Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Centribal is a Spanish AI chatbot and conversational platform headquartered in Madrid, used by enterprises in banking, retail and utilities to automate customer conversations across web, WhatsApp, Facebook Messenger and voice. The Centribal Cloud widget loads via a JavaScript snippet, sets first party cookies and routes conversations through Centribal infrastructure on AWS Europe, with optional integrations to large language model providers in the United States.
Centribal is a Spanish conversational AI vendor that markets a unified chatbot, voicebot and live agent platform. The product is widely deployed by Iberian banks, telcos, utilities and retailers to automate FAQ deflection, lead qualification and self service flows across the web, WhatsApp, Facebook Messenger and voice. Centribal operates from Madrid and runs its services primarily on AWS European regions, while offering optional connectors to external large language models for advanced natural language tasks.
On load, the Centribal widget sets first party cookies (typically centribal_session, centribal_visitor) used to maintain conversation continuity. It collects IP address, user agent, locale, page URL, complete conversation transcript, intent classification scores, entity extraction outputs and any data the user enters (name, email, phone, account number when shared). When CRM integration is active, customer identifiers are added to the conversation record.
Because the Centribal widget writes non strictly necessary cookies, Article 5(3) of the ePrivacy Directive requires prior consent unless the chat is loaded only after user action. For conversational AI specifically, the EU AI Act adds obligations: chatbots must clearly disclose that the user is interacting with an AI, sensitive decisions (credit scoring, eligibility) trigger high risk obligations, and certain prohibited uses (manipulative dark patterns, subliminal techniques) are banned outright. Spain''s LOPDGDD adds national specifications on top of the GDPR baseline.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
In practice, gate the Centribal widget behind your consent management platform (Functional or Marketing category depending on configuration), display an AI Act compliant disclosure (such as You are chatting with an automated assistant) in the first bot message, and offer the user a clear way to switch to a human agent. If you use the chat for marketing (proactive nudges, lead capture), the legal basis is consent; for reactive support, legitimate interest can apply with a documented balancing test.
Centribal hosts its core platform in AWS European regions. The main transfer risk arises when you enable optional LLM integrations (OpenAI, Anthropic or Google AI), which route prompts and responses to providers in the United States. These transfers rely on Standard Contractual Clauses and, where applicable, the EU, US Data Privacy Framework. You should pseudonymise or redact personal data before sending it to the LLM, log all transfers and disclose the AI sub-processor list in your privacy notice.
Sign the Centribal Data Processing Agreement, gate the widget behind consent, display AI disclosure, list all sub-processors including LLM providers, configure short retention for transcripts, prohibit training on customer data unless an extra consent layer is added, set up a fallback to a human agent for sensitive intents, monitor model outputs for hallucinations or unsafe advice, and run a DPIA for any deployment that automates eligibility or pricing decisions.
Websites using Centribal must obtain user consent under GDPR regulations.
DPIA considerations
Centribal processes visitor IP address, user agent, conversation transcripts, intent classification metadata, entity extraction results and (when integrated with CRM) customer identifiers. Key DPIA considerations: (1) conversational AI can capture special categories of data shared spontaneously and falls within EU AI Act scope when used for high risk contexts (eligibility decisions, employment, insurance); (2) some intents trigger calls to third party large language model providers in the US, raising both transfer and processor chain concerns; (3) chat transcripts may be used to train custom models, requiring an additional consent layer; (4) automated decisions on customer cases may fall under Art. 22 GDPR; (5) persistent visitor identifiers allow long term profiling. A DPIA is recommended for any deployment that touches eligibility or high stakes decisions.
Sample consent text
We use Centribal to operate our chatbot. When the chat opens, Centribal places cookies on your device, processes your messages on EU based servers and may send anonymised intent fragments to AI providers in the United States. You can withdraw your consent at any time via our cookie settings.
Third-party domains contacted
centribal.comcdn.centribal.comapi.centribal.comwebchat.centribal.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| centribal_session | Functional | Session | Session identifier used to maintain the chat conversation continuity within a single browsing session. |
| centribal_visitor | Functional | 1 year | Persistent visitor identifier used to recognise returning users and resume previous conversations across sessions. |
| centribal_locale | Preference | 6 months | Stores the visitor's language preference for the chat interface and bot responses. |
Centribal uses cookies for user preferences — inform visitors with a consent banner.
Centribal sets first party cookies on the publisher domain (typically centribal_session, centribal_visitor and a locale preference cookie). These cookies are used to maintain the conversation across page navigation and to recognise returning visitors.
Yes. The widget writes non strictly necessary cookies, so Article 5(3) of the ePrivacy Directive requires prior consent. Additionally, the EU AI Act requires clear disclosure that the user is interacting with an AI, which should appear in the first bot message regardless of cookie consent.
For tracking cookies and marketing chat flows, consent (Art. 6(1)(a) GDPR). For reactive support, legitimate interest (Art. 6(1)(f)) is possible with a balancing test. For automated decisions affecting users, Art. 22 GDPR additional safeguards apply.
By default, Centribal hosts data on AWS European regions. US transfers only occur if you enable LLM integrations (OpenAI, Anthropic, Google AI) where prompts may be routed to providers in the United States under SCCs and the EU, US Data Privacy Framework. The connection itself is optional and should be reviewed before activation.
Yes for any high risk use under the EU AI Act (eligibility decisions, employment screening, credit scoring), and recommended whenever the chatbot handles sensitive customer data, integrates external LLMs or automates decisions. For low risk FAQ deflection, a documented assessment is usually sufficient.
Sign the Centribal DPA, gate the widget behind consent, display an AI disclosure in the first bot message, list all sub-processors including LLM providers, configure short retention for transcripts, restrict training on customer data, set up human escalation for sensitive intents, and document a DPIA for high risk use cases.
EU based alternatives include Inbenta (Spain), iAdvize (France), Voiceflow (with EU residency), Iadvize, Ada (Canada with EU options) and Rasa (open source, self hosted). Self hosted open source is the strongest option for sensitive deployments where no third party processing is acceptable.
List Centribal by name, the cookies set, the data collected (IP, user agent, transcript, intents), the controller and processor relationship with Centribal, the AWS European region used, the retention period, the LLM sub-processors and their locations (if any), and a link to the Centribal privacy notice and AI transparency statement.