Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Qualaroo is an on-site survey and Nudge tool by ProProfs that targets website visitors with contextual micro-surveys using cookies and optional user identity data. Because it sets tracking cookies and transfers data to US servers, it requires explicit visitor consent under GDPR and the ePrivacy Directive.
Qualaroo, now part of the ProProfs suite, is an on-site survey platform that delivers targeted micro-surveys called Nudges to website visitors and app users. It loads a JavaScript snippet hosted on Amazon S3 (s3.amazonaws.com) and communicates with its collection endpoint at cl.qualaroo.com. The tool uses browser cookies to identify returning visitors, control survey frequency, and record whether a user has already responded to a particular survey.
Survey targeting can be refined using the Qualaroo Identity API, which allows operators to pass user properties such as an email address, a user ID, account plan, or other custom traits. These properties are used to segment audiences and personalise which survey a visitor sees. When identity data is passed, Qualaroo associates survey responses with a specific individual, making the data unambiguously personal under GDPR.
Qualaroo sets several cookies in the visitor''s browser. The primary cookie records whether the visitor has seen or responded to a survey and stores a unique visitor identifier. Additional cookies control throttling and survey suppression logic. The tool collects survey responses (which may include free-text answers containing personal information), technical metadata such as the page URL and referrer, and any user properties explicitly passed via the identity API. All collected data is transmitted to and stored on Qualaroo''s AWS-based infrastructure in the United States.
Under the ePrivacy Directive (implemented as national cookie laws across the EU), storing or accessing cookies on a user''s device requires prior informed consent unless the cookie is strictly necessary for a service explicitly requested by the user. Survey and targeting cookies set by Qualaroo are not strictly necessary and therefore require opt-in consent before the Qualaroo script is loaded. Under GDPR, the processing of personal data collected through surveys requires a valid lawful basis. Given the targeting and profiling capabilities of the tool, consent under Article 6(1)(a) is the most appropriate and defensible basis for EEA visitors.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Qualaroo processes data on AWS servers in the United States, any use by EEA-based organisations constitutes a transfer of personal data to a third country under Chapter V of GDPR. ProProfs participates in the EU-US Data Privacy Framework (DPF), which provides an adequacy decision for transfers to certified US organisations. Operators should verify that the current certification is valid at the time of deployment and document this in their Records of Processing Activities (RoPA). As a belt-and-braces measure, many organisations also rely on Standard Contractual Clauses (SCCs) alongside DPF certification.
Qualaroo must be classified under a consent-required category in your Consent Management Platform (CMP). The script tag or tag manager trigger should only fire after the visitor has actively accepted the relevant cookie category (typically labelled as Analytics, Feedback, or Research). The consent signal must be granular, freely given, specific, and informed. Pre-ticked boxes or implied consent are not valid under GDPR.
To deploy Qualaroo compliantly in the EU: gate the S3-hosted script behind CMP consent; list all Qualaroo cookies (name, purpose, duration) in your cookie policy and CMP cookie declaration; include qualaroo.com and cl.qualaroo.com as third-party service providers in your Privacy Policy; sign a Data Processing Agreement (DPA) with ProProfs; document the transfer mechanism (DPF or SCCs) in your RoPA; and consider a DPIA if using identity data or conducting large-scale profiling. Provide visitors with a clear description of what Qualaroo does in your consent notice.
Websites using Qualaroo must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment (DPIA) should be considered when deploying Qualaroo for large-scale visitor profiling or when combining survey responses with other behavioural data. Key risk areas include: the transfer of personal data to the United States under AWS infrastructure; the use of persistent cookies to recognise returning visitors; the potential to collect sensitive information through open-ended survey questions; and the linking of survey responses to user identity via the traits API. Organisations should document the lawful basis for each processing activity, assess the necessity and proportionality of the data collected, and implement appropriate safeguards such as SCCs or reliance on the EU-US DPF before deployment.
Sample consent text
We would like to use Qualaroo to display short surveys on this website to help us improve our service. Qualaroo uses cookies to recognise your visit and may transfer your responses to servers in the United States. Your participation is entirely voluntary. Please click "Accept" to allow survey cookies, or "Decline" to continue without them.
