Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
iPresta is an Iranian provider of PrestaShop modules, hosting, and store services. Its components set functional cookies for the storefront and can add analytics, and because it is operated from Iran it raises significant international data transfer concerns under the GDPR.
iPresta is an Iranian company that provides modules, hosting, and services for PrestaShop based online stores. Its modules add features to the storefront and checkout, and depending on the module they can process customer and order data and load scripts from iPresta infrastructure.
iPresta modules set functional cookies that keep the storefront and cart working, and some can add analytics or marketing cookies. They may process customer details entered during a purchase along with browsing data, all of which can be personal data under the GDPR.
Functional store cookies can be exempt under Article 5(3) ePrivacy, while analytics and marketing cookies require consent. The central concern is that iPresta is operated from Iran, a country with no EU adequacy decision and an elevated risk profile, so any personal data sent there is a third country transfer needing Standard Contractual Clauses and a careful transfer impact assessment.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Block analytics and marketing cookies until the visitor consents, and load only the strictly necessary store cookies by default. Because the Iran transfer is sensitive, minimise the personal data any iPresta module sends abroad and inform customers clearly in your privacy notice.
Map which iPresta modules send data outside the EU, put Standard Contractual Clauses in place, and complete a documented transfer impact assessment. Prefer self hosted or EU hosted components where possible, disclose the transfer, set short retention, and review whether the residual risk is acceptable.
Websites using iPresta must obtain user consent under GDPR regulations.
DPIA considerations
Because iPresta involves a transfer to Iran, a high risk jurisdiction without adequacy, a transfer impact assessment is essential and a DPIA is strongly recommended where customer data is involved. Reconsider the components if the residual risk cannot be reduced.
Sample consent text
We use iPresta components to run parts of our store. Analytics and marketing cookies, and any transfer of data outside the EU, are only used if you accept them.
Third-party domains contacted
ipresta.ircdn.ipresta.irCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ipresta_cart | Functional | Session | Keeps the storefront and cart session during a visit |
| ipresta_pref | Functional | 6 months | Remembers store preferences set by iPresta modules |
| ipresta_analytics | Analytics | 1 year | Measures how visitors use the store through an iPresta module |
iPresta uses cookies for user preferences — inform visitors with a consent banner.
iPresta modules set functional cookies for the storefront and cart, and some modules add analytics or marketing cookies. Only the store cookies are strictly necessary; the rest need consent.
The functional store cookies can rely on the ePrivacy exemption, but any analytics or marketing cookies require prior consent and must stay blocked until the visitor accepts them.
Store functions rely on performance of a contract under Article 6(1)(b), while analytics and marketing cookies rely on consent under Article 6(1)(a) and Article 5(3) ePrivacy. The Iran transfer needs its own safeguard.
Yes. iPresta is operated from Iran, which has no EU adequacy decision and is high risk. Any personal data sent there needs Standard Contractual Clauses, a transfer impact assessment, and clear disclosure, with data minimised.
Yes, it is strongly recommended where customer data is involved. The transfer to Iran raises elevated risk, so document a transfer impact assessment and a DPIA and reconsider the components if the risk stays high.
Block non essential cookies until consent, map the modules that send data abroad, put Standard Contractual Clauses in place, complete a transfer impact assessment, minimise data, and prefer EU hosted components.
EU based PrestaShop modules and hosting keep data within the EEA and avoid the high risk transfer, which is the cleanest way to reduce exposure for customer data.
List the iPresta functional, analytics, and marketing cookies with their purpose and duration, state that data may be transferred to Iran, and name the safeguard relied upon. Review the transfer regularly.