Table of Contents
- Privacy and security, by design
- 1. Who we are
- 2. Our role under data protection law
- 3. Real User Monitoring on customer websites
- 4. Browser identifiers and browser storage
- 5. Optional Business Metrics
- 6. Optional JavaScript and browser error monitoring
- 7. Optional responsiveness and interaction-health diagnostics
- 8. Optional additional device information
- 9. Custom dimensions and unintended personal data
- 10. Legal basis for customer website RUM
- 11. RUMvision account and subscription data
- 12. Billing and financial administration
- 13. Support and communications
- 14. Security and prevention of misuse
- 15. Our own website, analytics and cookies
- 16. Marketing communications
- 17. AI-supported features
- 18. MCP and customer-selected third-party AI services
- 19. Recruitment
- 20. Legal obligations and legal claims
- 21. Service providers, subprocessors and other recipients
- 22. International transfers
- 23. Retention
- 24. Automated decision-making
- 25. Your data-protection rights
- 26. Security
- 27. Data-protection contact
- 28. Complaints
- 29. Changes to this Privacy Policy
Privacy Policy
Version 3.0 - 10 September 2026
Privacy and security, by design
RUMvision is a Dutch company that helps website owners understand and improve how their websites perform for real visitors. Privacy, data minimisation and security have been part of the way we built RUMvision from the beginning.
In short: we measure how well websites work. We do not use visitor-level RUM Data for advertising or behavioural targeting, we do not fingerprint visitors, we do not track people across unrelated websites, and RUMvision is not a session replay or screen-recording service.
Some limited technical information can still count as personal data under the GDPR, even when it does not tell us who a visitor is. That is why we treat relevant RUM Data carefully and apply the safeguards described in this policy.
Our core visitor-level RUM processing infrastructure is located within the European Union. Some separate business services or optional functionality may involve other processing locations, in which case the applicable safeguards and current provider information are described in our data-processing documentation.
The sections below explain what we process, why we process it and what rights apply.
1. Who we are
RUMvision B.V.
Ubbo Emmiussingel 21
9711 BB Groningen
The Netherlands
KvK / Chamber of Commerce: 85752762
Email: info op rumvision punt com
Phone: +31 50 700 1973
2. Our role under data protection law
Our role depends on the processing activity.
2.1 When RUMvision acts as controller
RUMvision generally acts as controller when we process personal data for our own business purposes, for example in connection with:
- RUMvision customer accounts and subscriptions;
- billing and financial administration;
- customer support and communications;
- security and fraud prevention;
- our own website;
- marketing;
- recruitment; and
- compliance with legal obligations.
In these situations, RUMvision determines why and how the relevant personal data is processed.
2.2 When RUMvision acts as processor
When a customer uses RUMvision on its website to measure and improve website performance and effectiveness, the website operator generally acts as the controller and RUMvision generally acts as processor.
The customer determines why RUMvision is used, which websites are measured, which optional functionality is enabled and, where applicable, which custom dimensions or other customer-controlled settings are configured.
RUMvision processes visitor-level RUM Data on the customer's behalf and in accordance with documented instructions. Where RUMvision acts as processor, our standard Data Processing Agreement ("DPA") applies automatically as part of the contractual relationship. Customers do not need to request or separately sign the standard DPA.
If you are visiting a website that uses RUMvision, the operator of that website is normally the organisation responsible for providing you with information about its processing and for handling your data-protection rights. RUMvision assists its customers with those obligations where required.
The exact allocation of roles always depends on the actual processing activity and applicable law.
3. Real User Monitoring on customer websites
RUMvision measures the technical performance actually experienced by visitors while using a website.
The purpose is to help website operators measure, diagnose and improve the technical performance, reliability, user experience and effectiveness of their websites.
