Hotjar's DPA can now change without your signature

Stani Mihov
Founder & CEO
·

TL;DR
Vendor: Hotjar (now part of Contentsquare)
Document: Data Processing Agreement (v.2026.2)
Date detected: June 17, 2026
Key change: The DPA can now be modified unilaterally at Contentsquare's sole discretion, the customer's written opt-out from Contentsquare's own controller-side use of their data was removed, and that use is no longer limited to benchmarking and internal development
Hotjar's DPA is now the Contentsquare Data Processing Agreement, and two of its changes move control toward the provider: amendments no longer need both parties' written agreement, and the express opt-out from Contentsquare's own use of customer data is gone.
The change
On June 17, 2026, Venpo detected a new version of Hotjar's Data Processing Agreement (v.2026.2). The document is now published as the Contentsquare Data Processing Agreement, with Hotjar listed as one of several covered products alongside Heap, Loris, and Contentsquare's own analytics tools. Hotjar is the website behavior-analytics tool now operated by Contentsquare.
A DPA is the contract that governs how a processor handles your customers' personal data. For most teams it is signed once, at onboarding, and rarely reopened. Two changes in this version move meaningful control from the customer to Contentsquare, and the only on-page marker of the update is a revised “Last updated” date.
What changed
Two clauses stand out, both rated negative for customers.
1. The DPA can now be changed unilaterally. The modification clause (Section 10.1) previously required that “any modification to this DPA shall be made by mutual written agreement of both Parties,” with a good-faith negotiation process and a right to terminate the affected services if the parties could not agree. That language was replaced. Contentsquare now “reserves the right to change or modify this DPA at any time and in its sole discretion,” and gives notice mainly by revising the “Last updated” date at the top of the page. The earlier termination option tied to failed amendment negotiations was removed.
2. The opt-out from Contentsquare's own data use was removed, and that use was broadened. Section 2.1 previously limited Contentsquare's controller-side processing of customer data to two named purposes, benchmarking reports and internal development, and gave the customer a written opt-out from it. The new version removes the opt-out and no longer lists those purposes in the DPA itself. It instead points to a separate Contentsquare Services Privacy policy for that processing, and adds an express right for Contentsquare to anonymize customer data for the purposes set out in the agreement.
What this shifts onto you
Read together, the two changes move control toward the provider.
The modification change matters because a DPA is a control document. When it could only change by mutual written agreement, the data-processing terms a customer approved stayed fixed until both sides signed off. Now those terms can move at Contentsquare's discretion, with a changed date as the only signal. A DPA is also the instrument many security and legal teams rely on to demonstrate processor obligations under GDPR Article 28, so if its terms can be revised unilaterally, the version a team reviewed is not guaranteed to be the version in force later.
The opt-out change matters because it removes a lever. Customers could previously opt out, in writing, of Contentsquare using their data as a controller for its own purposes. That choice is gone, the two named purposes are no longer fixed in the DPA, and the governing description now sits in a separate policy that can itself change.
Why this matters
A DPA is one of the documents a company is least likely to re-read after signing, and one of the most consequential, because it defines how a processor may handle customer personal data. This is the category of change covered in our analysis of the hidden risk of vendor legal changes.
Tools like Hotjar are often adopted bottom-up, by a product or marketing team, without passing through the same review as a core platform. That makes a change in the governing data terms easy to miss, even though it changes the assumptions a team operates under. The same direction shows up elsewhere in the stack, as when Anthropic's terms let a model designation override zero-data-retention. Staying current with this kind of drift is the core argument for continuous vendor risk monitoring rather than reviewing a document once.
Potential impact for SaaS companies
Companies that use Hotjar, or another Contentsquare product such as Heap, may want to review whether:
their records of processing still reflect that the DPA can now change without their sign-off
they have a way to track future DPA revisions, given that notice is now a changed “Last updated” date rather than a signed amendment
their data-protection assessments still hold now that the written opt-out from Contentsquare's controller-side use has been removed
their internal documentation accounts for Contentsquare's added right to anonymize customer data for the purposes in the agreement
For teams that build on or resell a Contentsquare product, a change to how the processor can use and re-govern customer data can cascade into their own customer commitments. Tracking that across a full vendor portfolio is where structured vendor contract monitoring becomes a control rather than a periodic task.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as they are published. For this update, Venpo:
detected the new version of the Contentsquare DPA on June 17, 2026
isolated the two substantive clauses from routine renumbering and formatting
scored each as negative for customers and explained the impact in plain English
flagged the unilateral-modification clause as the most material
Instead of discovering a rewritten modification clause during a renewal or a customer security review, teams could understand the change in the same period it shipped. A DPA changes too rarely to watch by hand and too materially to miss, which is the core of our comparison of manual vs automated vendor monitoring.
Business outcome
Companies that caught this change early were able to:
note that the DPA can now change unilaterally and set up a way to monitor its revision date
reassess whether removing the controller-side opt-out affects their data-protection position
review how Contentsquare's broadened, separately governed use of customer data maps to their own disclosures
brief legal and compliance before the next renewal or customer audit
Instead of reacting to a clause discovered during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.
