FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Customer Support
  4. Krible

Krible

PreferencesWebsite

Related services

11Sight

11Sight is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 11Sight supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 11Sight ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

42Chat

42Chat is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42Chat integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42Chat helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

8x8

8x8 is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 8x8 supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 8x8 ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
A

Acquire Live Chat

Acquire Live Chat is a live chat and customer messaging platform that enables businesses to engage with website visitors in real time. It provides instant messaging, chatbot automation, and team collaboration tools to deliver fast, personalized customer support. Acquire Live Chat supports multi-channel communication, conversation routing, and canned responses to improve response times. With built-in analytics and CRM integration, Acquire Live Chat helps convert visitors into customers.

Preferences

ActivEngage

ActivEngage is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. ActivEngage integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, ActivEngage helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

Ada

Ada is a web accessibility solution that helps websites comply with ADA, WCAG, and accessibility standards. It provides automated scanning, remediation tools, and compliance monitoring to ensure content is accessible to all users, including those with disabilities. Ada offers screen reader optimization, keyboard navigation support, and color contrast adjustment. With regular audits and reporting, Ada helps create inclusive digital experiences for everyone.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Krible do?

Krible is a Russian customer engagement platform offering web chat, callback button and co-browsing features for websites. Founded in 2008 and headquartered in Moscow, it helps businesses interact with visitors in real time. The widget sets functional and analytics cookies, and personal data is processed on Russian servers, which raises significant compliance questions under the GDPR and the ePrivacy Directive for European publishers.

What Krible is and how it works

Krible is a Russian customer engagement platform that has operated from Moscow since 2008. It provides website publishers with a JavaScript widget that combines live chat, a callback request button and co-browsing tools, allowing support agents to interact with visitors in real time and even share their browser view. The service is positioned as a competitor to other on-site engagement suites such as LiveChat or JivoChat, and is mainly used by Russian language e-commerce sites, banks and online services. When the widget is embedded, the visitor's browser establishes a connection to Krible servers and exchanges identifiers, page context and chat content with them.

Data and cookies collected

Krible sets functional cookies for the chat session, the visitor identifier and the callback dialogue state, plus analytics cookies that track returning visitors, the pages they viewed before opening the chat and the time spent on the site. Server side, Krible records IP addresses, user agent strings, approximate geolocation derived from IP, full chat transcripts, any contact details typed into the widget and timestamps for every interaction. Co-browsing additionally streams DOM snapshots of the page the visitor is on. All of this constitutes personal data under Article 4 GDPR.

GDPR and ePrivacy implications

Article 5(3) of the ePrivacy Directive, transposed into national law across the European Economic Area, requires prior consent before storing or reading cookies that are not strictly necessary for a service explicitly requested by the user. Krible's analytics and visitor tracking cookies fall outside the strictly necessary exemption, so they cannot be set before the visitor has clicked Accept on a compliant consent banner. The processing of chat content and IP addresses also requires a valid GDPR legal basis and a transparent privacy notice listing Krible as a recipient and Russia as the destination country.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to Russia

Russia has never benefited from a European Commission adequacy decision, and Russian Federal Law 152-FZ on Personal Data does not provide a level of protection equivalent to the GDPR. Russian authorities have broad access powers to data processed on national territory, including under the so called Yarovaya laws, which require operators to retain communications and provide them to security services on request. Following the Schrems II judgment, exporters relying on Standard Contractual Clauses must perform a transfer impact assessment and add supplementary measures. For Russia, most European supervisory authorities consider that no realistic combination of measures restores GDPR equivalent protection, leaving explicit consent under Article 49(1)(a) as the only practical derogation, with all its limitations.

Consent and DPIA

Deploying Krible on a European audience site without prior consent is non-compliant. The consent banner must reject non-essential cookies by default, list Krible separately, name Russia as the destination, and explain the elevated risk so that consent is genuinely informed. A Data Protection Impact Assessment under Article 35 GDPR is strongly recommended, since the combination of systematic visitor monitoring, third country transfer to a high risk jurisdiction and potential capture of sensitive content typed in chat ticks several DPIA criteria from the EDPB list.

Practical compliance steps and alternatives

For most European publishers the proportionate option is to replace Krible with a European or self hosted alternative such as Crisp, Chatwoot or LiveChat with EU hosting, which avoids the third country transfer entirely. If Krible must remain, gate the widget behind a granular consent banner, block the script until consent is given, document the legal basis in the record of processing activities, complete a transfer impact assessment, and update the cookie policy to disclose Krible, the categories of data collected and the transfer to Russia in plain language.

GDPR consent category

Preferences

Websites using Krible must obtain user consent under GDPR regulations.

Legal basisConsent (Article 6(1)(a) GDPR and Article 5(3) ePrivacy Directive). Storage of and access to non-essential cookies on the visitor terminal requires prior, freely given, specific, informed and unambiguous consent. The international transfer additionally requires Article 49 GDPR derogations or explicit consent.
Risk levelhigh
Applicable regulationsGDPR (EU 2016/679), ePrivacy Directive 2002/58/EC, EDPB Recommendations 01/2020 on supplementary measures, Russian Federal Law 152-FZ, national data protection authority guidelines on transfers to Russia.

