Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Userlike is a German live chat and customer messaging platform founded in Cologne in 2012. It powers website chat widgets, AI bots, and messaging channel integrations (WhatsApp, Facebook Messenger, Telegram) for business support and sales. All chat data is hosted on Userlike servers in Frankfurt, Germany, making it one of the few enterprise live chat solutions with native EU data residency. Tracking and visitor identification cookies still require user consent under the GDPR and the ePrivacy Directive.
Userlike is a German messaging platform that combines website live chat, WhatsApp Business, Facebook Messenger, Telegram, SMS, and AI powered chatbots into one unified support workspace. Headquartered in Cologne and operating since 2012, Userlike has built its reputation on strict EU data residency and GDPR alignment, hosting all chat data exclusively on its own infrastructure in Frankfurt am Main.
The service is loaded onto a website via a small JavaScript widget delivered from userlike-cdn.com. When a visitor opens the widget, a chat session is established, first party cookies and localStorage entries are written to identify the visitor across page views, and conversation content is streamed to the Userlike backend.
When the widget loads, Userlike sets first party cookies (userlike_session, userlike_visitor, and several feature flags) and stores corresponding entries in localStorage on the visitor device. These identifiers allow the chat history to be reconstructed across pages and reopened on subsequent visits.
Once a chat is initiated, Userlike processes the IP address (used for geolocation and abuse prevention), browser User Agent, current page URL, referring URL, full message content, attached files, and any contact information voluntarily provided by the visitor (name, email, phone). Operator side metadata such as typing indicators and agent assignments is also stored. When AI bots are enabled, message content may be processed by additional natural language components.
Userlike EU only data residency is a clear advantage: by default no transfer to third countries takes place, no Standard Contractual Clauses are needed, and the Schrems II problem does not apply. This makes Userlike one of the simplest live chat options to deploy in a GDPR strict environment such as Germany, France, or Italy.
However, two key compliance gates remain. First, the cookies and localStorage writes performed by the widget require informed consent under Art. 5(3) of the ePrivacy Directive and §25 TTDSG in Germany, even though the chat is hosted in the EU. Second, the chat content itself is personal data under Art. 4 GDPR and must be processed under a lawful basis, typically contract performance for support requests or legitimate interest for sales chat, with a Data Processing Agreement (DPA) in place with Userlike GmbH.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A common compliant pattern is to render the widget in a closed state on first page load (no chat cookies set, full JavaScript widget not yet injected), and only initialise the chat when the user explicitly clicks an Open chat button. This avoids any cookie write before consent and aligns with EDPB Guidance 5/2020 on consent.
Alternatively, when the widget must be auto loaded on certain pages, integrate it with a consent management platform. Only inject userlike.js after the visitor has accepted the relevant cookie category, and ensure the consent banner explicitly names Userlike and links to its privacy policy.
The core chat platform stores no data outside Germany. Userlike GmbH acts as a processor under Art. 28 GDPR for chat content, while the IP address may also be processed by Userlike as controller for security purposes. A signed Auftragsverarbeitungsvertrag is mandatory and must be referenced in the controller Records of Processing Activities (Art. 30 GDPR).
If you connect Userlike to messaging channels such as WhatsApp Business or Facebook Messenger, those interactions inherit Meta data transfer practices and must be assessed separately under SCCs and the EU US Data Privacy Framework.
Sign a DPA with Userlike GmbH and document the processor relationship. List the userlike_session and userlike_visitor cookies in your cookie policy with purpose, lifetime, and provenance. Configure the widget to defer loading until consent is granted, or use the click to open pattern to avoid any cookies prior to user action. Enable IP anonymisation when offered.
For AI bot deployments, run an additional risk assessment: automated processing of message content can fall under Art. 22 GDPR and may trigger DPIA obligations under Art. 35 GDPR, particularly in regulated sectors such as healthcare or finance.
Websites using Userlike must obtain user consent under GDPR regulations.
DPIA considerations
Userlike processes IP addresses, browser fingerprints (User-Agent, language, screen resolution), full chat message content, and any contact details voluntarily provided. Key DPIA considerations: (1) EU-only data residency in Frankfurt significantly reduces transfer risk, no SCCs needed for the core service; (2) persistent visitor IDs in userlike_visitor cookies enable cross-session re-identification; (3) chat content may include special category data (Art. 9 GDPR) such as health information when used for medical support, requiring an explicit additional consent or another Art. 9(2) basis; (4) AI bot features trigger automated processing concerns under Art. 22 GDPR if decisions with legal or similarly significant effects are produced; (5) third-party integrations (Slack, Salesforce, WhatsApp Business) re-introduce third-country transfer risk that must be reassessed separately; (6) operator side processing of agent productivity metrics may also raise employee data protection concerns under works council laws (BetrVG in Germany).
