Built for the privacy-first era. Your data stays in the EU, processed under European law, with enterprise-grade security at every layer.
Data sovereignty is not a feature toggle — it is an architectural decision. Every GetCAPI container is deployed exclusively in EU regions, ensuring your tracking data never leaves European jurisdiction.
All containers run in Frankfurt (eu-west3) and Netherlands (eu-west4). No exceptions.
Data processed and stored exclusively under EU/EEA data protection law.
No data transfers to countries without an adequacy decision unless Standard Contractual Clauses are in place.
Getia AS is incorporated in Norway and governed by Norwegian and EU data protection regulations.
From collection to storage to forwarding
We use Google Cloud Platform's EU regions for container hosting. While GCP is a US company, all GetCAPI data is processed and stored exclusively in EU data centers, protected by Standard Contractual Clauses (SCCs) and GCP's EU data residency commitments.
We build to the standards your legal and compliance teams require. Not as a checkbox exercise, but as foundational architecture.
General Data Protection Regulation
Information Security Management
Enterprise Plan
Consent Mode v2 Ready
Enterprise-grade security is not reserved for enterprise plans. Every GetCAPI account benefits from the same security infrastructure.
All personally identifiable information is automatically hashed (SHA-256) before forwarding to any ad platform. Raw PII never leaves your container.
Built-in IP address anonymization strips the last octet before processing. Fully GDPR-compliant by default, no configuration needed.
Role-based access control (RBAC), multi-factor authentication (MFA), SSO via SAML on Business+, and complete audit logs for every action.
TLS 1.3 for all data in transit. AES-256 encryption at rest. Encrypted database backups with geo-redundancy within EU regions.
24/7 infrastructure monitoring with anomaly detection. Automated alerts for unusual traffic patterns, failed auth attempts, and system health.
Documented IR procedures following NIST framework. 48-hour breach notification commitment. Post-mortem reports for all incidents.
All the documentation your legal team needs, readily available.
GDPR-compliant DPA automatically incorporated into your agreement
How we collect, use, and protect your data
Service terms, SLAs, and usage policies
Complete list of third-party processors with notification of changes
Responsible disclosure policy and security contact information