Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Adoric is an on site marketing platform that displays popups, personalises website content and sends web push notifications to convert visitors. It loads a first party JavaScript snippet that sets cookies and browser storage to control how often messages appear and to tailor offers to visitor behaviour. Because it profiles visitors and can power targeted messaging, its use generally requires prior consent under European law.
Adoric is an on site marketing and conversion platform that lets websites display popups, slide ins, bars and personalised content blocks to their visitors. It also supports web push notifications and product recommendations driven by visitor behaviour. Website owners add a small first party JavaScript snippet to their pages, after which Adoric can show campaigns, capture email addresses and adapt messaging based on how each visitor interacts with the site. The company behind it, Adoric Technologies LTD, is based in Tel Aviv, Israel. Because the tool observes visitor behaviour and tailors what people see, it processes personal data on behalf of the website that deploys it.
Adoric sets first party cookies and uses browser localStorage to remember whether a visitor has already seen or closed a campaign so the same message is not repeated unnecessarily. These identifiers also support frequency capping, A B testing and behavioural personalisation, and they can persist from a single session up to around a year depending on configuration. When a visitor submits a form, Adoric processes the data entered, such as an email address, alongside technical signals like IP address, device and browser details and on site activity. If web push is enabled, a push subscription token is also stored. Taken together these data points allow Adoric to recognise returning visitors and build a behavioural picture used for targeting.
Under the ePrivacy Directive, storing or reading information on a visitor device requires consent unless it is strictly necessary to deliver a service the visitor explicitly requested. The cookies and storage Adoric uses for personalisation, targeting and web push go beyond what is strictly necessary, so they fall within the consent requirement. Under the GDPR the resulting profiling of visitor behaviour is processing of personal data that needs a valid lawful basis and transparent information. The website operator is the controller and is responsible for informing visitors and collecting consent before Adoric scripts load non essential cookies. Adoric acts as a processor for that data and offers a data processing agreement to formalise the relationship.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Marketing popups, behavioural personalisation, audience targeting and web push all rely on consent under Article 6(1)(a) of the GDPR. The practical way to honour this is to integrate Adoric with a consent management platform so that its non essential scripts are blocked until the visitor accepts the relevant category, usually marketing or personalisation. Consent should be freely given, specific and revocable, and the same banner should allow visitors to decline without being penalised. Basic display frequency capping might be argued under legitimate interest in narrow cases, but any reliance on Article 6(1)(f) should be backed by a documented balancing test. Records of consent should be retained so the operator can demonstrate compliance.
Adoric is an Israeli company, so visitor data may be processed outside the European Economic Area. Israel benefits from a European Commission adequacy decision, which means transfers of personal data to Israel are permitted without additional safeguards. Where Adoric relies on cloud infrastructure or sub processors located in other countries, those onward transfers should be covered by Standard Contractual Clauses or another recognised mechanism. Operators should review Adoric data processing agreement and its list of sub processors to confirm where data is hosted. Documenting the transfer position in the record of processing activities helps demonstrate accountability.
Start by signing Adoric data processing agreement and adding it to your record of processing activities and your list of sub processors. Configure your consent management platform so Adoric non essential cookies and scripts only fire after the visitor accepts marketing or personalisation. Disclose the cookies, their purposes and durations in your cookie policy and explain the personalisation and web push features in plain language. Provide an easy way for visitors to withdraw consent and to exercise access and deletion rights, and confirm Adoric can action deletion requests. Finally, review settings periodically so retention periods and active campaigns stay aligned with what visitors were told.
Websites using Adoric must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is recommended when Adoric is used for behavioural personalisation, audience targeting or web push at scale, because these activities involve systematic monitoring of visitor behaviour. Document the categories of data collected, the cookies and storage used, retention periods and the consent mechanism. Assess the international transfer position given that Adoric is an Israeli company, and record the lawful basis relied on for each processing purpose.
Sample consent text
We use Adoric to show you relevant offers, personalise content and, with your agreement, send web push notifications. This sets cookies and stores data in your browser to manage how often you see messages. Do you consent to these marketing and personalisation cookies?
Third-party domains contacted
adoric.comcdn.adoric.comapi.adoric.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| adoric_uid | first party | up to 1 year | Stores a visitor identifier used to recognise returning visitors, apply display frequency capping and support behavioural personalisation. |
| adoric_session | first party | session | Maintains the current browsing session so campaign state and interactions are tracked consistently during a visit. |
| adoric_popup_seen | first party | up to 1 year | Records which popups or campaigns a visitor has already seen or closed so the same message is not shown repeatedly. |
Adoric uses cookies for user preferences — inform visitors with a consent banner.
Adoric sets first party cookies and uses browser localStorage to remember whether a visitor has already seen or closed a campaign so the same popup is not shown repeatedly. These identifiers also support frequency capping, A B testing and behavioural personalisation, lasting from a session up to around a year. If web push is enabled, a subscription token is stored as well.
Yes, for most uses. Because Adoric sets non essential cookies and profiles visitor behaviour for personalisation, targeting and web push, prior consent is required under the ePrivacy Directive and the GDPR. Only very limited functions, such as basic frequency capping, might be argued under another basis, and even that should be documented.
The main legal basis is consent under Article 6(1)(a) of the GDPR for marketing popups, personalisation, audience targeting and web push. Legitimate interest under Article 6(1)(f) may be considered for basic display frequency capping, but only with a documented balancing test. The website operator acts as controller and decides the basis for each purpose.
Adoric is an Israeli company, so visitor data may be processed in Israel, which benefits from an EU adequacy decision that allows transfers without extra safeguards. If Adoric uses cloud infrastructure or sub processors in other countries, those onward transfers should be covered by Standard Contractual Clauses. Review the data processing agreement and sub processor list to confirm where data is hosted.
A data protection impact assessment is recommended when Adoric is used for behavioural personalisation, audience targeting or web push at scale, because these involve systematic monitoring of visitor behaviour. The assessment should document the data collected, the cookies used, retention periods, the consent mechanism and the transfer position. For light, occasional use a full DPIA may not be necessary but the reasoning should still be recorded.
Sign the Adoric data processing agreement, add it to your record of processing and integrate it with a consent management platform so non essential scripts only load after consent. Disclose the cookies and their purposes in your cookie policy and explain personalisation and web push clearly. Provide an easy way to withdraw consent and to action access and deletion requests.
Comparable on site marketing and popup tools include Poptin, Justuno, GetSiteControl, OptinMonster and Sleeknow. Each sets cookies and may profile visitors, so the same consent and transparency obligations apply. The right choice depends on features needed, hosting region and the strength of the provider data processing terms.
List the Adoric cookies and localStorage items along with their purposes and durations, and group them under marketing or personalisation rather than strictly necessary. Mention that Adoric is the provider, note the international transfer position and link to its privacy information. Keep the policy in sync with your consent banner categories and review it whenever you change Adoric features.