Sample consent text
We use Userlike to provide live chat and customer messaging on our website. When you open the chat, Userlike sets functional and analytics cookies on your device to maintain your session and recognise you across page views. All chat data is stored on Userlike servers in Germany. You can refuse non-essential cookies and still send us a one-off message via the contact form.
Third-party domains contacted
userlike.comuserlike-cdn.comwidget.userlike.comapi.userlike.commedia.userlike-cdn.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| userlike_session | Functional | Session | Maintains the active chat session between page reloads. Deleted when the browser is closed. |
| userlike_visitor | Functional / Analytics | 1 year | Persistent visitor identifier. Used to recognise returning visitors so that prior chat conversations can be reopened and operator history is preserved. |
| _ulkAuth | Functional | Session | Authentication token issued to logged in operators when using the agent console. Not set on regular visitor browsers. |
| userlike_widget_state | Functional | 30 days | Stores whether the chat widget was opened, minimised, or closed on previous visits to keep the user interface consistent. |
| userlike_locale | Functional | 1 year | Stores the preferred chat language so the widget displays in the same language on subsequent visits. |
Userlike uses cookies for user preferences — inform visitors with a consent banner.
Userlike sets first party cookies on your own domain, primarily userlike_session (chat session, expires on browser close) and userlike_visitor (persistent visitor ID, typically 1 year). Several widget state flags and an authentication token for staff (_ulkAuth) may also be written. The chat history itself is cached in localStorage rather than in cookies.
Yes for the auto loaded widget. The cookies and localStorage writes performed by userlike.js are not strictly necessary under §25 TTDSG and Art. 5(3) ePrivacy, so prior informed consent is required. A consent free alternative is to keep the widget closed until the user clicks Open chat, which defers all cookie writes to that explicit action.
For customer support requests, the most appropriate basis is contract performance under Art. 6(1)(b) GDPR, since the visitor is initiating a request related to a (pre)contractual relationship. For sales or marketing chat, legitimate interest under Art. 6(1)(f) GDPR is typically used, with a documented balancing test. The cookies that load the widget remain subject to consent regardless of the basis used for the chat content.
No by default. Userlike hosts all chat data on its own servers in Frankfurt am Main, Germany, and does not rely on US sub processors for the core service. The Schrems II problem does not apply to the core platform. Transfers only occur when you enable optional integrations with Slack, Salesforce, HubSpot, or WhatsApp Business via Meta, each of which must then be assessed separately under SCCs or the EU US Data Privacy Framework.
A full DPIA is generally not mandatory for standard support chat deployments, given the EU data residency and the limited scope of processing. However, a DPIA becomes likely when chat content systematically includes special category data (health, biometric, religious) under Art. 9 GDPR, when AI bots make automated decisions with legal effects under Art. 22 GDPR, or when chats are used in vulnerable contexts (children services, mental health support).
Sign the Auftragsverarbeitungsvertrag with Userlike GmbH, list it in your RoPA, declare the cookies in your cookie policy, defer the widget script until consent is granted (or use click to open), and ensure your privacy policy describes the chat purposes, retention period, and recipient (Userlike GmbH in Germany). For non chat features (analytics, surveys), keep them disabled or behind a separate consent toggle.
EU based: Chatwoot (open source, self hostable), Crisp (France), LiveChat (Poland), Smartsupp (Czech Republic), Tidio (Poland). US based with optional EU hosting: Intercom, HubSpot, Zendesk Chat, Drift. Self hosted: Rocket.Chat, Chaskiq. Userlike main differentiator remains its native German hosting combined with omnichannel features and AI bots.
List each cookie or storage entry with: name (userlike_session, userlike_visitor), provider (Userlike GmbH, Germany), purpose (maintaining chat sessions, recognising returning visitors), lifetime (session, 1 year), and category (functional or analytics depending on configuration). Add Userlike as a processor in your privacy policy with a link to its own data processing terms, and mention that no data is transferred outside the EU for the standard configuration.