Which privacy and legal documents does RUMvision provide?

We want privacy, legal, security and procurement reviews to be as straightforward as possible.

That is why we provide the main documents you may need to assess RUMvision, both as a Real User Monitoring provider and as a SaaS platform.

These documents cover different parts of our service, including visitor-level RUM processing, the RUMvision application, customer accounts, subprocessors, contractual terms and the way we handle personal data more broadly.

Each document has a different purpose, so you usually do not need to read everything in full.

Data Processing Agreement (DPA)

Our Data Processing Agreement covers the situations where RUMvision processes personal data on your behalf as a processor.

It sets out the contractual requirements around topics such as processing instructions, confidentiality, security, subprocessors, assistance with data protection obligations, retention and deletion.

Our standard DPA applies automatically where RUMvision acts as your processor. You do not need to request or separately sign the standard version. You sign it when you onboard with RUMvision.

When should I look at the DPA?

The DPA is usually the right document for your legal, privacy or procurement team when they want to understand the contractual processor relationship between your organisation and RUMvision.

Do you use your own vendor or DPA templates?

Our standard documentation is intended to cover standard privacy and procurement reviews. Completion or negotiation of customer-specific legal, security or compliance templates is available for Enterprise customers.

Link to DPA

Legitimate Interests Assessment (LIA)

Our Legitimate Interests Assessment focuses specifically on the use of RUMvision for Real User Monitoring where Article 6(1)(f) GDPR is relied upon.

It documents the technical processing, necessity assessment, balancing test, safeguards and feature-specific conclusions for the RUMvision capabilities included in the assessment.

We have done the underlying technical and privacy assessment so that customers do not need to recreate our analysis from scratch.

To apply the LIA to your own website, you review whether the documented assumptions and conditions match your implementation and complete the Customer Deployment Record included in the assessment.

Why is the LIA available on request?

Our LIA is intentionally not published as a public download.

It is a detailed working document that contains extensive information about how our monitoring features are designed, limited and assessed. Some of that detail goes significantly beyond what is needed for a general privacy overview and includes implementation information that we prefer to share directly with customers and their privacy, legal or security teams.

This gives organisations that need the full assessment access to it, while avoiding unnecessary public distribution of detailed implementation information that could also be useful for reverse engineering or security analysis.

How can I access the LIA?

You can access the RUMvision LIA in two ways:

  • Request the full PDF if you want the complete assessment for your privacy, legal, security or procurement review.
  • Use our guided LIA review if you want to ask questions about the assessment, understand specific sections or discuss how it applies to your own RUMvision configuration.

The guided version is based on the same RUMvision LIA and is intended to make the document easier to work with. It can help explain the assessment in plain language, point you to relevant sections and help identify which parts are relevant to your deployment.

The LIA itself remains the source document. The guided review is there to help you navigate and understand it, and does not replace your own legal assessment or the controller responsibilities described in the LIA. Request access via info op rumvision punt com

When should I look at the LIA?

The LIA is most relevant when your privacy or legal team wants to assess whether legitimate interest is an appropriate GDPR legal basis for your RUMvision deployment.

It is also useful when you want to understand which monitoring features are covered by the standard assessment, which have additional conditions and which require a separate review.

Privacy Policy

Our Privacy Policy explains how RUMvision processes personal data across our services.

This includes visitor-level RUM processing on customer websites, but also situations where RUMvision acts as controller, such as customer accounts, billing, support, security, our own website and other business operations.

When should I look at the Privacy Policy?

The Privacy Policy is the best general reference if you want a complete overview of how RUMvision handles personal data.

It can also be useful when preparing or reviewing your own privacy notice, although your own notice should describe your actual use of RUMvision rather than simply copying ours.

Link to privacy policy

Subprocessor information

We maintain current information about the service providers and subprocessors we use, including their role and relevant processing or hosting locations.

We keep this information separately so it can stay current when providers change, without requiring the full Privacy Policy or DPA to be rewritten each time.

When should I look at the subprocessor information?

This is usually relevant for vendor reviews, security assessments, international transfer checks and internal procurement processes.

Link to subprocessors

Terms of Service

Our Terms of Service govern the commercial and operational use of RUMvision.

They cover topics such as subscriptions, service delivery, customer responsibilities, acceptable use, data handling, security, liability and termination.

They also explain how the DPA forms part of the agreement where RUMvision acts as processor.

When should I look at the Terms of Service?

The Terms of Service are the main contractual document for using RUMvision and are usually reviewed during procurement or contract approval.

Link to TOS

Which document should I start with?

If you are not sure where to begin, this is usually the easiest route:

  • Want a general overview of how RUMvision handles personal data? Start with our Privacy Policy.
  • Reviewing RUMvision as a processor? Read the DPA.
  • Assessing legitimate interest for Real User Monitoring? Request or review the LIA.
  • Checking service providers or processing locations? Review the subprocessor information.
  • Reviewing the contractual relationship? Read the Terms of Service.

Do I need to request these documents?

Most of our standard privacy and contractual documentation is available upfront so that you can review RUMvision without going through a sales process.

Our Legitimate Interests Assessment is the main exception. Because it contains extensive technical and implementation detail, we provide it directly to customers and organisations carrying out a genuine privacy, legal, security or procurement review.

You can request the full document as a PDF or use the guided LIA review if you prefer to work through the assessment interactively.

For Enterprise customers with specific contractual, security or compliance requirements, additional review or custom agreements may also be available as part of the Enterprise process.