Piwik PRO
Commercial (closed-source SaaS / on-premises) SaaS only From $38/mo
← All tools

Piwik PRO Review (2026)

Enterprise GDPR-strict analytics suite — ISO 27001 + SOC 2 Type II + HIPAA BAA, multi-region SaaS, Polish closed-source (forked from Matomo 2016)

🇵🇱 Poland Since 2013 Commercial (closed-source SaaS / on-premises)

Piwik PRO is the only privacy-first analytics vendor in this directory with a signed HIPAA BAA, SOC 2 Type II across all five trust principles, and ISO 27001 in production. That trio matters when you're a hospital, a bank, or a public-sector department where the security questionnaire alone is a 200-row spreadsheet.

— Mark Sutton, editor
Main dashboard view
Editor score 4.3/5
From $38/mo Cloud only
GitHub ★ 0 0 forks · last commit —
Hosting SaaS only EU hosted · US hosted
Privacy passport

Piwik PRO compliance at a glance

GDPR posture, sub-processors under DPA, per-jurisdiction stance, and encryption — everything a procurement team checks.

GDPR Compliant EU General Data Protection Regulation EU's omnibus privacy law requiring a lawful basis for processing personal data (consent, legitimate interest, etc.). Applies to anyone handling EU-resident data. Piwik PRO's posture: Consent or legitimate interest.
CA
CCPA Compliant California Consumer Privacy Act California Consumer Privacy Act — rights for California residents (access, deletion, opt-out of sales). Triggered at $25M revenue or 50k+ CA-consumer records.
UK PECR Compliant UK Privacy and Electronic Communications Regulations UK Privacy and Electronic Communications Regulations sit on top of GDPR specifically for cookies and electronic marketing. PECR Reg 6 governs analytics-cookie consent.
SOC 2 · II Compliant SOC 2 Type II SOC 2 Type II — independent audit verifying security/availability controls operate effectively over 6+ months. Standard B2B procurement requirement.
ISO27001
ISO 27001 Compliant ISO/IEC 27001 information-security ISO/IEC 27001 — international information-security management standard, certified by accredited bodies on a 3-year renewal cycle.
HIPAA Compliant US HIPAA (with BAA) US health-data law requiring a Business Associate Agreement (BAA) for any tool touching protected health information. Without BAA the tool cannot legally process PHI.

Per-jurisdiction posture

🇫🇷
France CNIL Banner recommended Default mode uses cookies + session fingerprints; consent typically required. Anonymous Mode is configurable for banner-free posture.
France · CNIL Default mode uses cookies + session fingerprints; consent typically required. Anonymous Mode is configurable for banner-free posture.
🇬🇧
United Kingdom UK ICO / PECR Banner recommended Default cookies trigger PECR Reg 6 consent. Anonymous Mode bypasses.
United Kingdom · UK ICO / PECR Default cookies trigger PECR Reg 6 consent. Anonymous Mode bypasses.
🇩🇪
Germany TTDSG Banner recommended TTDSG §25 applies to cookie/storage default; Anonymous Mode bypasses.
Germany · TTDSG TTDSG §25 applies to cookie/storage default; Anonymous Mode bypasses.
🇮🇹
Italy Garante Banner required Italian Garante is strictest. Default mode requires consent banner; even Anonymous Mode benefits from disclosure.
Italy · Garante Italian Garante is strictest. Default mode requires consent banner; even Anonymous Mode benefits from disclosure.

Sub-processors (10)

GDPR Art. 28 disclosure — third parties under DPA that may receive data.

Microsoft Ireland Operations Limited (Azure) Hosting (Germany / Netherlands / United States / Hong Kong regions) Ireland
Elastx AB Hosting (Sweden, EU-only Business tier) SE
Orange Business Services / Flexible Engine Hosting (France region) France
Amazon Web Services Database exports (Frankfurt) Germany
HubSpot, Inc. CRM / marketing automation United States
Intercom, Inc. Customer support (AI-enabled) United States
Stonly Onboarding / in-app guides France
Paddle.com Market Limited Merchant of record / billing United Kingdom
Cookie Information A/S Sister company / consent management (post-2023 merger) DK
Fraud0 GmbH Fraud / bot prevention Germany

Collected

  • URLs visited and page titles
  • HTTP referrer + UTM parameters
  • Browser, OS, device type, screen resolution
  • Country / region / city geolocation
  • Custom events with properties
  • Cookie identifiers (default mode) — disable via Anonymous Tracking Mode
  • IP address (default mode, configurable masking)

Explicitly NOT collected

  • (in Anonymous Tracking Mode) cookies, session data, fingerprints
  • Default visitor-level PII unless customer enables it
Data retention

Default 60 months for website analytics. Configurable to 14/25 months on lower tiers. Business plan retains 25 months.

