Hotjar provides the processor-side contract GDPR requires, but where that contract lives has moved. Hotjar is now part of Contentsquare, and Hotjar's own legal hub points its data processing agreement at Contentsquare's privacy centre. The agreement is incorporated rather than signed, Hotjar has appointed a data protection officer, and the product suppresses keystrokes by default.
This article is about the vendor facts — where the paperwork actually is now, what it says about retention and transfers, and what the product captures. Whether recording your visitors' sessions is lawful in the first place, and on what basis, is a separate question with its own answer in our guide to session replay under GDPR.
Where The DPA Actually Is Now
This is the detail most write-ups get wrong, including older Hotjar pages.
Hotjar's legal overview at hotjar.com/legal/ lists the documents making up your agreement — Terms of Service, Privacy Policy, Data Processing Agreement, Acceptable Use Policy — and points the Data Processing Agreement at
contentsquare.com/privacy-center/data-processing-agreement/
. That is the governing document, and the version live when we checked on 7 August 2026 was marked June 2026, v.2026.2.
Hotjar's separate GDPR commitment page still links to an older Hotjar-hosted path and still states that Hotjar does not offer the option to download or digitally sign a DPA. Treat that page as the historic position rather than the current one: it points at a location the legal hub no longer uses, which is a reliable sign it has not been revisited since the Contentsquare move. The mechanism is still incorporation rather than signature — the Contentsquare DPA states that by entering into the agreement the customer is deemed to have signed the incorporated Standard Contractual Clauses — but if a buyer demands a countersigned document, ask Contentsquare rather than assuming the old answer holds.
The same legal page names the contracting entity precisely: Hotjar Limited, a private limited liability company registered under the laws of Malta, company number C65490. That is the detail to put in your vendor register, not "Hotjar."
Hotjar's guidance on the related questions remains useful: one agreement covers multiple sites on the same account, and for agencies the agreement sits with whichever entity actually accepted the Terms of Service.
Hotjar Is Part Of Contentsquare Now
Hotjar's own site carries a banner stating that Hotjar is now part of Contentsquare, and the practical evidence is all over the surface: sign-in and sign-up route to Contentsquare domains, pricing points at Contentsquare, and the trust centre for Hotjar sits on Contentsquare's trust site.
The paperwork has followed. In Contentsquare's DPA, the Hotjar products sit inside the Voice of Customer schedule, which covers products "also licensed under the names Hotjar, Ask, Engage or Observe." That single line is what connects the tool you installed to the contract that governs it, and it is the reason a search for "Hotjar DPA" sends most people to a stale page.
So your subprocessor list, your processing locations and your security documentation now live on Contentsquare's privacy centre and trust portal rather than Hotjar's. Before your next customer questionnaire, confirm which entity you contract with, and update the URLs in your records. Corporate changes are one of the standard triggers for revisiting a processor record, and this is a live example — our guide to subprocessor management covers what a change of this kind should prompt.
The Dual Role: Processor For Your Visitors, Controller For You
Both documents set out the same split, and the second half gets missed.
For your end users' personal data — the visitors whose sessions and interactions are captured — you are the controller and the vendor is the processor. Hotjar's own guidance says exactly that, and the Contentsquare DPA repeats it at clause 2.1, adding that Contentsquare may also process customer data as a controller in its own right under its services privacy policy.
That split is normal and most vendors have it. It matters in your records because the two halves route differently. Questions about visitor data come to you and are governed by the DPA. Questions about your own account data are answered by the vendor as a controller.
One mechanism worth locating before you need it: the Contentsquare DPA directs customers to forward data subject requests through a dedicated data subject request portal, and commits Contentsquare to referring any request it receives directly back to you. Find that portal now rather than during a statutory deadline.
The Capture Controls To Set Before You Launch
This is where the vendor facts get useful, because Hotjar ships controls that change what is captured rather than what is stored.
The defaults are better than people assume. Hotjar states that it automatically suppresses all user keystrokes by default, which removes the single most dangerous category of capture — a visitor typing a password, a card number or a health condition into a form.
Beyond the default, Hotjar documents three product areas built for this purpose: suppression controls, which let you mark elements so their content is never captured; visitor lookup, which lets you find and act on data associated with a particular visitor; and feedback consent controls for its survey and feedback tools. Each has its own documentation in Hotjar's help centre.
Two things follow. First, defaults protect the obvious case and not yours. A page that renders an order confirmation, an account detail, an uploaded document name or an email address in the DOM is exposing it to capture whether or not anyone types. Suppression is something you apply deliberately, element by element, on the pages that need it. Second, visitor lookup is the mechanism you will reach for when an erasure request arrives, so find it before you need it rather than during a thirty-day statutory clock.
