Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
ITORIS is a web development company offering Magento and Adobe Commerce extensions and web tools. Its website and embedded tools use functional and analytics cookies, so consent is required under GDPR and the ePrivacy Directive.
ITORIS is a web development company that has built Magento and Adobe Commerce extensions and web tools since 2007, including product configurators, grouped product options, form builders and dynamic product options. On its own website and within the tools it hosts, ITORIS relies on standard functional and analytics cookies, which brings it within the scope of GDPR and the ePrivacy Directive whenever those pages reach visitors in the European Union.
ITORIS Inc is a Canadian registered web development company with development operations in Eastern Europe. It is best known for its catalogue of Magento and Adobe Commerce extensions, alongside hosted web tools such as configurators and form builders. When you visit the ITORIS website to evaluate or buy an extension, or when you use one of its embedded tools, your browser interacts with ITORIS systems that may place cookies.
ITORIS uses two broad categories of cookies. Functional cookies keep your session active, remember your preferences and support core features of the website and embedded tools, and these are strictly necessary for the service to work. Analytics cookies, typically through a provider such as Google Analytics, measure page views, traffic sources and how visitors move through the site. The data involved includes IP addresses, device and browser details and usage events, which can qualify as personal data under GDPR.
Under the ePrivacy Directive, storing or reading non essential cookies on a user device requires prior consent, and the GDPR sets the standard for that consent as freely given, specific, informed and unambiguous. Functional cookies that are strictly necessary do not need consent, but the analytics cookies that ITORIS uses do. Because the company processes personal data, it must also offer transparency, honour data subject rights and document its processing activities.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Analytics and other non essential cookies must be blocked until the visitor actively agrees, so a consent banner that loads analytics only after an explicit opt in is the safest approach. The banner should let users accept, reject or choose categories with equal ease, and it should record when and how consent was given. Strictly necessary functional cookies can rely on legitimate interest or contractual necessity rather than consent, which keeps core features working even before a choice is made.
Because ITORIS is based in Canada and may use analytics services and content delivery networks operated from the United States, data from European visitors can leave the European Economic Area. Transfers to Canada are covered by the European Commission adequacy decision, while transfers to the United States rely on the EU US Data Privacy Framework or Standard Contractual Clauses. You should confirm which providers are in scope and ensure a valid transfer mechanism is in place for each one.
Map every cookie set by the ITORIS website and any embedded tools, classify each as functional or analytics and block the analytics ones until consent is captured. Publish a clear cookie policy that names the providers and transfer mechanisms, connect a consent management platform that logs choices, and review the setup whenever you add new tools. These steps keep your use of ITORIS aligned with GDPR and the ePrivacy Directive at a consistently low risk level.
Websites using ITORIS must obtain user consent under GDPR regulations.
DPIA considerations
ITORIS uses functional cookies for core features and analytics cookies to measure usage on its website and embedded tools, which present a low privacy risk. A full data protection impact assessment is usually not required, but you should document the analytics processing and the international transfers to Canada and the United States. Review the configuration if you embed ITORIS tools that collect customer input on regulated or high volume pages.
Sample consent text
We use functional and analytics cookies on this site and within embedded ITORIS tools, and we set analytics cookies only after you give your consent.
Third-party domains contacted
itoris.comwww.google-analytics.comwww.googletagmanager.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| frontend | Functional | Session | Maintains the visitor session and core state on the ITORIS website and embedded tools. |
| store | Functional | 1 year | Remembers the selected store view, language and display preferences. |
| _ga | Analytics | 2 years | Google Analytics cookie that distinguishes unique visitors to measure traffic and usage. |
| _gid | Analytics | 24 hours | Google Analytics cookie that distinguishes visitors over a single day to measure usage. |
ITORIS uses cookies for user preferences — inform visitors with a consent banner.
ITORIS sets functional cookies that keep your session active and remember preferences on its website and embedded tools, plus analytics cookies, usually through Google Analytics, that measure traffic and usage. The functional cookies are strictly necessary, while the analytics cookies are optional and require consent.
Yes. The strictly necessary functional cookies can run without consent, but the analytics cookies ITORIS uses must not load until the visitor gives prior consent under the ePrivacy Directive and GDPR. A consent banner that activates analytics only after an explicit opt in keeps you compliant.
Core functional cookies rely on legitimate interest or contractual necessity because they are needed to deliver the service. Analytics and other non essential cookies rely on consent under Art. 6(1)(a) GDPR, which must be freely given, specific, informed and unambiguous.
ITORIS is a Canadian company and may use analytics and content delivery services operated from the United States, so European visitor data can leave the European Economic Area. Transfers to Canada rely on the European Commission adequacy decision, and transfers to the United States rely on the EU US Data Privacy Framework or Standard Contractual Clauses.
In most cases a full data protection impact assessment is not required, because the analytics and functional cookies present a low privacy risk. You should still document the analytics processing and international transfers, and reconsider a DPIA if you embed ITORIS tools that collect customer input on regulated or high volume pages.
Inventory every cookie set by the ITORIS website and embedded tools, classify each as functional or analytics, and block the analytics cookies until consent is captured. Connect a consent management platform that logs choices and publish a cookie policy that names the providers and transfer mechanisms.
You can pair ITORIS functional features with a privacy friendly or cookieless analytics tool, or configure analytics to run only after consent. ITORIS itself does not offer a cookieless mode, so reducing analytics reliance is the main way to lower cookie exposure.
List the functional and analytics cookies that ITORIS sets, name the analytics providers such as Google Analytics, and describe the transfers to Canada and the United States with their legal mechanisms. Refresh the policy whenever you add or remove ITORIS tools so it always reflects the cookies actually in use.