GDPR session recording, no US transfer.
GDPR session recording at visz.ai means: EU hosting with Hetzner in Nuremberg, no transfer of your visitors' data to the US, PII masking in the browser before anything is sent, and IP anonymisation before storage. Consent-first and cookieless-capable.
Why visz.ai is low-risk.
Session replays and heatmaps record behaviour. That is why the architecture is built for data minimisation from the start, not retrofitted:
EU hosting with Hetzner
Core operation and storage sit with Hetzner in Nuremberg, including the replay and snapshot blobs in EU object storage.
Raw data never leaves the EU
The recordings themselves, the IP address, the visitor identifier and free text from forms and surveys never leave the EU. Where something different applies to an individual processor, the subprocessor list states it with location and transfer basis.
PII masking in the browser
Sensitive input is masked client-side before anything is sent. It never even reaches our servers.
IP anonymisation before storage
IP addresses are anonymised before they are stored.
Consent-first
The snippet is built to run behind a consent banner and supports Google Consent Mode. Recording starts only after consent.
Cookieless-capable
Tracking works without cookies. No cookie requirement for your visitors.
To be honest: you still need your visitors' consent with visz.ai (§ 25 TDDDG, Art. 6 GDPR). EU hosting does not replace consent. It takes the transfer problem off your plate.
GDPR checklist for shop owners.
What makes a session-recording setup GDPR-ready, regardless of vendor:
- Consent BEFORE the script loadsSession recording requires consent under § 25 (1) TDDDG and Art. 6 (1)(a) GDPR: active, informed, revocable. Pre-ticked checkboxes are invalid, and the script may only load after opt-in.
- A dedicated consent categoryGerman supervisory authorities (DSK) require a per-function view. Declare recording and heatmaps as their own category, not hidden under “statistics”.
- Client-side PII maskingPasswords, payment data and free-text fields must be masked before data leaves the browser. visz.ai masks client-side by default.
- IP anonymisationTruncating or anonymising IP addresses before storage is the industry standard. visz.ai anonymises before storage.
- Check for EU-only processingIf the vendor including subprocessors processes only in the EU, third-country checks (TIA) and the dependency on the EU-US Data Privacy Framework disappear. With US vendors: verify DPF status and agree SCCs as a fallback.
- Sign a DPA (Art. 28 GDPR)For snippet data you are the controller and the vendor is the processor, so a data processing agreement is mandatory. With visz.ai you sign it in the dashboard.
- Define retention periodsDocumented, short retention for raw data. visz.ai deletes raw replay data automatically after 30 days.
- Plan a DPIAExtensive tracking of user behaviour is on the DSK's mandatory-DPIA list. Plan a data protection impact assessment (Art. 35 GDPR) for recording use.
- Update your privacy policyDescribe purposes, legal basis, recipients, retention, withdrawal and complaint rights for the tool.
This checklist is general information, not legal advice. For binding guidance, consult a lawyer or data protection officer. As of: July 2026.
Security facts.
Measures enforced in the system, not just promised:
- Row-level security (RLS)Tenant isolation is enforced in the database itself (Postgres RLS on tenant tables), not only in application code.
- TLS encryptionAll connections to visz.ai run exclusively over HTTPS/TLS.
- Account securityArgon2id password hashing, server-side sessions, optional two-factor sign-in (TOTP) with hashed backup codes.
- EU object storageThe recordings themselves live as blobs in EU object storage, not in the database. Where a processor's location differs from that, the subprocessor list names it together with the transfer basis.
- Automatic deletion of raw dataRaw replay data is deleted automatically after 30 days. Data minimisation is system behaviour here, not an option.
Documents & transparency.
Everything essential is public or available directly in the product:
- DPA (data processing agreement)
Sign and download it in the dashboard under Settings → Legal.
- Privacy policy
How visz.ai itself handles data, complete and public.
- Subprocessor list
All processors with location and transfer legal basis (Annex 2 to the DPA).
- Documentation
Install and product documentation at docs.visz.ai.
- Status page
Availability and incidents, transparent at status.visz.ai.