Encryption
  • In transit: HTTPS, dedicated firewalls, cryptographically secure key pairs
  • At rest: AES-256 (explicitly stated for HIPAA hosting; standard for all tiers)
DPA Yes · manual
AI & Modern Capabilities

How Piwik PRO works with AI agents

Tier 2 — AI add-ons — 2 available + 1 beta. Selective AI footprint vs full suite.

AI Chat Not yet

Conversational natural-language interface

Natural-language access via external MCP clients only

MCP Server Available

Model Context Protocol — Claude / Cursor / Codex

Official PiwikPRO/mcp Python server on GitHub + PyPI — controls Analytics/CDP/Tag Manager via Claude/Cursor Source ↗

Agent API Not yet

Programmatic AI-agent endpoints

Not advertised by vendor

AI Insights Beta

Anomaly detection / hypothesis / summaries

Anomaly-detection experiment opt-in via Settings (recruiting closed but feature exists) Source ↗

Export for AI Available

Structured export formatted for LLM ingestion

"AI-ready data" structured/timestamped/session-scoped exports formatted for AI pipelines Source ↗

Strengths & weaknesses

What makes Piwik PRO worth a look — and where it falls short.

Strengths 8

  • ISO 27001 + SOC 2 Type II (all 5 trust principles) + HIPAA BAA
  • Multi-region pinning at provisioning (SE / DE / NL / FR / US / HK)
  • Integrated suite — Analytics + Tag Manager + Consent Manager + CDP
  • Healthcare-credible — Boston Children's, Rochester Regional, Children's Nebraska as named customers
  • On-premises deployment available (Docker / Kubernetes)
  • GA4-shaped UX — low migration cost for analysts
  • Three configurable privacy modes (cookies / no-cookies-with-session / fully anonymous)
  • Multi-language support (English / Polish / German / French)

Weaknesses 6

  • Closed-source — not auditable like Matomo
  • No free tier as of 2025 (Core plan discontinued)
  • Heavy ~86 KB gzipped tracker (3-4× Plausible)
  • Default mode requires consent banner (Anonymous Mode is a downgrade)
  • Pricing opacity at Enterprise — three of four tiers are "contact sales"
  • DNT signal not addressed publicly by vendor

Feature matrix

All 38 verified checks across 4 categories. Hover any row for the editor's note.

Tracking & Reporting 15

  • Pageviews & visitors Yes
  • Live visitor count Yes
  • Top pages report Yes
  • Top referrers Yes
  • UTM campaign tracking Yes
  • Country & city breakdown Yes
  • Device, browser, OS Yes
  • Bounce / engagement Yes
  • Time on site Yes
  • Custom events Yes
  • Goals / conversions Yes
  • Funnels Yes
  • Outbound link tracking Yes
  • File download tracking Yes
  • 404 / error tracking Yes

Privacy & Compliance 9

  • Cookieless by default ~Partial
  • No personal data collected ~Partial
  • GDPR-compliant out of the box ~Partial
  • Data hosted in EU Yes
  • Data hosted in US Yes
  • Self-hostable ~Partial
  • Open source No
  • Data retention period 60
  • Bot & spam filtering Yes

Setup & Integrations 10

  • Script weight (KB) 86
  • Single-snippet install Yes
  • WordPress plugin Yes
  • Proxy / first-party domain Yes
  • Public API Yes
  • Data export (CSV/JSON) Yes
  • Google Search Console connector ~Partial
  • Email digests Yes
  • Slack / webhook alerts Yes
  • Public shareable dashboard Yes

Pricing & Plans 4

  • Free tier exists No
  • Entry price ($/mo) $38/mo
  • Price at 100k pageviews $38/mo
  • Unlimited sites on entry plan ~Partial

Piwik PRO vs alternatives

How it compares to the closest 3 rivals on key buyer-decision fields.

Pirsch

Pirsch

Cookieless EU-hosted analytics built in Germany, with open-source AGPLv3 core

  • From$6/mo
  • HostingSaaS only
  • EU-hostedYes
  • CookielessYes
Plausible

Plausible

Privacy-first GA alternative, EU-hosted, simple dashboard

  • From$9/mo
  • HostingSelf-host ✓
  • EU-hostedYes
  • CookielessYes

Compare Piwik PRO against

Side-by-side comparisons with other tools in the directory.

