Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
ASAPP is a United States based enterprise artificial intelligence platform for customer experience and contact centres. When embedded as a chat or messaging widget it loads from ASAPP servers, opens a conversation session and applies machine learning to automate messaging and voice interactions and to assist human agents. The widget records the customer interaction, which can include sensitive details, and it reads and writes cookies and browser storage to keep the session and to identify the user. Because this involves large scale processing of potentially sensitive data and non essential identifiers, ASAPP should load only after the visitor has given consent.
ASAPP is an enterprise artificial intelligence platform for customer experience and contact centres, based in the United States. It automates messaging and voice interactions and assists human agents with machine learning models that suggest replies, summarise conversations and predict outcomes. When it is added to a website, ASAPP runs as an embedded chat or messaging widget that loads its code from ASAPP servers and renders inside the host page.
When a visitor opens the widget, ASAPP creates a conversation session and records the customer interaction: the messages exchanged, the intents detected, agent handovers and the outcome of the contact. Because customers can type anything into a chat, these interactions may reveal sensitive information such as health, financial or account details. ASAPP applies machine learning models to this content to automate and assist the exchange. It stores session and identifier values in cookies and browser storage so that the conversation persists and the user can be recognised, and it connects the page session to its own session through a context provider.
The interaction content and identifiers that ASAPP processes are personal data under the GDPR, because they relate to an identifiable person, and they can include special category data when a customer shares sensitive details. Storing and reading identifiers on the visitor device also falls within Article 5(3) of the ePrivacy Directive, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all enforce as a strict prior consent obligation for non essential trackers. The scale of the processing and the use of machine learning raise both the risk level and the compliance obligations of the controller.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is required before the ASAPP widget loads, because the identifier storage and behavioural processing it performs are not strictly necessary to deliver the content of the page. That consent must be freely given, specific, informed and unambiguous, and it must be as easy to refuse as to accept. Until the visitor accepts, the widget script should not run and no cookies or browser storage entries should be written. Where the widget is offered as an optional support channel, the moment the visitor opens it should be paired with clear information rather than treated as an implied agreement.
ASAPP processes data on United States infrastructure, so European customer data is transferred outside the European Economic Area. Such transfers require the EU Standard Contractual Clauses 2021/914 within the ASAPP Data Processing Agreement and a documented Transfer Impact Assessment that considers United States surveillance law, in line with the Schrems II ruling and the guidance of the European Data Protection Board. Because the interactions can be sensitive and are processed at large scale, the supplementary measures assessed in that document deserve particular attention.
Gate the ASAPP widget behind your consent management platform so it fires only after the relevant category is accepted. Describe ASAPP clearly in your cookie policy, including the session and identifier values it sets and their lifetime. Sign the ASAPP Data Processing Agreement, complete a Transfer Impact Assessment and, given the large scale processing of potentially sensitive interactions, carry out a Data Protection Impact Assessment under Article 35 GDPR. Apply the shortest workable retention on conversation records, restrict access to the machine learning outputs and minimise the personal data sent to ASAPP.
Websites using ASAPP must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is likely to be mandatory under Article 35 GDPR, because ASAPP carries out large scale processing of customer interaction data with machine learning and those interactions can reveal sensitive information. Document the interaction data captured by the widget, the session and identifier values stored in cookies and browser storage, the automated processing and profiling performed by the models, the transfer of data to the United States and the retention period applied to conversation records. Configure the widget so that it loads only after consent and minimise the personal data sent to ASAPP.
Sample consent text
We use ASAPP, an artificial intelligence customer experience service operated by ASAPP, Inc. (United States), to power our chat and messaging. ASAPP records your conversation, applies machine learning to assist it and stores session and identifier values in cookies and browser storage on your device. This data may be transferred to the United States under the EU Standard Contractual Clauses. ASAPP will only load if you click Accept.
Third-party domains contacted
asapp.comsdk.asapp.comapi.asapp.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ASAPP-session | HTTP cookie (first party) | Session | Maintains the active chat or messaging session so that the messages and context of a single visit are grouped together while the visitor interacts with the widget. |
| ASAPP-anon-id | HTTP cookie (first party) | Persistent (up to 12 months) | Stores a persistent identifier so that ASAPP can recognise a returning user, link a conversation to its context provider session and attribute interactions to a single profile. |
| asapp_sdk_state | localStorage | Persistent (until cleared) | Holds the widget state and buffers interaction events (messages, intents and outcomes) before they are sent to ASAPP endpoints on api.asapp.com. |
ASAPP collects user analytics data — you legally need a consent banner. Try FlowConsent free.
ASAPP sets a first party session cookie that lasts for the visit, a persistent identifier that can last up to twelve months, and browser storage entries that hold the widget state and buffered interaction events. Together they let ASAPP keep the conversation, recognise a returning user and record how the chat is used.
Yes. ASAPP writes identifiers to the visitor device and processes chat interactions with machine learning, which is not strictly necessary to display the page, so under the ePrivacy rules you must obtain prior consent before the widget loads. The script should stay blocked until the visitor accepts.
The valid legal basis is consent under Article 6(1)(a) GDPR, combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest cannot be used for this non essential and large scale processing, and where interactions reveal special category data an explicit consent condition also applies.
Yes. ASAPP hosts its platform on United States infrastructure, so European customer data is transferred there. You need the EU Standard Contractual Clauses 2021/914 in the ASAPP Data Processing Agreement and a Transfer Impact Assessment, in line with the Schrems II ruling, to cover the transfer.
Very likely yes. A Data Protection Impact Assessment is expected under Article 35 GDPR because ASAPP carries out large scale processing of interaction data with machine learning and those interactions can be sensitive. Assess the tracking, the identifiers, the automated processing and the United States transfer.
Load the widget only through your consent management platform after the relevant category is accepted, describe ASAPP in your cookie policy, sign the Data Processing Agreement and complete a Transfer Impact Assessment and a Data Protection Impact Assessment. Minimise the data sent, restrict access to model outputs and apply a short retention period.
Alternatives include Cognigy, Ada, Kore.ai, LivePerson and Zendesk AI agents. They raise similar consent, cookie and transfer questions, so evaluate their hosting location, their machine learning practices and their data processing terms before assuming any of them is lighter on privacy.
Add a dedicated entry that names ASAPP as the provider, lists the session and identifier values with their lifetimes, explains the interaction data collected and the machine learning applied, and discloses the United States transfer and its safeguard. Keep the entry in step with your consent categories.