact: a compromised database or overly broad ops access does not yield plaintext browsing histories the way a typical self-hosted analytics DB would.

  • Auditorium for both operators and visitors

    Operators see aggregates across pages where the installation is active (unique users/sessions, top pages, filters). Each opted-in visitor can open the same style of UI for their own data only, with plain-language metric explanations, and can delete data or fully opt out later. This is the fair design point: measurement is not a one-way glass.

  • Essential metrics without IP or User-Agent capture

    Dashboards cover real-time activity, page views, unique users and sessions, bounce rate, returning users, top pages, referrers, UTM campaign/source, landing and exit pages, weekly retention, and load time. Location is country-level from timezone mapping; mobile share uses orientation capability—not IP geolocation or UA parsing. No heatmaps, session replay, or warehouse-grade product analytics.

  • Lightweight self-host: binary, Docker, SQLite or SQL

    Production installs use a single binary (Linux/Windows/macOS) or the offen/offen image; docs also cover Heroku, Uberspace, and YunoHost. Default store is SQLite; MySQL and Postgres are supported. AutoTLS can request Let's Encrypt certificates. Config is environment variables or offen.env. You own uptime, backups, SMTP for password reset, and the subdomain layout.

  • Multi-site accounts, teams, and short retention

    One installation can cover multiple websites with shared team access. Default retention is six months with automatic deletion; operators can shorten retention (e.g. 12 weeks, 30 days, 7 days) knowing shorter values purge older events on startup. Consent banner appearance is customizable; UI locales include EN, DE, FR, ES, PT, and VI.

Piwik PRO

  • ClickHouse-backed web & mobile analytics

    Session-level web and app analytics with custom reports, funnels, user flows, multi-channel attribution, and calculated metrics. Vendor positions unsampled collection by default with optional sampling for extreme volumes, plus raw export via API, files, and BigQuery—aimed at teams that outgrew pre-aggregated MySQL-style tools.

  • Anonymous tracking when cookies are declined

    Collect privacy-safe behavioral signals without identifiers when visitors refuse cookies or when you configure limited measurement modes. Marketing can still see channels and journeys; personal identifiers and full attribution wait for a valid lawful basis—useful under GDPR/ePrivacy friction.

  • Integrated Consent Manager and Tag Manager

    Capture and store consent, drive tag firing from preferences, and handle visitor data requests in-product. Optional Cookie Information CMP and server-side tagging paths reduce the usual glue code between a separate CMP, GTM, and analytics.

  • Data Activation for real-time personalization

    Segment audiences from live behavior and trigger on-site or outbound actions without exporting every event to a second CDP first. Suited to regulated marketers who want activation on first-party data they control.

  • Selectable cloud residency (Azure + Elastx)

    Public cloud regions include Azure US, NL, DE, and HK plus Elastx Sweden; Enterprise private cloud spans 60+ Azure regions and Elastx. Business plan marketing highlights EU-operated Swedish hosting—pick region in procurement, not after go-live.

  • Regulated-industry packaging (GDPR tooling, HIPAA BAA path)

    DPA available on Business signup; Enterprise adds private cloud, higher action volumes, SLAs, and HIPAA Business Associate Agreements for healthcare marketing analytics. Vendor also claims ISO 27001 and SOC 2—request current certificates in diligence.

Assurance & compliance: Offen Fair Web Analytics vs Piwik PRO
Assurance & complianceLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: Piwik PROPiwik PRO
Independent security / architecture audit
Not found

No public third-party audit PDF found; coordinated disclosure via SECURITY.md email only.

Partial

Vendor states regular external security audits and SOC 2/ISO programs; no public third-party no-logs-style audit PDF reviewed for this draft. Request reports under NDA.

ISO 27001
Not found

No public ISO 27001 certification claim found on official site or docs.

Vendor claimed

Asserted on privacy-security and platform pages; certificate not independently re-verified against a public registry for this entry.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Vendor claimed

Vendor claims SOC 2 (comparison content references type II) and SOC 2-certified infrastructure; obtain current report in diligence.

