Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Clym is a consent and privacy compliance platform (CMP) that provides cookie consent banners, a preference centre, DSAR handling, a policy hub and accessibility features. Clym's own cookies are the consent mechanism and are strictly necessary. The platform has Romanian and US presence and transfers data to the US under Standard Contractual Clauses.
Clym is a consent and privacy compliance platform (CMP) with operational presence in Romania and the United States. It helps organisations comply with GDPR, ePrivacy, CCPA/CPRA, LGPD and other data protection regulations by providing a cookie consent banner and preference centre, a Data Subject Access Request (DSAR) handling portal, a privacy policy hub, and an accessibility widget. Clym is deployed on operator websites via a JavaScript snippet loaded from cdn.clym.io. When a visitor arrives, Clym presents the consent banner, records the visitor''s choices, stores them in consent cookies and logs them in Clym''s compliance audit trail.
Clym sets consent-record cookies in the visitor''s browser to store their preference decisions (accepted, rejected, or customised categories). These cookies contain no personal profile data and no advertising identifiers; they record only the consent state and the timestamp of the decision. Clym also processes a minimal set of technical data server-side: the visitor''s IP address (typically truncated), the consent decision, the timestamp and the domain on which the decision was made. This data is stored in Clym''s consent audit log, which the operator can use to demonstrate compliant consent collection under Article 7(1) GDPR.
Clym is the consent tool itself, which places it in a unique position: the cookies it sets are the mechanism by which GDPR and ePrivacy compliance is implemented, not a further compliance risk. Under ePrivacy Directive Article 5(3), cookies that are strictly necessary for a service explicitly requested by the user are exempt from the consent requirement. Consent-record cookies set by a CMP are treated as strictly necessary because without them the website cannot honour the user''s privacy choices. The operator''s deployment of Clym is therefore not subject to a prior consent layer for Clym''s own cookies. Under the GDPR, the operator''s legal basis for using Clym is legitimate interest in fulfilling its legal compliance obligations.
Clym also supports CCPA/CPRA compliance for California residents (opt-out of sale/sharing mechanisms) and LGPD for Brazilian data subjects. Operators deploying Clym internationally benefit from a single platform managing consent signals across multiple regulatory frameworks.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A common question is whether a CMP itself requires consent before loading. The answer, consistently confirmed by EU DPA guidance and the IAB Europe TCF framework, is no: a CMP''s own operational cookies are strictly necessary and may fire before consent is collected. Clym''s cookies must be excluded from the consent-gated category and should be listed in the cookie notice as strictly necessary with the purpose described as consent management and legal compliance. This distinguishes Clym from analytics or advertising scripts that must await consent before loading.
Clym''s CDN and primary infrastructure are hosted in the United States. Data transfers from the EU and UK to Clym US infrastructure are governed by Standard Contractual Clauses. Romania, where Clym has an operational presence, is an EU member state and no transfer mechanism is required for Romania-based processing. Operators should ensure that their Data Processing Agreement with Clym references the SCCs as the transfer mechanism and confirm that Clym''s sub-processors also comply with equivalent transfer requirements.
To deploy Clym correctly: sign a Data Processing Agreement with Clym under Article 28 GDPR covering the consent log and DSAR data. List Clym''s consent cookies in your cookie notice under the strictly-necessary category with the purpose of consent management. Configure the Clym banner to meet GDPR consent standards (freely given, specific, informed, unambiguous indication by clear affirmative action; no pre-ticked boxes; reject-all option as prominent as accept-all). Verify that the consent audit log records the required proof elements for Article 7(1). Review Clym''s SCC documentation annually. If you operate a CCPA-regulated site, configure Clym''s opt-out of sale mechanism and update your California privacy notice accordingly.
Websites using Clym must obtain user consent under GDPR regulations.
DPIA considerations
A formal DPIA is unlikely to be required solely for the deployment of Clym as a consent management platform, given its low-risk profile and the fact that its cookies are strictly necessary for compliance purposes rather than for tracking. However, operators should document in their records of processing activities that Clym is deployed as a compliance tool and acts as a data processor under Article 28 GDPR. The primary compliance consideration is ensuring that Clym's US data transfer mechanism (Standard Contractual Clauses) is current and that Clym's consent records infrastructure satisfies the evidential requirements of Article 7(1) GDPR (demonstrable proof of consent). Operators in highly regulated sectors may include Clym in a broader privacy infrastructure review.
