Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
LiveZilla is a German live chat, ticketing and visitor monitoring software developed by LiveZilla GmbH. It is available as a self hosted PHP and MySQL application or as a cloud service in Germany, making it a popular choice for GDPR conscious teams. The chat widget loads a JavaScript snippet, sets first party cookies on the publisher domain and may record visitor IP, page URL, referrer and chat content.
LiveZilla is a customer service platform from LiveZilla GmbH (Germany) that combines live chat, ticketing, visitor monitoring and a small CRM. It is distributed as a PHP and MySQL application that publishers can install on their own server, or as a cloud subscription. The self hosted model is one of the main reasons LiveZilla is chosen by German speaking SMBs: it lets the publisher keep all visitor and chat data on infrastructure they fully control.
On load, the LiveZilla widget writes first party cookies (typically prefixed lz_, including lz_visitor and lz_session) on the publisher domain. It also records the visitor IP, user agent, referrer, time on page, navigation path, mouse activity (when typing preview is enabled) and the full chat content. When configured for visitor monitoring, agents can see live page views and even pre-empt conversations with proactive invites.
Because LiveZilla writes non strictly necessary cookies and may capture mouse activity before a message is sent, Article 5(3) of the ePrivacy Directive applies: prior consent is required unless the widget is loaded only after explicit user action. German regulators have specifically flagged the typing preview feature as intrusive, so most compliant deployments either disable it or treat it as a high risk processing requiring a DPIA.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For a compliant deployment, gate the widget behind your consent management platform (block the LiveZilla overlay script until consent), or use a click to load Contact button. Disable typing preview and proactive monitoring unless you have a strong legitimate interest and a documented DPIA. Anonymise IP addresses in the LiveZilla configuration where the feature is available, and restrict access to visitor data to support agents who genuinely need it.
In the self hosted deployment, no data leaves your infrastructure, which makes LiveZilla one of the most attractive options for organisations that cannot accept any third country transfer. In the cloud deployment, data is processed by LiveZilla GmbH in Germany under a DPA, again without systematic non EU transfer. This is a strong argument for the deployment model, but the controller still has to verify any optional integrations (email gateways, push notifications) that might involve third country sub-processors.
List LiveZilla in your cookie policy and record of processing activities, gate the widget behind consent or use click to load, disable typing preview and proactive monitoring by default, anonymise visitor IPs, restrict agent access, configure short retention for chat transcripts, secure your LiveZilla server with HTTPS and updated PHP, sign a DPA with LiveZilla GmbH when using the cloud, and train agents not to capture sensitive data in transcripts.
Websites using LiveZilla must obtain user consent under GDPR regulations.
DPIA considerations
LiveZilla collects visitor IP address, browser user agent, screen resolution, referrer, page URL, time on page, mouse activity (where the typing preview feature is enabled) and full chat transcript. Key DPIA considerations: (1) the typing preview feature lets agents see what a visitor is typing before they hit send, which is intrusive and should be reviewed for proportionality; (2) visitor monitoring panels expose live IPs and locations to agents, raising data minimisation concerns; (3) when self hosted, the controller bears full responsibility for security (TLS, backups, access controls); (4) chat transcripts can include special categories of data shared spontaneously; (5) integration with email or CRM may create additional processing chains. A DPIA is recommended whenever the typing preview or proactive visitor monitoring features are active.
Sample consent text
We use LiveZilla to offer live chat support. When you load this page, LiveZilla places cookies on your device to identify your session and may record your IP address, page URL and chat content on our own (or LiveZilla's European) servers. You can withdraw your consent at any time via our cookie settings.
Third-party domains contacted
livezilla.netself hosted publisher domain (when self deployed)cdn.livezilla.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| lz_visitor | Functional | 1 year | Persistent visitor identifier used by LiveZilla to recognise returning visitors across sessions and reconnect them with their previous chat history. |
| lz_session | Functional | Session | Session identifier used to maintain the chat window state during a single browsing session. |
| lz_status | Functional | Session | Tracks the open or closed state of the chat window so the widget can be restored on page navigation. |
| lz_language | Preference | 1 year | Stores the visitor's language preference for the chat interface. |
LiveZilla uses cookies for user preferences — inform visitors with a consent banner.
LiveZilla writes first party cookies on the publisher domain, typically prefixed lz_ (such as lz_visitor for a persistent visitor identifier and lz_session for the chat session). Because LiveZilla is often self hosted, these cookies live on your own domain rather than a vendor domain.
Yes. The widget writes non strictly necessary cookies and may capture mouse activity (typing preview), which Article 5(3) of the ePrivacy Directive treats as terminal device access requiring consent. The exception is a click to load Contact pattern that initialises the widget only after explicit user action.
For the cookies and tracking elements (typing preview, visitor monitoring), consent under Art. 6(1)(a) GDPR is the standard basis. For the chat content itself in a support context, Art. 6(1)(b) (pre-contractual steps or contract performance) or Art. 6(1)(f) (legitimate interest) typically apply, subject to a balancing test.
No, not by default. Self hosted LiveZilla keeps data on your infrastructure. The cloud option is hosted by LiveZilla GmbH in Germany. Third country transfer only arises if you opt in to certain integrations (e.g. external email or notification services). Always verify the sub-processor list before going live.
A DPIA is recommended whenever you enable the typing preview, proactive visitor monitoring or systematic recording of chats. For a basic, reactive deployment without typing preview, a documented assessment is usually enough but should still describe the data flows, retention and access controls.
Choose self hosting if you want the strictest data minimisation, gate the widget behind your consent management platform or use click to load, disable typing preview and proactive monitoring by default, anonymise IP addresses where the setting exists, restrict agent permissions, set short retention for chat transcripts, and train agents not to store sensitive data in the platform.
Privacy oriented alternatives include Userlike (Germany, cloud), Chatwoot (open source, self hosted), Rocket.Chat (open source, self hosted), Crisp (France) and Tawk.to (free, but with US infrastructure). For German speaking customers wanting cloud chat in the EU, Userlike and Tidio EU are the closest comparables.
List LiveZilla by name, the cookies set (lz_visitor, lz_session and any others enabled), the data collected (IP address, user agent, chat content), the hosting model (self hosted on your own domain or cloud hosted in Germany), the retention period, the sub-processors if any, and a link to the LiveZilla privacy notice or your own privacy notice if you self host.