Answers to Your Questions About Our Privacy Policy
Does your service require consent under the ePrivacy Directive, given that you access a user's terminal to execute JavaScript or determine viewport size?
We do not access any information already stored on a visitor’s device and would require informed consent upfront, according to the TDDDG (German implementation of the ePrivacy directive).
The screen resolution is approximately retrieved via CSS media queries, and not requested directly from the device. Direct requests of that nature would indeed require consent under the directive. See also Maximum Data Privacy Mode for more information.
When in Maximum Privacy mode, does the service disable features like Heatmaps, Session recordings, and Ecommerce, given that these features are generally more invasive and can potentially identify individuals?
Heatmaps can contain personal information (when maybe activated behind a login) --> we are working on a solution to obfuscate textual information also for heatmaps (like already provided for Session Recordings).
Session Recordings have the option to obfuscate text if needed.
The eCommerce module only uses the information you provide, so you can simply leave out any PII (Personally Identifiable Information) as we do not collect it by default.
How does your service's use of JavaScript align with the ePrivacy Directive, given that some data protection officers interpret JavaScript execution as active device access that requires consent?
Our JavaScript does not access any user or device information. Instead, it only accesses content from your website to enable heatmaps, session recordings, and eCommerce functionality.
Everything has been thoroughly and legally approved by our Legal Consultancy Team, led by Dr. Andreas Splittgerber.
We do not consider the pure execution of JavaScript as something that contradicts the §25 TDDDG / ePrivacy directive, and neither do our lawyers.