LoyJoy in the Cookie Banner: Classify & Configure
This overview explains how the LoyJoy Chat Assistant is correctly classified and configured in your consent manager (cookie banner). It is written for everyone responsible for or involved in this classification: Data Protection Officers (DPOs) and data protection contacts as well as marketing and web stakeholders. These notes are not legal advice; the final assessment is made as part of your data protection review.
Why classification matters
If LoyJoy is misclassified as “Marketing,” the chat only loads after the user actively clicks “Accept All.” Since the chat is often the primary entry point for support and lead generation, this loses measurable interactions.
Two legal layers, kept separate
Two questions are often conflated, but legally they need to be assessed separately:
- Storage on the user’s device (Art. 5(3) ePrivacy Directive / § 25 TDDDG in Germany): Concerns the writing and reading of information in the browser, for example in Local Storage. Consent is required here unless the storage is strictly necessary to provide a service explicitly requested by the user.
- Processing of personal data (GDPR): Concerns everything that happens with personal data during the operation of the service, for example transmission of the IP address when the script loads. The legal basis here is Art. 6 GDPR, not the ePrivacy storage rule.
The storage type (Local Storage instead of classic cookies) does not change the consent question under the ePrivacy Directive, because the rule covers any storage of and any access to information on the user’s device. What matters is not the storage medium, but whether the storage is necessary and for how long it persists.
Configurable storage duration
How long LoyJoy keeps context in Local Storage is up to you. The options are:
- Off: no persistent storage in the browser. In that case there is nothing under Art. 5(3) ePrivacy that would require consent.
- 30 minutes, 1 day, 1 week, or 14 days (14 days is the maximum).
A short storage duration supports the classification as technically necessary and actively documents data minimisation under Art. 5(1)(c) and (e) GDPR. For the simplest possible integration we recommend a short duration (for example 30 minutes or 1 day) or “Off.”
Classification as Essential / Strictly Necessary
LoyJoy performs no cross-site tracking. When Local Storage is used, it primarily serves the technical function of maintaining the chat context across page views. Under common legal interpretation (Art. 5(3) ePrivacy Directive / § 25(2) no. 2 TDDDG), no consent is required if the storage is strictly necessary to provide a service explicitly requested by the user.
“Strictly necessary” does not mean the website fails without the tool. Shopping-cart analogy: the site works for browsing without a cart cookie; once the user wants to buy, the cookie becomes strictly necessary. The same applies to the LoyJoy chat context once the user uses the chat.
An honest note on scope: how far this argument carries depends on the use case. For a pure service and support chat, the necessity is well defensible. If the chat primarily serves lead generation or marketing, the assessment may turn out differently. Treat “Essential” as a well-defensible option for many service scenarios, not as an automatic default.
Arguments for the classification as strictly necessary
You can adopt or adapt the following wording for your data protection documentation:
“The LoyJoy Chat is integrated as ‘Strictly Necessary’ (Essential). No cross-site tracking takes place. The use of Local Storage serves exclusively to provide the technical chat functionality (maintaining the session context). The storage duration is configurable and limited to the necessary minimum (selectable from ‘Off’ to a maximum of 14 days). The CDN providers used for delivery are based in the EU; no third-country transfer takes place when the chat loads.”
The IP address case at script load
When the script loads, the IP address is transmitted before the user opens the chat. Legally this is a processing operation under the GDPR (the IP is personal data), not a storage question under the ePrivacy Directive. Our position:
- Legal basis: Receiving the IP address is technically required to deliver content over the internet, and serves delivery and security (for example DDoS protection). The legal basis is legitimate interest under Art. 6(1)(f) GDPR; GDPR Recital 49 explicitly names network and information security as a legitimate interest.
- No profiling: The IP is used exclusively for delivery and security, not for tracking or profiling, and is not joined with chat data.
- Retention: IP address, user agent, and timestamp are visible in the Live view for a maximum of 24 hours and not accessible thereafter.
