Privacy Policy — visz.ai
Final version. An external legal review is still pending.
Covers visz.ai and app.visz.ai. For data our snippet collects on customers' sites, the respective customer is the controller (section 12 and DPA).
1. Controller
Domantas Paradauskas (sole proprietorship), Talstr. 29, 69231 Rauenberg, Germany. Email: info@visz.ai (phone: see Imprint).
2. Data Protection Officer
A data protection officer must be appointed for visz.ai. The obligation follows from § 38(1) sentence 2 BDSG, because our processing is subject to a data protection impact assessment under Art. 35 GDPR, and from Art. 37(1)(b) GDPR, because our core activity consists of the regular and systematic monitoring of website visitors. The appointment of an external data protection officer has been initiated and will take place before paid operation starts. Until then you can reach us on all data protection matters at info@visz.ai; you can exercise your rights under section 16 through that address without restriction.
3. Data we process (account and website)
Email, name (optional), password (hash only), 2FA secret (encrypted); Google/Apple OAuth (email, display name, verify status, permanent provider user ID, sign-in tokens — section 7); dashboard usage (login times, device/browser, anonymised IP); website logs (anonymised IP, time, user agent); cookies (section 14).
4. Purposes
Service delivery, account management, security, bot protection, error diagnostics, legal duties.
5. Legal bases
Art. 6(1)(b) contract (account/service); Art. 6(1)(f) legitimate interest (security, anonymised IP, bot detection); Art. 6(1)(a) consent (non-essential cookies); Art. 6(1)(c) legal obligation (record retention).
6. Account data and retention
Until 30 days after account deletion (grace period), then permanent erasure. Periods: section 15.
7. Third-party sign-in (OAuth)
Sign-in with Google or Apple: from the provider we receive your email address, your display name and whether the address is verified there. We do not take a profile picture. Beyond that, the sign-in itself produces technical values that we store and that we disclose here rather than leave unsaid: the permanent identifier under which the provider holds your account (with Apple the “sub” value), the access token and the identity token of the sign-in, any refresh token, and the scope of the request. These values are stored unencrypted in our database; we do not use them to call any provider interface. If you disconnect the sign-in method in Settings under Security, they are deleted immediately; if you delete your account, they are erased together with the rest of your account data once the 30-day grace period has passed (sections 6 and 15). Google (Ireland/USA) and Apple (Ireland/USA) act as their own controllers in this respect; for transfers to the USA we rely on the EU-US Data Privacy Framework or EU Standard Contractual Clauses (section 11). Apple offers “Hide My Email”: if you choose it, we receive an anonymous forwarding address from Apple instead of your address and do not learn your real one. If you sign in through one of these providers with an address that already has an account, we link the provider to that account instead of creating a second one. There are two exceptions, which we name rather than promise something and then do otherwise. If the email address of the existing account has not been verified yet, we refuse the link and show an error message; this is deliberate, because otherwise an account created under someone else's never-verified address could be taken over this way. In that case, verify your address first, or connect the provider while signed in, in Settings under Security. And if you choose “Hide My Email” with Apple, there is no shared address: a second, separate account is created, and it currently cannot be connected to the existing one afterwards either, because the two addresses do not match. You can see and disconnect the sign-in methods linked to your account in Settings under Security.
8. Security and 2FA
Argon2id hashing, server-side sessions, optional TOTP 2FA and hashed backup codes. The two-factor prompt protects sign-in with email address and password. Sign-in with Google or Apple does not pass through it: there, the provider's own check alone decides access, and we do not ask for the second factor on that path even if you have enabled it. So secure your account at the provider with its own two-factor method, or disconnect that sign-in method in Settings under Security. Token lifetimes: verify 24 hours, reset 1 hour, magic link 20 minutes, invite 7 days, single-use.
