--- title: "Your responsibilities (Help Center / Privacy & security / Monitoring)" ai_context: "Use this article for questions about customer responsibilities when using RUMvision, including controller obligations, legal basis, consent requirements, privacy notices, feature selection and keeping customer-configured data within intended privacy boundaries. It covers reviewing optional features, persistent browser storage, custom dimensions, Business Metrics, events, URL structures, DOM selectors and other customer-controlled fields, and explains which personal or sensitive data should not be intentionally sent to RUMvision. Relevant for questions about GDPR controller versus processor roles, Legitimate Interests Assessments, Customer Deployment Records, consent gating, withdrawing consent, URL paths containing personal data, privacy-policy disclosures, retention information and what RUMvision handles versus what the website operator must assess and configure." canonical: "https://www.rumvision.com/help-center/privacy-security/monitoring/your-responsibilities/" --- Breadcrumbs: [Home](https://www.rumvision.com/?format=md) > [Help Center](https://www.rumvision.com/help-center/?format=md) > [Privacy & security](https://www.rumvision.com/help-center/privacy-security/?format=md) > [Monitoring](https://www.rumvision.com/help-center/privacy-security/monitoring/?format=md) > Your responsibilities # What am I responsible for as a RUMvision customer? RUMvision is designed to do as much of the privacy and technical groundwork as possible for you. We provide the controls, documentation and pre-assessed framework behind the service. You still remain responsible for how RUMvision is actually configured and used on your own website. In practice, that mainly means making a few conscious choices about your setup and making sure your own website does not send data that RUMvision was never intended to collect. ## Decide which RUMvision features you want to use RUMvision is modular, so you decide which monitoring capabilities are enabled for your property. Core Real User Monitoring can be used independently from optional functionality such as JavaScript error monitoring, responsiveness diagnostics, Business Metrics or additional browser and device information. You should review the features you enable and make sure they fit the purpose for which you are using RUMvision. ## Determine your legal basis and consent requirements As the website operator, you generally act as the controller for visitor-level RUM data. RUMvision generally acts as your processor. This means you are responsible for determining the legal basis that applies to your use of RUMvision. You should also separately consider whether your configuration requires prior consent for browser storage or other access to information on the visitor's device. If a particular capability requires consent, it should be configured so that it does not start before that consent has been obtained. Our Legitimate Interests Assessment can help with this. It contains our pre-assessed analysis for the RUMvision processing covered by the document, so you do not need to recreate our technical and legal assessment from scratch. ## Review your own configuration Because every website is different, you should check that the assumptions in our documentation match the way RUMvision is actually deployed on your website. This includes things such as: - which optional features are enabled - whether persistent browser storage is enabled - whether any feature is gated behind consent - which custom dimensions you have configured - which events or Business Metrics you measure - how your URLs are structured If you use our Legitimate Interests Assessment, you can document this in the Customer Deployment Record included in the LIA. ## Keep customer-controlled data clean Some parts of RUMvision can be configured using information from your own website. This can include custom dimensions, event names, goal names, URL structures, DOM identifiers, selectors or additional debugging context. You should not intentionally configure these fields to send unnecessary personal or sensitive information. In particular, avoid sending: - names or email addresses - customer or account identifiers - authentication credentials or security tokens - payment information - form contents - special-category personal data - other direct identifiers that are not necessary for performance analysis ## Check your URL structure RUMvision can process page paths because knowing where a performance problem occurred is often essential for diagnosing it. If your website places personal or sensitive information directly in URL paths, you should change, exclude or transform that information before sending it to RUMvision. Query parameter values and URL fragments are not collected as ordinary RUM dimensions by default, but optional configurations that add more URL context should be reviewed separately. ## Keep your visitors informed Your own privacy information should accurately describe how you use RUMvision. Depending on your configuration, this may include explaining that you use Real User Monitoring to measure website performance, the types of technical information involved, the legal basis you rely on, relevant retention periods and whether browser storage is used. If you rely on consent for a particular capability, visitors should also be able to withdraw that consent where required. You do not need to reproduce the entire RUMvision LIA or our technical documentation in your privacy policy. Your notice should describe what actually happens on your website in clear language. ## What if I enable something later? If you enable an optional feature later, review whether that changes your privacy information, legal basis, consent setup or internal documentation. This is one reason RUMvision keeps optional monitoring features modular. You can assess a new capability before enabling it instead of accepting every possible type of processing from the start. ## What does RUMvision take care of? You are not expected to audit our internal implementation yourself. RUMvision is responsible for the technical design and operation of the service, our processor obligations, the safeguards described in our documentation and maintaining the underlying Legitimate Interests Assessment for the processing we have assessed. We also provide a standard Data Processing Agreement where we process personal data on your behalf. Your responsibility is mainly to make sure that the configuration you choose matches your own legal and privacy requirements. ## In short You do not need to become a RUM privacy expert before using RUMvision. We document how the service works and provide a pre-assessed framework. You decide which features you use, keep your own configuration within the intended boundaries, assess any consent requirements that apply to your deployment and explain your actual use of RUMvision to your visitors.