Sample consent text
This website uses Clym, a consent management platform, to present you with cookie and privacy preference choices and to record your decisions in accordance with applicable data protection laws including the GDPR and ePrivacy Directive. The cookies set by Clym to record your consent preferences are strictly necessary for this legal compliance function and do not require your separate consent. Clym processes a minimal set of technical data (your consent choices, IP address and timestamp) on our behalf as a data processor. Data is transferred to Clym's infrastructure in the United States under Standard Contractual Clauses. You can update your preferences at any time by clicking the [Privacy Settings] link in the website footer.
Third-party domains contacted
clym.iocdn.clym.ioapp.clym.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| clym_consent | Strictly Necessary | 1 year | Records the visitor's consent decisions (accepted, rejected, or custom category choices) made via the Clym consent banner. Required for the website to honour privacy preferences and demonstrate consent under Article 7(1) GDPR. |
| clym_session | Strictly Necessary | Session | Session cookie used by the Clym DSAR portal and preference centre to maintain the user's authenticated session while interacting with the privacy management interface. |
| clym_version | Strictly Necessary | 1 year | Stores the version identifier of the consent notice displayed to the visitor. Used to determine whether the consent notice has been updated and whether a new consent decision is required from returning visitors. |
| clym_uid | Strictly Necessary | 1 year | A pseudonymous identifier assigned to the consent session, used to link consent decisions stored in the Clym audit log with the corresponding browser session for compliance reporting purposes. |
Clym is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Clym sets consent-preference cookies that record your visitors' consent decisions (accepted, rejected, or customised). These cookies contain no advertising identifiers or personal profile data; they store only the consent state and decision timestamp. Clym also sets a session cookie for the DSAR portal if that feature is enabled. All Clym cookies are classified as strictly necessary.
No. Clym is the consent management mechanism and its own operational cookies are strictly necessary under ePrivacy Directive Article 5(3). A CMP may fire before consent is obtained because without it the website cannot present consent choices or record them. Clym cookies should be listed in your cookie notice as strictly necessary with the purpose described as consent management.
The operator's legal basis for deploying Clym is legitimate interest under Article 6(1)(f) GDPR: the organisation has a legitimate interest in fulfilling its legal obligation to obtain and record valid consent, and deploying a CMP is the proportionate means of doing so. No separate consent is required for Clym's own strictly-necessary processing.
Yes. Clym's infrastructure is hosted in the United States, so consent log data (including truncated IP addresses and consent decisions) is transferred from the EU to the US. This transfer is covered by Standard Contractual Clauses. Romania, where Clym has an operational presence, is an EU member state and no transfer mechanism is required for processing there. Verify the SCC documentation in your Data Processing Agreement with Clym.
A DPIA is unlikely to be required solely for Clym due to its low-risk profile: it processes minimal data (consent decisions and truncated IPs) for a compliance purpose rather than for profiling or tracking. However, if your overall consent and privacy infrastructure processes sensitive data at scale, a broader privacy infrastructure DPIA may be appropriate and should include Clym as one component.
Configure the Clym banner so that: (1) consent is freely given (no pre-ticked boxes, no consent walls), (2) reject-all is as prominent as accept-all, (3) the consent request is granular by purpose category, (4) withdrawal of consent is as easy as giving it, (5) the consent audit log captures the required proof elements for Article 7(1) GDPR. Sign a Data Processing Agreement with Clym and list its cookies in your cookie notice under the strictly-necessary category.
Alternatives include Cookiebot (by Usercentrics), OneTrust, TrustArc, Axeptio and Didomi. Some are EU-hosted (Axeptio, Didomi are France-based) which avoids US transfer concerns. The choice depends on features (DSAR handling, accessibility, multi-regulation support), pricing, hosting location preferences and IAB TCF certification requirements for programmatic advertising.
Clym scans your website for cookies and can generate updated cookie disclosures automatically. Review the Clym-generated cookie list at least every six months or whenever you add new third-party scripts to your site. Ensure that any new cookies detected by Clym are categorised correctly before they are added to your live cookie notice. Keep a version history of your cookie policy with dates of each update.