Wingify Data Privacy Compliance Guide for Insights Customers: Navigating Data Protection Laws w.r.t Session Recordings and Safeguarding

Ensuring Compliance with use of Wingify Insights

Welcome to the Wingify Compliance Guide for Wingify Insights – Session recordings, a detailed resource designed to empower our valued customers with actionable steps for ensuring privacy and legal adherence when using Wingify Insights for visitor user session recordings. As a responsible Data Processor for your visitor/user data, Wingify is committed to providing support for your compliance efforts under data protection laws such as GDPR, IN DPDP, CCPA, PIPEDA, and more. This guide covers essential information, offering an exhaustive compliance checklist, in-depth considerations, and additional details to help you navigate the complex legal landscape especially when it comes to visitor user session recordings.

We at Wingify owe our growth to our customers and building their trust is our top priority. We understand the importance of data in today’s ever-evolving digital landscape and its significance to our customers’ operations and thus, keeping it secure and compliant is paramount to us.

Recent legal actions highlight the critical importance of meticulous compliance with privacy laws when employing session replay softwares. The main reason behind these lawsuits is not the “session replay software” but the lack of “legitimate grounds for processing of personal data” and non-adherence to privacy principles, typically article 5 and 6 of the GDPR if we talk about EU and UK. It is mandatory to have a legitimate ground for the processing of personal data and adherence to privacy principles while using session recordings. Consent is the legitimate ground in this case and it is mandatory for all data controllers to show all data subjects cookie notice, privacy notice and get consent from the data subject for these things.

To fortify your position and ensure the utmost protection for both your users and your organization, consider the following detailed guidelines:

1. Understand Your Role:

2. Privacy Notice and Consent:

3. Wingify Terms and DPA:Wingify Terms and DPA:

4. Default Anonymization Settings:

5. Anonymization of Non-Input Fields:

Anonymization can be done by the owner and admin of the account and whitelisting can only be done by the owner.

For complete details and procedures, refer KB article hosted at https://help.wingify.com/hc/en-us/articles/58760372362649-How-to-secure-your-visitors-data-in-Wingify-Session-Recordings  

6. Regular Review and Update:

7. Transparency:

8. Consent and Cookies:

9. Limited Access:

By meticulously adhering to these procedures and guidelines and regularly reviewing and adapting your practices, you can ensure the responsible and compliant use of Wingify Insights. This not only safeguards your users but also strengthens your organization’s credibility in the digital realm. Remember, your commitment to privacy is a testament to your organization’s dedication to user trust and legal integrity.

Please note:

  1. This checklist and these procedures only act as a friendly guide and not as a legal advice to our clients. It is advisable client check with your in-house DPO/Compliance team/Attorney for the legal advices.
  2. Wingify shall not be responsible for notifying any client about any update in the legal regime or any additions in their region-specific legal requirements.
  3. Wingify shall not be liable in case of any non-adherence to regional/sectoral law of client’s jurisdiction by the client as this guide is generic in nature and not cover regional/sectoral compliance requirements.
  4. Showing privacy notice and taking user consent is the responsibility of Wingify’s customer as the same is mentioned under 3.4 of the Wingify terms hosted at Wingify Terms and 2.2 of the Wingify DPA hosted at Wingify DPA