9. Payment data
Paid plans are processed by payment providers: Stripe Payments Europe, Ltd. (Ireland) for direct purchases and — where installed via the Shopify App Store — Shopify International Ltd. (Ireland). Billing is set up so that the respective provider acts as merchant of record, i.e. is the seller towards you, collects the fee and issues the invoice in its own name; who issues the invoice in a given case is stated on the invoice itself. Full payment details — card number, bank details — never reach us; they are entered exclusively at the provider. We transmit to the provider your account email address as a customer identifier and the contractual details needed for billing (chosen plan, billing period, and the time and version of your declaration regarding the right of withdrawal). What we hold ourselves is contract and billing data: the provider's identifiers (customer, subscription and invoice ID), plan, billing interval, amount and currency, term, cancellation and payment status including failed payments, and for Shopify the shop domain. Legal bases: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (statutory retention). Invoice and receipt data is kept even after account deletion for as long as commercial and tax retention duties apply (§ 147 AO, § 257 HGB). For the payment data these providers are independent controllers within the meaning of Art. 4(7) GDPR and not our processors: they process payment, invoicing and identification data for their own, legally mandated purposes (anti-money-laundering, fraud prevention, payment supervision, tax retention) over which we have no influence. Their own privacy notices apply to that processing. Both belong to groups with companies outside the EU; for transfers there the providers rely on standard contractual clauses and, where applicable, on the EU-US Data Privacy Framework. As long as no paid plan is booked, no payment data arises.
10. Hosting and data location
Hetzner Online GmbH, data centres in Falkenstein and Nuremberg, Germany. The entire core operation — database, recordings, backups — is located in the EU; replay and snapshot blobs live in EU object storage. Where something different applies to an individual processor, the complete list at visz.ai/subunternehmer (group 1) states it with the location and the transfer basis; the entry in the respective row is what governs.
11. Processors and third-country transfer
The complete, versioned list of our processors is publicly available at visz.ai/subunternehmer and forms part of the data processing agreement. We announce any intended change to that list at least 30 days before it takes effect and grant a right to object and to terminate (§ 21 of the terms, Art. 28(2) GDPR). Not on that list — because they are not processors but independent controllers: sign-in with Google and Apple (section 7) and Stripe and Shopify (payment, section 9). They are named in the respective sections of this policy; the 30-day announcement does not apply to them because they are not part of the processor list. Please note that the name Google appears in TWO different roles in this policy, which must not be confused: Google Ireland Ltd. / Google LLC is an independent controller for sign-in with Google and is therefore NOT on the processor list; Google Cloud EMEA Limited is a processor for the AI analysis, appears in group 1 of that list and is therefore covered by the 30-day announcement. The same relationship between the Irish contracting entity and the US parent applies to Anthropic. Where processors have group companies outside the EU, or make no commitment on the processing location, we base the transfer on standard contractual clauses (Implementing Decision (EU) 2021/914) and, where applicable, on the EU-US Data Privacy Framework, in each case after a transfer impact assessment; which route applies to which row is stated in the list itself. Geo lookup uses a local MaxMind database without any external call and is therefore not a processor.
11a. Open points before a broad rollout
We disclose what is still outstanding before a broad rollout:
- Data protection impact assessment (Art. 35 GDPR): it exists. The final review by the external data protection officer (Art. 35(2) GDPR) is still pending.
- External data protection officer: still to be appointed (section 2).
- Data processing agreements: for three providers in the areas of operations monitoring and support, the contracts are not yet concluded.
- Final legal review: this is a final version; an external legal review of this version is still pending.
12. Dual role
For snippet data on customer sites the customer is the controller; we act as processor (DPA). This policy only concerns our own role.
13. Compliance records
Consent, DSR and deletion logs are kept longer (section 15).
