Privacy and cookie policy
I. General information and declarations
This document (hereinafter also: the “Privacy policy” or the “Policy”) sets out the privacy rules of the heyhey.ae website, as well as the rules for processing personal data in connection with legal relationships that the Controller enters into under contracts.
In the remainder of this document, the heyhey.ae website, together with the Controller’s other websites and infrastructure, including the heyhey dashboard (the application), is also referred to as the “Service”, the “Website” or “heyhey”.
The controller of the personal data of users of the Service and of Customers is NNBL Software FZE, licence no. 4431402.01, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates (hereinafter: the “Controller” or the “Personal Data Controller”).
For the purposes of this document, users means all visitors to the pages of the Website, unless the context indicates otherwise.
Other capitalised terms have the meaning given to them in the terms of service of the Service, available on the Website (hereinafter also: the “Terms of service” or the “Service Terms”), unless this Privacy policy expressly states otherwise.
The Privacy policy is continuously available on the website of the Service in a way that allows its content to be obtained, reproduced and recorded at any time by printing it or saving it on a storage medium.
Personal data collected by the Controller is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, OJ L 119, p. 1), hereinafter: the “GDPR”.
For persons under the age of 16, the services available through the Service (including the contact form) require action or consent by a legal guardian. The Controller processes the personal data of minors only with the knowledge and consent of their parents or guardians, in order to provide the services.
The Controller takes particular care to protect privacy and the information provided to or collected by it, which concerns above all users of the Service and customers. The Controller selects and applies, with due diligence, appropriate technical measures, in particular of a software and organisational nature, that ensure the protection of the data processed. In particular, it protects the data against access by unauthorised persons, disclosure, loss and destruction, unauthorised modification, and processing in breach of applicable law.
The Website may use so-called plug-ins and other social media tools, in particular tools that allow a user of the Service to share content with other users of social networks (in particular Facebook, Instagram, YouTube and TikTok) or to recommend it through their account with the provider of the relevant platform. The providers of these services may also process personal data as independent controllers.
II. Contacting the Controller
You can contact the Controller about personal data matters:
- by email, at: info@heyhey.pl,
- by post, to: NNBL Software FZE, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates.
The Personal Data Controller informs you that no Data Protection Officer has been appointed.
III. Personal data: purposes and legal bases of processing
Purposes and legal bases of processing personal data related to running the Service and providing services or Service features
The Personal Data Controller processes personal data for the following purposes and to the following extent, on the basis of the following legal provisions:
1. Performance of contracts and provision of services
Legal basis: personal data is processed on the basis of Article 6(1)(b) GDPR, i.e. for the performance of a contract and in order to take steps at the request of the data subject prior to entering into a contract, and, where processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, on the basis of Article 6(1)(f) GDPR.
Purpose and scope: on this basis, the Controller processes data for the following purposes and to the following extent:
- to conclude and perform the Contract, in particular to deliver Products (including digital products, Digital Content and Digital Services), to provide Services or to provide other benefits offered through the Website, regardless of the form and scope of the Contract concluded. For this purpose, the Controller processes the personal data provided by the data subject when concluding the Contract and other data provided or otherwise transferred in order to fulfil an Order or Service, or in connection with such fulfilment, in particular data such as first name and surname, address details, email address, telephone number and payment details,
- to provide Services, in particular the data provided by the User when registering on the Website, i.e. email address, first name and surname and the password they set; in addition, when providing other Services, such as a newsletter, the Controller processes in particular personal data concerning the User’s activity on the Website, including the content, Products or Services they view, data concerning their device session, browser, IP address, unique ID, operating system and location, as well as data provided for the purpose of providing Services or a Product, including data entered by the User in forms available on the Service.
Legitimate interest of the Controller: where personal data is processed for the above purposes, the legitimate interest pursued by the Controller consists of: building and maintaining positive relationships with data subjects, including in particular responding to their enquiries and contacting them, building and maintaining the proper image of the Controller itself, and developing and raising the standard of the business and services of the Controller.
2. Statistics, security, and the establishment, exercise and defence of claims
Legal basis: where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, the Controller processes personal data on the basis of Article 6(1)(f) GDPR.