GDPR / EU data protection
Vendor claimed

EU authors; opt-in, data minimization (no IP/UA), visitor access/erasure, short default retention, Datensparsamkeit framing. Self-host means operator remains controller—confirm your legal basis and notice.

Vendor claimed

EU legal entity, residency options, consent tooling, anonymization, and DPA. Compliance depends on customer configuration and purposes.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: no known US parent; product not delivered as US-hosted vendor SaaS. Operator-chosen infrastructure (including optional Heroku/US cloud) can still create CLOUD Act paths for stored ciphertext/metadata. Not legal advice.

Partial

No known US parent (Polish SA). Medium exposure due to Microsoft Azure as public/private cloud subprocessor and optional US region; Elastx Sweden is EU-operated alternative. Not legal advice.

Data processing agreement (B2B)
Not applicable

No multi-tenant vendor analytics processing relationship documented; operator self-hosts and is typically controller. Custom development/support via offen.software is separate from a standard SaaS DPA.

Vendor claimed

Business DPA linked from Business plan signup (piwik.pro/business-dpa/); Enterprise contracts expand terms.

EU AI Act
Not applicable

Web analytics metrics product; not an AI system product.

Not applicable

Analytics/activation platform; not marketed as an AI system provider. Customer AI use of exported data is out of product scope.

HIPAA / BAANot listed
Vendor claimed

HIPAA-oriented offering with BAA on Enterprise path per vendor; not available on all plan tiers.

Considerations & known limitations: Offen Fair Web Analytics vs Piwik PRO
Considerations & known limitationsLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: Piwik PROPiwik PRO
Opt-in undercounts absolute traffic
High

Visitors who never consent generate no events. Growth and content KPIs will not match cookieless tools or GA-style default measurement—treat as design, not a misconfiguration.

Not listed
You own uptime, backups, and secrets
Medium

No managed Offen cloud. Operators must run HTTPS/subdomain layout, set OFFEN_SECRET for stable sessions, configure SMTP for resets, and back up SQLite/SQL—plus avoid reverse proxies that log IPs if minimization is a goal.

Not listed
E2E crypto is vendor-claimed architecture
Medium

Browser-side encryption and server inability to decrypt are core claims from project docs/README, not independently audited in public materials found. Security-sensitive orgs should review source or commission assessment.

Not listed
Hosting choice reintroduces cloud jurisdiction
Medium

Self-host on US-group cloud or Heroku means CLOUD Act/subprocessor analysis shifts to your host even though Offen itself is Berlin-based OSS without a vendor SaaS region map.

Not listed
No public ISO/SOC or audit pack
Low

Procurement checklists that require vendor ISO 27001/SOC 2 will stall; evidence is open source and design docs, not cert registry entries.

Not listed
Essential metrics only
Medium

No heatmaps, session replay, advanced funnels, or product-analytics warehouse features. Wrong tool if the shortlist criterion is UX research depth rather than fair traffic statistics.

Not listed
US-group cloud (Azure) in hosting pathNot listed
Medium

Even with EU region selection, Azure introduces US-group infrastructure risk. Pin region, review SCCs/subprocessors, and escalate if policy forbids US cloud groups entirely.

Closed source and no classic self-hostNot listed
Medium

Cannot independently audit full source or run fully air-gapped on customer iron. Private cloud still involves vendor-managed stack on Azure/Elastx.

Certifications not independently verified hereNot listed
Low

ISO 27001, SOC 2, and HIPAA are vendor-claimed. Request certificates/reports and BAA text before treating them as assured.

Paid plans only after Core sunsetNot listed
Low

Free Core has been discontinued; evaluation relies on trials and paid Business/Enterprise metering by actions/domains.

Compliance depends on configurationNot listed
Medium

Anonymous modes and CNIL exemption require correct setup and purpose limitation. Misconfiguration can recreate the same legal exposure teams left GA to avoid.