Depending on the website configuration, RUM Data may include:
- Core Web Vitals and other loading, rendering and responsiveness timings;
- page and navigation context;
- relevant URL paths;
- timestamps and pageview, navigation or limited visit context;
- browser and operating-system categories;
- device category, viewport and relevant technical capabilities;
- relevant network characteristics;
- country-level location information;
- limited engagement context, such as time on page and scroll depth;
- information used to identify automated traffic, measurement noise or unreliable measurements;
- relevant consent-management or CMP state where applicable;
- customer-configured dimensions; and
- randomly generated request, navigation, visit or browser identifiers.
RUMvision does not use visitor-level RUM Data to identify visitors by name, create advertising profiles, perform behavioural targeting, personalise advertising, make decisions about individual visitors or recognise visitors across unrelated websites.
Query parameter values and URL fragments are not collected as ordinary RUM dimensions by default.
Exact URL paths may be processed where they are necessary to diagnose and reproduce performance issues. Customers should configure their websites so that URLs containing direct identifiers, authentication credentials, sensitive information or other unnecessary personal data are excluded or appropriately transformed.
Raw IP addresses are not retained in the normal RUM measurement dataset. IP addresses may nevertheless be processed transiently as part of normal internet, hosting, security or infrastructure operations, including where necessary to derive country-level information.
4. Browser identifiers and browser storage
4.1 Persistent first-party Browser Identifier
Where persistent browser storage is enabled, RUMvision may use a randomly generated first-party Browser Identifier to support limited visit continuity and associate relevant RUM measurements over a limited period.
The Browser Identifier:
- is randomly generated;
- is not derived from browser fingerprinting;
- does not contain a name, email address, customer account identifier or other direct identifier;
- is specific to the website on which RUMvision is deployed;
- is not used to recognise a browser across unrelated websites; and
- has a maximum lifetime of 90 days.
After expiry, the persistent state is removed and a new random identifier may be generated for subsequent processing. The lifetime is measured from the first pagehit that created the persistent state and is not extended indefinitely simply because a visitor returns to the website.
Although the Browser Identifier does not directly identify a person, RUMvision conservatively treats the Browser Identifier and associated visitor-level RUM Data as personal data where the GDPR may apply. We do not describe this data as anonymous.
4.2 Temporary browser storage
RUMvision may also use sessionStorage and temporary in-memory state for technical information needed to operate the RUM functionality efficiently.
This may include measurement or sampling state, configuration, visit-related technical information, URL matching rules and temporary transport or plugin state.
sessionStorage is limited to the relevant browser tab or session and is not intended to be a long-term visitor identifier.
4.3 Persistent browser storage controls
RUMvision may use localStorage, where enabled, for limited first-party persistent state such as the Browser Identifier, visit information, counters and technical timestamps.
Persistent browser storage is enabled in the standard RUMvision property configuration because it supports limited visit continuity. Customers can disable this storage through the supported RUMvision configuration.
Where prior consent is required under applicable law, the relevant browser storage or processing capability must remain inactive until that consent has been obtained.
The GDPR legal basis for processing personal data and the rules governing storage of or access to information on a visitor's device are separate legal questions. Customers are responsible for assessing both for their own deployment.
5. Optional Business Metrics
Customers may optionally enable Business Metrics.
Business Metrics are used to analyse how website performance relates to relevant website actions and outcomes.
Depending on the customer's configuration, Business Metrics may include:
- configured events or goals;
- event or goal name and version;
- goal eligibility or completion state;
- timestamps;
- technical visit, pageview or request references;
- relevant page or URL context;
- relevant website-performance measurements; and
- limited quantitative values, such as a conversion value or item count, where supported and enabled.
Business Metrics are not intended to collect names, email addresses, customer or account identifiers, order IDs, product IDs, product names, basket contents, payment information, form contents, free-form conversion text or arbitrary customer-defined objects.
Event and goal definitions should also not be configured in a way that intentionally reveals special-category personal data or similarly sensitive information without a separate lawful assessment.
Business Metrics are not intended for advertising, retargeting, behavioural marketing profiles, individual visitor scoring, personalised advertising or cross-site attribution.
