Abla Analytics (Astra Porta)

This work is licensed under CC BY-SA 4.0

Privacy Configuration Guide

Abla Analytics is a cookieless web audience-measurement tool developed and published by Astra Porta SARL, a French start-up based in Marseille. It measures page views, visits, visitors, bounce rate, time on site, traffic sources, and country-level geolocation via a lightweight, cookie-free script. Astra Porta hosts all data in France on Scaleway (Groupe Iliad) infrastructure. The service is offered in three tiers — Abla Analytics (the free/base tier), Abla Analytics+, and Abla Analytics x — which differ in which analytical features are enabled, and this is what drives the two configurations below.


Summary Oversight — Step 1 & Step 2

ConfigurationStep 1 — Abla Analytics setupStep 2 — CP tracking methodStep 2 — CP legal roleStep 2 — CP personalisation
A — Lower RiskBase tier (Abla Analytics): CNIL-exempt configuration — import, export with identifiers, Google Search Console keyword display, parameter filters, and event/link tagging all disabled by defaultFirst party tracking (single session)ProcessorNo personalisation
B — Higher RiskAbla Analytics+ / Abla Analytics x: parameter filters, event/link tagging, data export with anonymised visitor IDs, Google Search Console integration, and ad-blocker circumvention enabledFirst party tracking (cross-session)ProcessorNo personalisation

Step 1 — Abla Analytics Configuration

Astra Porta publishes an official CNIL exemption configuration guide for Abla Analytics, confirming that only the base tier meets the exemption conditions by default, and specifying exactly which features must remain disabled to preserve that status. Certain protections apply identically across all three tiers and are not configurable: it is not possible to build visitor cohorts for differentiated content display, location data is limited to country level, visitor IP addresses are anonymised instantaneously, and cross-site or cross-device tracking of a visitor is not possible. All tiers must offer visitors a copy-paste opt-out button that disables all tracking for that visitor.

#Configuration AreaWhere in Abla AnalyticsConfiguration A — Lower RiskConfiguration B — Higher Risk
1Consent requirementTier selection at account/contract levelNo consent required — base tier is configured by default to meet the CNIL exemption conditions for audience-measurement tools; no manual configuration is neededConsent required — Abla Analytics+ and Abla Analytics x enable features the official CNIL exemption guide identifies as incompatible with the exemption
2Data import from other toolsDashboard → Import (disabled on base tier)Disabled — cannot import historical audience data from competing solutionsEnabled
3Data exportDashboard → Export (disabled on base tier)Disabled — no data export feature availableEnabled — exported data includes anonymised visitor identifiers, allowing individual visit paths to be reconstructed outside the platform
4Google Search Console integrationDashboard → Integrations (disabled on base tier)Disabled — cannot display the search keywords visitors used to arrive from GoogleEnabled
5Parameter filteringDashboard → Filters (disabled on base tier)Disabled — cannot filter by browser, traffic source, country, or other parameters, preventing individualisation of a visitor's journeyEnabled
6Event/link taggingDashboard → Tag Manager (disabled on base tier)Disabled — cannot add tags to buttons, pages, or hyperlinks to track specific interactionsEnabled — individual on-page interactions (clicks, conversions) can be tagged and tracked per visitor path
7Ad-blocker circumventionScript delivery methodNot a differentiator described in the official exemption guide, but third-party sources indicate this capability is a general product feature; where enabled alongside Configuration B's other features, it materially increases the share of traffic effectively trackedPresent — traffic otherwise blocked by ad-blocking browser extensions is captured
8Processing locationFixed; not configurableFrance (Scaleway / Groupe Iliad); no CLOUD Act riskSame as Configuration A

Configuration A — Lower Risk

Use this configuration when Abla Analytics is deployed on its base (free) tier exactly as shipped by default, with no feature upgrades enabled. In this configuration, Astra Porta disables — at the platform level, not merely as a customer setting — the features that its own official CNIL exemption guide identifies as incompatible with consent-free audience measurement: data import from other tools, data export (even export without personal identifiers is unavailable), Google Search Console keyword display, filtering by browser/source/country or other parameters, and event/link tagging. Combined with the baseline protections that apply to all tiers (instantaneous IP anonymisation, country-level-only location, no cohort building, no cross-site/cross-device tracking, and a mandatory visitor opt-out), this configuration was assessed by the CNIL and is intended to meet the ePrivacy/CNIL strictly-necessary audience-measurement exemption, meaning prior visitor consent is not required.

