Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
US based low code platform whose embedded DataPages set cookies and collect form data, often sensitive, with hosting mainly in the United States.
Caspio is a United States based low code platform that lets organisations build online databases and applications without writing much code. The core building blocks are DataPages, embeddable components that display data and capture form submissions, and Flex apps that bundle these features into full applications. Site owners typically embed Caspio DataPages into their own websites, where they collect and display information from end users. Because forms frequently gather contact details, account data and sometimes sensitive information, Caspio sits squarely within the scope of data protection law whenever it is used with European visitors.
Caspio sets cookies that keep authenticated sessions secure and that support the operation of DataPages. Authenticated DataPages and externally deployed Flex apps require third party cookies, so logins and filtered views can break when cross site tracking prevention blocks them. Beyond cookies, the most significant processing happens through the form data that visitors submit, which can include names, email addresses, identifiers and, depending on the application, special category data. The combination of session cookies and rich form submissions means Caspio often processes substantial volumes of personal data on behalf of the site owner.
Under Art. 5(3) of the ePrivacy Directive, storing or reading any cookie that is not strictly necessary requires prior consent. Session and security cookies tied to a login the user actively requested can often be treated as essential, but any analytics or convenience cookies need consent. Processing of the personal data inside form submissions must rest on a valid legal basis under Art. 6(1) GDPR, and the site owner remains the controller responsible for transparency and data subject rights. Caspio normally acts as a processor, so a data processing agreement under Art. 28 GDPR is required.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent must be obtained before any non essential cookie is set, which means the consent banner should block such cookies until the visitor has actively agreed. Where form data is collected for purposes that go beyond performing a contract, for example marketing follow up, consent for that processing should also be captured clearly and separately. The request must be specific, informed and as easy to withdraw as it is to give. Pre ticked boxes and implied consent do not meet the GDPR standard.
On the standard editions, data submitted through Caspio is processed in AWS datacenters in the United States, which is a third country under the GDPR. Caspio relies on the EU to US Data Privacy Framework and on Standard Contractual Clauses for these transfers, and a transfer impact assessment should confirm that the safeguards are adequate. Organisations that want to avoid a third country transfer entirely can use the EU Compliance Edition, which keeps data in AWS datacenters in Ireland and Germany. Choosing the EU edition is the cleanest way to keep European personal data within the EEA.
Start by mapping every DataPage, the data it collects and the cookies it sets, then sign a data processing agreement with Caspio. Configure a consent banner that blocks non essential cookies until consent is given and document the legal basis for each form. Evaluate whether the EU Compliance Edition is appropriate to remove the US transfer, and if you keep the standard edition record the Data Privacy Framework and Standard Contractual Clauses in your transfer documentation. Finally, update your privacy notice and cookie policy to name Caspio, describe the data flows and explain how visitors can exercise their rights.
Websites using Caspio must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended when Caspio DataPages collect sensitive or special category data, when forms gather data on a large scale, or when default US hosting leads to transfers outside the EEA. The assessment should document the categories of data collected through forms, the cookies set, the legal basis, the transfer mechanism and the residual risk after safeguards. Using the EU Compliance Edition materially lowers the transfer risk and should be considered as a mitigation.
Sample consent text
We use Caspio to power forms and interactive applications on this site. Caspio sets cookies needed to keep your session secure and may process the information you submit on servers located in the United States. By selecting Accept you consent to these cookies and to this transfer of your data.
Third-party domains contacted
caspio.comcaspio.appbridge.caspio.comc1.caspio.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| cbAppSession | third party | session | Maintains the authenticated user session for DataPages and apps, expiring when the browser session ends |
| cb_token | third party | session | Carries the authentication token that secures access to authenticated DataPages and Flex apps |
| ASP.NET_SessionId | third party | session | Standard server session identifier used by the Caspio platform to keep state during a visit |
| csrf_token | first party | session | Protects forms and DataPage submissions against cross site request forgery |
Caspio collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Caspio sets cookies that keep authenticated user sessions secure and that support the operation of embedded DataPages. Authenticated DataPages and externally deployed Flex apps rely on third party cookies, which is why logins and filtered views can fail when cross site tracking prevention blocks them. Flex apps hosted on the caspio.app domain are designed not to require third party cookies.
Yes, for any cookie that is not strictly necessary. Session and security cookies tied to a login the user actively requested can often be treated as essential, but analytics or convenience cookies require prior consent under Art. 5(3) ePrivacy. Where form data is used for purposes beyond a contract, such as marketing, consent for that processing is also needed.
Setting non essential cookies relies on consent under Art. 6(1)(a) GDPR together with Art. 5(3) ePrivacy. Processing the personal data in form submissions usually rests on consent under Art. 6(1)(a) or on the performance of a contract under Art. 6(1)(b), depending on the purpose. The site owner is the controller and Caspio is normally the processor under an Art. 28 data processing agreement.
On the standard editions, yes. Data submitted through Caspio is processed in AWS datacenters in the United States, a third country under the GDPR. Caspio relies on the EU to US Data Privacy Framework and Standard Contractual Clauses, and the EU Compliance Edition keeps data in Ireland and Germany to avoid the transfer entirely.
A data protection impact assessment is strongly advised when DataPages collect sensitive or special category data, when forms gather data at scale, or when default US hosting creates a transfer outside the EEA. The assessment should record the data collected, the cookies set, the legal basis, the transfer mechanism and the residual risk. Using the EU Compliance Edition is a meaningful mitigation that lowers the assessed risk.
Map every DataPage and the data it handles, sign a data processing agreement with Caspio, and configure a consent banner that blocks non essential cookies until consent is given. Decide whether the EU Compliance Edition is appropriate to remove the US transfer, and document your transfer mechanism if you keep the standard edition. Then update your privacy notice and cookie policy to reflect these flows.
Alternatives include other low code and database platforms such as Knack, Zoho Creator and Microsoft Power Apps, as well as EU hosted form and database tools for stricter data residency. The right choice depends on whether you need US features or strict EEA hosting. For Caspio itself, the EU Compliance Edition is the privacy friendlier option within the same product.
List the Caspio cookies, naming the session and security cookies and noting that authenticated DataPages use third party cookies, and explain their purpose and duration. State that form data may be processed in the United States under the Data Privacy Framework and Standard Contractual Clauses, unless you use the EU Compliance Edition. Keep the policy aligned with what your consent banner actually blocks and allows.