6. Optional JavaScript and browser error monitoring
Customers may optionally enable JavaScript and browser error monitoring to detect, reproduce and resolve technical website errors.
Depending on the error and configuration, this may include:
- error type or name;
- error message;
- relevant stack trace;
- source URL;
- source line and column;
- page or template context;
- timestamps and occurrence counts;
- browser-reporting information;
- technical information about failed network requests; and
- limited technical navigation, click or submit breadcrumbs preceding an error.
Breadcrumbs are intended to provide bounded technical context and are not intended to contain form-field values or general page contents.
Where failed-network monitoring is enabled, RUMvision is designed to process failed requests only. Request bodies, response bodies, request headers and response headers are not intentionally read by this functionality.
Query strings and URL fragments are not retained as part of standard error URL processing unless an optional configuration is explicitly enabled.
Because application-generated errors and stack traces cannot always be predicted, error information may exceptionally contain personal data outside the intended scope. Where this occurs, RUMvision may work with the customer to stop or minimise further collection and, where appropriate, remove affected stored data.
7. Optional responsiveness and interaction-health diagnostics
Customers may optionally enable additional diagnostics to understand why a website feels slow or does not respond as expected.
This can include browser timing information and limited technical interaction-health signals. For example, RUMvision may identify a bounded pattern such as repeated clicking, repeated submission attempts, delayed response or unusual scroll behaviour that indicates a possible website-quality problem.
To identify these patterns, eligible interactions may be processed temporarily in the browser. Ordinary interactions that do not form a relevant diagnostic episode are not intended to become detailed stored interaction records.
RUMvision responsiveness monitoring is not session replay. It is not designed to record screen contents, keystrokes, form values, continuous pointer movement or a complete clickstream.
Some additional context, such as interaction-label text or URL query-string or fragment details, can be more privacy-sensitive and is not treated as part of the ordinary baseline processing. Customers must separately assess such functionality before enabling it.
8. Optional additional device information
Certain additional browser and device characteristics are not required for baseline RUM functionality.
Where available, these may include additional technical signals used for performance segmentation, compatibility analysis or measurement-integrity purposes.
Such functionality is only processed according to the configuration selected for the relevant website and must be assessed separately where the nature of the information or applicable law requires this.
9. Custom dimensions and unintended personal data
Customers may configure custom dimensions and other customer-controlled fields to provide additional context relevant to RUM analysis.
These fields are intended only for information that is necessary and proportionate for website-performance, reliability, responsiveness and effectiveness purposes.
Customers should not intentionally use custom dimensions, URLs, Business Metrics, event or goal names, error context, DOM identifiers or selectors, labels, console context or similar fields to send:
- names;
- email addresses;
- customer or account identifiers;
- authentication credentials or tokens;
- payment information;
- special categories of personal data; or
- other direct identifiers or unnecessary personal data.
Because customers control parts of their website and RUMvision configuration, personal data outside the intended scope may occasionally be transmitted unintentionally.
Where RUMvision becomes aware of such information, we may work with the customer to stop or minimise further collection and determine appropriate remediation. Depending on the circumstances and technical structure of the data, this may involve removal of individual records, affected periods or broader domain-level data.
10. Legal basis for customer website RUM
The website operator, as controller, is responsible for determining and documenting the legal basis that applies to its use of RUMvision.
For the RUM processing assessed in RUMvision's Legitimate Interests Assessment, the assessment is based on Article 6(1)(f) GDPR and considers the legitimate interest in measuring, diagnosing and improving website performance, reliability, responsiveness, user experience and effectiveness against the rights and interests of website visitors.
The assessment relies on safeguards including limited purposes, data minimisation, the 90-day maximum for the persistent first-party Browser Identifier, no cross-site identification, no fingerprint-based identifier, no advertising or behavioural targeting, limited location information and restrictions on direct identifiers and sensitive customer-controlled data.