Because filtering and individual event tagging are disabled, and no export of visitor-level identifiers is possible, this configuration does not support reconstructing an individual visitor's journey either on the platform or via exported data. All hosting takes place in France (Scaleway/Groupe Iliad); Astra Porta acts as data processor.


Configuration B — Higher Risk

Use this configuration when Abla Analytics+ or Abla Analytics x is deployed with filtering, event/link tagging, data export, Google Search Console integration, and/or ad-blocker circumvention enabled. Astra Porta's own exemption documentation states plainly that only the base tier meets the CNIL exemption conditions by default — meaning Configuration B falls outside the scope of that exemption, and prior visitor consent must be obtained before tracking occurs.

With filtering and tagging enabled, individual visitor interactions (specific pages, links, or buttons) can be tracked and analysed by parameter, and exported data includes anonymised visitor identifiers that allow an individual visit path to be reconstructed outside the dashboard — a capability the base tier deliberately withholds to preserve its exemption status. Google Search Console integration additionally surfaces the search keywords used by individual visitors arriving from Google. Ad-blocker circumvention, where enabled, increases the share of visitors from whom data is captured, including visitors who have taken active steps (installing an ad/tracker blocker) to limit such collection.

The baseline protections common to all tiers still apply: IP addresses remain anonymised instantaneously, location remains country-level only, and no cross-site or cross-device tracking occurs. Astra Porta continues to act as data processor, and hosting remains exclusively in France (Scaleway/Groupe Iliad); no CLOUD Act risk applies.


Step 2 — Mapping in the Customer Panel

Using the Abla Analytics configurations defined in Step 1, apply the following mappings in the Consenter Manager to ensure the consent banner correctly reflects the data processing activities. Select the "Audience measurement / analytics" processing purpose in line with the Consenter processing purposes documentation.


2.1 Configuration A — Lower Risk

Customer Panel SettingValue to Select
Tracking methodFirst party tracking (single session)
IdentifierNo identifier
Data categoriesAggregated site statistics, Non-precise location data
Legal role of data recipientProcessor
Personalisation modelNo personalisation
Maximum storage durationNot publicly specified by Astra Porta — confirm the applicable retention period directly in your customer contract
Processing locationFrance (Astra Porta; Scaleway/Groupe Iliad hosting; no CLOUD Act risk)
Processing purposesAudience measurement / analytics (strictly necessary)

2.2 Configuration B — Higher Risk

Customer Panel SettingValue to Select
Tracking methodFirst party tracking (cross-session)
IdentifierProbabilistic identifiers
Data categoriesAggregated site statistics, Browsing and interaction data, Device characteristics, Non-precise location data, Probabilistic identifiers
Legal role of data recipientProcessor
Personalisation modelNo personalisation
Maximum storage durationNot publicly specified by Astra Porta — confirm the applicable retention period directly in your customer contract
Processing locationFrance (Astra Porta; Scaleway/Groupe Iliad hosting; no CLOUD Act risk)
Processing purposesAudience measurement / analytics

Step 3 — Privacy Policy

Reflect the Abla Analytics configuration you have implemented in your privacy policy, including the legal basis relied upon (exemption or consent), the categories of data processed, and the retention period confirmed with Astra Porta. For guidance on aligning contextual consent language with your privacy policy, see the Consenter contextual consent integration guide.

Shape Consenter Together

Consenter is built on an open and participatory process that grows through community collaboration. Whether you share feedback, improve the documentation, or contribute to the Risk Configuration Guides or Technical Integration Guides, your expertise helps make Consenter more privacy-friendly, interoperable, and useful for everyone—including your own users and services: Get finally your benefits and control the risks when sharing personal data.

Last updated on

On this page