Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Keap (formerly Infusionsoft) is a US-based CRM and marketing automation platform used by small businesses to manage contacts, send marketing emails, create web forms and track website visitor behaviour via a JavaScript tracking script. Because Keap is exclusively US-hosted and transfers all European contact data to American servers, its integration creates a significant GDPR compliance obligation including the requirement for valid transfer mechanisms and explicit consent for tracking and marketing activities.
Keap (formerly Infusionsoft) is a US-headquartered CRM and marketing automation platform designed for small businesses. Its core capabilities include contact management, email marketing, pipeline automation, appointment scheduling and web form creation. When deployed on a European website, Keap installs a JavaScript tracking snippet that links website visitor sessions to contact records in the CRM. This enables behaviour-triggered automations, such as sending a follow-up email when a contact visits a pricing page. The tracking script sets cookies on the visitor's browser that persist across sessions and allow Keap to stitch together a contact's journey across multiple website visits. All data collected by the tracking script is sent directly to Keap's US-based infrastructure, making every website visit by a European user a personal data transfer to the United States.
The Keap tracking script sets a persistent visitor identifier cookie (typically named INFUSIONSOFT_COOKIE or a variant) that is linked to a contact record once the visitor submits a form or clicks a tracked email link. Additional session cookies track page sequences and time on page. Email marketing pixels embedded in Keap campaign emails record opens (via a 1x1 pixel image request) and link clicks, attributing engagement data to the contact record. Web forms embedded from infusionsoft.app or keap.page capture name, email, phone and custom fields, sending them directly to the US CRM. Contact records accumulate tags, scores and activity histories over time, building a detailed marketing profile.
The Keap tracking script constitutes non-essential electronic communications surveillance under the ePrivacy Directive and requires prior opt-in consent in all EU member states. Consent must be obtained via a CMP before the Keap JS snippet loads, and the user must be able to decline without any detriment to the service they receive. For marketing email communications, Art. 6(1)(a) GDPR consent is required from B2C contacts; B2B prospecting to business email addresses may use legitimate interests in some jurisdictions, but this is increasingly restricted by national ePrivacy implementations. Keap's web forms create contact records: the initial data capture on a transactional form may use Art. 6(1)(b) (contractual necessity), but subsequent marketing use of that same email requires a separate consent.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Keap has no EU data residency option; every contact record, website visit log, email open and form submission is stored on AWS infrastructure in the United States. The transfer relies on Keap's EU-US Data Privacy Framework certification and the availability of Standard Contractual Clauses in Keap's Data Processing Addendum. Controllers must verify Keap's current DPF listing, execute the DPA, complete a Transfer Impact Assessment for any sensitive data categories, and disclose the US transfer clearly in their privacy notice. UK controllers use the UK IDTA addendum to Keap's DPA for UK-to-US transfers under the UK GDPR. Given that Keap is a US CLOUD Act subject, surveillance risk should be evaluated in the TIA, particularly for highly sensitive B2C databases.
The Keap tracking script must be placed in a CMP-conditional tag so it fires only after the user has consented to analytics or marketing cookies. Keap forms embedded via iframe or hosted on keap.page or infusionsoft.app load resources from Keap's US servers the moment the page renders, so consent must be captured before these embedded forms are displayed. One compliant approach is to display a static privacy-friendly form placeholder until the user consents, then replace it with the Keap iframe. Email consent captured through Keap forms must store a consent record with a timestamp, the form URL and the CMP consent version, as Keap's native consent logging may not be sufficient for GDPR audit purposes without additional customisation.
Organisations using Keap for EU audiences should: (1) gate the Keap tracking script and embedded forms behind CMP consent; (2) execute Keap's DPA and verify the DPF certification annually; (3) conduct a TIA given the US-only hosting; (4) implement a double opt-in workflow in Keap for EU email marketing lists to evidence consent; (5) configure Keap automation tags to distinguish EU and non-EU contacts and apply stricter suppression rules for EU contacts; (6) set contact retention policies in Keap and implement a deletion workflow for data subject erasure requests; (7) disclose Keap as a sub-processor in your privacy notice, naming the US transfer and mechanism; and (8) review CAN-SPAM compliance if sending to US recipients from the same Keap account.
Websites using Keap (formerly Infusionsoft) must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is recommended before deploying Keap's tracking script on any European-facing website, particularly for organisations with large European contact databases. Key risk factors include: (1) all European personal data (contact records, behavioural data, email engagement metrics) is transferred to the United States without an EU-adequacy equivalent, relying on the EU-US DPF or SCCs; (2) the Keap tracking script monitors individual visitor behaviour across pages, building contact-level activity profiles that constitute systematic behavioural profiling; (3) automated marketing email sequences and contact scoring involve automated decision-making elements that may require transparency disclosures under Art. 22 GDPR if they influence access to services; (4) form submissions capture personal data directly into the US-based CRM in real time, bypassing any EU data residency controls; (5) CCPA obligations may interact where US citizens are also in the contact database. The DPIA must document all processing activities, assess the adequacy of the DPF transfer mechanism, and define data minimisation and retention policies for the Keap contact database.
Sample consent text
This website uses Keap (formerly Infusionsoft), a CRM and marketing automation tool operated by Keap Inc. in the United States. If you interact with forms on this site or if you consent to website tracking, your personal data (including name, email address and browsing activity) will be transferred to and stored on Keap's servers in the USA under the EU-US Data Privacy Framework. We use this data to manage our customer relationships and send you marketing communications if you have subscribed. You can withdraw your consent to marketing communications at any time by clicking the unsubscribe link in any email, and withdraw consent to tracking by adjusting your cookie preferences below.
