Skip to content
UserExplorer

Data Processing Agreement

When you record your users with UserExplorer, you are the controller and we act as your processor. This page summarises our Data Processing Agreement under GDPR. The account owner accepts the full agreement in account settings, and it then applies to all projects in the account.

Last updated October 11, 2026

Roles of the parties

The customer is the controller of personal data recorded on its websites and apps. The administrator of the userexplorer.com service is the processor and processes that data only on the customer's documented instructions, which are the agreement, the customer's project settings and its use of the service.

Subject matter and duration

Processing covers recording, storing, analysing and displaying user behavior data to provide session replay, heatmaps, funnels, form analytics, user profiles, surveys, AI interviews and AI analysis. It lasts for the term of the subscription and ends with deletion as described below.

Categories of data and data subjects

Data subjects are visitors and users of the customer's websites and apps. Depending on the customer's setup, the data may include:

  • interaction data such as page views, clicks, scrolls, taps and navigation,
  • device, browser, approximate location derived from IP address and traffic source,
  • events and user properties the customer chooses to send, including user identifiers,
  • survey answers, NPS scores and AI interview replies.

Special category data must not be recorded. Inputs and sensitive text are masked by default.

Sub-processors

We use sub-processors in the following categories, each bound by written terms that offer at least the same protection as the agreement:

  • hosting provider in the EU or the US, according to the region chosen for the project,
  • AI model provider, only for paid AI features the customer uses,
  • email delivery provider, for survey and interview invitations sent by the service where enabled.

We inform customers about intended changes of sub-processors in advance, and customers may object on reasonable grounds.

Security measures

  • masking of inputs and sensitive text by default, with custom selectors for more,
  • consent mode that starts recording only after the consent signal of the customer's banner,
  • encryption of data in transit,
  • role based access, with SSO and SCIM on Enterprise,
  • access to customer data limited to staff who need it to provide support, under confidentiality duties,
  • logging and regular review of access.

More detail is on our privacy and security page.

Hosting region

Customers on Scale and Enterprise plans choose EU or US hosting for each project. Transfers outside the European Economic Area rely on appropriate safeguards such as standard contractual clauses.

Assistance and breach notification

We help the customer respond to data subject requests and with data protection impact assessments where reasonable. We notify the customer of a personal data breach affecting its data without undue delay after becoming aware of it, with the information the customer needs to meet its own duties.

Deletion at the end

Customers can delete recordings and projects at any time. At the end of the subscription and the plan retention period, we delete customer personal data, unless the law requires us to keep it. Where the plan includes exports, customers can export data before that.

How to accept the agreement

The account owner accepts the full Data Processing Agreement in account settings. The date of acceptance is recorded in the account. Questions about the agreement can be sent to [email protected].