- EU delivery: Delivery runs through CDN providers based in the EU (Bunny.net, Slovenia, with G-Core Labs, Luxembourg, as a backup). No transfer to a third country takes place here. The full list is in our Sub-Processors List.
”Loading already transfers data” — a critical look
A common objection raised from a data protection perspective is that personal data (IP address, browser, timestamp) is already transmitted by merely loading the script, regardless of whether the user actually uses the chat. The objection is technically correct and applies to every resource loaded over the internet, since IP-based communication cannot work without transmitting the IP address.
Our view:
- Legally this falls under Art. 6 GDPR (delivery and security, legitimate interest), not under Art. 5(3) ePrivacy / § 25 TDDDG, because no storage on the user’s device takes place.
- The data goes only to EU CDN providers, is visible for at most 24 hours, and is not used for profiling. The processing is therefore limited to what is technically necessary.
- To avoid this transmission entirely, you can gate the loading on prior consent via the consent manager (see Path 1 and Basic mode). In that case the script only loads after consent, and the chat is not available without consent.
Two integration paths
Path 1: The cookie banner controls loading (manual administration). You manage the consent manager yourself: add LoyJoy as a service, store a description text, and assign a category. The consent manager then decides whether the LoyJoy snippet is allowed to load. Classified as “Essential,” the chat loads immediately. Classified as “Marketing,” the chat only appears after “Accept,” which costs reach but avoids any data transmission before consent.
Path 2: LoyJoy controls consent (the shortcut). You skip administering the cookie banner and instead select your consent manager in the LoyJoy settings. LoyJoy then behaves toward the user’s choice via one of two modes:
- Basic mode: LoyJoy adapts its snippet to the consent manager. You give LoyJoy a cookie category; the chat loads only after the banner is closed. Drawback: classified as marketing the chat does not appear on rejection; classified as essential the instant loading may collide with the banner.
- Smart mode (recommended): LoyJoy always shows the chat, waits for the banner to close, and enables persistent storage (Local Storage) only if consent was given. On rejection the storage duration is automatically set to “Off” and the chat keeps running without persistent storage. Benefit: a classification as essential, functional, or marketing is not required for the storage, because the chat respects the choice on its own. Transparency note: since the chat is shown immediately, the script loads on page view, so the IP address is transmitted as described above (legal basis Art. 6(1)(f) GDPR, EU CDN, 24 hours). To avoid that as well, use the consent-gated variant from Path 1.
Note: if your consent manager blocks unknown scripts by default, the LoyJoy snippet must still be allowed to load once (typically marked “Essential”) even on Path 2, so it can load at all.
Technical pitfall
For LoyJoy to load immediately as “Essential,” the consent manager must not block the script. Do not rewrite the script tag to type="text/plain", or the chat will not appear for new users. Keep it as a standard JavaScript tag and assign the vendor “LoyJoy” to the “Essential” category.
Template for the cookie banner entry
This service description is filed in the consent manager. The category depends on the specific use case: what data the chat stores, for how long, and the business role the agent plays on your site. The final classification is made as part of your data protection review, not by LoyJoy. The remaining fields are independent of that decision:
- Category: to be determined as part of your data protection review. The sections above explain why many LoyJoy customers conclude “Essential / Strictly Necessary” for pure service scenarios. Treat that as input for the review, not as a default.
- Service name: LoyJoy Chat Assistant
- Provider: LoyJoy GmbH, Münster, Germany
- Purpose: Provides an interactive chat service (AI Agent). Storage is technically required to maintain chat history and conversation context across page views.
- Storage type: Local Storage; no classic tracking cookies. Storage duration is configurable: “Off,” 30 minutes, 1 day, 1 week, or a maximum of 14 days.
- Delivery: CDN providers based in the EU (Bunny.net, Slovenia; backup G-Core Labs, Luxembourg); no third-country transfer.
Text variants for your privacy policy are available under Supplement to Your Privacy Policy. A broader Data Privacy Overview and FAQ explains the overall data processing. The Sub-Processors List names all providers used. The technical step-by-step setup is in our documentation.