Third-party domains contacted
qualaroo.comcl.qualaroo.coms3.amazonaws.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _qualaroo_session | persistent | 1 year | Stores a unique visitor identifier used to recognise returning visitors and control survey display frequency across sessions. |
| _qualaroo_s | persistent | 1 year | Records which surveys the visitor has already seen or completed to prevent repeated display of the same Nudge. |
| _qualaroo_t | session | Session | Controls survey throttling and suppression logic within a single browsing session. |
| _qualaroo_identity | persistent | 1 year | Stores user identity traits passed via the Qualaroo Identity API to enable targeted survey delivery to specific user segments. |
Qualaroo collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Qualaroo sets a primary visitor identifier cookie that persists between sessions to recognise returning visitors and prevent survey repetition. It also sets session cookies to control survey display logic and throttling. The exact cookie names vary by account but are typically prefixed with "_qualaroo" or similar identifiers. All cookies should be listed by name, purpose, and duration in your cookie declaration.
Yes. Under the EU ePrivacy Directive, consent is required before Qualaroo sets any cookies on a visitor's device, as these cookies are not strictly necessary for a service the user has requested. Under GDPR, processing survey response data linked to identifiable individuals also requires a valid lawful basis, and consent is the most appropriate basis given the targeting and profiling features of the tool.
Consent under Article 6(1)(a) of GDPR is the recommended legal basis for deploying Qualaroo for EEA visitors, particularly when cookies are set or when the Identity API is used to link responses to individual users. Legitimate interest under Article 6(1)(f) might be argued for purely anonymous surveys without cookies, but this is difficult to sustain given Qualaroo's standard operation. Always document your chosen basis in your Records of Processing Activities.
Yes. Qualaroo is a US-based service operated by ProProfs, and all survey data is processed and stored on Amazon Web Services (AWS) infrastructure in the United States. This constitutes a transfer to a third country under GDPR Chapter V. ProProfs participates in the EU-US Data Privacy Framework (DPF), which provides an adequacy-equivalent mechanism. Operators should also consider executing Standard Contractual Clauses (SCCs) with ProProfs for additional legal certainty.
A Data Protection Impact Assessment (DPIA) is recommended if you plan to use Qualaroo to profile visitors at scale, combine survey data with other behavioural datasets, or use the Identity API to link responses to individual users. A DPIA is mandatory under GDPR Article 35 when processing is "likely to result in a high risk" to individuals. Even if a full DPIA is not strictly required, documenting your risk assessment is good practice before deploying any third-party tool that transfers data to the US.
Integrate Qualaroo with your Consent Management Platform (CMP) so that the S3-hosted script only loads after the visitor has given explicit consent for the relevant cookie category. List all Qualaroo cookies in your cookie declaration, include Qualaroo and ProProfs in your Privacy Policy as sub-processors, sign a Data Processing Agreement (DPA) with ProProfs, and document the EU-US DPF or SCCs as the transfer mechanism in your Records of Processing Activities. Avoid using the Identity API unless you have a separate specific consent for that level of data linkage.
Privacy-friendly alternatives include Hotjar Ask (with EU data residency options), Typeform (with GDPR controls), or self-hosted open-source survey tools such as LimeSurvey, which can keep data entirely on your own infrastructure. For NPS-style surveys, tools with EU-based hosting or stronger data minimisation defaults may reduce compliance overhead. The right alternative depends on your feature requirements, audience size, and willingness to self-host.
Add a dedicated entry for Qualaroo in your cookie policy table, listing each cookie by name, type (analytics or targeting), duration, and purpose. Reference qualaroo.com and cl.qualaroo.com as the third-party domains involved. Update the service provider section of your Privacy Policy to name ProProfs as a data processor and describe the US data transfer. If you use an automated cookie scanner, scan after deploying Qualaroo to capture any newly detected cookies. Review and update at least annually or after any significant change to your Qualaroo configuration.