Third-party domains contacted
keap.cominfusionsoft.cominfusionsoft.appkeap.pageCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| INFUSIONSOFT_COOKIE | marketing | 1 year | Persistent visitor identification cookie that links anonymous website sessions to Keap CRM contact records. Triggered when a visitor submits a Keap form or clicks a tracked link in a Keap email, enabling cross-session contact tracking and behaviour-triggered automation sequences. |
| inf_session | functional | Session | Session-scoped cookie that tracks the visitor's current page sequence within a website session and maintains state for Keap form submissions and hosted landing pages on keap.page and infusionsoft.app. |
| keap_email_pixel | marketing | Session (server-side) | 1x1 tracking pixel embedded in Keap marketing emails that records email open events by logging a pixel request to Keap's servers, attributing opens to specific contact records and campaign sequences. |
| inf_contact_key | marketing | 1 year | Contact key cookie that persists a hashed identifier linking the current browser session to a specific Keap contact record, enabling personalised content delivery and automation triggers even without a new form submission. |
| inf_ab | analytics | 30 days | A/B testing cookie used by Keap to assign visitors to different form variants and email sequence experiments, measuring conversion rates across different messaging and landing page treatments. |
Keap (formerly Infusionsoft) places tracking cookies for advertising — comply with GDPR using FlowConsent.
Keap places a persistent visitor-identification cookie (INFUSIONSOFT_COOKIE) that links anonymous website visitors to CRM contact records once an identity event occurs, such as a form submission or an email link click. It also sets session cookies to track page sequences and a marketing measurement cookie. Additionally, Keap's email campaigns send messages containing 1x1 tracking pixels that record email opens, and link-click tracking is applied to every outbound URL in Keap emails. All these technologies send data to Keap's US-based servers and require prior consent under the ePrivacy Directive.
Yes, prior informed consent is mandatory for Keap's JavaScript tracking script under the ePrivacy Directive, which all EU member states have implemented into national law. The script is non-essential and builds detailed behavioural profiles, placing it firmly in the category of tracking technologies that require an affirmative opt-in before any script execution or cookie placement. Marketing email consent is separately required under Art. 6(1)(a) GDPR for B2C contacts. B2B email prospecting via legitimate interests is still possible in some EU jurisdictions but increasingly restricted.
Keap processes data under multiple legal bases depending on the activity: consent (Art. 6(1)(a)) for tracking cookies and marketing email communications; contractual necessity (Art. 6(1)(b)) for contact records created during a purchase transaction; and legitimate interests (Art. 6(1)(f)) for fraud prevention and B2B prospecting in permitted jurisdictions. Importantly, the legal basis for initial data capture does not automatically extend to subsequent marketing use, so a separate consent is required before adding a transactional contact to a Keap marketing sequence.
Yes, and this is a significant compliance consideration. Keap has no EU data centre; 100% of its CRM data, behavioural tracking data, email content and engagement metrics are stored on Keap Inc.'s infrastructure in the United States. The legal transfer mechanism is the EU-US Data Privacy Framework (Keap is a certified participant) supplemented by Standard Contractual Clauses in Keap's Data Processing Addendum. UK transfers use the UK IDTA. Controllers should execute Keap's DPA, verify DPF certification annually, conduct a Transfer Impact Assessment and disclose the US transfer prominently in their privacy notice.
A DPIA is recommended for any organisation using Keap with a substantial European contact database, particularly if automated marketing sequences, lead scoring or behavioural profiling are involved. The combination of website behavioural tracking, email engagement data and cross-campaign contact profiling stored exclusively in the United States creates a data protection risk profile that warrants a documented impact assessment. If Keap automation is used to make decisions that affect individuals' access to products or prices, Art. 22 GDPR considerations around automated decision-making may also apply.
Gate the Keap tracking script behind CMP consent so it fires only after opt-in. For embedded forms, display a static placeholder until consent is given, then load the Keap iframe. Implement Keap's double opt-in feature for all EU marketing lists. Execute Keap's DPA and confirm DPF certification. Segregate EU contacts in Keap using tags, apply stricter suppression logic, and configure data retention automations to delete inactive EU contacts after your retention period expires. Update your privacy notice to disclose Keap, the US transfer, legal basis and retention period. Ensure your unsubscribe flow is functioning correctly and triggering suppression in Keap immediately.
EU-hosted alternatives include ActiveCampaign (has EU data residency), HubSpot (has EU data centres and strong GDPR tooling), Brevo (formerly Sendinblue, French company with EU data processing), and Mailchimp (Intuit, US-based but with GDPR tools). For businesses prioritising data sovereignty, tools like Mautic (open source, self-hosted) or Brevo give the most control. The key compliance differentiators are EU data residency, built-in double opt-in, suppression list management and GDPR-ready DPA documentation.
In your cookie policy, list the INFUSIONSOFT_COOKIE as a marketing/tracking cookie with a 1-year duration, and any Keap session cookies as functional with session duration. In your privacy notice, add a section on Keap (or Infusionsoft) as a US-based data processor, specifying: categories of data sent (contact details, web behaviour, email engagement), purpose (CRM and marketing automation), legal basis, US transfer mechanism (EU-US DPF plus SCCs), Keap's data retention practices, and your contact's right to opt out. Link to Keap's privacy policy. Review both documents after any Keap DPA update or DPF re-certification.