Not every RUMvision feature or configuration is automatically covered by that assessment. Some optional functionality may require a separate assessment, additional safeguards, consent or another appropriate legal basis.
The use of localStorage, sessionStorage, browser APIs and similar technologies must also separately comply with applicable rules concerning the storage of or access to information on a visitor's device.
For customers subject to Dutch law, Article 11.7a of the Dutch Telecommunications Act may apply separately from the GDPR. Whether consent is required depends on the actual implementation, purpose and applicable rules.
RUMvision does not represent that every configuration of the Service is automatically exempt from consent requirements.
11. RUMvision account and subscription data
When you create or use a RUMvision account or act as a contact person for a customer, we may process information including:
- your name;
- business email address;
- phone number;
- company and job information;
- account and authentication information;
- subscription and product configuration;
- domains associated with the account;
- account activity; and
- communication and support history.
Where you personally enter into an agreement with us, processing necessary to perform that agreement may be based on Article 6(1)(b) GDPR.
Where you act on behalf of a company or other organisation, we generally process your business contact information based on our legitimate interest under Article 6(1)(f) GDPR in managing the customer relationship, providing the Service and communicating with our customers.
12. Billing and financial administration
We process billing and transaction information to:
- administer subscriptions;
- issue and process invoices;
- process payments;
- maintain our financial administration; and
- comply with tax and accounting obligations.
This may include company and contact details, billing addresses, VAT information, transaction information and payment-related information.
Payment information may also be processed by external payment service providers.
Depending on the processing activity, the legal basis is performance of a contract under Article 6(1)(b) GDPR or compliance with a legal obligation under Article 6(1)(c) GDPR.
13. Support and communications
When you contact us, request support or otherwise communicate with RUMvision, we may process:
- your contact information;
- your question, request or complaint;
- correspondence and support history;
- information you provide as part of a support request; and
- limited technical information necessary to diagnose or secure the Service.
We process this information where necessary to perform or prepare a contract or based on our legitimate interest in supporting customers, responding to enquiries and operating our business.
Please avoid sending unnecessary personal data, confidential information, passwords or special-category personal data through support channels.
14. Security and prevention of misuse
We process information where necessary to protect our accounts, customers and infrastructure against unauthorised access, abuse, fraud and other security threats.
This may include:
- authentication information;
- login attempts;
- IP addresses and technical logs;
- account activity;
- security events;
- device or browser information relevant to security; and
- domain-verification information.
Our legal basis is generally our legitimate interest under Article 6(1)(f) GDPR in securing our systems and preventing misuse. Where processing is required by law, Article 6(1)(c) GDPR may apply.
15. Our own website, analytics and cookies
This section concerns RUMvision's own websites and platform, rather than the RUMvision snippet operating on customer websites.
We may use functional, analytical and, where enabled, marketing technologies on our own website.
Some technical or low-impact analytical technologies may be used without consent where permitted by applicable law.
Where cookies or similar technologies require consent, we activate them only after the required consent has been obtained.
Our current cookie settings or Cookie Statement should identify the technologies, purposes, providers and applicable retention periods used on our website and allow you to manage your choices.
You can withdraw consent at any time through our cookie settings where consent is used.
16. Marketing communications
We may use business contact information to send information about RUMvision products, services, events or related developments where permitted by applicable law.
Where prior consent is required, we rely on consent.
Where applicable law allows communications to existing customers concerning our own similar products or services, we may rely on our legitimate interests under the GDPR, provided the applicable electronic-communications requirements are satisfied.
You can unsubscribe from marketing communications at any time. This does not affect necessary account, billing, security or service communications.
17. AI-supported features
Certain RUMvision subscriptions may include optional AI-supported analyses, recommendations or other features.
When a customer enables an AI Feature, RUMvision and an AI Provider engaged by RUMvision may process the prompts, inputs, outputs and other information required to provide and secure the enabled feature.
