SilentChat
Back to BlogGDPR

Embedding a live chat in WordPress the GDPR-compliant way — step by step

Marc WagnerOctober 5, 20265 min read
TL;DR

The easiest way to embed SilentChat is our free WordPress plugin: enter your widget key and you're done. Without the plugin, paste a snippet via a header/footer plugin such as WPCode. Consent before the chat and AI labelling in the dashboard, optionally loading only on click, and a paragraph in your privacy policy make the embed privacy-friendly.

1. Create a widget

After signing up, the setup assistant creates a widget. Your widget key (starts with pk_) and the snippet are in the dashboard under Chat Systems → Widgets → your widget → Install.

Our plugin is free and runs on WordPress 6.3+ and PHP 7.4+. It is not yet in the WordPress plugin directory; download it directly from us: silentchat.zip.

  1. Under Plugins → Add New Plugin → Upload Plugin, upload the ZIP file and activate it.
  2. Under Settings → SilentChat, enter your widget key (starts with pk_) and save. Without a key, the plugin loads nothing.

There you can also hide the chat on individual pages (e.g. /checkout/*) and load it only on click (step 5). Updates appear under Plugins as usual. You still set consent and AI labelling in the dashboard (step 4).

3. Without the plugin: paste the snippet

The snippet from your dashboard is a single line and also carries a version parameter (?v=…); at its core it looks like this:

<script
  src="https://cdn.silentchat.de/silentchat.min.js"
  data-widget-key="pk_YOUR_WIDGET_KEY"
  data-api-url="https://api.silentchat.de"
  data-ws-url="wss://ws.silentchat.de"
  async
></script>
  1. With a header/footer plugin: such as WPCode. Paste the snippet into the footer section and save — this survives theme switches and updates.
  2. Alternatively: into the footer.php of a child theme before </body>. Without a child theme, the change is lost on the next theme update.

4. Configure privacy in the widget

In the dashboard under Chat Systems → Widgets → your widget → Privacy:

  • Legal: enter the addresses of your privacy policy and imprint. They appear in the consent notice.
  • Require consent: a notice with these links appears before the chat; session and identifier only come into being after the visitor agrees.
  • AI labelling: on by default — visitors see that an AI is answering (Art. 50 AI Act).

The widget sets no cookies in any configuration. Before the first chat it creates no identifier unless the visitor has agreed to the live visitor view (step 6). Otherwise the browser holds at most markers such as “greeting already seen” or settings like sound off and language choice.

5. Optional: load only on click

If you don't want the widget to contact our chat API on page load, load it only on click. Until then, the browser only loads the script file from cdn.silentchat.de — IP address and browser details reach our server as with any file. Configuration, session and connection only come into being on the click.

  • With the plugin: tick “Load only on click” under Settings → SilentChat.
  • Without the plugin: choose the “Click-to-Open” mode under Install, save and copy the snippet again (it then carries data-mode="trigger").

There is then no floating chat button. The chat opens via a link — with the plugin via the shortcode [silentchat_link text="Start chat"] or a menu item pointing to #silentchat-open, otherwise like this:

<a href="#" data-silentchat-open>Start chat</a>
  • Borlabs Cookie, Real Cookie Banner, Complianz: these tools usually only block services they know or that you add. If SilentChat should load only after consent, create a service or script rule for cdn.silentchat.de there — this also applies with the plugin, because it adds a normal script tag.
  • Live visitor view: if your team should see visitors before their first message, that needs consent. Enable it under your widget → Privacy → Presence tracking (off by default) and choose “External consent tool” as the consent source. Your consent tool then reports consent through the JavaScript interface:
window.SilentChat.setConsent('presence_tracking', true);  // consent
window.SilentChat.revokeConsent('presence_tracking');      // withdrawal

7. Update your privacy policy

What belongs in it, including a template, is covered in Chatbot on your website: what goes into the privacy policy?. You conclude the data processing agreement in the dashboard.

8. Test

  1. Open the page in a private window.
  2. Developer tools → Application → Cookies: nothing from SilentChat is listed.
  3. Open the chat, check the consent notice and AI labelling, send a test message — it appears in the dashboard under Conversations.

Common pitfalls

  • Widget does not appear: clear the page cache (WP Rocket, W3 Total Cache). Optimisation plugins that combine or delay scripts should exclude silentchat.min.js.
  • Loaded twice: SilentChat is in the SilentChat plugin and also added as a snippet (WPCode, theme) — remove one.
  • Domain protection: if you restricted the allowed domains in the dashboard, your WordPress domain must be on the list, otherwise the server refuses (console: “Domain-Schutz”).
  • Content Security Policy: if cdn.silentchat.de is not in script-src, the browser does not load the script; the console states why.

Prices and plans: silentchat.de/pricing. There is a permanently free plan; AI from €19 per month.

wordpressdsgvolive-chateinbindunganleitung

Related articles

Embed a live chat in WordPress GDPR-compliantly: guide | SilentChat