| Independent security / privacy audit | ⚠️Vendor claimedePrivacyseal materials and vendor pages describe independent ePrivacy Consult audit of consent-free cookieless analytics posture; not a full public penetration-test report. Vendor also claims regular infrastructure pen tests. | 🔒On request / NDAVendor claims annual external penetration tests and publishes a Trust Portal with pentest reports behind access. No public independent no-logs audit (this is a recorder, not a no-logs VPN). |
|---|
| ISO 27001 | ⚠️PartialIPHH housing described as ISO/IEC 27001:2013-certified. No public organisation-level ISO 27001 certificate for etracker/JustRelate analytics found in materials reviewed. | ⚠️Vendor claimedContentsquare states it is ISO 27001 certified (also claims ISO 27017, 27018, 27701). Certificates are on the Trust Portal; not independently downloaded for this draft. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo public SOC 2/SOC 3 report located on official trust/security pages reviewed. | ⚠️Vendor claimedTrust portal and security pages claim a SOC 2 Type II report. Report not independently downloaded. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedEU/DE controller-processor setup; cookieless default under legitimate interest; Art. 28 DPA on registration; privacy notice + objection patterns documented. | ⚠️Vendor claimedEU parent and contracting entity for non-Americas Hotjar Services. Public DPA, SCCs, and GDPR language. Customer is controller and must supply a lawful basis for visitor capture. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialEuropeanStack assessment: German entity, no known US parent, own-server housing at IPHH (no public AWS/GCP/Azure analytics store) → core exposure low. Partial because optional conversion sync and Google connectors can send data to US-group destinations when enabled by the customer. Not legal advice. | ⚠️PartialAssessment, not a vendor slogan. French parent and no known US parent, but AWS and Azure host visitor data, Content Square, Inc. and Zendesk process support data, and US regions exist. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedVendor states DPA/AV concludes on account registration; public DPA PDFs and in-app DPA under Settings → Data processing agreement. | ⚠️Vendor claimedPublic Contentsquare DPA incorporated by the MSA. Execution of the MSA or an order form is treated as execution of the DPA and SCCs. |
|---|
| ePrivacyseal (privacy seal) | ⚠️Vendor claimedVendor and ePrivacy listing materials assert seal for consent-free cookieless mode under GDPR/TDDDG. Scope is privacy/consent posture, not a general security cert. | Not listed |
|---|
| EU AI Act | —Not applicableProduct is web/marketing analytics, not an AI-system offering as primary positioning. | —Not applicableCore product is analytics and replay, not an AI system sold as such. Sense AI and survey LLMs exist as optional features. Confirm AI Act role if you enable those modules. |
|---|
| CSA STAR | Not listed | ⚠️Vendor claimedSecurity page displays a STAR badge. Scope and level not independently verified. |
|---|