Key takeaway
The most consequential vendor changes are often not in the privacy policy but in the DPA, where the rules for handling customer data live. This version of the Contentsquare DPA moved two of them toward the provider in a single revision: it can now be changed unilaterally, and the customer's opt-out from Contentsquare's own data use is gone. The only on-page signal was a revised date. A closer look at why scheduled reviews keep missing this kind of change is in our analysis of manual vs automated vendor monitoring.
The change
On June 17, 2026, Venpo detected a new version of Hotjar's Data Processing Agreement (v.2026.2). The document is now published as the Contentsquare Data Processing Agreement, with Hotjar listed as one of several covered products alongside Heap, Loris, and Contentsquare's own analytics tools. Hotjar is the website behavior-analytics tool now operated by Contentsquare.
A DPA is the contract that governs how a processor handles your customers' personal data. For most teams it is signed once, at onboarding, and rarely reopened. Two changes in this version move meaningful control from the customer to Contentsquare, and the only on-page marker of the update is a revised “Last updated” date.
What changed
Two clauses stand out, both rated negative for customers.
1. The DPA can now be changed unilaterally. The modification clause (Section 10.1) previously required that “any modification to this DPA shall be made by mutual written agreement of both Parties,” with a good-faith negotiation process and a right to terminate the affected services if the parties could not agree. That language was replaced. Contentsquare now “reserves the right to change or modify this DPA at any time and in its sole discretion,” and gives notice mainly by revising the “Last updated” date at the top of the page. The earlier termination option tied to failed amendment negotiations was removed.
2. The opt-out from Contentsquare's own data use was removed, and that use was broadened. Section 2.1 previously limited Contentsquare's controller-side processing of customer data to two named purposes, benchmarking reports and internal development, and gave the customer a written opt-out from it. The new version removes the opt-out and no longer lists those purposes in the DPA itself. It instead points to a separate Contentsquare Services Privacy policy for that processing, and adds an express right for Contentsquare to anonymize customer data for the purposes set out in the agreement.
What this shifts onto you
Read together, the two changes move control toward the provider.
The modification change matters because a DPA is a control document. When it could only change by mutual written agreement, the data-processing terms a customer approved stayed fixed until both sides signed off. Now those terms can move at Contentsquare's discretion, with a changed date as the only signal. A DPA is also the instrument many security and legal teams rely on to demonstrate processor obligations under GDPR Article 28, so if its terms can be revised unilaterally, the version a team reviewed is not guaranteed to be the version in force later.
The opt-out change matters because it removes a lever. Customers could previously opt out, in writing, of Contentsquare using their data as a controller for its own purposes. That choice is gone, the two named purposes are no longer fixed in the DPA, and the governing description now sits in a separate policy that can itself change.
Why this matters
A DPA is one of the documents a company is least likely to re-read after signing, and one of the most consequential, because it defines how a processor may handle customer personal data. This is the category of change covered in our analysis of the hidden risk of vendor legal changes.
Tools like Hotjar are often adopted bottom-up, by a product or marketing team, without passing through the same review as a core platform. That makes a change in the governing data terms easy to miss, even though it changes the assumptions a team operates under. The same direction shows up elsewhere in the stack, as when Anthropic's terms let a model designation override zero-data-retention. Staying current with this kind of drift is the core argument for continuous vendor risk monitoring rather than reviewing a document once.
Potential impact for SaaS companies
Companies that use Hotjar, or another Contentsquare product such as Heap, may want to review whether:
their records of processing still reflect that the DPA can now change without their sign-off
they have a way to track future DPA revisions, given that notice is now a changed “Last updated” date rather than a signed amendment
their data-protection assessments still hold now that the written opt-out from Contentsquare's controller-side use has been removed
their internal documentation accounts for Contentsquare's added right to anonymize customer data for the purposes in the agreement
For teams that build on or resell a Contentsquare product, a change to how the processor can use and re-govern customer data can cascade into their own customer commitments. Tracking that across a full vendor portfolio is where structured vendor contract monitoring becomes a control rather than a periodic task.
How Venpo detected it
Venpo continuously monitors vendor legal documents and detects changes as they are published. For this update, Venpo:
detected the new version of the Contentsquare DPA on June 17, 2026
isolated the two substantive clauses from routine renumbering and formatting
scored each as negative for customers and explained the impact in plain English
flagged the unilateral-modification clause as the most material
Instead of discovering a rewritten modification clause during a renewal or a customer security review, teams could understand the change in the same period it shipped. A DPA changes too rarely to watch by hand and too materially to miss, which is the core of our comparison of manual vs automated vendor monitoring.
Business outcome
Companies that caught this change early were able to:
note that the DPA can now change unilaterally and set up a way to monitor its revision date
reassess whether removing the controller-side opt-out affects their data-protection position
review how Contentsquare's broadened, separately governed use of customer data maps to their own disclosures
brief legal and compliance before the next renewal or customer audit
Instead of reacting to a clause discovered during due diligence, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.
Key takeaway
The most consequential vendor changes are often not in the privacy policy but in the DPA, where the rules for handling customer data live. This version of the Contentsquare DPA moved two of them toward the provider in a single revision: it can now be changed unilaterally, and the customer's opt-out from Contentsquare's own data use is gone. The only on-page signal was a revised date. A closer look at why scheduled reviews keep missing this kind of change is in our analysis of manual vs automated vendor monitoring.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
