| Independent security / no-logs audit | ❌Not foundVendor describes anonymization defaults and mentions external pen tests in ISO materials; no public independent no-logs audit report found. | 🔒On request / NDAVendor claims annual external penetration tests and publishes a Trust Portal with pentest reports behind access. No public independent no-logs audit (this is a recorder, not a no-logs VPN). |
|---|
| ISO 27001 | ⚠️Vendor claimedVendor publishes ISO/IEC 27001:2022 certification covering the company/products with a certificate PDF; not independently re-verified against the cert body registry in this draft. | ⚠️Vendor claimedContentsquare states it is ISO 27001 certified (also claims ISO 27017, 27018, 27701). Certificates are on the Trust Portal; not independently downloaded for this draft. |
|---|
| SOC 2 / SOC 3 | ❌Not foundNo SOC 2/3 claim found on security/about pages reviewed. | ⚠️Vendor claimedTrust portal and security pages claim a SOC 2 Type II report. Report not independently downloaded. |
|---|
| GDPR / EU data protection | ⚠️Vendor claimedSwiss entity; public materials assert nFADP and GDPR alignment; cookieless defaults and CH processing described in DPA. | ⚠️Vendor claimedEU parent and contracting entity for non-Americas Hotjar Services. Public DPA, SCCs, and GDPR language. Customer is controller and must supply a lawful basis for visitor capture. |
|---|
| US CLOUD Act exposure (indicative) | ⚠️PartialSwiss entity, no known US parent; Analytics product hosts are Swiss (Infomaniak/Netstream/Hosttech). Medium/partial because company subprocessors include US SaaS (e.g. Google Workspace, HelpScout, Stripe, Cloudflare). AWS not used for Analytics per vendor list. Indicative only—not legal advice. | ⚠️PartialAssessment, not a vendor slogan. French parent and no known US parent, but AWS and Azure host visitor data, Content Square, Inc. and Zendesk process support data, and US regions exist. Not legal advice. |
|---|
| Data processing agreement (B2B) | ⚠️Vendor claimedPublic DPA text for Friendly GmbH; customers asked to contact to sign. Enterprise also references DORA/NDA/SLA packs. | ⚠️Vendor claimedPublic Contentsquare DPA incorporated by the MSA. Execution of the MSA or an order form is treated as execution of the DPA and SCCs. |
|---|
| EU AI Act | —Not applicableWeb analytics SaaS; not positioned as an AI system product. | —Not applicableCore product is analytics and replay, not an AI system sold as such. Sense AI and survey LLMs exist as optional features. Confirm AI Act role if you enable those modules. |
|---|
| ISO 9001 | ⚠️Vendor claimedVendor publishes ISO 9001 certification materials alongside ISO 27001. | Not listed |
|---|
| CSA STAR | Not listed | ⚠️Vendor claimedSecurity page displays a STAR badge. Scope and level not independently verified. |
|---|