FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Duda

Duda

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Duda do?

Duda is a website builder targeted at agencies and SaaS resellers. Provides a drag and drop editor, dynamic content, multi site management, an integrated CRM and a marketplace of widgets. Strictly necessary cookies; consent required for native analytics, visitor tracking and installed widgets.

What Duda is

Duda is a website builder designed for agencies, SaaS resellers and large publishers managing many sites. The product line covers the editor, the staging environment, the white label client preview, dynamic content for multilingual or location based pages, an integrated CRM that captures form leads, a widget builder, an email marketing module and a marketplace of third party widgets. Duda is the engine behind several SaaS website plans bundled with marketing automation tools.

Cookies set by Duda

Strictly necessary: DUDA_SESSION (session, editor and viewer session), dudamobile_token (1 year, mobile site detection), _dd_session (session, edit mode token), DUDA_AB_TEST (90 days, internal A/B test split). With Duda Visitor Tracking activated: duda_visitor (1 year, anonymous visitor identifier), duda_pageview (session, page view counter for native analytics). Third party widgets installed from the App Store add their own cookies (Google Analytics, Meta Pixel, Hotjar, Calendly, etc.).

GDPR, ePrivacy and form submissions

The strictly necessary cookies are exempt under ePrivacy art. 5(3) and rely on legitimate interest (GDPR art. 6(1)(f)). The Duda native analytics, the visitor tracking and the form submission flow that feeds the Duda CRM require consent under GDPR art. 6(1)(a). Email marketing campaigns sent through the Duda Email Marketing module need a separate consent under the ePrivacy direct marketing rules and the local opt out rules. The Duda widgets marketplace surfaces a privacy section but does not automatically gate widgets behind a CMP.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

EU edge and US storage

Duda delivers sites through CloudFront, with EU edge nodes that serve European visitors closer to their location. The site content, the CRM database, the analytics records and the customer billing are stored in the United States by default; EU storage is available on the higher plans contractually. The corporate platform, the customer support and the engineering team operate from the US, Israel and India. Duda is certified under the EU US Data Privacy Framework, with 2021 SCCs as fallback.

Compliance checklist for European agencies

Sign the Duda Data Processing Addendum, request the EU storage region on the higher plans, gate every visitor tracking, native analytics and widget behind a CMP via the Duda cookie banner widget or your own CMP, document the form submission flow with a clear consent text for the email marketing list, set the strictest retention for the Duda CRM and document the chain in your record of processing under GDPR art. 30.

GDPR consent category

Other

Websites using Duda must obtain user consent under GDPR regulations.

Legal basisStrictly necessary cookies (DUDA_SESSION, dudamobile_token, _dd_session): legitimate interest of the publisher and ePrivacy art. 5(3) exemption. For Duda native analytics, the visitor tracking module, the form submissions sent to Duda servers and any installed widget that loads tracking pixels: consent under GDPR art. 6(1)(a) and ePrivacy art. 5(3). The Duda CRM that stores visitor contact data relies on contract or legitimate interest depending on the flow.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CNIL guidance on website builders, EU US Data Privacy Framework, Israeli Protection of Privacy Law, AEPD ecommerce guidelines

DPIA considerations

A DPIA is recommended when the Duda native analytics, the visitor tracking module or the Duda CRM are activated, because they build a profile of website visitors and link it to email and phone identifiers when forms are submitted. The DPIA should document the EU edge delivery option, the US storage default, the retention of visitor profiles and CRM records, the integration with third party widgets and the legal basis for marketing emails sent via the Duda Email Marketing module.

Sample consent text

Our website is built with Duda. Strictly necessary cookies (DUDA_SESSION, dudamobile_token, _dd_session) keep the editor and the site working. With your consent we activate the Duda native analytics, the visitor tracking, the Duda CRM and any widget that loads tracking pixels. Site delivery is on CloudFront with an EU edge option, and the management layer runs in the United States under the EU US Data Privacy Framework. You can accept, refuse or withdraw at any time.

