SmartProfile
This work is licensed under CC BY-SA 4.0
Privacy Configuration Guide
Step 1: Choose which configuration matches your demands and configure SmartProfile accordingly
Step 2: Configure the Consent Banner in the Consenter Manager accordingly
Step 3: Explain how you use SmartProfile in your privacy policy
SmartProfile is a unified data marketing platform developed and published by Net Solution Partner (NSP), a French software company headquartered at 1 Traverse des Brucs, 06560 Valbonne (Sophia Antipolis), France. The platform combines four integrated modules: a Web Analytics module for measuring website and mobile app audience; a Customer Data Platform (CDP), optionally AI-augmented, for centralising, unifying, and enriching data from all customer touchpoints into a single customer repository; a Marketing Automation module for orchestrating personalised multichannel campaigns (email, SMS, landing pages, forms, pop-ins); and a GDPR compliance module for managing consent, data mapping, retention, and data subject rights. The platform is offered as a hosted SaaS solution — data hosted on redundant infrastructure located in France and the European Union, within ISO 27001 certified organisations of European right — or as an on-premise deployment on the customer's own infrastructure. Contractually, NSP acts as subcontractor/processor; all data collected and processed on behalf of a customer remains the sole property of that customer.
The three configurations below reflect the most privacy-relevant use patterns and correspond to meaningfully different risk levels and legal bases for processing.
Summary Oversight — Step 1 & Step 2
| Configuration | Step 1 — SmartProfile setup | Step 2 — CP tracking method | Step 2 — CP legal role | Step 2 — CP personalisation |
|---|---|---|---|---|
| A — Lower Risk | CNIL self-assessed exemption mode: anonymised IP, 13-month cookie (no renewal), 25-month raw data cap, analytics-only, no cross-referencing | First party tracking (cross-session) | Processor | No personalisation |
| B — Medium Risk | Consent-gated web analytics linked to identified CRM contacts (form fill, login, email click) | First party tracking (cross-session) | Processor | Profile based |
| C — Higher Risk | Consent-gated, full multi-source CDP (CRM, ERP, e-commerce, POS, call centre) with AI clustering, scoring, and multichannel automation | First party tracking (cross-session) | Processor | Profile based |
Step 1 — SmartProfile Configuration
| # | Configuration Area | Where in SmartProfile | Configuration A — Lower Risk | Configuration B — Medium Risk | Configuration C — Higher Risk |
|---|---|---|---|---|---|
| 1 | Web analytics collection and consent mode | Web Analytics module settings; CMP/consent integration | Self-assessed CNIL-exemption mode — IP address last octet anonymised; cookie lifetime capped at 13 months with no automatic renewal on subsequent visits; raw data retained for a maximum of 25 months; data used exclusively for audience measurement and not cross-referenced with any other data source or shared with third parties; no prior consent required from visitors in France where the exemption conditions are met and documented (consent required in other EU jurisdictions); an opt-out mechanism must be offered | Consent-gated mode — full web analytics collection after consent is granted; individual visitor sessions tracked via first-party cookie; page views, interaction events, referrers, and session parameters collected and capable of being linked to an individual visitor record; IP address not anonymised | Consent-gated mode — same base tracking as Configuration B; web analytics data additionally enriched with data from all connected sources (CRM, ERP, e-commerce, call centre, offline POS) to build a comprehensive multi-source profile per contact |
| 2 | CDP profile integration | CDP → Data Sources → integrations (CRM, ERP, e-commerce connectors, API, import); Contact Profile settings | Disabled — analytics data remains isolated in the analytics module; no individual visitor record is linked to a CRM contact or any other identified data source; only anonymous, aggregate statistics are produced | Enabled — web analytics events are linked to known CRM contacts where the visitor can be identified (e.g. via form submission, email click, or authenticated session); individual profiles are created, combining online behavioural data with CRM fields (name, email, purchase history, contact history, preferences) | Enabled — full multi-source integration across web, mobile app, CRM, ERP, e-commerce platform, call centre, and offline POS; a single customer repository is maintained per contact and updated in near real time |