The specific AI provider or model used may change over time as we evaluate available services for quality, security, privacy and functionality.
We and AI Providers acting on our behalf do not use Customer Data, prompts, inputs or outputs in identifiable or customer-linked form to train or improve general-purpose or cross-customer AI models unless the customer has expressly agreed to such use and the processing is otherwise permitted by applicable law.
Where information has been lawfully and irreversibly anonymized so that neither an individual nor the relevant customer can reasonably be identified, such information may be used for service evaluation and improvement where permitted under our agreements and applicable law.
AI Providers that process personal data on behalf of RUMvision are treated as subprocessors where applicable and are identified in our current service provider and subprocessor information rather than being fixed by name in this Privacy Policy.
18. MCP and customer-selected third-party AI services
Customers may use RUMvision's Model Context Protocol ("MCP") integration to make data available to an external AI or other service selected or configured by the customer.
Where the external service is selected and controlled by the customer rather than engaged by RUMvision to provide a RUMvision AI Feature, that provider is not automatically a RUMvision subprocessor.
The customer's use of that external service is subject to the provider's own terms, privacy practices and applicable data-protection arrangements.
The parties' respective roles under data-protection law depend on the actual processing activity and cannot be determined solely by a contractual label.
19. Recruitment
If you apply for a position with RUMvision, we may process:
- your name and contact information;
- CV and application documents;
- employment and education history;
- interview notes;
- information you voluntarily provide during the recruitment process; and
- references where appropriate.
We process this information to evaluate your application and take steps at your request before potentially entering into an employment contract.
Information concerning unsuccessful applicants is generally deleted within four weeks after completion of the application procedure, unless we agree with you that the information may be retained for possible future opportunities. Where you consent to longer retention, we may retain the application for up to one year.
20. Legal obligations and legal claims
We may process personal data where necessary to:
- comply with applicable laws and binding requests from competent authorities;
- maintain legally required financial or corporate records;
- establish, exercise or defend legal claims; or
- investigate violations of our agreements or applicable law.
The applicable legal basis may be Article 6(1)(c) GDPR or our legitimate interests under Article 6(1)(f) GDPR.
21. Service providers, subprocessors and other recipients
We use third parties to help provide and operate our services.
These may include providers of:
- hosting and cloud infrastructure;
- database, search and technical infrastructure;
- security and monitoring services;
- payment and accounting services;
- email and communications systems;
- customer-support and productivity tools;
- AI services where an AI Feature is enabled; and
- website analytics and marketing services for our own website.
Access is limited to what is necessary for the relevant service.
Where a provider processes personal data on our behalf, we enter into appropriate data-processing arrangements and apply the requirements of Article 28 GDPR where applicable.
We maintain separate, up-to-date service provider and subprocessor information identifying relevant providers, their functions and applicable processing or hosting locations.
Where required, customers are informed about additions or replacements of subprocessors and are given the rights provided by the DPA and applicable data-protection law.
Where a third party acts as an independent or joint controller rather than as our processor, its own privacy terms may also apply.
22. International transfers
Our core visitor-level RUM processing infrastructure is located within the European Union.
Some other service providers or optional functionality may involve processing personal data outside the European Economic Area ("EEA").
Where personal data is transferred outside the EEA, we apply an appropriate transfer mechanism as required by Chapter V GDPR. Depending on the destination and provider, this may include:
- a European Commission adequacy decision;
- Standard Contractual Clauses approved by the European Commission; or
- another legally permitted transfer mechanism.
Where required, we assess whether supplementary safeguards are appropriate.
Further information about relevant service providers, subprocessors, locations and transfer safeguards is available through our DPA and current service provider and subprocessor information.
23. Retention
We do not keep personal data for longer than necessary for the purposes for which it is processed, unless a longer period is required by law or is necessary for legal claims.