Retention, Transfers And Subprocessors
Going to the Contentsquare DPA rather than the Hotjar marketing pages answers the questions that usually go unanswered.
On retention, the Voice of Customer schedule is specific and differs by product. For surveys and feedback, customers can delete data manually at any time within the platform on a self-serve basis, and data is deleted automatically when the account is deleted. For interviews and user tests, recordings are kept for two years from the date of the session. Note that "deleted when the account is deleted" is not a retention period in the sense a regulator means — storage limitation is a decision you make and enforce, and self-serve deletion is the mechanism, not the policy.
On transfers, Contentsquare states it is certified to the EU-US Data Privacy Framework, the UK Extension and the Swiss-US Framework, with its certification checkable on the public Data Privacy Framework list, and its DPA incorporates the EU Standard Contractual Clauses in Schedule 2 as a fallback should the Framework be invalidated. Modules Two and Three both apply. The clauses are governed by French law with the courts of France as forum, and the French data protection authority named as competent supervisory authority.
On subprocessors and where data rests, both are published on Contentsquare's privacy centre subprocessors page, and you can subscribe there for advance notice of changes. The objection window is thirty calendar days from notice, by email to Contentsquare's privacy address, and silence counts as acceptance. If an objection cannot be resolved within thirty days, your remedy is to terminate the affected services with a pro-rata refund of prepaid fees — a narrower remedy than terminating the agreement, and worth knowing before you rely on it.
Common Mistakes With Hotjar And GDPR
Filing the wrong DPA. The governing document is now Contentsquare's, published on its privacy centre. Older Hotjar pages still link to a superseded location, so a vendor file built from a search result is probably pointing at the wrong document.
Assuming keystroke suppression covers everything. It covers typing. Personal data rendered on the page — order details, names, email addresses — is a separate exposure that only deliberate element-level suppression addresses.
Leaving the vendor record on the pre-Contentsquare position. The contracting entity is Hotjar Limited, Malta, company number C65490, and the subprocessor, residency and security documentation now sits on Contentsquare's privacy centre and trust portal. Update the URLs before your next security review.
Forgetting the controller half of the relationship. Hotjar is your processor for visitor data and a controller for your own account data. Requests about the second do not route through your DPA.
Treating installation as a decision. Adding the script is a two-minute job that starts collecting behavioural data about every visitor. Whether that collection is lawful, and on what basis, is decided before the script goes on — see our guide to session replay under GDPR.
FAQ
Where is Hotjar's DPA, and can I sign it?
Hotjar's legal overview points the data processing agreement at Contentsquare's privacy centre, and that published document is the governing one. It works by incorporation rather than signature — entering the agreement is deemed to be signing the incorporated Standard Contractual Clauses. Hotjar's older GDPR page says no downloadable or digitally signed DPA is offered; since that page links to a superseded location, confirm the current position with Contentsquare if a buyer requires countersigned paper.
Is Hotjar a controller or a processor?
Both, in different directions. Hotjar's documentation states that you are the controller of your end users' personal data and Hotjar is the processor of it, while for your own entity's data Hotjar is the controller. Record both halves, because they route requests differently.
Does Hotjar record what visitors type?
Hotjar states that it automatically suppresses all user keystrokes by default. That default addresses typed input. Personal data displayed on the page is not covered by it, and requires suppression controls applied to the specific elements concerned.
Where is Hotjar data stored, and how long is it kept?
Processing and storage locations are published on Contentsquare's privacy centre subprocessors page, which is where the DPA points for both. On retention, the Voice of Customer schedule covering the Hotjar products allows self-serve deletion at any time with automatic deletion when the account is deleted, and sets two years for interview and user test recordings. Confirm the specifics for the products on your plan.
Closing Thought
Behaviour analytics has an odd property: the more useful a recording is, the more of a person it contains. A session that shows nothing much is worthless, and a session that explains exactly why someone abandoned a form usually shows you what they typed, hesitated over, and corrected. The tool's value and its risk are the same property viewed from two sides, which is why the setup work is not overhead — it is the whole job.
Your customers are asking the same questions about you that this article asks about Hotjar. ComplyDog hosts a compliance portal on your own domain carrying your DPA, your subprocessor list — Hotjar included — your data subject request intake and your security page. It will not configure your suppression rules. It will mean that when a buyer asks who watches their users and where that data goes, the answer is a link rather than a week.