Spectra

Session recording and the GDPR

Written for the person who has to approve this: a data protection officer, a lawyer, or the founder who is both. Every claim below is stated again in the Privacy Policy and the Data Processing Agreement, which are the documents that bind us. This page explains them.

Why session recording is usually the problem

A session recorder watches what a person does on a website: where they moved, what they clicked, what they typed. Under the GDPR that is personal data about that person, and the website running the recorder is the controller of it. The recorder's vendor is a processor acting on their instructions.

Three things usually stall the approval. The tool collects IP addresses, which are personal data on their own and rarely necessary for the purpose. The recordings are held outside the European Economic Area, so every session becomes an international transfer that has to be justified. And form fields are captured and then filtered on the vendor's servers, which means the unfiltered version existed on somebody else's machine, however briefly.

What Spectra collects

For each recorded visit: the pages visited, pointer movement and clicks, scrolling, the structure of the page as it changed, errors the page produced, the browser family, the operating system, and a device class of phone, tablet or desktop. A random identifier groups one person's pages into one visit. It contains nothing about them and is not shared between customers.

What Spectra never collects

IP addresses

Not collected, not truncated, not held briefly and discarded. There is no field for a visitor IP address anywhere in the system: not in the recorder, not in the ingest path, not in the database schema. This is the one worth checking us on, because it is unusual and because it is the claim that does the most work in an assessment. A visitor IP we do not take is one that cannot leak, cannot be demanded of us, and does not need a retention rule.

Anything masked, which is masked before it is sent

Masking happens on the visitor's own device, in their browser, before anything is transmitted. Password fields are never sent at all. Form field contents are masked by default. Text matching common patterns for email addresses and card numbers is redacted, and page addresses have credential-bearing parameters removed. What reaches us is already covered up, so a breach of our systems does not expose it: it was never there.

Tracking across sites

No advertising or cross-site tracking cookies, and no profile of a person assembled across different customers' websites. We do not sell data and we do not train models on it.

Where recordings are held

In France, inside the European Economic Area, and they are not copied anywhere else. For a customer in the EEA or the UK, the recordings themselves stay in the Union.

Spectra is run from India, so operating the service means reaching data held in France from outside the EEA. That access is a restricted transfer and we do not pretend otherwise. It is made under the European Commission's Standard Contractual Clauses, Decision 2021/914, Module Two, controller to processor, and under the UK International Data Transfer Addendum where UK data is involved. Both are part of the Data Processing Agreement.

Lawful basis, and who decides it

The customer decides, because the customer is the controller. Most rely on legitimate interests, which needs a balancing test on their side, and some rely on consent. Spectra supports either: the recorder can be held until a consent gate releases it, and until then it stores nothing and sends nothing. It also honours Global Privacy Control and Do Not Track.

Rights requests

A controller can delete one visitor's recordings, delete an entire site's, or close the account and have everything removed. Deletion takes effect immediately wherever a recording is held, listed or searched, and there is no archived copy anywhere to outlive it. Account records roll off within thirty days, which is the longest anything can persist.

What we cannot claim

An assessment that only hears good news is not worth reading, and these come up in every serious review, so they are here rather than in a reply three weeks later.

What to ask for

The Data Processing Agreement is published in full rather than produced on request. It sets out roles, security measures, sub-processors by category, international transfers, deletion, and audit rights. We name every sub-processor, and what it does, to any customer who asks: write to privacy@spectra-trace.com. We give thirty days' notice by email before a new one starts, and a customer may object.