Last updated · 2026-08-31

04 · In practice

One tenant.One server. Yours.

juuna keeps each customer’s analytics on a dedicated instance provisioned in the EU, with its own server and its own Postgres, no third parties in the tracking path, and erasure and export built into the dashboard. It is a tool for your GDPR posture, not a compliance badge.

I

The premise

Where does the data actually live?

Every paid plan is one machine rented for you alone, provisioned in the EU, running its own Postgres. There is no shared warehouse and no pooled cluster: your visitors’ events land on your instance and mix with nobody else’s. When you cancel, we hand you a full export, then destroy the instance and its backups.

The tracking path contains no third parties. The script loads from your instance, events post to your instance, and enrichment happens on the box: even the IP-to-geo lookup is a local GeoLite2 database on the instance, not a call to a geolocation service. The parties involved are you, us operating the instance for you, and the data centre the machine stands in. That is the whole list.

II

The posture

What does juuna do for a GDPR posture?

Compliance is a property of your processing, not of any product, so juuna does not claim it for you. What it supplies is the machinery a defensible posture leans on: collection kept minimal, retention that actually expires, and subject rights reduced to a dashboard action.

Concretely: raw events are kept about 90 days by default and then dropped, while long-range dashboards read aggregate rollups that carry no identifiers. Session recordings are masked by default, never store IPs, and expire after about 30 days. An erasure request removes a person’s events, traits and recordings in one transaction. Export to CSV is a dashboard view, not a support ticket.

Consent, lawful basis and your records of processing remain decisions you make with counsel. What juuna changes is the length of the appendix: one instance, one region, and no subprocessor chain inside the tracking path to enumerate.

III

The architecture

What does single-tenant change?

With multi-tenant analytics, your visitors’ data lives inside a vendor’s shared infrastructure, and your data map inherits that vendor’s subprocessor list. Single-tenant collapses the picture: the blast radius, the access model and the answer to “where exactly is it” are all one machine you can point at.

It shows up in the boring places. Backups are dumps of your database alone, taken daily with the last seven kept, and on request hourly dumps can be written to an S3-compatible bucket that you own. Leaving is not a deletion request in someone’s queue; it is your machine being destroyed.

IV

The ledger

The facts a privacy review asks for

Tenancy
One dedicated instance per customer: own server, own Postgres
Region
Provisioned in the EU
Third parties in the tracking path
None; geo enrichment is a local database on the instance
Raw event retention
About 90 days by default; long-range rollups carry no identifiers
Session recordings
Masked by default, no IPs stored, kept about 30 days by default
Erasure
One transaction removes a person: events, traits, recordings
Export
CSV from the dashboard, any time
On cancellation
Full export handed over, then the instance and its backups are destroyed

§

Asked and answered

Is juuna GDPR compliant?
Compliance describes your processing, not a product, so no vendor can truthfully stamp it for you. What juuna gives you is the posture’s raw material: single-tenant EU hosting, minimal collection, scheduled deletion, one-transaction erasure and CSV export. Lawful basis and consent remain your calls, made with your counsel.
Is Google Analytics illegal in Europe?
Not a question a vendor should answer for you, and decisions have moved back and forth as transfer frameworks changed. The practical observation is narrower: with juuna the transfer question barely arises, because the data stays on one EU instance and no third party sits in the tracking path.
Where exactly does my data live?
On one dedicated machine in an EU data centre, in a Postgres that serves only you. Nothing about your traffic is processed anywhere else, and backups are dumps of that one database. If you carry a residency requirement, write to us first and we will say plainly whether we can meet it.
How do erasure requests work?
The dashboard has an erase-a-person view: give it a user id or an anonymous id and one transaction deletes the matching events, identity traits and session recordings, including activity from before the person was identified. It covers your instance; systems outside juuna remain yours to handle.

Keep reading

Cookieless analytics · Session replay · juuna vs Matomo · juuna vs Google Analytics · juuna vs Plausible · The integration docs · Pricing

Keep the next answer on your own server.

Flat plans, everything included; every paid plan is a dedicated instance of your own.