GDPR & KVKK Compliant

Built for privacy, not around it

Lynq Studio is designed from the ground up to respect user privacy while giving you the web and app analytics data you need. No workarounds, no gray areas.

No personal data collected

We don't collect names, emails, or IP addresses from website or app visitors. Visitor IDs are randomly generated and cannot be linked to a real person.

First-party only

Our tracking runs entirely on your domain. No data is sent to third-party servers. No cross-site tracking. No advertising networks involved.

EU-hosted infrastructure

All data is processed and stored within the European Union. No transfers to the US or other non-EU countries.

Privacy by design

Raw IP addresses never reach the disk. They are hashed with a salt that changes daily, so records from different days cannot be linked back together.

Data retention controls

You control how long data is kept. Default retention is 2 years. You can request deletion of all data at any time.

Full data portability

Export everything as CSV or JSON whenever you want. The dataset is yours, and it leaves with you if you go.

Do your visitors need a cookie consent banner?

In the EU and the UK, yes. Lynq stores a first-party cookie on the visitor's device, and Article 5(3) of the ePrivacy Directive requires consent for storing anything on a device that is not strictly necessary to deliver the page. That rule applies to the act of storing, not to how sensitive the stored value is, so a random identifier still falls under it.

We could avoid the banner by forgetting every visitor at midnight, which is how the cookieless analytics tools do it. We do not, because connecting a campaign click to a purchase weeks later is the reason the product exists. That is a deliberate trade: you run a banner, and in exchange the attribution actually holds.

Once consent is given, the analytics processing that follows rests on the website owner's legitimate interest under Article 6(1)(f), supported by the safeguards listed on this page. Part of every implementation is wiring the tracker to your consent platform so nothing fires before permission exists.

Requirements differ by market and by how you use the data, so treat this as our reading rather than legal advice, and confirm it with your own counsel.

KVKK Compliance (Turkey)

Lynq Studio complies with the Turkish Personal Data Protection Law (KVKK, Law No. 6698). Our approach:

  • Visitors are recorded under a pseudonymous identifier, with no name, email or contact detail attached
  • Data processed within the EU, which KVKK recognises as adequate protection
  • Customer data handled per KVKK Articles 5 and 6 (contractual necessity)
  • Data deletion available upon request per KVKK Article 7

What we collect vs. what we don't

What we collect

  • Page URLs, including the query string, and page titles
  • Referrer URLs
  • Browser type and version
  • Operating system
  • Device type (mobile/desktop)
  • Country and city, resolved from the IP before it is hashed
  • Screen resolution
  • Browser language
  • UTM campaign parameters
  • Custom events and conversions (if configured)
  • A pseudonymous visitor ID, kept for two years

What we never collect

  • Names or email addresses, unless you send them yourself
  • Raw IP addresses, which are hashed and never written to disk
  • Browser fingerprints
  • Cross-site browsing history
  • Form inputs or keystrokes
  • Financial or health data
  • Social media profiles
  • Advertising identifiers
  • Third-party cookies

The script cannot read your forms. It can only store what you choose to put in a URL or an event property, which is why we review those parameters with you during setup.