23.1 RUM Service retention
| Data | Retention |
|---|---|
| Persistent Browser Identifier | Maximum 90 days |
Temporary sessionStorage information | Relevant browser tab/session |
| Server-side RUM measurement data | Up to 13 months |
| Business Metrics forming part of the RUM Service | Up to 13 months |
| JavaScript and browser error-monitoring data | Up to 13 months |
| Responsiveness and interaction-health data | Up to 13 months |
| Customer RUM Data after termination | Deleted within up to 2 months, unless continued retention is lawfully required or instructed |
For more context-rich optional telemetry, a shorter retention period may be appropriate where the same diagnostic purpose can be achieved with less retention.
23.2 Other RUMvision retention periods
| Data | General retention |
|---|---|
| Customer account data | For the active relationship and generally up to 3 years afterwards where necessary |
| Financial and invoicing records | Generally 7 years where required under Dutch tax and accounting law |
| Simple one-off contact enquiries | Generally up to 3 months where no longer required |
| Customer support history | Generally up to 3 years after the last relevant interaction |
| Security logs | Generally up to 1 year, unless longer retention is required for an investigation |
| Marketing information | Until consent is withdrawn, an objection is made, or generally after 3 years of inactivity where no longer required |
| Unsuccessful recruitment applications | Generally 4 weeks, or up to 1 year with consent |
Specific data may be deleted earlier where it is no longer required or retained longer where this is necessary to comply with law, investigate security incidents or establish, exercise or defend legal claims.
Information that has been irreversibly anonymized and can no longer reasonably relate to an identifiable person is no longer personal data under the GDPR.
24. Automated decision-making
RUMvision does not use visitor-level RUM Data to make solely automated decisions about website visitors that produce legal effects or similarly significantly affect them.
AI-generated analyses and recommendations provided to customers are intended as decision-support information and should be reviewed by the customer before being relied upon.
25. Your data-protection rights
Where RUMvision acts as controller, you may have the following rights under the GDPR:
- access to your personal data;
- correction of inaccurate personal data;
- deletion of personal data where the legal requirements are met;
- restriction of processing;
- data portability where applicable;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time where processing is based on consent; and
- the right to lodge a complaint with a supervisory authority.
If processing is based on Article 6(1)(f) GDPR, you have the right to object on grounds relating to your particular situation. The controller must then stop that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms or the processing is required for legal claims.
To exercise your rights in relation to personal data for which RUMvision is controller, contact us at info op rumvision punt com.
We generally respond within one month. In complex cases, this period may be extended in accordance with the GDPR, in which case we will inform you within the initial one-month period.
25.1 Visitors to customer websites
If your request relates to a website operated by a RUMvision customer, please normally contact that website operator first, because it generally acts as controller.
RUMvision will assist the customer with requests concerning RUM Data in accordance with our DPA and applicable law.
26. Security
We maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the relevant systems and risks, these measures may include access controls, authentication controls, encryption, logging and monitoring, incident-response processes, backup procedures, employee confidentiality obligations and appropriate security requirements for service providers.
We also use data-minimisation, sanitisation and configurable collection controls within the RUM Service to reduce unnecessary processing where appropriate.
Further information about security measures applicable to customer data is provided through our DPA and associated security documentation.
27. Data-protection contact
Questions about this Privacy Policy, RUMvision's processing of personal data or the exercise of your privacy rights can be sent to:
RUMvision B.V.
Ubbo Emmiussingel 21
9711 BB Groningen
The Netherlands
Email: info op rumvision punt com
Phone: +31 50 700 1973
28. Complaints
If you believe that RUMvision is processing your personal data unlawfully, please contact us so that we can review your concern.
You also have the right to lodge a complaint with the competent supervisory authority.
For RUMvision in the Netherlands, this is the Autoriteit Persoonsgegevens.
29. Changes to this Privacy Policy
We may update this Privacy Policy when our services, processing activities or applicable legal requirements change.
We will publish the current version and effective date on our website. Where changes materially affect how we process personal data, we will provide additional notice where required.