DPIA considerations

A Data Protection Impact Assessment is strongly recommended before deploying Krible on a European website. Personal data, including IP addresses, behavioural data and chat content, is transferred to Russia, a third country without an adequacy decision and with documented surveillance and access powers that are not equivalent to those in the European Economic Area. The DPIA should address the systematic nature of monitoring, the categories of data collected (potentially including special categories shared in chat), the absence of supplementary technical measures such as end to end encryption, the realistic likelihood of public authority access, and whether the processing is strictly necessary or could be carried out with a European provider.

Sample consent text

We use Krible, a Russian live chat and callback service, to enable our visitor support widget. Krible sets cookies on your device and transfers your data, including your IP address, browsing activity on this site and any messages you send through the widget, to servers in Russia. Russia is not covered by a European adequacy decision and offers a lower level of data protection than the EU. By clicking Accept you give your explicit consent to this transfer under Article 49(1)(a) GDPR.

Technical details

Tracking methodJavaScript widget loaded from krible.com that sets first-party and third-party cookies for chat sessions, visitor identification, and callback functionality. Includes server-side logging of visitor interactions and IP addresses.
Server locationRussia (Moscow). Operated by Krible LLC with infrastructure hosted on Russian providers.
Data transferred outside the EUPersonal data is transferred to Russia, a country without a European Commission adequacy decision. Russian Federal Law No. 152-FZ on Personal Data applies, but it does not provide equivalent protection to GDPR. Following the Schrems II ruling and the geopolitical context, transfers to Russia carry elevated legal and operational risk.

Third-party domains contacted

krible.comcdn.krible.comapi.krible.com

Cookies placed

NameTypeDurationPurpose
krible_sessionfunctionalSessionIdentifies the current chat session and links incoming messages with the visitor and the support agent.
krible_visitoranalytics1 yearPersistent visitor identifier used to recognise returning users across pages and visits.
krible_statefunctional30 daysStores the open or minimised state of the chat widget and the callback dialogue.
krible_trackanalytics6 monthsRecords page visits, referrers and time on site for the visitor analytics dashboard.

Krible uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Krible set on my visitors browsers?

Krible typically sets a session cookie that identifies the chat conversation, a persistent visitor cookie that recognises returning users across visits, a state cookie that remembers whether the widget was open or minimised, and a tracking cookie used for visitor analytics such as pages viewed and time spent. The exact names can vary between releases, but only the chat session cookie is plausibly strictly necessary, and only when the visitor has actively opened the chat.

Is visitor consent required before loading Krible?

Yes. Because Krible loads a third party JavaScript widget that sets non-essential cookies and transmits IP addresses and browsing data to Russia, prior, freely given, specific, informed and unambiguous consent is required under Article 5(3) of the ePrivacy Directive and Article 6(1)(a) GDPR. The widget script must be blocked until the visitor has accepted, and a refusal must be just as easy as acceptance.

What is the appropriate legal basis for using Krible?

For cookie storage and access, the only valid legal basis is consent (Article 5(3) ePrivacy). For the underlying personal data processing (chat content, IP, behavioural data), consent under Article 6(1)(a) GDPR is the most defensible basis because legitimate interest is hard to balance against the surveillance risks linked to Russia. The international transfer further requires either explicit consent under Article 49(1)(a) or another Article 49 derogation.

Where does Krible store and process my visitors data?

Krible operates from Moscow and uses Russian infrastructure. Visitor IP addresses, chat content, callback requests and analytics data are transmitted to and stored on servers located in Russia. There is no European Commission adequacy decision for Russia, and Russian law grants security services broad access powers over data held on national territory, so any transfer must be assessed and documented as a third country transfer to a high risk jurisdiction.

Is a Data Protection Impact Assessment required for Krible?

A DPIA is strongly recommended and in most cases mandatory. The combination of systematic monitoring of website visitors, transfer of personal data to a third country without an adequacy decision and very high surveillance risk, and the potential capture of sensitive content typed in chat triggers several criteria from the EDPB DPIA guidelines. Documenting the assessment also helps demonstrate accountability under Article 5(2) GDPR.

How can I implement Krible in a compliant way?

Block the Krible script in your tag manager or CMP until explicit consent has been collected; list Krible as a separate vendor mentioning Russia as destination; configure a granular consent banner where reject is as visible as accept; complete a transfer impact assessment and a DPIA; sign a written data processing agreement covering Article 28 GDPR obligations; and update your privacy and cookie policies with the categories of data, retention periods and information about transfers.

What are good alternatives to Krible for European websites?

European or EU hosted live chat tools such as Crisp (France), Chatwoot (self hosted, France origin), LiveChat with EU servers, Userlike (Germany) and Tidio (Poland) avoid the third country transfer issue entirely. They typically offer comparable features (chat, callback, visitor analytics, sometimes co-browsing), simpler GDPR documentation and a standard EU data processing agreement.

How should I update my cookie policy to reflect the use of Krible?

Add a dedicated entry for Krible listing the cookies set, their purposes, lifetimes, the controller and the destination country. Explicitly state that data is transferred to Russia, that there is no adequacy decision and that consent is the legal basis. Provide a link to Krible's privacy policy, the date of the last review and an easy way to withdraw consent through the CMP. Re-prompt for consent after material changes.