Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Smartsupp is a Czech live chat and AI chatbot platform founded in 2013 in Brno, used by more than 100,000 small and medium businesses across Europe. It provides a website chat widget, visitor recording, and AI shopping assistants for e commerce sites. All chat data is hosted in the EU. Tracking and chat cookies require user consent under the GDPR and the ePrivacy Directive.
Smartsupp is a Czech live chat and customer engagement platform founded in Brno in 2013. It combines a real time chat widget, video visitor recordings, AI shopping assistants (Mira), and Facebook Messenger integration in one product designed primarily for e commerce and small business websites.
The widget is loaded on a website with a small JavaScript snippet served from www.smartsuppchat.com. Once initialised, it places first party cookies, opens a websocket to Smartsupp servers in the Czech Republic, and (when enabled) starts recording visitor interactions on the page.
Smartsupp processes the visitor IP address, browser User Agent, current page URL, referrer, persistent visitor ID (cookie ssupp.vid), visit counters (ssupp.visits), approximate geolocation derived from IP (cookie ssupp.geoip), full chat message content, and any contact information voluntarily provided.
When session recording is enabled, Smartsupp additionally captures mouse movements, clicks, scrolling and form interactions, reconstructed as a replayable video. This is a high risk feature: unless sensitive fields are explicitly masked, payment details, passwords, health information, or other special category data may end up in the recording.
The main first party cookies are ssupp.vid (visitor identifier, 1 year), ssupp.visits (session counter, 1 year), ssupp.geoip (geolocation by IP, 1 year), ssupp.chatid (active chat identifier, session), and ssupp.utid (user tracking ID, 1 year). LocalStorage is also used to cache transcripts and configuration.
These cookies are not strictly necessary for the visitor to use the website itself, so they fall under Art. 5(3) ePrivacy and §25 TTDSG: prior informed consent is required before the script writes them.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Smartsupp s.r.o. acts as a processor under Art. 28 GDPR for chat content and visitor recordings. A signed Data Processing Agreement is mandatory and the relationship must appear in your Records of Processing Activities (Art. 30 GDPR). Smartsupp stores chat data in the European Union (Czech Republic) and explicitly markets EU data residency as a differentiator versus US competitors.
Smartsupp uses Cloudflare as CDN for static widget assets, which may transit through global edge nodes. This typically does not involve personal data processing of chat content but should be noted in the transfer impact assessment. AI assistant features rely on third party LLM backends and may introduce additional transfers that must be evaluated separately.
Because the widget script writes non essential cookies on load, the recommended pattern is to gate the smartsuppchat.com script behind a consent management platform: only inject the script after the visitor has accepted the Functional and Analytics categories. If video recording is enabled, present it as a separate analytics or marketing toggle.
Avoid the click to open pattern for Smartsupp specifically, since the visitor recording feature must be loaded with the page to be useful, and post click activation defeats the analytics purpose.
Sign the Smartsupp DPA. List Smartsupp s.r.o. in your RoPA as processor. Configure recording masking for all input fields and any element with sensitive data (CSS class data sensitive or data smartsupp ignore). Defer the script until consent. Document the legal basis for chat content (typically contract for support, legitimate interest for sales).
If you use Mira AI assistant, validate the location of the underlying LLM provider, document it as sub processor, and review whether your sector regulator (CNIL, BfDI, AEPD, Garante) treats it as high risk processing requiring a DPIA.
Websites using Smartsupp must obtain user consent under GDPR regulations.
DPIA considerations
Smartsupp combines a chat widget with session recording (video visitor recordings) and AI assistants. Key DPIA considerations: (1) the optional video recordings reproduce mouse movement, scrolling, clicks, and form input on the page, which can capture personal data and even special categories if forms collect such data; sensitive fields must be masked; (2) the ssupp.vid cookie is a persistent visitor identifier (typically 1 year) that enables long term cross session tracking and combined with the IP address constitutes personal data; (3) EU hosting in the Czech Republic reduces transfer risk, but Cloudflare CDN edge nodes may process metadata in third countries; (4) AI assistant features may process chat content through additional NLP backends, which must be assessed for sub processor location and Art. 22 GDPR concerns; (5) Smartsupp acts as processor under Art. 28 GDPR, a signed DPA is required.