Technical details

Tracking methodhosted_website_builder_with_first_party_cookies_and_optional_analytics_marketing
Server locationDuda is operated by Duda Inc., a US company headquartered in Palo Alto, California. The Duda platform runs on Amazon Web Services with primary regions in the United States (us-east-1) and Europe (eu-west-1 Ireland). EU customer sites are served from CloudFront edge nodes worldwide, with content fetched from the US or EU storage region depending on the contract. The site builder and the editor run from the US infrastructure.
Data transferred outside the EUDuda Inc. is a US company. The Duda platform, the corporate analytics, the customer support and the engineering team operate from the United States with additional teams in Israel and India. Duda is certified under the EU US Data Privacy Framework. The 2021 Standard Contractual Clauses cover the transfers as a fallback. Customer sites can be configured to use a CloudFront EU edge but the management layer stays in the US.

Third-party domains contacted

duda.comultiscreensite.comcdn-website.comstatic.cdn-website.comlirp.cdn-website.comdudamobile.com

Cookies placed

NameTypeDurationPurpose
DUDA_SESSIONFirst party (Duda)SessionEditor and viewer session token used by the Duda platform
dudamobile_tokenFirst party (Duda)1 yearStores whether the visitor should be served the mobile or desktop version of the Duda site
_dd_sessionFirst party (Duda)SessionIdentifies the edit mode session in the Duda editor
DUDA_AB_TESTFirst party (Duda)90 daysUsed by the Duda A/B testing module to keep the visitor in the same variant
duda_visitorFirst party (Duda Visitor Tracking, optional)1 yearAnonymous visitor identifier used by the Visitor Tracking module when activated
duda_pageviewFirst party (Duda Visitor Tracking, optional)SessionPage view counter used by the native analytics module

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Duda set?

Strictly necessary: DUDA_SESSION (session), dudamobile_token (1 year, mobile detection), _dd_session (session, edit mode), DUDA_AB_TEST (90 days, A/B testing). With Visitor Tracking: duda_visitor (1 year, anonymous identifier), duda_pageview (session). Installed widgets add their own cookies (GA, Meta Pixel, Hotjar, Calendly).

Is consent required for Duda?

Strictly necessary cookies do not need consent. Consent is required for the Duda native analytics, the Visitor Tracking module, the email marketing list and every widget that loads tracking pixels. The Duda cookie banner widget can be used to gate them.

What is the legal basis for Duda?

Legitimate interest (GDPR art. 6(1)(f)) and the ePrivacy art. 5(3) exemption for the session cookies. Contract (art. 6(1)(b)) for form submissions you fulfil. Consent (art. 6(1)(a)) for analytics, visitor tracking, marketing automation and CRM follow up beyond the form.

Are data transferred to the United States?

Yes by default. Site content, CRM and analytics data are stored in US AWS regions. EU storage is available on higher plans. Duda is certified under the EU US Data Privacy Framework with SCCs 2021 as fallback.

Do I need a DPIA for Duda?

Recommended when Duda Visitor Tracking, native analytics or the CRM with email marketing is activated, because they build a profile of website visitors. The DPIA should describe storage region, retention, third party widgets and the email marketing legal basis.

How do I implement Duda compliantly?

Sign the DPA, request EU storage on higher plans, gate Visitor Tracking, native analytics and widgets behind a CMP, configure the Duda Cookie Banner Widget for the banner, document the email marketing consent in the form fields, set CRM retention to the minimum and document the chain in your record of processing.

What are the alternatives to Duda?

EU first website builders: Strikingly (EU plan), Webflow (US with EU edge), Squarespace (US), Wix (Israel with EU storage), Jimdo (Germany), 1&1 IONOS MyWebsite (Germany), Hostinger Website Builder (Lithuania), WordPress.com (US with global infrastructure), Sitebuilder.com. Jimdo and 1&1 IONOS are the most EU centric agency friendly builders.

How do I update my cookie policy after adding Duda?

List Duda as a sub processor, declare the strictly necessary cookies and the consent based cookies separately, mention the US storage default and the EU storage option, reference the Data Privacy Framework certification, link to the Duda Privacy Policy and provide a DSAR contact.