Friendly Analytics is designed with privacy and data minimisation in mind. In the standard configuration used for our Essentials and Professional subscriptions, analytics cookies are disabled and IP addresses are anonymised immediately before being stored. The standard configuration is designed so that no personal data is stored in Friendly Analytics.
Enterprise subscriptions can be configured individually. This may include the use of cookies or other features and data that can involve personal data. The applicable retention periods and privacy requirements therefore depend partly on the individual configuration.
The following sections explain which data Friendly Analytics retains, for how long, and which responsibilities remain with you as our customer.
In accordance with the GDPR and the Swiss FADP, we follow these principles whenever we process data:
We only retain data where there is a clear purpose for doing so. We define this purpose for each data category (see table below), document it and review it regularly. Once the purpose no longer applies, we delete the data.
We only collect and retain data that we genuinely need to operate our services, provide support or meet legal requirements. Features are designed to avoid generating unnecessary data.
We retain data where this is necessary to fulfil our contractual obligations, handle support requests, ensure technical quality or comply with legal requirements. Retention periods are defined for each data category and supported by a clear rationale (see table below).
Once the defined retention period has expired, data is deleted automatically. This applies both to production systems and to actively used archive areas.
We maintain a central overview of all retention periods. We can explain at any time why specific data is retained, for how long, and how it is deleted.
Deletion processes are automated and tested regularly. Access to systems is protected, and relevant activities are logged. Internal responsibilities for data retention and deletion are clearly defined.
Backups are used exclusively for recovery in the event of an emergency. They are not used for production purposes. Data is not selectively restored from backups and is automatically removed as part of the backup rotation.
Friendly is responsible for the retention and deletion of the analytics data technically generated and stored through the operation of Friendly Analytics.
This primarily includes:
Our standard configuration is designed to minimise the amount of data collected. In particular, we use cookieless tracking and anonymise IP addresses before storing them.
Retention periods are defined for each data category and supported by a clear rationale. Detailed raw analytics data is retained for a limited period, while aggregated historical data and reports can remain available for long-term analysis.
The following retention periods apply:
| Data category | Retention period | Purpose / rationale for retention |
|---|---|---|
| Raw analytics data | **24 months (Standard) | |
| Contractually agreed (Enterprise)** | Detailed analytics data is retained to calculate reports and enable detailed analysis, segmentation and troubleshooting. Once the retention period expires, the raw data is deleted automatically. | |
| Archived analytics data | No expiry | Aggregated historical analytics data is retained for long-term analysis and comparisons. This may also include historical analytics data imported from external systems such as Google Analytics. |
| Reports | No expiry | Reports remain available so that historical metrics, trends and developments can be analysed and compared over time. |
The 24-month raw-data retention period applies to all Friendly-hosted Starter and Professional instances.
For Enterprise instances, the retention period for raw analytics data is agreed individually as part of the customer configuration. If an Enterprise configuration introduces additional data categories, their retention can also be agreed individually.