Sample consent text
We use Smartsupp to provide live chat and visitor analytics on our website. When you accept, Smartsupp sets first party cookies to maintain your chat session, recognise returning visitors, and optionally record your interactions with the page (mouse movements, clicks, scrolling). Chat data is stored in the European Union. You can decline these cookies and still contact us via the regular contact form.
Third-party domains contacted
smartsupp.comwww.smartsuppchat.comwidget-files.smartsuppcdn.comapi.smartsupp.comrecordings.smartsupp.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ssupp.vid | Functional / Analytics | 1 year | Persistent visitor identifier. Used to recognise returning visitors and link new sessions to historical chat conversations and recordings. |
| ssupp.visits | Analytics | 1 year | Counts the number of visits and pages viewed by the same visitor across sessions. |
| ssupp.geoip | Functional | 1 year | Stores an approximate location derived from the visitor IP address. Used to route conversations to the right operator and apply localised greetings. |
| ssupp.chatid | Functional | Session | Identifier of the active chat conversation. Used to reconnect the visitor to the same chat thread across page reloads. |
| ssupp.utid | Analytics | 1 year | User tracking identifier used to link visitor recordings to the corresponding chat conversation. |
Smartsupp uses cookies for user preferences — inform visitors with a consent banner.
Smartsupp writes first party cookies on your domain: ssupp.vid (persistent visitor ID, 1 year), ssupp.visits (visit counter, 1 year), ssupp.geoip (approximate location, 1 year), ssupp.chatid (active chat session), and ssupp.utid (user tracking ID, 1 year). Several localStorage entries are also created to cache chat transcripts and widget configuration.
Yes. The cookies set by Smartsupp on page load are not strictly necessary, so Art. 5(3) ePrivacy and §25 TTDSG require prior informed consent. The script should be injected only after the visitor accepts the relevant cookie category (typically Functional or Analytics). If video recording is enabled, treat it as a separate consent purpose.
Chat content processing typically rests on contract performance (Art. 6(1)(b) GDPR) for customer support requests, or legitimate interest (Art. 6(1)(f) GDPR) for sales chat, supported by a documented balancing test. Visitor recording adds a separate processing operation that usually requires explicit consent because of the broad personal data captured.
No, chat data is stored in the European Union (Czech Republic). Smartsupp markets EU residency as a key differentiator. However, the widget assets are served through Cloudflare CDN, which uses global edge nodes; this is generally limited to static asset routing. AI assistant features (Mira) rely on LLM backends that may sit outside the EU and must be assessed separately.
A DPIA is generally required when video session recording is enabled because the EDPB lists "systematic monitoring" and "innovative use" of technology among the criteria for high risk processing (WP248 guidelines). For chat only deployments without recording, a full DPIA is not always mandatory but a risk assessment is good practice.
Sign the DPA with Smartsupp s.r.o. Register it as a processor in your RoPA. Configure recording masking for all sensitive fields (data-smartsupp-ignore or input masking rules). Defer the script behind your consent management platform. Document all sub processors. List the cookies in your cookie policy with name, lifetime, purpose and provenance.
EU based alternatives: Userlike (Germany), Crisp (France), LiveChat (Poland), Tidio (Poland), Chatwoot (open source). US based alternatives with EU hosting options: Intercom, HubSpot Chat, Zendesk Chat. Smartsupp main differentiator is the bundled visitor recording feature plus Mira AI assistant tailored for e commerce.
List each Smartsupp cookie with name (ssupp.vid, ssupp.visits, ssupp.geoip, ssupp.chatid, ssupp.utid), provider (Smartsupp s.r.o., Czech Republic), purpose, lifetime and category (Functional / Analytics). Disclose the visitor recording feature explicitly, including which fields are masked and how long recordings are retained. Provide a link to the Smartsupp privacy policy.