Fit

Offen Fair Web Analytics

Best fit when

  • Public-sector, media, NGO, or mission-driven sites that need visitor-visible transparency and strict opt-in
  • EU teams that must keep analytics off third-party trackers and can run a small always-on instance
  • Operators who want first-party subdomain cookies, CSP-aware embedding, and no IP/User-Agent collection
  • Organisations evaluating fair-processing design over maximum measurement coverage
  • Teams comfortable with SQLite or SQL self-host ops (binary or Docker) and publishing their own privacy notice

Poor fit when

  • Product or growth teams that require near-complete traffic measurement without consent friction
  • Needs for heatmaps, session replay, funnels, or ad-ecosystem attribution comparable to Hotjar/Mixpanel/GA
  • Buyers seeking a vendor-managed multi-tenant analytics cloud with SLAs and a signed vendor DPA as processor
  • Large enterprises that require public ISO 27001/SOC 2 or third-party security audit packs before shortlist

Consider instead when

  • When: You want privacy-oriented analytics with managed EU hosting and lower consent friction

    Consider: Plausible Analytics or Pirsch Analytics

    Typically optimised for simpler cookieless or low-friction models and hosted plans; less radical visitor Auditorium design than Offen.

  • When: You need EU hosted privacy analytics with operator support and less self-host burden

    Consider: Friendly Analytics

    European catalog peer oriented to hosted privacy analytics; compare consent model and feature depth to Offen’s opt-in + E2E approach.

  • When: You need deep product analytics, funnels, or session UX tooling rather than fair traffic metrics

    Consider: Hotjar, Mixpanel, or a full GA4 stack (with legal review)

    Different category: richer product/UX analytics, different jurisdiction and subprocessor profile.

Piwik PRO

Best fit when

  • Regulated marketing/analytics teams that want one suite for measurement, consent, tags, and activation under a Polish legal entity
  • Public sector and EU enterprises that need selectable EU residency (e.g. Elastx Sweden or Azure NL/DE) plus a formal B2B DPA
  • Healthcare digital teams evaluating HIPAA-aware analytics with a signed BAA on Enterprise
  • Organizations leaving GA4 primarily for residency, no vendor ad-network reuse, and anonymous pre-consent measurement options
  • Teams that need enterprise reporting depth (custom reports, funnels, flows, attribution) beyond lightweight privacy analytics

Poor fit when

  • Buyers who mandate fully self-hosted open-source analytics with no cloud hypervisor vendor
  • Sites that only need simple cookieless page analytics without tag management or activation
  • Teams that refuse any US-group infrastructure (Azure appears in public hosting options even when EU regions are chosen)
  • Orgs seeking a free forever analytics tier (Core plan sunset; paid Business/Enterprise only)

Consider instead when

  • When: You need open-source code and true on-premises control

    Consider: Matomo (self-host) or Friendly Analytics / Matomo by Stackhero for managed Matomo

    Piwik PRO is proprietary cloud/private-cloud only.

  • When: You want minimal, cookieless EU analytics without enterprise suite complexity

    Consider: Plausible Analytics or Simple Analytics

    Far smaller feature surface; no HIPAA/CDP-style activation packaging.

  • When: You need a German enterprise analytics vendor with long public-sector presence

    Consider: etracker

    Different product depth and packaging—compare consent tooling and activation needs.

Open questions for due diligence

Offen Fair Web Analytics

  • Will your traffic and KPI model tolerate opt-in-only measurement after a pilot on a non-critical property?
  • Where will you host the instance (EU on-prem/VPS vs US-group cloud), and who holds OFFEN_SECRET and DB backups?
  • Do procurement rules require third-party audits or ISO/SOC that Offen does not publish?
  • Do you need a signed vendor DPA as processor, or is controller-only self-host acceptable to counsel?
  • Is subdomain + CSP (script-src/frame-src + unsafe-inline styles for the banner) feasible on your main site?

Piwik PRO

  • What exact subprocessor list and backup/DR locations apply to the contracted region (Azure vs Elastx) today?
  • Can the vendor provide current ISO 27001 certificate scope and SOC 2 Type II report under NDA?
  • For healthcare: which plan tier, region, and BAA wording cover the intended PHI workflows?
  • Does the Business Swedish hosting path avoid Azure entirely for production data, or only for selected components?
  • What residual free/legacy Core accounts remain, and what is the migration deadline for this tenant?