Privacy Policy

How Loggify UG (haftungsbeschränkt) processes personal data when you visit cobrowse.loggify.app, use the Cobrowse dashboard, or take part in a co-browsing session. The guiding principle is simple: the content of a session never reaches our servers, so there is very little for us to process in the first place.

Last updated: 12 July 2026

1. Controller

The controller responsible for the processing described here is:

Company
Loggify UG (haftungsbeschränkt)
Address
Wilhelmstr. 57, 50733 Cologne, Germany

We are not legally required to appoint a Data Protection Officer. For any question about your data or this policy, write to the e-mail address above and we will handle it directly.

2. The principle: privacy by architecture

Cobrowse mirrors a web page between a visitor's browser and a support agent's browser. That content — the page the visitor sees, everything they type or click, pointer movements, annotations, and the audio of a voice call — travels directly between the two browsers over an end-to-end encrypted WebRTC channel. It is never transmitted to, stored on, or readable by our systems.

As a result, our backend only ever processes the small amount of metadata needed to broker and manage a session. The sections below list exactly what that is. Where a direct connection cannot be established, the encrypted stream falls back to a relay (Cloudflare) that forwards packets it cannot decrypt and stores nothing.

3. Visiting our website

When you open a page on our website, your browser necessarily transmits technical data to our hosting provider so the page can be delivered. This is processed in server log data and typically includes your IP address, the requested URL, date and time, referrer, and browser/OS information.

Purpose: delivering the website securely and reliably, and defending against attacks. Legal basis: our legitimate interest in a functioning, secure website (Art. 6 (1) (f) GDPR). This data is retained only briefly by the hosting provider for security and troubleshooting and is not used to identify you.

Our website is served by Vercel (see recipients below). We do not run advertising trackers on it. Any cookie or storage beyond what is strictly necessary is only set with your consent — see the Cookie section.

4. Cookies & consent management

We use the consent management platform Cookiebot (by Usercentrics A/S) to obtain and document your consent for any non-essential cookies or similar technologies. When you first visit, Cookiebot shows a banner; your choice is stored so we can honour it on later visits, and you can change it at any time.

Strictly necessary cookies and functional local storage (for example, keeping you signed in to the dashboard, or keeping an already-consented co-browsing session alive across a page reload) are set on the basis of § 25 (2) TDDDG and our legitimate interest (Art. 6 (1) (f) GDPR); they do not require consent. Any non-essential storage is set only after you consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR), and you can withdraw that consent at any time with effect for the future.

Cookiebot itself stores a consent cookie and an anonymised, encrypted record of your consent as evidence that it was given. The consent banner and declaration are loaded from Cookiebot's servers.

5. Your account & the dashboard

To use the Cobrowse dashboard you create an account. We process your e-mail address, display name, an optional profile photo, authentication identifiers, your workspace memberships and role, your availability status, and your last-used settings.

Sign-in is passwordless: a magic link sent to your e-mail, or a social/enterprise identity provider you choose (for example Google). We process this data to provide the service you signed up for. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). Authentication is handled by Firebase Authentication (Google); see recipients below.

We keep account data for as long as your account exists. When you delete your workspace/account, the associated personal data is deleted without undue delay, unless we are required by law to retain it (e.g. records with tax or commercial-law retention periods).

6. Operating a co-browsing session (session metadata)

When a co-browsing session, callback, or voice call runs, our backend processes only the metadata required to set it up and manage it — never the content, which is peer-to-peer:

  • WebRTC signaling: short-lived handshake metadata (session descriptions, network candidates) and, transiently, the participants' IP addresses needed to establish the connection;
  • support codes: the short code that pairs a visitor with an agent, and the opaque room it maps to;
  • session records: status and timing metadata (which agent ran which session, when) — never any session content;
  • agent availability: heartbeat presence so the widget knows whether help is available;
  • callback requests: the phone number and optional name a visitor submits to be called back;
  • voice/browser-call records: ring/answer metadata only (who answered, when).

For our customers' agents, we process this to provide the contracted service (Art. 6 (1) (b) GDPR). For a website visitor's data, we act as our customer's processor (next section). All of this metadata carries an automatic expiry and is hard-deleted on schedule — see Retention.

