GDPR Compliance

How to use TypeUI Insights as part of a privacy-conscious analytics setup for your website.

Effective date: August 20, 2026

TypeUI gives you privacy-conscious analytics controls, but no analytics tool makes a website automatically compliant. This page is practical product guidance, not legal advice.

Your role and ours

You choose the website, install the tracker, decide when consent allows collection, define custom events, manage dashboard access, and decide how to use the results. This normally makes you the controller for your visitors' analytics. Bergside LLC normally acts as the processor while providing TypeUI Insights. The Data Processing Addendum documents those processing terms.

Connect Insights to your consent tool

The installation code includes functions your consent-management platform can use to start or stop analytics. Configure it so the tracker loads only after you receive any consent required by the GDPR, ePrivacy rules, or local law. When someone withdraws consent, stop collection and remove the local session. Global Privacy Control and Do Not Track also prevent collection.

You must decide whether consent, legitimate interests, or another lawful basis fits your situation. TypeUI cannot make that legal decision for you, and we do not claim that every website can use analytics without a consent banner.

Collect useful analytics with less visitor data

Insights is designed to measure traffic, engagement, acquisition, page-by-page journeys, custom events, click patterns, frustration signals, scroll depth, and heatmaps without intentionally collecting typed text, form values, page DOM, raw IP addresses, complete user-agent strings, query strings, URL fragments, or complete referrer URLs. The full field list and exclusions are in the Insights Data Policy.

A random identifier unique to your website links events inside one 30-minute session. It is not designed to recognize someone across separate sessions, websites, or devices. Do not place names, email addresses, user IDs, or other personal data in custom-event names or campaign values.

The live count represents pseudonymous sessions with activity in the previous 90 seconds. Treat it as approximate recent-presence analytics, not proof that an identified person is currently viewing the website.

Your setup checklist

Before enabling Insights on your website:

  • explain why you use analytics, what is collected, who receives it, how long it stays, and visitor rights in your privacy or cookie notice;
  • connect your consent platform and preserve consent records where needed;
  • avoid sign-in, health, financial, children-directed, and other sensitive pages unless a qualified adviser has approved the use;
  • exclude sensitive areas and review public pages before requesting a heatmap preview;
  • have a process for withdrawal, objections, deletion requests, incidents, and supervisory-authority communications; and
  • complete any required DPIA, transfer assessment, or legitimate-interest assessment.

Choose shared-dashboard visibility carefully

Insights dashboards are private by default. A verified website owner can deliberately make a read-only dashboard available through an unlisted link, a password, or a public page. Public dashboards may be indexed by search engines. Unlisted and password-protected dashboards send no-index, no-follow, and no-archive instructions, but a person who has the link or password can still forward it.

Before sharing, decide whether publishing live activity, traffic, location, campaign, event, and pseudonymous journey information is compatible with your notice, lawful basis, and visitor expectations. Shared dashboards are read-only, omit heatmap and scroll-position data, and replace private journey identifiers with site-specific one-way values. Those safeguards reduce exposure but do not remove your responsibility for the disclosure you choose.

When a visitor asks about their data

Insights does not build a named identity profile for each visitor. You may therefore be unable to find a particular session using only a name or email address. We will provide the reasonable assistance described in the DPA based on the information available. Do not ask visitors for a session identifier that TypeUI does not expose to them.

How long the data stays

Detailed sessions, their page journeys, and connected custom events are kept for a rolling 90 days. Aggregate traffic, engagement, and UI interaction totals remain available while your Insights subscription is active. If access ends, collection pauses and we keep remaining data for 30 days in case you return. You can also delete a website immediately. An isolated recovery copy may remain inaccessible for up to 32 additional days under its protected retention period. See Data Retention for details.

How paid usage limits affect collection

The subscription allowance is a rolling 30-day workspace pageview total. Sessions and events are not independent paid quotas. When the pageview allowance is reached, new batches are rejected before analytics storage until rolling usage falls below the limit or the plan is upgraded. This prevents unpriced collection rather than silently keeping a partial event batch.

Where processing can happen

TypeUI uses Cloudflare's global network and other providers described in the DPA. Private storage used for heatmap previews and recovery copies is configured with an EU jurisdiction. This does not mean every request or temporary operation stays only inside the EEA. You are responsible for assessing any international-transfer requirements that apply to your website using the information and contractual options available from TypeUI and its providers.

Appropriate safeguards reduce risk but do not make any online system perfectly secure, available, or recoverable. This does not remove Bergside's or the Customer's obligations or data-subject remedies that cannot be limited under applicable law.

Official GDPR resources