FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. Tomi.ai
T

Tomi.ai

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does TomiAI do?

TomiAI is a marketing AI platform that predicts conversion intent, churn risk, and audience scores from website behaviour and CRM data, with a JavaScript SDK that captures events and a scoring API that powers personalisation, lead scoring, and audience activation.

What TomiAI is

TomiAI is a marketing artificial intelligence platform that helps brands predict conversion intent, churn risk, and audience affinity from a combination of website behaviour, CRM data, and transactional history. The product offers a JavaScript SDK that captures events on the advertiser site, server side connectors with Shopify, HubSpot, and Salesforce, and a scoring API that returns predicted scores and recommended audiences. Marketing teams use TomiAI to drive personalisation on the homepage and product pages, to feed audience exports into ad platforms, and to prioritise leads in the CRM. The platform sits at the intersection of predictive analytics and customer data activation.

Cookies and event collection

TomiAI is implemented through a JavaScript SDK that writes a first-party cookie carrying a TomiAI visitor identifier and forwards pageviews, form submits, add to cart, signup, and purchase events to the TomiAI ingestion endpoint. Hashed email addresses and CRM identifiers can be added to the events to support cross device matching with the customer record. The cookie has a long lifetime and is used to persist the visitor identifier across sessions, which means that ePrivacy Article 5(3) applies and consent is required before the SDK is loaded for personalisation, scoring, and AI driven audience building.

GDPR roles and AI obligations

When a brand uses TomiAI, the brand is the controller and TomiAI acts as a processor under Article 28 GDPR for behavioural events and CRM data. The AI models are trained on aggregated data and require a clear legal basis, including consent for non strictly necessary scoring and legitimate interest with a balancing test for some CRM scoring use cases. The EDPB guidelines on automated decision making and profiling apply, especially when scores influence the offers presented to customers, and the EU AI Act adds transparency obligations and a categorisation that may classify some use cases as limited risk profiling.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent, profiling, and direct marketing

Behavioural scoring that targets visitors with personalised messages or audiences relies on Article 6(1)(a) GDPR consent. The CNIL recommendation on profiling for direct marketing and the EDPB guidance confirm that storing identifiers, building profiles, and serving personalised content require prior consent, and that the refuse option must be as accessible as the accept option. Some narrow CRM scoring on existing customers can rely on legitimate interest with a documented balancing test and a clear right to object, but TomiAI default deployments lean towards consent because they combine web events, CRM data, and AI driven personalisation.

US transfers and Schrems II

TomiAI ingestion and AI training run on US infrastructure for most customers, with optional EU residency for the event store. Transfers must be documented under Standard Contractual Clauses and, where TomiAI is certified, the EU: US Data Privacy Framework, and a transfer impact assessment in line with the EDPB recommendations. Supplementary measures include IP truncation, hashing of identifiers, field level encryption, and limited retention. Customers should also map the access of US support and engineering teams to EU customer data and document the relevant safeguards.

Practical compliance steps

Treat TomiAI as a high risk profiling service that requires consent for non strictly necessary uses. Configure the consent management platform to load the SDK only after consent for personalisation and AI driven analytics, and ensure that no event is sent before consent. Sign the data processing agreement and the data protection addendum, request the latest sub processor list, and document the supplementary measures enabled. Update the cookie policy and the privacy notice to mention TomiAI as a processor, the categories of data, the retention, the AI use cases, and the transfer mechanism. Run a DPIA before go live.

GDPR consent category

Marketing

Websites using TomiAI must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(a) GDPR consent for the behavioural identifiers, scoring cookies, and AI driven personalisation that fall within the scope of ePrivacy Article 5(3) for storage and access on the device. CRM scoring of existing customers based on transactional data can rely on Article 6(1)(b) performance of contract and on Article 6(1)(f) legitimate interest with a documented balancing test, in line with the EDPB direct marketing guidelines and the CNIL position on customer scoring.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, French Data Protection Act and CNIL guidelines on profiling and scoring, German TDDDG, Spanish LSSI and AEPD cookie guidance, UK PECR, EDPB guidelines on automated decision making and profiling, EU AI Act provisions on profiling and high risk uses, EU: US Data Privacy Framework, US state privacy laws including CCPA, CPRA, and the Virginia, Colorado, Connecticut, and Utah laws.

DPIA considerations

A DPIA is required for most TomiAI deployments because the platform performs systematic profiling, automated scoring of conversion intent and churn, and combines website behaviour with CRM and transactional data. Document the categories of personal data, the AI models used, the scoring outputs, the human oversight applied to high impact decisions, and the supplementary measures used for transfers to the United States. Reference the EDPB guidelines on automated decision making and profiling, the CNIL position on customer scoring, and the EU AI Act categorisation for the relevant use cases.

Sample consent text

We use TomiAI to predict your interests and to personalise our communications. With your consent, we set a first-party cookie and send your interactions on this site to the TomiAI scoring API in the United States to compute audience and intent scores. You can change or withdraw your choice at any time from the cookie settings link in the footer.

