For IT & Security

Security & Compliance — transparent, isolated per client

How we host, process and protect data. Written for IT professionals evaluating Server Side Support for internal approval.

What you need to know

Nine core aspects that IT reviews usually assess. Concise. Ask follow-up questions via the security contact below.

Hosting & data residency

  • All client VPSes run in Amsterdam (UpCloud, nl-ams1)
  • GTM server containers 100% within the EU
  • Dashboard on Google Cloud Run in europe-west1 (Belgium)
  • No data transfer outside the EU without an explicit client choice (e.g. Meta CAPI to Meta)

Per-client isolation

  • Dedicated VPS per website — no multi-tenancy at the infrastructure level
  • Own Docker container + own GTM server container ID
  • Own SSL certificate per hostname via Let's Encrypt
  • Per-hostname nginx server blocks (no certificate SAN overlap)

Encryption

  • TLS 1.2+ required, HTTPS redirect enforced
  • Let's Encrypt certificates, auto-renew via certbot timer
  • Data at rest: UpCloud block-storage encryption
  • No HTTP fallback available

Authentication & access

  • Login via Google OAuth (SSO with the client's own Google account)
  • Multi-user per client with a primary-owner role for provisioning
  • Admin endpoints IAM-gated on Cloud Run (service-account-only)
  • No passwords stored → no credential-leak risk
  • OAuth callback with CSRF protection via a signed state cookie (login-CSRF mitigation)

Data minimisation

  • Live event payloads are not logged persistently
  • Only aggregated request volume in the client dashboard
  • No PII storage in our systems
  • The public tracking scanner stores only cookie names from scanned sites — no values or content. Scan results expire automatically after 24 hours (Firestore TTL).
  • Enhanced Matching & CAPI: SHA-256 hashing server-side before transmission
  • First-party cookies on the client domain, no cross-site tracking
  • GA4 Data API reads via our service account (Viewer role only on the client property, OAuth scope limited to analytics.manage.users + analytics.readonly). From the client's GA4 we store only aggregate event counts per event name — no user IDs, amounts or session details.

Security hardening

  • Unattended upgrades on every VPS (auto-patch Ubuntu)
  • fail2ban active on the SSH port
  • Self-heal systemd timer restores containers on boot issues
  • Rate limiting on all public endpoints
  • Idempotent webhooks via atomic claims (Firestore transactions)
  • HTTP security headers on all public services: Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy
  • Server-side request forgery (SSRF) mitigation on the public scanner: outbound requests are resolved against an IP blocklist (loopback, private, link-local, cloud-metadata)
  • nginx regex allowlist on user-input query parameters (click-ID endpoints) — no cookie-attribute-injection vector

Consent Mode v2

  • Enabled by default on all server containers
  • Granted / denied signals are passed through correctly to Google & Meta
  • Works with Cookiebot, Usercentrics, Iubenda, CookieYes and other CMPs
  • The client retains full control over what is and isn't sent

GDPR

  • Our role: data processor (the client is the controller)
  • DPA (Data Processing Agreement) available on request
  • EU data residency guaranteed for our own infrastructure
  • Right to erasure: via the dashboard or email within 30 days
  • Breach notification: within 72 hours per GDPR art. 33

Business continuity

  • Cancellable monthly, no notice period
  • Export of the GTM server container possible on cancellation
  • No vendor lock-in on data or containers
  • On business closure: a 30-day migration window with all exports

Subprocessors

Full list of third parties that may process data in the Server Side Support stack.

UpCloud
VPS hosting for client tracking servers
Amsterdam (NL) · ISO 27001
Google Cloud
Dashboard + Firestore + Cloud Run microservices
europe-west1 (BE)
Mollie
Payments (iDEAL, credit card, SEPA)
Amsterdam (NL)
Rompslomp
Invoicing + PDF generation
Netherlands
Let's Encrypt
SSL/TLS certificates (public CA)
Internet Security Research Group (US non-profit)
Anthropic
AI chat support (optional, per session)
US — no persistent data collection

Honest about what we don't (yet) have

No ISO 27001 or SOC 2 certification. We're a Dutch SME SaaS; formal certification is on the roadmap but not active in 2026. If your internal compliance standard requires certification, request our DPA first — it covers most GDPR-related review questions, and we can answer a targeted security questionnaire.

Security contact

Questions about a DPA, pentest reports, security questionnaires or incident notifications.

Email

support@ga4support.nl

For formal DPA requests, security questionnaires or incident reporting. Reply within 1 business day.

Direct contact

WhatsApp · +31 6 25 11 82 13

For quick questions during vendor intake or pentest planning.

Ready for internal review?

Request the DPA now and place it alongside your intake checklist.

Request a DPA