New Surveys feature now available! Learn more →

Committed to
Privacy & Security

We are fully committed to providing features that help you be compliant with privacy regulations by taking a privacy by design approach. As well as partnering with the best in class security providers to keep all your data safe.

Compliance

Designed to support compliance with GDPR, UK GDPR, CCPA/CPRA and other applicable privacy regulations

Security

Your data is safe, secure, and always available

Enabled compliance

Lawful basis and transparency

As part of our compliance to data protection regulation, we enter into Data Processing Agreements (DPAs) with all our customers. This DPA, a binding agreement signed between the controller and the processor when the latter processes data from the controller, details the standard contractual terms required under the GDPR. We are also transparent as regard internal organizations and processes and as regard the sub-processors, we are working with.

Accountability and Governance

Air360 has appointed a Data Protection contact to monitor GDPR compliance, assess data protection risks, advise on data protection impact assessments, exchange with clients and cooperate with regulators.

GDPR Compliance

Air360 privacy features

Privacy by default - minimization

Air360 automatically prevents the collection of user-entered text in input fields by default. Additional configuration controls allow customers to exclude sensitive page elements, metadata, and custom events from collection.

Exercises of right

We are committed to assist you in order to respondent efficiently to exercises of rights requests from given users, based on GDPR provisions as right of access, right of erasure, right etc. As regard right of erasure, Air360 offers a function that will allow you to delete a specific user and related sessions with just a single click. As regard right of access and data portability as example, You can retrieve specific user details simply by going through our application or using our API.

Restrict specific data acquisition

Air360 enables you to go further by also hiding explicitly parts of your pages from being recorded during session replays.

Secure data handling & protection

Limit Access to your data

Air360 follows strict data security regulations to ensure that we secure and limit access to your data.

Database icon representing secure data storage

Air360 Security Measures

Monitoring of our Tracking pixel

Constantly conducted to detect any malicious modification and ensure its delivery, integrity and safety.

Security best practices

Reviewed by third party companies regularly when important updates are performed on our systems.

Multi-Factor Authentication (MFA)

Required for all our users to access to Air360 application adding an extra layer of security and keeping your accounts safe.

Third-party security audits

Conducted regularly and before major releases, including penetration tests and vulnerability scans.

Customer data processed & stored in the EU

Although Air360's headquarters are located in Japan, Air360 core systems are hosted on OVHcloud and Amazon Web Services (AWS) servers located in France and Ireland and leverage all the security and compliance provided by OVHcloud/AWS: ISO (9001, 27001, 27017, and 27018), SOC 1, 2, and 3, PCI DSS.

State-of-the-art encryption

Used in all Air360 products for data in transit and at rest.

We are also compliant with

HIPAA Support

Air360 is designed according to the principle of data minimization and is intended to operate without collecting Protected Health Information (PHI). Configurable controls let you prevent the collection of user-entered text, sensitive page elements, and customer-defined metadata during behavioral analytics and session replay. Healthcare organizations are responsible for configuring Air360 so that PHI is not transmitted to the Services. For eligible healthcare customers, Air360 can execute a Business Associate Agreement (BAA) to govern the parties' obligations in the event PHI is inadvertently transmitted to the Services.

Business Associate Agreement (BAA)

Available for eligible healthcare customers to govern the parties' obligations regarding any PHI inadvertently transmitted to the Services.

View the BAA

HIPAA Deployment Guide

Implementation guidance for configuring Air360 so that PHI is excluded from collection.

View the deployment guide

HIPAA Compliance Checklist

The 18 HIPAA identifiers, how they leak into analytics, and a checklist for vetting any analytics vendor.

Read the checklist