Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Nootiz is an Austrian visual feedback and annotation tool that embeds a lightweight widget on websites so clients, designers and developers can leave pinned comments directly on the page. It is commonly used on staging sites and during production reviews. The widget sets functional cookies for the reviewer's session, comments and project state. Servers are located in Austria, which keeps processing within the EEA and lowers the compliance burden compared to non European tools.
Nootiz is an Austrian visual feedback and annotation tool designed for web teams. A small JavaScript widget is embedded on a staging or production website; authorised users such as clients, project managers, designers and developers can click anywhere on the page and leave a pinned comment that captures the element, the browser context and an optional screenshot. Threads, assignees and statuses are managed in the Nootiz dashboard, which becomes the source of truth for review rounds. The widget is intentionally lightweight and runs alongside the existing site without rewriting markup.
Nootiz sets functional first-party cookies for the reviewer''s authentication session, the active project, the open or minimised state of the widget and a CSRF token. It processes the comment content, the URL on which it was left, browser metadata (user agent, viewport, optional screenshot) and the identity of the reviewer who posted the annotation. No tracking or marketing cookies are set by default. The personal data involved is mostly that of the project team rather than the general public, which keeps the exposure narrow.
Because Nootiz is targeted at reviewers, not anonymous visitors, the functional cookies it sets can rely on the strictly necessary exemption of Article 5(3) ePrivacy when the user has actively logged into the tool. The associated GDPR processing rests on legitimate interest under Article 6(1)(f) (running and documenting a website project) or on contract performance where Nootiz is part of an agency contract. If the widget is exposed to end users who are not part of the project, consent under Article 5(3) ePrivacy becomes required because the cookies are no longer strictly necessary for a service that user requested.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Nootiz hosts its infrastructure in Austria and operates within the European Union. There are no third country transfers in the default configuration, which removes the Schrems II problematic associated with US based collaboration tools. The data processing agreement should still be reviewed for sub-processors (email delivery, error monitoring, file storage) but these are typically also EU based or DPF certified. EU hosting is one of the strongest compliance arguments for choosing Nootiz over equivalent US tools.
A full Article 35 DPIA is generally not necessary if Nootiz is used on a staging environment with a limited reviewer team. The picture changes when the widget captures screenshots of pages that contain real personal data, for instance dashboards showing customer records: those screenshots are themselves personal data and must be retained no longer than necessary, with documented access controls. In that case a short DPIA focusing on screenshots and access controls is appropriate, and consent banners may not be needed if the widget is restricted to staff with adequate notice.
Load the Nootiz widget only on staging or behind an authentication gate; remove it from public production unless your business case justifies leaving it in place; document the data processing agreement with Nootiz GmbH and list it in your record of processing activities; mention Nootiz in the internal privacy notice provided to reviewers and clients; set sensible retention periods for closed annotations and screenshots; and review the sub-processor list yearly. These steps keep the compliance overhead minimal for a low risk tool.
Websites using Nootiz must obtain user consent under GDPR regulations.
DPIA considerations
A formal DPIA is rarely required for Nootiz because the tool is used by a closed group of authorised reviewers (clients, designers, developers), not by anonymous end users, and the processing is limited to annotation content, project metadata and reviewer identity. A short risk assessment is enough in most cases. If Nootiz is left active on production with public visibility, or if it captures screenshots of pages that contain personal data of real end users, a DPIA becomes appropriate and should focus on access controls, retention of annotation screenshots, and the lawful basis for capturing those screenshots.
Sample consent text
This site uses Nootiz, an Austrian visual feedback tool, to let our team and clients leave annotations during the review phase. Nootiz sets functional cookies for the reviewer session and to link comments to the right project. Data is hosted in Austria, within the European Union. The widget is loaded only for users with reviewer access and is removed on the public production version of this site.
Third-party domains contacted
nootiz.comapp.nootiz.comcdn.nootiz.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| nootiz_session | functional | Session | Maintains the authenticated session of the reviewer in the Nootiz widget. |
| nootiz_project | functional | 30 days | Stores the identifier of the active project so that comments are attached to the correct workspace. |
| nootiz_state | functional | 30 days | Remembers the open or minimised state and position of the widget across page loads. |
| nootiz_csrf | functional | Session | Provides CSRF protection for actions submitted through the widget such as new comments or replies. |
Nootiz uses cookies for user preferences — inform visitors with a consent banner.
Nootiz sets a small set of first-party functional cookies: a session cookie for the reviewer's authentication, a project cookie that links comments to the right workspace, a state cookie that remembers the open or minimised state of the widget and its position, and a CSRF token cookie that protects form submissions. No analytics or marketing cookies are placed by default.
When Nootiz is restricted to authenticated reviewers (via an environment variable, IP whitelist or login check), its cookies are strictly necessary for the requested service and fall under the Article 5(3) ePrivacy exemption: no consent banner is required. If the widget is exposed to general visitors, consent becomes necessary because those visitors did not request the annotation tool.
The most appropriate legal basis is legitimate interest under Article 6(1)(f) GDPR (running and documenting a website project) or contract performance under Article 6(1)(b) where Nootiz is part of an agency or client engagement. Functional cookies rely on the strictly necessary exemption of Article 5(3) ePrivacy. Where Nootiz is used to capture screenshots containing data of real end users, those end users may need separate consideration.
No, not in the default configuration. Nootiz hosts servers and operates from Austria, within the European Union, so the personal data of reviewers and the content of annotations remain in the EEA. Sub-processors such as email delivery or error monitoring should still be reviewed in the data processing agreement, but the baseline transfer profile is comfortable from a Schrems II standpoint.
A formal DPIA under Article 35 GDPR is rarely needed because Nootiz is used by a closed group of reviewers on a project, processing is limited and EU hosting removes transfer risk. A short documented risk assessment is normally enough. A DPIA becomes appropriate when Nootiz captures screenshots of pages containing real end user data or when it is left active on a public production site.
Load the widget only on staging environments or behind authentication; do not ship the script to anonymous public visitors; provide the project team with a short internal notice describing the tool, the data it processes and the retention period; sign the data processing agreement provided by Nootiz GmbH; list it in your record of processing activities; and clean up closed projects and their screenshots periodically.
Comparable visual feedback tools include BugHerd (Australia, EU hosting available), Pastel (US, DPF certified), Markup.io (US), Marker.io (Belgium, EU based) and Userback (Australia). For European teams, EU based or DPF certified vendors are easier to document; tools hosted only in the US require a transfer impact assessment. Self-hosted alternatives such as Sentry feedback widgets or Penpot review modes can also fit.
If Nootiz is restricted to internal reviewers, no entry in the public cookie policy is strictly required, but the internal privacy notice should describe the tool. If the widget is exposed to general visitors, add a dedicated section in the public cookie policy listing the four functional cookies, their purposes, their durations, the controller (Nootiz GmbH) and the country (Austria). Review the entry whenever Nootiz changes sub-processors.