14. Cookies, storage access and consent
This section separates two things that are often mixed up: what is stored on visz.ai itself, and what our snippet stores on the websites of our customers. A) On visz.ai and app.visz.ai we set the following necessary entries: the sign-in cookie „visz.session_token“ (httpOnly; session length as set by the sign-in service), the cookie „visz.csrf“ protecting against cross-site request forgery (until the browser is closed), the language cookie „lang“ (1 year), the cookie „visz_consent“ holding your cookie decision as a record (12 months), further short-lived cookies prefixed „visz.“ for technical intermediate steps of signing in (third-party sign-in, two-factor authentication), and in local storage „visz-theme“ for light or dark appearance as well as the dashboard display settings prefixed „visz:“ or „visz.“ (role preset, collapsed filter bar, dismissed hints, frequency capping of dialogs); local storage entries remain until you delete them. We set these necessary entries without consent; they are strictly necessary for us to provide the service you have expressly requested (§ 25(2) no. 2 TDDDG). Everything else — analytics and error diagnosis tools — we set only with your consent via the banner (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can withdraw your consent at any time via „Change cookie settings“ in the footer. We do not currently set any marketing cookies. We respect the „Do Not Track“ browser setting: if it is active, no analytics take place. B) On our customers' websites our snippet sets no cookies. It stores entries in the browser's local storage and session storage; these are first-party entries of the respective website and are not read across websites. The controller for this processing is the operator of the website; the following list is part of our assistance under Art. 28(3)(e) GDPR. There are exactly six entries. „visz_cb_<site key>“ in local storage holds your decision at the consent banner („accepted“ or „rejected“) with a timestamp so the banner does not ask again on every page view; it is set without consent because it is the consent decision itself and therefore strictly necessary (§ 25(2) no. 2 TDDDG), and it remains indefinitely until you delete it. „visz_aid“ in local storage is a random identifier for this one website and serves to recognise returning visitors; it is created only after consent and has no expiry. „visz_ses“ in session storage holds the identifier, counter and timestamps of the current session until the browser tab is closed; after 30 minutes of inactivity a new session begins. „visz_q“ in local storage holds up to 50 event batches not yet sent, so that no events are lost if the network is interrupted, and is cleared once they are sent. „visz_sv_<survey id>“ in local storage records with a timestamp whether a survey was answered or dismissed; answered it remains indefinitely, dismissed the same survey does not reappear for 7 days. „visz_fb_<site key>“ in local storage holds the timestamp of feedback you submitted so the confirmation is not shown again. If you reject at the banner, „visz_aid“ is nevertheless created in your browser: the rejection process itself generates the identifier before reporting it to us. We discard it on the server and do not store it; the entry does however remain in your browser and is not deleted automatically — you can remove it at any time via your browser's website data. „Do Not Track“ is a hard stop: if the setting is active in your browser, our snippet loads nothing, stores nothing, sends nothing and shows no banner, regardless of the website operator's settings. And even if an operator has disabled the consent prompt in their settings, your choice at the banner alone decides once a banner is shown. C) On the assessment of „visz_aid“ under § 25 TDDDG: the identifier is a randomly generated UUID version 7, stored separately per website and with no expiry. It contains no information about you and is not derived from device characteristics — no fingerprinting takes place. It is however persistent: as long as you do not clear the website data, the same website recognises you over months and years. § 25(1) TDDDG applies, because the provision attaches to the storage operation in terminal equipment and not to whether the stored information is personal data; that „visz_aid“ is not a cookie makes no difference, since § 25 TDDDG is technology-neutral and covers local storage in the same way. The exception in § 25(2) no. 2 TDDDG does not apply: from the visitor's perspective the expressly requested service is the website, not its audience measurement, and recognising a visitor is not necessary to display the website. Consent is therefore mandatory, and that is how it is implemented. The subsequent processing of the identifier must additionally be justified under the GDPR; because it allows recognition over time, we treat it as pseudonymous personal data (recital 26 GDPR) on the basis of the consent obtained by the website operator as controller (Art. 6(1)(a) GDPR). Two points we disclose rather than leave between the lines: a storage entry without any time limit sits badly with the principle of storage limitation (Art. 5(1)(e) GDPR); a maximum lifetime for „visz_aid“ and a renewed prompt for the banner decision after 12 months at the latest are planned and not implemented today. And that „visz_aid“ is created even when you reject is not compatible with § 25(1) TDDDG — discarding the identifier on the server does not cure this, because the provision already covers the storage operation. That correction is planned as well; until then the note stands here.
15. Retention
Recordings and raw data are kept for different periods depending on your plan: 30 days (Free), 60 days (Starter), 90 days (Pro). The period is set per recording when it is created and does not change retroactively. Anonymised IP 30 days. Aggregated, non-personal summaries (daily and demographic roll-ups) 90 days. Click and scroll heatmaps 365 days, move heatmaps 90 days. Account data 30 days post-deletion. Security and platform log 1 year. Compliance records up to 3 years. Invoice and receipt data are subject to the statutory tax and commercial law periods (§ 147 AO, § 257 HGB).
16. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal (Art. 7(3)). Requests: info@visz.ai; reply within one month.
17. Automated decisions
None with legal effect within the meaning of Art. 22.
18. Right to complain
Competent authority: LfDI Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, poststelle@lfdi.bwl.de, +49 711 615541-0.
19. Obligation to provide
An account email is required to use the service; without it no account.
20. „Your data belongs to you“
We never sell data, never use it for AI training and never for third-party advertising.
21. Changes
Updated as needed; material changes notified 30 days in advance by email. The version published here applies; the German version prevails.