Pricing tiers

Real plans, real numbers — pulled from piwik.pro (verified May 2026).

Trial

Trial/30 days

Full Business access

  • ✓ No card required
Business

$38/mo

up to 2M actions

  • ✓ EU-only Sweden (Elastx)
  • ✓ 25-month retention
  • ✓ DPA included
  • ✓ SOC 2 NOT included
  • ✓ HIPAA NOT supported
Data Fundamentals

$396/mo

1M-100M actions

  • ✓ Multi-region
  • ✓ SOC 2 included
  • ✓ HIPAA NOT supported
  • ✓ Annual contract
Trusted Insights

Custom

1M-500M actions

  • ✓ SOC 2 included
  • ✓ HIPAA BAA supported
  • ✓ Multi-region
  • ✓ CDP unlocked
  • ✓ Contact sales
Secure Intelligence

Custom

2M+ unlimited

  • ✓ Private cloud
  • ✓ SOC 2 + BAA
  • ✓ 60+ regions
  • ✓ Custom SLA
  • ✓ Contact sales

Tech specs

Stack, repo health, deployment options — for engineers evaluating self-host.

Stack

  • Written inClosed-source (no public stack disclosure)
  • HostingMicrosoft Azure (multi-region) · Elastx SE · Orange Flexible Engine FR
  • CDNNot disclosed
  • Tag layerBuilt-in Tag Manager + Consent Manager + CDP
  • LicenseCommercial (closed-source SaaS / on-premises)
  • Min specsOn-premises specs per quote

GitHub github.com/PiwikPRO

  • Stars★ 0
  • Forks0
  • Open issues0
  • Last commit

Deploy

  • · Cloud SaaS (multi-region pinning)
  • · On-premises Analytics Suite (Docker / Kubernetes, commercial agreement)

Used by

Companies and projects that publicly trust Piwik PRO.

Boston Children's Hospital
Boston Medical Center
Rochester Regional Health
Children's Hospital & Medical Center, Nebraska
Shepherd Center
Mark Sutton

Editor review

Independently reviewed by Mark Sutton, cross-checked against vendor documentation. Click any panel to expand.

+ What it does well

Piwik PRO is the only privacy-first analytics vendor in this directory with a signed HIPAA BAA, SOC 2 Type II across all five trust principles, and ISO 27001 in production. That trio matters when you're a hospital, a bank, or a public-sector department where the security questionnaire alone is a 200-row spreadsheet.

Official MCP server published on GitHub + PyPI (PiwikPRO/mcp) — controls Analytics, CDP, and Tag Manager via Claude or Cursor with natural-language queries. Plus a dedicated "AI-ready data" export pipeline (piwik.pro/ai-ready-data) that ships structured, timestamped, session-scoped data formatted for AI consumption. Plus opt-in beta anomaly detection inside Settings. Three AI/MCP capabilities — most in the directory.

Integrated suite (Analytics + Tag Manager + Consent Manager + Customer Data Platform) means one vendor, one DPA, one invoice. Most rivals make you stitch together three.

Multi-region data residency is real and customer-selectable: Sweden, Germany, Netherlands, France for the EU; US Azure for HIPAA; Hong Kong for APAC. You pin where the data lives at provisioning, not after a support ticket.

The GA4-shaped UX trims migration cost — analysts who used GA4 last week can run reports on day one.

Weaknesses & gotchas

Piwik PRO is closed-source and priced for enterprise. The freemium Core plan was discontinued in 2025, so the floor is €35/mo Business or €366/mo for SOC 2 / multi-region, with three of four tiers gated behind sales calls. If you're an indie blog or a 50k-pageview SaaS, this is not your tool.

The tracking script is heavy — ~86 KB gzipped, ~40-80× the size of Plausible (~1KB) or Fathom (~2KB) — which dents Core Web Vitals on slow connections.

The default mode still uses cookies and session fingerprints, so unlike Plausible or Fathom you typically still need a consent banner. (The Anonymous Mode exists, but it's a deliberate downgrade.)

The DNT browser signal is not addressed publicly by the vendor — verify behaviour during procurement.

Best for

Best for: regulated enterprises that need a signed BAA or SOC 2 evidence in a vendor questionnaire. Healthcare systems (Boston Children's, Rochester Regional, Children's Nebraska are public references), banks under DORA/EBA, insurers, government departments, EU-only B2B with strict Schrems II posture.