| 3 | Marketing automation and AI personalisation | Marketing Automation module; AI clustering/scoring settings (requires CDP module) | Not applicable — analytics-only mode; no marketing activation or personalisation based on visitor data | Basic marketing automation — rule- or behaviour-triggered campaign scenarios (e.g. abandoned-cart follow-up, welcome sequence); manual or rule-based segmentation; multichannel dispatch (email, SMS, landing pages, pop-ins) | Full AI-powered marketing automation — proprietary AI algorithms for contact clustering, lead scoring, churn/disengagement prediction, and product recommendation; fully personalised multichannel scenarios; distributed marketing module available for brand/franchise networks |
| 4 | Processing location and deployment model | Selected at contract stage; hosting managed by NSP (SaaS) or by the customer (on-premise) | SaaS (default): France/EU hosting, ISO 27001 certified organisations of European right; no CLOUD Act risk; on-premise option available | Same as Configuration A | Same as Configuration A |
Configuration A — Lower Risk
Use this configuration when SmartProfile is used solely for anonymous website audience measurement under a self-assessed CNIL exemption from consent. The web analytics module is configured to meet the substantive conditions the CNIL has set out for audience-measurement exemptions: the last octet of each visitor's IP address is anonymised before storage; a first-party cookie is set with a lifetime capped at 13 months and is not automatically renewed on subsequent visits; raw data is retained for a maximum of 25 months; the data is used exclusively to measure the operator's own website audience and is not cross-referenced with CRM or any other data source, nor shared with third parties. Where these conditions are met and documented, no prior consent is required to place the cookie and collect analytics data from visitors in France; users must nonetheless be informed via the privacy policy and offered an opt-out mechanism.
The data produced under Configuration A consists exclusively of aggregated, anonymous statistics — page views, sessions, bounce rates, referrer sources, device types — from which no individual visitor can be identified. No individual contact profile is created in the CDP module, and no marketing automation or personalisation is triggered.
As NSP is a French company with exclusively EU/French hosting for its SaaS offering, there is no CLOUD Act risk and no need to document an international transfer mechanism for this entry. NSP acts as data processor/subcontractor; a DPA is included in the standard SmartProfile customer agreement.
Configuration B — Medium Risk
Use this configuration when SmartProfile is used both for web analytics and for CRM-integrated individual visitor profiling. Consent must be obtained before the analytics and CDP tracking scripts are activated. Once consent is granted, the web analytics module tracks individual visitor sessions in full fidelity: page views, interaction events, referrer, device type, IP address (not anonymised), and session parameters are captured and capable of being associated with an individual visitor record.
Where the visitor can be identified — for example through a form submission, an authenticated account login, or a click on a tracked email link — their web analytics data is linked to the corresponding CRM contact record in the CDP, creating or enriching an individual profile. This profile combines online behavioural data with existing CRM fields (name, email address, purchase history, campaign interaction history, stated preferences). Resulting profiles can be used for manual or rule-based segmentation and basic marketing automation scenarios (welcome emails, abandoned-cart follow-ups, re-engagement sequences), dispatched via the Marketing Automation module.
Data retention is configurable by the operator within the SmartProfile GDPR module, which supports mapping data, setting per-field retention rules, managing consent records, and logging access/deletion requests.
As in Configuration A, NSP acts as data processor with EU/French hosting; no CLOUD Act risk; a DPA is included.
Configuration C — Higher Risk
Use this configuration when SmartProfile is used as a full Customer Data Platform with multi-source data integration, AI-based personalisation, and multichannel marketing automation. Consent must be obtained before any tracking is activated. Configuration C extends Configuration B by connecting additional data sources to the CDP — such as ERP systems, e-commerce platforms, point-of-sale data, call centre records, and offline transaction data — to build a comprehensive, continuously updated single customer repository.
Proprietary AI algorithms are applied to the unified profile data for customer clustering, lead scoring, churn/disengagement prediction, and personalised product recommendation. Marketing automation scenarios are fully personalised at the individual profile level and dispatched across all available channels, including email, SMS, push notifications, landing pages, and pop-ins. A distributed marketing module is also available for brand and franchise networks, enabling decentralised local campaign execution from a centralised data and template repository.