Technical details

Tracking methodJavaScript SDK loaded on advertiser sites that captures pageviews, form submits, add to cart, signups, and purchase events, sets a first-party cookie with a TomiAI visitor identifier, and forwards events to the TomiAI scoring API. Server side ingestion accepts CRM exports through secure file uploads and webhook integrations with Shopify, HubSpot, and Salesforce, where AI models score conversion intent, churn risk, and recommended audiences.
Server locationUnited States and European Union, with TomiAI processing event data and AI scoring on Amazon Web Services regions in the United States and selectively in Frankfurt for European customers. Customers can request EU data residency for the event store, but the AI training pipeline and historical reporting may still rely on US infrastructure depending on the contract.
Data transferred outside the EUVisitor event payloads, IP addresses, hashed email addresses, behavioural scores, and CRM uploads can be processed by TomiAI on infrastructure located in the United States. Transfers rely on Standard Contractual Clauses and on the EU: US Data Privacy Framework where TomiAI is certified, with supplementary measures such as IP truncation and field level encryption that the controller can enable. Customers on the EU residency tier limit the bulk of processing to Frankfurt, but support and engineering access from the United States remains in scope.

Third-party domains contacted

tomi.aiapi.tomi.aievents.tomi.aicdn.tomi.aiapp.tomi.ai

Cookies placed

NameTypeDurationPurpose
_tomi_uidfirst_party1 yearFirst-party identifier set by the TomiAI SDK to recognise the visitor across sessions and to feed AI scoring and audience activation.
_tomi_sessfirst_partySessionShort-lived cookie used by the TomiAI SDK to group events of the current visit before they are sent to the scoring API.
_tomi_consentfirst_party6 monthsStores the visitor consent state shared with the TomiAI SDK so that scoring and personalisation only run after consent.
_tomi_audfirst_party180 daysCaches the audience and intent scores returned by TomiAI for the current visitor to power on site personalisation.

TomiAI places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Does TomiAI set cookies on visitor devices?

Yes. TomiAI sets a first-party cookie that carries the TomiAI visitor identifier and is used to persist the visitor across sessions, link events to a profile, and feed the AI scoring models. The cookie is non strictly necessary because it powers profiling, personalisation, and audience activation, so ePrivacy Article 5(3) applies and consent is required before the SDK is loaded.

Is consent required to use TomiAI in the EU?

Yes for the behavioural scoring, personalisation, and audience activation features, which store identifiers on the visitor device and build a profile of the visitor. Some narrow CRM scoring on existing customers can rely on legitimate interest with a documented balancing test, but the default web SDK requires Article 6(1)(a) GDPR consent collected through a compliant cookie banner.

What is the legal basis for TomiAI?

The web SDK relies on Article 6(1)(a) GDPR consent. CRM scoring on existing customers can rely on Article 6(1)(b) performance of contract or Article 6(1)(f) legitimate interest where the controller has documented a balancing test, in line with the EDPB direct marketing guidelines. Special categories should not be sent to TomiAI unless a specific lawful basis under Article 9 applies.

Where is TomiAI data sent?

Most processing runs on Amazon Web Services in the United States, with optional EU residency in Frankfurt for the event store. Transfers rely on Standard Contractual Clauses and the EU: US Data Privacy Framework where TomiAI is certified, and a transfer impact assessment with supplementary measures such as IP truncation and field level encryption.

Do I need a DPIA before using TomiAI?

Yes. The platform performs systematic profiling, AI driven scoring, and combines web behaviour with CRM data, which the EDPB DPIA guidelines and the lists adopted by the CNIL and the AEPD identify as high risk processing. Document the categories of data, the models, the human oversight, and the supplementary measures, and consider the EU AI Act categorisation.

How do I implement consent gating with TomiAI?

Configure the consent management platform to expose a personalisation and AI scoring purpose, and load the TomiAI SDK only after consent for that purpose. Ensure that no first-party cookie is set before consent and that the visitor identifier is generated only after opt in. Make the refuse option as accessible as the accept option, and document the configuration.

What are the alternatives if consent is refused?

When consent is refused, fall back to non personalised content and to aggregated CRM scoring built on transactional data only. Server side scoring of existing customers can run without web events, and personalisation can rely on context and content categories rather than visitor identifiers. The TomiAI SDK does not load, no first-party cookie is written, and no behavioural event is sent.

How should the cookie policy describe TomiAI?

List TomiAI as a processor for behavioural scoring, personalisation, and AI driven audience activation. Describe the cookie it sets, its duration, and purpose, and mention the categories of events captured by the SDK. State that data is transferred to the United States, reference the EU: US Data Privacy Framework and the Standard Contractual Clauses, and link to the TomiAI privacy notice. Provide the channels for data subject access, erasure, and objection requests.