Back

Use OpenReplay Cloud GDPR compliant. Follow these instructions:

Services & integrations

Back

First of all, we have to clarify whether consent is required in order to integrate OpenReplay Cloud GDPR compliant.

Due to the fact that the integration of OpenReplay Cloud is not necessary for the operation of the website, the integration requires consent.

In principle, the integration of OpenReplay Cloud can only be carried out on the basis of consent, since other legal bases are not suitable.

Data is transmitted to the independent controller Asayer SAS. This information must be included in the privacy policy.

1. Obtain explicit consent for OpenReplay Cloud from users by opt-in

Before OpenReplay Cloud becomes active on the website and begins to collect user data, the user must first give their explicit consent. If the user refuses to consent, which must also be possible - OpenReplay Cloud must not be activated. No data is allowed to be forwarded to the 3rd party. This opt-in procedure is mandatory in order to comply with data protection regulations.

2. Always offer the option to revoke the consent (opt-out) for OpenReplay Cloud

Even if the user has agreed to the use of OpenReplay Cloud, he or she must still be given the opportunity to reverse this decision and deactivate tracking at any time. For this reason, it is necessary to provide an opt-out procedure that is easy for the website visitor to access at any time. The user must be able to revoke his consent. The option to revoke must be just as easy as the option to consent.

3. Mention OpenReplay Cloud in the privacy policy completely, simply and transparently

The privacy policy on your website must be comprehensive, transparent and accurate. It should be readable and understandable by anyone, even without legal training. It is important to include a section on OpenReplay Cloud that clearly describes what data is collected, for what purpose it is used and who is responsible for it, as well as whether data is shared and what legal basis applies.

Privacy Statement for the Service OpenReplay CloudBeim Besuch dieser Website werden personenbezogene Daten verarbeitet. Dabei verarbeitete Datenkategorien: Technische Merkmale des von Ihnen verwendeten Endgeräts, die Ihnen nicht eindeutig zugeordnet werden können, wie z. B. die Sprache, die Zeitzone oder das Betriebssystem., Bei Ihrer IP-Adresse handelt es sich um eine Nummer, die von Ihrem Internetdienstanbieter für jede Internetverbindung vergeben wird. Diese Nummer ist nicht immer gerätespezifisch und es handelt sich nicht immer um eine dauerhaft Kennung. Sie wird verwendet, um Informationen im Internet zu übertragen und Online-Inhalte (einschließlich Werbung) auf Ihrem verbundenen Gerät anzuzeigen. und Daten über die Nutzung der Website sowie die Protokollierung von Klicks auf einzelne Elemente. Zweck der Verarbeitung: Informationen über Ihre Aktivitäten auf diesem Angebot, wie z. B. Ihre Interaktion mit Anzeigen oder Inhalten, können dabei helfen, Produkte und Angebote zu verbessern und neue Produkte und Angebote zu entwickeln basierend auf Benutzerinteraktionen, der Art der Zielgruppe usw. Dieser Verarbeitungszweck umfasst nicht die Entwicklung, Ergänzung oder Verbesserung von Benutzerprofilen und Kennungen., Optimierung von Inhalten und Untersuchung des Nutzungsverhaltens. Die Rechtsgrundlage für die Verarbeitung: Ihre Einwilligung nach Art. 6 (1) a DSGVO. Eine Übermittlung von Daten erfolgt: an den selbständigen Verantwortlichen Asayer SAS, 16 Rue Washington, 75008 Paris, Frankreich (https://www.asayer.io). Die Rechtsgrundlage für die Datenübermittlung an Asayer SAS ist Ihre Einwilligung nach Art. 6 (1) a DSGVO. 

4. Additional Information for OpenReplay Cloud and GDPR

In addition to the above information, the data protection information must also contain the mandatory information from Art. 13 or 14 GDPR: Name and contact details of the controller, if necessary the contact details of the data protection officer, the purposes for which the personal data are to be processed, the legitimate interests, if the processing is based on Article 6 (1) f GDPR, the duration of the processing, information on the rights of the data subjects including the right to lodge a complaint with a supervisory authority, the possibility of simply revoking consent given, and information as to whether the Provision of the data is required by law or contract or what the possible consequences of non-provision would be. In the event that the data is used for automated decision-making, including profiling, meaningful information about the logic involved and the scope and impact on the data subject must be provided. The processing of the data must also be documented in the list of processing activities in accordance with Art. 30 GDPR. The information required for this can already be found in the privacy statement, which can be created from the previous information.

Before the user agrees or rejects the use of OpenReplay Cloud, he must be informed in detail about the respective purposes. Therefore, a precisely formulated consent text is of great importance. This should also be placed so that it is immediately recognizable for the user. The user's consent must be active. Individual services must not be preselected.

6. Use a Consent Management Provider CMP (cookie banner/cookie popup/cookie bar)

Different names, but usually the same purpose. CMP supports you with consent (opt-in and opt-out, data protection declaration and other GDPR topics. Technical support is recommended with regard to the GDPR and consent management in order to avoid errors.

Preconfigured services & integrations

Individually expandable

Privacy
The controller (legal web GmbH, Austria) would like to use the following services in order to process your personal data. Technologies such as cookies, localStorage, etc. can be used for personalization. This is not necessary for the use of the website, but allows us to interact with you more closely. If you wish, you can adjust or revoke your consent at any time via our privacy policy.