Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Antsomi CDP 365 is a customer data platform that collects and unifies customer data from a website, mobile apps and other channels into a single profile, then uses those profiles for segmentation, personalisation and omnichannel marketing. Because it builds rich, identifiable customer profiles and is operated from Singapore and Vietnam, which have no EU adequacy decision, it both requires consent for its tracking and depends on a valid international transfer mechanism.
Antsomi CDP 365 is a customer data platform aimed at marketing and ecommerce teams. Through a JavaScript SDK and channel connectors, it collects web and app events, combines them with CRM and transactional data, resolves them to a single customer profile, and powers segmentation, predictive scoring, personalisation and campaign orchestration across email, ads and messaging. It is a profile building system rather than a simple analytics tag.
On the website, Antsomi sets a first party cookie that stores a persistent visitor identifier, and it records page views, clicks and ecommerce events. These are linked to known identifiers such as an email address or a customer ID when the visitor logs in or converts, producing a detailed, identifiable profile that includes behaviour, preferences and predicted attributes. The platform is designed to recognise the same person across sessions, devices and channels.
Because Antsomi creates identifiable cross channel profiles for marketing, its web tracking cookies are not strictly necessary and require prior consent under article 5(3) of the ePrivacy Directive, with consent as the legal basis under GDPR article 6(1)(a). The profile enrichment and predictive scoring can amount to profiling under article 22, and the platform processes personal data as your processor, so a data processing agreement under article 28 is required.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Antsomi is operated from Singapore and Vietnam, neither of which benefits from a European Commission adequacy decision, so transfers of European personal data require standard contractual clauses and a transfer impact assessment that considers local access laws. Document where the customer profiles are stored, who can access them, and the safeguards in place, and reflect this in your privacy policy and records of processing.
Gate the Antsomi SDK behind marketing consent so that no profile is built before the visitor accepts, and pass the consent state to the platform so that suppression is respected. Sign a data processing agreement, put standard contractual clauses in place for the Asia transfer, set retention limits on the profiles, and provide a way to honour access, erasure and objection requests. Disclose Antsomi, its purpose and the transfer in your privacy policy.
Websites using Antsomi CDP 365 must obtain user consent under GDPR regulations.
DPIA considerations
A customer data platform that unifies identifiable profiles across channels for marketing is high risk processing, so a DPIA under GDPR art. 35 is normally required for Antsomi CDP 365. Assess the profile resolution, the predictive scoring and any automated decisions, the retention of the profiles, the data processing agreement and the transfers to Singapore and Vietnam, and define how data subject rights are handled.
Sample consent text
With your consent, this website uses Antsomi CDP 365, a customer data platform, to recognise you across visits and channels and to build a profile from your activity for personalised marketing. Antsomi processes this data on our behalf in Singapore and Vietnam under standard contractual clauses. No profiling cookie is set until you accept marketing cookies, and you can change or withdraw your consent, or ask us to access or erase your profile, at any time.
Third-party domains contacted
cdp.antsomi.comcdp-platform.antsomi.comantsomi.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _antsomi_uid | First party, persistent | 1 year | Stores a persistent visitor identifier used by Antsomi CDP 365 to recognise the visitor across sessions and attach behaviour to a customer profile. |
| _antsomi_ses | First party, session | Session | Stores a session identifier used to group events within a single visit. |
Antsomi CDP 365 collects user analytics data — you legally need a consent banner. Try FlowConsent free.
On the website Antsomi sets a first party cookie that stores a persistent visitor identifier used to recognise you across visits and to attach your behaviour to a customer profile. It is a profiling identifier, not a strictly necessary cookie, and it is linked to known identifiers such as your email when you log in or buy.
Yes. Antsomi builds identifiable marketing profiles, so its web tracking requires prior consent under article 5(3) of the ePrivacy Directive. Keep the SDK blocked until the visitor accepts marketing cookies, and pass that consent state to the platform.
The web tracking relies on consent under GDPR article 6(1)(a) and ePrivacy article 5(3). Because Antsomi acts as your processor, you also need a data processing agreement under article 28, and the profiling and scoring may engage the rules on automated decision making in article 22.
Yes. Antsomi is operated from Singapore and Vietnam, which have no EU adequacy decision, so the transfer of European customer data requires standard contractual clauses and a transfer impact assessment. Document the storage location and access controls in your records.
Normally yes. Unifying identifiable profiles across channels for marketing, with predictive scoring and international transfers, is high risk processing under GDPR article 35. Assess the profiling, retention, the processing agreement and the transfers.
Block the SDK until marketing consent, pass consent signals so suppression works, sign a data processing agreement, put standard contractual clauses in place, set retention limits and build a process for access, erasure and objection requests. Disclose Antsomi and the Asia transfer in your privacy policy.
Other customer data platforms include Segment, Tealium, Salesforce Data Cloud and the open source RudderStack, while EU hosted options reduce the transfer question. Choose based on where the profiles are stored, the consent integration and the data processing terms.
List the Antsomi cookie, its profiling purpose, the recipients and the Singapore and Vietnam transfer in your cookie and privacy policies, and review them when you change what data you send to the platform. Keep the consent categories aligned with how the profiles are used.