Real value at the Trusted Insights tier (~€800-2k+/mo). That's where you unlock HIPAA BAA, SOC 2 evidence, multi-region pinning, and the CDP. Below that you're paying for Tag Manager + Analytics that other privacy vendors give you cheaper.

Not for indie sites, side projects, blogs, or anything under ~€20k ARR. The €35/mo Business floor is technically reachable, but you'd see better value in Plausible or Umami. The Piwik PRO sales cycle, security questionnaire, and onboarding workflow are designed for procurement, not solo founders.

Setup walkthrough

Piwik PRO ships as a single Tag Manager container snippet that you paste once; everything else (Analytics, Consent Manager, custom events) is configured inside the Tag Manager UI. Expect ~86 KB gzipped on first paint — async, but worth measuring on mobile LCP.

WordPress: official plugin handles the snippet, opt-out, and Consent Manager hand-off. GTM users: Piwik PRO publishes a GTM template so you can fire it as a tag inside an existing Google Tag Manager container — useful during migration.

Server-side / first-party proxy: Enterprise tiers include a server-side container (CNAME + custom domain) so the tracker loads from yourdomain.com — bypasses ad blockers and improves data accuracy.

Mobile: native SDKs for iOS, Android, Flutter, React Native are published on github.com/PiwikPRO. HIPAA setup: sign BAA first → vendor provisions Azure US workspace → activate before any patient data is collected.

Migrating from GA4

From GA4: the data model maps almost 1:1 (events, parameters, user properties, custom dimensions). Piwik PRO publishes a migration guide; in practice, ship Piwik PRO in parallel for 30-60 days, reconcile core KPIs, then sunset GA4. Many teams keep GA4 running for Google Ads attribution while Piwik PRO becomes the source of truth — Piwik PRO's BigQuery export covers the analytics warehouse half.

From Matomo Cloud or Matomo On-Prem: the harder migration despite the shared lineage — Piwik PRO's data model diverged after the 2016 fork and event schemas don't translate cleanly. Expect to redefine goals, custom variables, and segment definitions. The win is the compliance package (HIPAA BAA, SOC 2) you can't get from Matomo. If you're moving because Matomo Cloud's pricing scaled poorly above 5-10M actions or because you need a BAA, the migration cost is justified at Trusted Insights tier and above.

Help & FAQ

Where to get help with Piwik PRO and the questions buyers email us about.

Support

HoursBusiness hours + 24/7 critical (Enterprise)Europe/Warsaw (UTC+1/+2)
ChannelsEmail · Phone · Live chat · Intercom
LanguagesEnglish, Polish, German, French
Response SLA~24h

FAQ (7)

Will Piwik PRO sign a Business Associate Agreement for HIPAA workloads?

Yes, on the Trusted Insights and Secure Intelligence Enterprise tiers. The BAA is customised and signed before any patient data is collected; HIPAA workloads run on Microsoft Azure US with AES-256 encryption. Business and Data Fundamentals tiers do NOT support BAAs.

Can we keep all customer data inside the EU?

Yes. Choose Sweden (Elastx), Netherlands (Azure), Germany (Azure), or France (Orange Flexible Engine) at provisioning. Business tier is EU-only Sweden by default. Some support tooling (Intercom) is US-hosted under SCCs.

What certifications can we verify in our vendor risk review?

ISO 27001 (August 2024), SOC 2 Type II (September 2022, all five trust principles, 107-page report on 129 controls), and HIPAA self-attestation with BAA. SOC 2 report available under NDA from your account executive.

Is Piwik PRO related to Matomo / Piwik open source?

No, separately operated. Piwik PRO is a Polish company founded 2013 that started as consulting around the open-source Piwik project. In 2016 it forked off and built its own proprietary suite. Piwik PRO is closed-source enterprise SaaS; Matomo (InnoCraft NZ) is the GPL-3.0 open-source line.

Can we deploy on-premises on our own Kubernetes cluster?

Yes. The Piwik PRO Analytics Suite is offered as an on-premises deployment (Docker / Kubernetes). Separate DPA applies, pricing is per-quote, includes dedicated technical contact.

What happens to our data on contract termination?

Per the standard DPA, customer data is exported in JSON/CSV/XML on request and deleted from production systems within the contractual window. Default analytics retention is configurable (14, 25, or 60 months); Business tier retains 25 months.

Does Piwik PRO honour the Do Not Track browser signal?

Not disclosed by vendor. Neither the privacy policy nor privacy-security page explicitly addresses DNT. Anonymous Tracking Mode and the in-house Consent Manager are the recommended privacy controls; verify DNT behaviour via account executive.