This configuration represents the most data-intensive use of SmartProfile, combining direct identifiers (name, email, phone) from CRM with transactional, behavioural, and AI-derived profile attributes. Data retention remains fully configurable within the GDPR compliance module.
As in Configurations A and B, NSP acts as data processor with EU/French hosting. The on-premise deployment option — under which the entire SmartProfile platform runs on the customer's own servers — provides the highest level of data sovereignty and is particularly suited to customers with strict data-locality requirements (e.g. banking, insurance, public sector); in this mode, NSP does not have access to the data at all.
Step 2 — Mapping in the Customer Panel
Using the SmartProfile configurations defined in Step 1, apply the following mappings in the Consenter Manager to ensure the consent banner correctly reflects the data processing activities. Processing purposes should be selected in line with the Consenter processing purposes documentation — typically "Audience measurement / analytics" for Configuration A, and "Audience measurement / analytics" plus "Marketing" and/or "Personalisation" for Configurations B and C.
2.1 Configuration A — Lower Risk (self-assessed exemption)
| Customer Panel Setting | Value to Select |
|---|---|
| Tracking method | First party tracking (cross-session) |
| Identifier | No identifier |
| Data categories | Aggregated site statistics, Browsing and interaction data, Device characteristics, IP-Address anonymised, Non-precise location data |
| Legal role of data recipient | Processor |
| Personalisation model | No personalisation |
| Maximum storage duration | 13 months (cookie) / 25 months (aggregated raw data) |
| Processing location | France / EU (Net Solution Partner, Valbonne, France; ISO 27001 certified EU hosting; no CLOUD Act risk) |
| Processing purposes | Audience measurement / analytics (strictly necessary) |
2.2 Configuration B — Medium Risk
| Customer Panel Setting | Value to Select |
|---|---|
| Tracking method | First party tracking (cross-session) |
| Identifier | Authentication-derived identifiers, Device identifiers |
| Data categories | Authentication-derived identifiers, Browsing and interaction data, Device characteristics, Device identifiers, IP address, Non-precise location data, User-provided data, Users' profiles |
| Legal role of data recipient | Processor |
| Personalisation model | Profile based |
| Maximum storage duration | Configurable per operator's data retention policy (managed in the SmartProfile GDPR module) |
| Processing location | France / EU (Net Solution Partner, Valbonne, France; ISO 27001 certified EU hosting; no CLOUD Act risk) / customer's own servers (on-premise) |
| Processing purposes | Audience measurement / analytics, Marketing |
2.3 Configuration C — Higher Risk
| Customer Panel Setting | Value to Select |
|---|---|
| Tracking method | First party tracking (cross-session) |
| Identifier | Authentication-derived identifiers, Device identifiers, Direct identifier |
| Data categories | Authentication-derived identifiers, Browsing and interaction data, Device characteristics, Device identifiers, Direct identifier, e-commerce Activity, IP address, Non-precise location data, User-provided data, Users' profiles |
| Legal role of data recipient | Processor |
| Personalisation model | Profile based |
| Maximum storage duration | Configurable per operator's data retention policy (managed in the SmartProfile GDPR module) |
| Processing location | France / EU (Net Solution Partner, Valbonne, France; ISO 27001 certified EU hosting; no CLOUD Act risk) / customer's own servers (on-premise) |
| Processing purposes | Audience measurement / analytics, Marketing, Personalisation |
Step 3 — Privacy Policy
Reflect the SmartProfile configuration you have implemented in your privacy policy, including the legal basis relied upon (exemption or consent), the categories of data processed, retention periods, and — where CDP/marketing automation modules are active — the purposes of profiling and personalisation. For guidance on aligning contextual consent language with your privacy policy, see the Consenter contextual consent integration guide.
Shape Consenter Together
Consenter is built on an open and participatory process that grows through community collaboration. Whether you share feedback, improve the documentation, or contribute to the Risk Configuration Guides or Technical Integration Guides, your expertise helps make Consenter more privacy-friendly, interoperable, and useful for everyone—including your own users and services: Get finally your benefits and control the risks when sharing personal data.
Last updated on