Privacy Policy
Last Updated: 25.09.2025
This Privacy Policy describes how Lendasat ("we," "us," or "our") collects, uses, and shares information about you when you use our website and services. By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Session Recording Technology Notice​
IMPORTANT: We use session recording technology that captures your interactions with our website in real-time. This technology records a video-like replay of your browsing session, including all mouse movements, clicks, scrolls, and typing (with sensitive information automatically masked). By continuing to use our website after being informed of this practice, you provide explicit consent to session recording.
We use PostHog, a privacy-focused analytics platform, to understand how visitors interact with our website. PostHog automatically collects usage information including but not limited to page views, navigation paths, time spent on pages, button clicks, scrolls, form interactions, session duration and frequency of visits, referrer URLs, and search queries within our site. Technical information collected includes browser type and version, operating system and device type, screen resolution and viewport size, IP address for geographic location at country/city level, language preferences, and timezone settings.
Session Recording Details
When session recordings are enabled (only with your consent), we capture:
- Visual recordings of your entire browsing session
- Mouse movements, clicks, and hover actions in real-time
- Scrolling behavior and viewport changes
- Form interactions (with ALL input fields, passwords, and payment data automatically masked)
- Page transitions and navigation patterns
- Error messages and console warnings for debugging
- Time spent on each page element
Privacy Protections in Session Recording:
- All text inputs are masked by default
- Password fields are never recorded
- Credit card and payment information is automatically blocked
- Social Security Numbers and tax IDs are detected and masked
- Email addresses in sensitive contexts are partially masked
- Health and medical information fields are blocked
- The recordings respect "Do Not Track" browser signals
- You can opt-out at any time
We use first-party cookies and local storage to maintain analytics session continuity, remember your privacy preferences, store unique visitor identifiers, and track feature usage for improvement. PostHog cookies include ph_[project_key]_posthog for user identification across sessions with a duration of 1 year as first-party only cookies with no third-party tracking. The collected data is used to improve our website functionality and user experience, understand which features and content are most valuable, identify and fix bugs, errors, and performance issues, analyze user behavior patterns and navigation flows, optimize our services based on usage patterns, generate aggregated statistics about site usage, conduct A/B testing for feature improvements, and ensure website security and prevent fraud.
Our legal basis for processing under GDPR includes legitimate interest for analytics data to improve our services, consent for users in the EU/EEA before placing analytics cookies, and contract performance when processing is necessary to provide our services. For EU/EEA residents under GDPR, you have the right to access and request a copy of your personal data, rectification to correct inaccurate personal data, erasure to request deletion of your data known as the right to be forgotten, restriction to limit how we process your data, portability to receive your data in a machine-readable format, object to oppose processing of your personal data, and withdraw consent at any time. California residents under CCPA have the right to know what personal information we collect and how it's used, delete to request deletion of your personal information, opt-out though we do not sell personal information, and non-discrimination for equal service regardless of privacy choices.
To exercise your rights, you may opt-out of analytics by clicking "Decline" on our cookie banner or using the opt-out button, make data requests by emailing [email protected], and expect responses to all requests within 30 days. We implement comprehensive security measures including encryption with all data transmitted using TLS/SSL encryption, storage with data encrypted at rest in PostHog's infrastructure, access control with role-based access and multi-factor authentication, infrastructure hosted on secure AWS servers, and 24/7 security monitoring and intrusion detection. PostHog maintains SOC 2 Type II certification, GDPR-compliant data processing practices, CCPA compliance for California residents, and regular third-party security audits.
PostHog acts as our Data Processor for product analytics, user behavior tracking, and session recordings. Data is processed in PostHog Cloud EU located in Frankfurt, Germany for GDPR compliance. Their privacy policy is available at https://posthog.com/privacy. We share usage data, technical information, and anonymized IP addresses with PostHog with a default retention of 7 years which is configurable. PostHog is SOC 2 Type II certified and GDPR compliant. We also use Cloudflare for content delivery network and DDoS protection with their privacy policy available at https://www.cloudflare.com/privacy/.
You can control cookies and tracking through our cookie banner by choosing "Accept" or "Decline" when you first visit, browser settings to block or delete cookies, an opt-out button to stop all tracking, and we respect browser "Do Not Track" signals. Opting out of PostHog analytics means your choice will be stored in a cookie, no analytics data will be collected from your device, session recordings will be disabled, and your preference persists across visits, though opting out only affects this device and browser requiring separate opt-out on other devices or browsers.
PostHog analytics data is retained as follows: event data for 7 years as default PostHog Cloud retention, session recordings for 90 days, person profiles until deletion requested, A/B test data for duration of test plus 90 days, and custom events for 7 years. You can request deletion at any time via [email protected] with automated deletion after retention period expires, though aggregated or anonymized data may be retained indefinitely.
For EU/EEA residents, Lendasat acts as Data Controller determining why and how data is processed, PostHog, Inc. acts as Data Processor processing data on our behalf, and AWS in Frankfurt region serves as sub-processor for EU data residency. Legal basis for processing includes consent for placing analytics cookies and session recordings, legitimate interest for essential website functionality and security, and contract performance when necessary to provide requested services. International data transfers store data in EU Frankfurt for EU/EEA visitors with Standard Contractual Clauses for any required transfers and a Data Processing Agreement in place with PostHog. You have GDPR rights including the right to be informed through this privacy policy, right of access to your personal data, right to rectification of inaccurate data, right to erasure or right to be forgotten, right to restrict processing, right to data portability, right to object to processing, and rights related to automated decision-making. You have the right to lodge a complaint with your local data protection authority if you believe we have violated your rights.
Under CCPA, personal information includes identifiers such as IP address, device ID, and cookie IDs, internet activity including browsing history on our site and interaction data, geolocation data as approximate location from IP, and inferences drawn from the above to create user profiles. California residents have the right to know and request disclosure of personal information collected, right to delete and request deletion of personal information, right to opt-out though we do not sell personal information, and right to non-discrimination with no different treatment for exercising rights. We collect information directly from you through website interactions, automatically through PostHog analytics, and from your device for technical information. Business purposes for collection include providing and improving our services, analytics and performance monitoring, security and fraud prevention, and legal compliance. We share data with service providers like PostHog for business purposes only, do not sell, rent, or trade personal information, and do not share for cross-context behavioral advertising.
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. We may update this privacy policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. Material changes will be announced via website banner with an updated "Last Updated" date at the top of this policy. Continued use after changes constitutes acceptance, and for significant changes, we may request renewed consent. Current Version is 2.0 as PostHog Integration Update with previous updates available upon request.
For privacy inquiries or to exercise your rights, contact our Data Protection team at [email protected] with response time within 30 days. For specific requests including data access requests, deletion requests, or opt-out assistance, email [email protected]. Community support is available on Discord at https://discord.gg/a5MP7yZDpQ. For questions about PostHog's data practices, contact PostHog Privacy Team at [email protected], PostHog DPO Charles Cook as VP Operations, or view documentation at https://posthog.com/docs/privacy.
By using our website, you acknowledge that you have read and understood this privacy policy.