Data Privacy

GermainUX provides configurable controls that help organizations protect sensitive data and support internal privacy policies and regulatory requirements such as GDPR and PCI DSS.

Four complementary mechanisms are available:

Feature

Description

Masking

Replaces sensitive characters with symbols such as ***, optionally preserving the original length and whitespace.

Anonymization

Replaces original values with hashed values so the source content is not exposed during analysis.

Exclusion

Prevents selected data from being collected, transmitted, or stored.

AI-Driven PII Detection

Identifies fields that may contain personal or sensitive information and flags them for review.

The appropriate control depends on whether the data must remain structurally recognizable, support recurring analysis, or never be collected.

😷 Masking

Masking replaces sensitive characters before the values are transmitted or stored.

Use masking when the structure of a value remains useful but its original content should not be visible.

Option

Description

Example

Preserve Length

Maintains the original number of characters.

admin*****

Preserve Whitespace

Retains spaces while masking the other characters.

This is a test**** ** * ****

👤 Anonymization

Anonymization replaces an original value with a hashed representation.

Use this option when recurring values must remain available for analysis without exposing their original content.

admin → a1f5d4e3...

Because hashed values may remain linkable across records, organizations should assess whether their configuration satisfies their specific privacy and compliance requirements.

⛔ Exclusion

Exclusion prevents selected information from entering the GermainUX data pipeline.

Use exclusion when the information is not required for monitoring or analysis, particularly for highly sensitive values such as:

Example Sensitive Values

Social Security numbers

Payment-card information

Passwords

Authentication tokens

Sensitive form fields

Because excluded values are not collected, transmitted, or stored, exclusion provides the strongest protection for data that GermainUX does not need.

🤖 AI-Driven PII Detection

AI-driven PII detection analyzes stored fields and identifies those that may contain personal or sensitive information.

Examples may include:

Field Type

Usernames

Email addresses

Customer identifiers

Session identifiers

Contact information

Detected fields are presented for review. Administrators can then determine whether masking, anonymization, or exclusion should be applied.

📊 Data Privacy Dashboard

▶️ Access the Dashboard

Go to:

GermainUX Workspace -> Left Menu → Settings → Analytics -> Data Privacy

image-20250126-234347.png
Data Privacy Dashboard - GermainUX


The dashboard provides visibility into potentially sensitive stored data and the privacy controls already configured.

🔍 Detection of Stored PII

This view lists unprotected fields identified as potentially containing personal or sensitive information.

See Detection of Stored PII for more information.

⚙️ Configured Privacy Controls

This view shows fields already configured for masking, anonymization, or exclusion.

See Configured Exclusion for configuration details.

🧾 Form Privacy and UX Monitoring Profiles

Form Privacy rules prevent designated sensitive information entered into form elements from being collected.

GermainUX provides predefined rules that can be applied and customized through UX Monitoring Profiles.

See Form Privacy and UX Monitoring Profiles for more information.

This page focuses specifically on GermainUX data-privacy controls. Related compliance and security capabilities are documented separately:

Topic

Link

Compliance, Data Privacy and Security Overview

https://docs.germainux.com/main/compliance-privacy-and-security

Certifications and Policies

https://docs.germainux.com/main/compliance

Cookie Consent and User Privacy

https://docs.germainux.com/main/cookie-consent

Data Security

https://docs.germainux.com/main/data-security

Privacy controls support an organization’s broader compliance program but should be configured and reviewed according to its legal, regulatory, security, and data-retention requirements.


Service: Management

Feature Availability: