Privacy and security, by design

RUMvision was built in the Netherlands, and we have deliberately kept it that way.

We are an independent, bootstrapped European company focused on Real User Monitoring, Core Web Vitals and frontend observability. Today (Sept 14, 2026), RUMvision monitors more than 1,500 domains, from smaller ecommerce websites to large enterprise environments.

That independence matters to us. It gives us the freedom to make long-term choices about our product, our infrastructure and the way we handle data, without building a business around advertising, visitor profiles or selling data.

Our goal is simple: give you the real-world performance data you need to make your website faster, while collecting as little information about the people using it as possible.

Privacy should not be an enterprise-only feature, and choosing a privacy-conscious monitoring platform should not mean giving up the insights you need.

Built and operated from Europe

RUMvision B.V. is based in Groningen, the Netherlands.

Our core visitor-level RUM processing infrastructure is located within the European Union. Some separate business services or optional functionality may use other processing locations, in which case we document the applicable providers and safeguards separately.

This distinction is important to us. We do not want to make broad claims that sound good but become inaccurate as soon as you look at the details.

For the actual Real User Monitoring data collected from your visitors, our architecture is designed around European processing and data minimisation.

What RUMvision measures

Real User Monitoring is about understanding how a website actually performs for the people using it.

That can include things such as Core Web Vitals, loading and rendering timings, responsiveness, page and navigation context, browser and operating system categories, device characteristics, network conditions, country-level location and limited visit context. Depending on your configuration, RUMvision may also process additional diagnostics such as JavaScript errors or configured website goals.

We use this information to help you answer questions such as:

  • Which pages are slow for real visitors?
  • Which devices or browsers are affected?
  • Where is a performance regression happening?
  • Is a technical problem affecting conversions or other website outcomes?
  • Why does a page feel unresponsive even when synthetic testing looks fine?

The purpose is to understand and improve the website, not to understand the person using it.

What we deliberately do not do

There are some things RUMvision is simply not built for.

We do not use visitor-level RUM data for advertising or behavioural targeting. We do not fingerprint visitors, build advertising profiles or recognise people across unrelated websites. RUMvision is also not a session replay or screen-recording service.

Our baseline processing is not intended to collect names, email addresses, account identifiers, payment details, form contents or other direct identifiers.

That does not mean every piece of technical RUM data is legally anonymous.

Some technical information can still qualify as personal data under the GDPR, even when it does not tell us who a visitor is. We therefore treat relevant RUM data accordingly and apply the privacy safeguards described in our documentation.

We think that is a more useful and responsible approach than simply saying "no personal data" and leaving it at that.

Limited identifiers, not identities

Some RUM features need to understand whether measurements belong to the same visit or browser.

Where persistent browser storage is enabled, RUMvision may therefore use a randomly generated first-party Browser Identifier. It is not based on fingerprinting, does not contain a name, email address or customer account identifier, and is not designed to recognise a browser across unrelated websites.

Persistent identifiers have a maximum lifetime of 90 days and are rotated after expiry.

Customers can also configure browser storage according to their own requirements. Whether browser storage or access requires consent is a separate question under applicable electronic communications law, so it must be assessed for the actual deployment.

We cover this in more detail in our separate article on browser storage and identifiers.

Optional features stay optional

RUMvision is modular.

Not every feature available in the platform is automatically active on every website. Customers decide which optional functionality is enabled for a property.

This matters because there is a difference between measuring Core Web Vitals and enabling more context-rich diagnostics.

Features such as Business Metrics, JavaScript error monitoring, responsiveness diagnostics or additional browser information may have their own privacy considerations and configuration options.

Our documentation makes those differences explicit rather than treating every possible feature as one large processing activity.

Some configurations fall within our standard assessment, some are subject to additional conditions, and some require a separate assessment before they are enabled.

You stay in control of your implementation

When you use RUMvision on your website, you generally act as the controller for your visitors' data and RUMvision acts as processor.

You decide why RUMvision is used, which websites are monitored, which optional features are enabled and which customer-controlled dimensions or settings are configured.

That also means there are a few things you remain responsible for, such as making sure your own configuration does not intentionally send unnecessary personal information and determining whether consent or another legal requirement applies to your deployment.

We provide the controls and documentation to help you make those decisions without having to reverse-engineer how our tracker works.

We have done the homework

Privacy documentation should be useful, not just something that exists because procurement asked for it.

For that reason, we maintain a pre-assessed Legitimate Interests Assessment for Real User Monitoring. It documents the technical processing, necessity assessment, safeguards and feature-specific conclusions behind the service.

Customers that want to rely on that assessment do not have to recreate the entire technical analysis themselves. They can review whether the assumptions and feature conditions match their implementation and document their actual configuration in the Customer Deployment Record.

Our standard Data Processing Agreement also applies automatically where RUMvision processes personal data on your behalf as processor. A separate signature is not required for the standard DPA.

If you just want to understand how RUMvision handles visitor data, this article should give you the practical overview.

If you are carrying out a privacy, security, legal or procurement review, we also provide the underlying documentation:

  • Data Processing Agreement for the contractual processor terms
  • Legitimate Interests Assessment for our pre-assessed RUM privacy and necessity analysis [available upon request both in PDF or via LLM chat via info op rumvision punt com]
  • Privacy Policy for the complete description of how RUMvision processes personal data
  • Subprocessor information for current service providers and processing locations
  • Terms of Service for the contractual terms governing use of RUMvision

We would rather give you the information upfront than make you ask for it through a sales process.

Our principle is straightforward: collect what is needed to understand website performance, minimise what is not needed, keep privacy-sensitive functionality under control, and be clear about where the boundaries are.