FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Customer Support
  4. Combodo iTop

Combodo iTop

PreferencesWebsite

Related services

11Sight

11Sight is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 11Sight supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 11Sight ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

42Chat

42Chat is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42Chat integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42Chat helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

8x8

8x8 is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 8x8 supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 8x8 ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
A

Acquire Live Chat

Acquire Live Chat is a live chat and customer messaging platform that enables businesses to engage with website visitors in real time. It provides instant messaging, chatbot automation, and team collaboration tools to deliver fast, personalized customer support. Acquire Live Chat supports multi-channel communication, conversation routing, and canned responses to improve response times. With built-in analytics and CRM integration, Acquire Live Chat helps convert visitors into customers.

Preferences

ActivEngage

ActivEngage is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. ActivEngage integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, ActivEngage helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

Ada

Ada is a web accessibility solution that helps websites comply with ADA, WCAG, and accessibility standards. It provides automated scanning, remediation tools, and compliance monitoring to ensure content is accessible to all users, including those with disabilities. Ada offers screen reader optimization, keyboard navigation support, and color contrast adjustment. With regular audits and reporting, Ada helps create inclusive digital experiences for everyone.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Combodo iTop do?

Combodo iTop is an open source ITSM and CMDB platform for IT service desks, asset management and ITIL processes, self hosted or available as the EU based iTop Hub SaaS.

What Combodo iTop is and what it does

Combodo iTop is an open source IT Service Management and Configuration Management Database platform developed by Combodo SAS in Grenoble, France. It implements ITIL aligned processes such as incident, problem, change, service request, configuration and SLA management on top of a PHP and MySQL stack. The software is licensed under AGPL and is typically deployed on the customer's own infrastructure as an internal backoffice application used by IT staff. Combodo also offers iTop Hub, a SaaS variant hosted in the European Union, alongside consulting and support services.

Data and cookies set by Combodo iTop

iTop processes data that IT operations generate, including user accounts of IT staff and end users with tickets, incident and change records, configuration items in the CMDB, asset inventories, contracts and SLA metrics. From a web technology perspective the application only sets first party functional cookies, typically itop-cookie, PHPSESSID for the session, itop-user-prefs for user interface preferences and itop-token for CSRF protection. These cookies are server set, scoped to the iTop hostname and used solely to authenticate staff and maintain a working session. No advertising, profiling or cross site tracking technologies are loaded by default.

GDPR and ePrivacy implications

Under the GDPR the organisation operating iTop is the controller for the personal data stored in tickets, asset and user records, while Combodo acts as processor only for the iTop Hub SaaS variant. ePrivacy obligations are limited because iTop is not a public website tracker and its cookies are strictly necessary to authenticate staff and protect against CSRF, which falls under the Article 5(3) exception of the ePrivacy Directive. The main GDPR work consists of documenting records of processing, defining retention periods for incidents and audit logs, securing access and ensuring data subject rights for staff and end users referenced in tickets.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements and legal basis

No cookie banner consent is required for the functional session cookies used by iTop because they are strictly necessary to deliver the requested service to authenticated users. The lawful basis for processing through iTop is normally a combination of legitimate interest under Article 6(1)(f) for IT operations and information security, contract performance under Article 6(1)(b) where the data subject is an employee or customer of the operator, and national employment law. Where iTop captures employee performance data through ticket metrics, employers must observe local employment law and any works council consultation obligations.

Cross border transfers and practical compliance steps

When iTop is self hosted on the customer's own EU infrastructure there are no third country transfers, and the iTop Hub SaaS option is hosted on French and EU providers such as OVH and Scaleway by default, so transfers outside the EEA are not part of the standard configuration. Practical compliance steps include restricting administrator access, enabling LDAP or SSO with multi factor authentication, configuring retention rules to archive or purge closed tickets, recording iTop in the records of processing, signing an Article 28 contract with Combodo when using iTop Hub, and updating the internal privacy notice for IT staff.

