GDPR session recording, no US transfer.
GDPR session recording at visz.ai means: EU hosting with Hetzner in Nuremberg, no transfer of your visitors' data to the US, PII masking in the browser before anything is sent, and IP anonymisation before storage. Consent-first and cookieless-capable.
Why visz.ai is low-risk.
Session replays and heatmaps record behaviour. That is why the architecture is built for data minimisation from the start, not retrofitted:
EU hosting with Hetzner
All data lives with Hetzner in Nuremberg, including replay and snapshot blobs in EU object storage.
No US transfer of visitor data
Your website visitors' data never leaves the EU. That removes transfer impact assessments (TIA), DPF dependency and CLOUD Act exposure for this data.
PII masking in the browser
Sensitive input is masked client-side before anything is sent. It never even reaches our servers.
IP anonymisation before storage
IP addresses are anonymised before they are stored.
Consent-first
The snippet is built to run behind a consent banner and supports Google Consent Mode. Recording starts only after consent.
Cookieless-capable
Tracking works without cookies. No cookie requirement for your visitors.
To be honest: you still need your visitors' consent with visz.ai (§ 25 TDDDG, Art. 6 GDPR). EU hosting does not replace consent. It takes the transfer problem off your plate.
GDPR checklist for shop owners.
What makes a session-recording setup GDPR-ready, regardless of vendor (as of July 2026):
Consent BEFORE the script loads
Session recording requires consent under § 25 (1) TDDDG and Art. 6 (1)(a) GDPR: active, informed, revocable. Pre-ticked checkboxes are invalid, and the script may only load after opt-in.
A dedicated consent category
German supervisory authorities (DSK) require a per-function view. Declare recording and heatmaps as their own category, not hidden under “statistics”.
Client-side PII masking
Passwords, payment data and free-text fields must be masked before data leaves the browser. visz.ai masks client-side by default.
IP anonymisation
Truncating or anonymising IP addresses before storage is the industry standard. visz.ai anonymises before storage.
Check for EU-only processing
If the vendor including subprocessors processes only in the EU, third-country checks (TIA) and the dependency on the EU-US Data Privacy Framework disappear. With US vendors: verify DPF status and agree SCCs as a fallback.
Sign a DPA (Art. 28 GDPR)
For snippet data you are the controller and the vendor is the processor, so a data processing agreement is mandatory. With visz.ai you sign it in the dashboard.
Define retention periods
Documented, short retention for raw data. visz.ai deletes raw replay data automatically after 30 days.
Plan a DPIA
Extensive tracking of user behaviour is on the DSK's mandatory-DPIA list. Plan a data protection impact assessment (Art. 35 GDPR) for recording use.
Update your privacy policy
Describe purposes, legal basis, recipients, retention, withdrawal and complaint rights for the tool.
This checklist is general information, not legal advice. For binding guidance, consult a lawyer or data protection officer. As of: July 2026.
Security facts.
Measures enforced in the system, not just promised:
- Row-level security (RLS). Tenant isolation is enforced in the database itself (Postgres RLS on tenant tables), not only in application code.
- TLS encryption. All connections to visz.ai run exclusively over HTTPS/TLS.
- Account security. Argon2id password hashing, server-side sessions, optional TOTP 2FA with hashed backup codes.
- EU object storage. Replay and snapshot blobs live in EU object storage with Hetzner. All data stays in the EU.
- 30-day raw retention. Raw replay data is deleted automatically after 30 days. Data minimisation is system behaviour here, not an option.
Documents & transparency.
Everything essential is public or available directly in the product:
- DPA (data processing agreement)
Sign and download it in the dashboard under Settings → Legal.
- Privacy policy
How visz.ai itself handles data, complete and public.
- Subprocessor list
All processors with location and transfer legal basis (Annex 2 to the DPA).
- Documentation
Install and product documentation at docs.visz.ai.
- Status page
Availability and incidents, transparent at status.visz.ai.
Your visitors leave. They know why, but do you? See what they see.