7. When we act as a processor (website visitors)

If you took part in a co-browsing session as a visitor of another company's website, that company — not us — is the controller for your personal data. We only process it on their behalf, as their processor, strictly to run the session, under a Data Processing Agreement (Art. 28 GDPR).

Because session content is exchanged directly between your browser and the agent's browser, we never receive it. Password fields are always excluded from mirroring at the source, and the website operator can exclude any further field. For questions about how a specific website uses Cobrowse — or to exercise your rights regarding that session — please contact the operator of the website you were using. We will support them as required.

8. Contacting us, e-mail & CRM

If you contact us by e-mail (for support, sales, or otherwise), we process the content of your message and your contact details to handle your request. Legal basis: performance of or steps toward a contract (Art. 6 (1) (b) GDPR) and/or our legitimate interest in responding to enquiries (Art. 6 (1) (f) GDPR).

Our product e-mail (sign-in links, workspace invitations, and inbound/outbound correspondence with us) is delivered by Resend. Business correspondence is stored in our internal CRM to keep track of the relationship, for as long as needed for that purpose and any statutory retention obligations. We do not send marketing e-mail without a separate legal basis (your consent or a permitted existing-customer relationship), and every marketing message includes an unsubscribe option.

9. Recipients & processors

We keep our stack deliberately small. We engage the following processors, each under a data processing agreement, and — where relevant — with an EU adequacy safeguard (EU–US Data Privacy Framework and/or EU Standard Contractual Clauses):

  • Google (Firebase: Firestore database & Authentication) — Google Cloud EMEA Ltd. / Google LLC. Backend metadata and authentication; data stored in the EU region (europe-west).
  • Vercel Inc. — hosting of the website, the embeddable snippet, and the serverless API endpoints; processes transient request metadata such as IP addresses.
  • Cloudflare, Inc. — the TURN relay fallback for WebRTC; forwards end-to-end-encrypted packets it cannot decrypt.
  • Resend (Plusdocs, Inc.) — transactional and business e-mail delivery and inbound routing.
  • Usercentrics A/S (Cookiebot) — the consent management platform (banner, consent logging, cookie declaration).

We do not sell personal data and do not process it for advertising. Beyond these processors, we disclose personal data only where legally required (e.g. to authorities under a valid legal obligation).

10. International data transfers

Backend data is stored in the European Union. Some of the processors above are US-based or have US parent entities; where a transfer to a third country occurs, it is safeguarded by an EU Commission adequacy decision (including the EU–US Data Privacy Framework, where the recipient is certified) and/or the EU Standard Contractual Clauses under Art. 46 (2) (c) GDPR. The TURN relay fallback is currently globally routed; an EU-pinned relay is on our roadmap.

11. Retention

Session content is never stored — there is nothing to retain. Operational metadata is deleted automatically on a fixed schedule; deletion is the default, not a request:

  • WebRTC signaling messages: deleted within 1 hour;
  • support codes: expire after 5 minutes, records swept within ~15 minutes;
  • agent availability heartbeats: deleted 24 hours after the last update;
  • browser/voice call records (metadata only): deleted after 7 days;
  • callback requests (contain a phone number): deleted after 30 days;
  • session records (metadata only): deleted after 90 days;
  • account, workspace, and app configuration: kept while your account exists, then deleted (subject to statutory retention).

12. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on our legitimate interests (Art. 21); and
  • withdraw any consent you gave, at any time, with effect for the future (Art. 7 (3)) — for example your cookie consent, via the Cookie page.

To exercise any of these, contact us at the e-mail address in Section 1. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77). The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW).

Where our processing rests on a legitimate interest, you can object under Art. 21 GDPR at any time on grounds relating to your particular situation.

13. Security

We protect personal data with appropriate technical and organisational measures (Art. 32 GDPR). The most important one is architectural: session content never reaches our systems. In addition, all transport is encrypted (WebRTC channels end-to-end; all backend traffic over TLS), backend data is encrypted at rest, workspaces are strictly isolated by server-side security rules, and relay credentials are short-lived and minted server-side. The full list is Annex 1 of the DPA.

14. Changes to this policy

We may update this policy as the service evolves or the law changes. The current version is always published here with its revision date. For material changes affecting registered users, we will provide appropriate notice.