GDPR consent category

Preferences

Websites using Combodo iTop must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) for IT operations and security, contract performance (Art. 6(1)(b)) with the employer for staff use, and applicable national employment law for processing employee data through the ITSM tool.
Risk levellow
Applicable regulationsGDPR (the operating organisation is controller), ePrivacy Directive (mostly inapplicable since cookies are strictly necessary for staff authentication), French and EU employment law for IT staff use

DPIA considerations

A DPIA is generally not required just because iTop is deployed, since it is an internal backoffice ITSM tool used by IT staff under the controller's authority. A DPIA may still be appropriate when iTop stores special category data, very large volumes of incident or HR linked records, or when it is integrated with monitoring tools that produce systematic evaluation of employees. Document the records of processing, restrict admin access, log changes and review retention of incident and asset data.

Sample consent text

No cookie banner consent is required for the strictly necessary session cookies set by Combodo iTop. Inform IT staff in an internal privacy notice that iTop is used to manage incidents, changes, assets and user accounts, and explain the legal basis (legitimate interest and contract performance with the employer), the retention periods and their rights as data subjects.

Technical details

Tracking methodServer side PHP application with admin/agent login, minimal front end JavaScript and first party functional session cookies for authentication
Server locationCustomer choice when self hosted, EU (France) by default on the Combodo iTop Hub SaaS variant

Third-party domains contacted

combodo.comcombodo.fritophub.iocommunity.combodo.comsupport.combodo.comwiki.openitop.orgstore.itophub.io

Cookies placed

NameTypeDurationPurpose
PHPSESSIDfunctionalsessionStandard PHP session identifier issued by the iTop server to keep the authenticated user logged in during a working session. Strictly necessary.
itop-cookiefunctionalsessionApplication session cookie set by iTop to maintain login state and user context between page loads. Strictly necessary, first party.
itop-user-prefsfunctional1 yearStores per user interface preferences such as language, list filters and pagination so the agent finds the same configuration on next login.
itop-tokenfunctionalsessionAnti CSRF token used by iTop to protect form submissions and API calls from cross site request forgery. Strictly necessary security cookie.
XSRF-TOKENfunctionalsessionAdditional CSRF protection token that some iTop installations or reverse proxies set. Exact name depends on configuration. Strictly necessary.
itop-remember-mefunctional30 daysOptional persistent authentication cookie issued when the user ticks the remember me option at login, so the session can be resumed without retyping credentials.

Combodo iTop uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies or identifiers does Combodo iTop set?

iTop sets only first party functional cookies on the application hostname: itop-cookie, PHPSESSID for the session, itop-user-prefs for interface preferences and itop-token for CSRF protection. There are no advertising or analytics identifiers by default.

Is consent required before loading Combodo iTop?

No cookie banner consent is needed. The session and CSRF cookies are strictly necessary to authenticate IT staff, so they fall under the Article 5(3) ePrivacy exception. Inform users via the internal privacy notice instead.

What is the legal basis for processing with Combodo iTop?

The operating organisation typically relies on legitimate interest under Article 6(1)(f) for IT operations and security, contract performance under Article 6(1)(b) for staff and customers, and applicable employment law when iTop processes employee data.

Does Combodo iTop transfer data outside the EU?

No when the software is self hosted on EU infrastructure. The iTop Hub SaaS variant is hosted in France and the EU by default (OVH, Scaleway), so transfers outside the EEA are not part of the standard configuration.

Do I need a DPIA before deploying Combodo iTop?

Generally no, because iTop is an internal backoffice tool used by IT staff under the controller's authority. A DPIA may still be appropriate where iTop stores special category data, very large ticket volumes or feeds systematic employee evaluation.

How do I implement Combodo iTop compliantly?

Host iTop on EU infrastructure or use iTop Hub, enable SSO or LDAP with multi factor authentication, restrict admin roles, configure retention to archive or purge closed tickets, record iTop in your processing register and sign an Article 28 contract for the SaaS variant.

Are there alternatives to Combodo iTop?

Yes. Open source alternatives include GLPI (French), Zammad (German), OTRS and OsTicket. Commercial SaaS options include Jira Service Management, ServiceNow and Freshservice. Pick based on hosting region, ITIL coverage and CMDB depth.

How do I update my cookie policy for Combodo iTop?

You usually do not need to mention iTop in a public cookie policy because it is a backoffice tool with strictly necessary cookies. Instead document iTop in the internal staff privacy notice and the records of processing, listing the data categories, retention periods and lawful basis.