Purpose and scope: on this basis, the Controller processes data for the following purposes and to the following extent:
- to determine the extent of, and keep statistics on, the use of individual features of the Service, Services or functionalities, to facilitate or otherwise optimise the use of the Service and the Services, and to ensure the IT security of the Service and of the Services themselves. For this purpose, the Controller processes in particular personal data concerning Users’ activity on the Service, including the use of the infrastructure of the Service and its individual elements, the time spent on each page, search history, clicks, location, IP address, device ID, and data about the User’s web browser and operating system, in the case of a User who only visits the website of the Service. For Users who have an account, the scope of processing may be extended to information about the Service provided to that User and their use of it,
- to establish, exercise and enforce claims and to defend against claims in court proceedings and before other enforcement authorities. For this purpose, the Controller may process above all the personal data provided by the User on the Service, data obtained during contact with the Controller, including when concluding the Contract, data needed to conclude the Contract or in connection with it, data concerning the use of Services, Products or features (including data provided or collected in individual parts and resources of the Service), and other data necessary to prove the existence of a claim or resulting from a legal requirement, court order or other legal procedure.
Legitimate interest of the Controller: where personal data is processed for the above purposes, the legitimate interest pursued by the Controller consists of: the ability to establish, exercise and enforce claims and to defend against claims in proceedings before courts and other state authorities, raising the level of the services provided and of the business, and the efficiency and security of the Website, as well as building and maintaining positive relationships with users and Customers.
3. Marketing and cookies
Legal basis: where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, and, where the consent of the data subject was also required for the processing of personal data, on the basis of that consent, i.e. on the basis of Article 6(1)(f) GDPR and Article 6(1)(a) GDPR. Where personal data is processed for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract, on the basis of Article 6(1)(b) GDPR.
In addition, for certain marketing activities, including sending commercial or marketing information or other similar communications, in particular communications subject to specific legal rules, the legal basis for processing personal data also includes the applicable laws governing electronic communications and the sending of commercial information.
Purpose and scope: on this basis, the Controller processes data for the following purposes and to the following extent:
- marketing of the Controller’s services, including remarketing. For this purpose, the Controller mainly processes the personal data provided by the data subject and data concerning that person’s activity on the Service, including data recorded and stored through cookies, in particular the history of activity and actions on the Service, including the history and activity related to communication with the Controller, and, for users who are also Customers, data concerning contracts and data provided in connection with concluding those contracts. For remarketing, the Controller also uses data about the activity of the data subject in order to reach them with marketing messages, including dedicated content outside the Service. For this purpose, the Controller may use the services of external providers that supply specific mechanisms. These services consist in particular of displaying the Controller’s messages on websites other than the pages of the Service. Details can also be found in the provisions on cookies later in this document,
- the Controller’s use of cookies on the Website. Depending on the type (category) of cookies, the processing of personal data is based on different legal bases: for necessary cookies, the basis is Article 6(1)(f) GDPR and Article 6(1)(b) GDPR; for cookies in the Analytics and Marketing categories, the basis is Article 6(1)(a) GDPR. Where the Controller has not categorised a cookie, the basis is also Article 6(1)(a) GDPR. More information can be found in the provisions on cookies later in this document, which set out the rules for using these files,
- market and opinion research, measurements and statistics carried out by the Controller itself: for this purpose, the Controller uses in particular data concerning contracts, data provided by the user of the Service on the Service, in particular in the individual forms on the Service, and data about the user’s behaviour during visits to the Service. Precise information is provided in the notice about the relevant survey or form, or at the place where the data subject enters their data.
Legitimate interest of the Controller: where personal data is processed for the above purposes, the legitimate interest pursued by the Controller, in cases where it is the basis for processing, consists of: the ability to inform about the Controller’s offer, in particular the products and services offered, and to build a positive image, to carry out direct marketing of products and services, to ensure the most optimal use of the features of the Website and its pages in general and to raise their standard and security, as well as to optimise and change the Controller’s offer.
4. Complaints, grievances and requests, and competitions and promotions
Legal basis: the performance of a contract and, where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (legitimate interest of the controller), i.e. on the basis of Article 6(1)(f) GDPR and Article 6(1)(b) GDPR.
Purpose and scope: on this basis, the Controller processes data for the following purposes and to the following extent:
- handling complaints, grievances and requests and answering questions from users and customers: for this purpose, the Controller processes above all the personal data provided in the contact form and in other electronic forms on the Website, by email, in text messages, in complaints, grievances and requests, and in questions submitted in any other form. For this purpose, the Controller also processes certain data concerning contracts and other services provided by the Controller that gave rise to the complaint, grievance, request or question, and data contained in documents attached to complaints, grievances, requests and questions,
- organising and running competitions, promotions, loyalty programmes and similar campaigns and promotional events, including notifying people of benefits received and prizes won and advertising the Controller’s offer: for this purpose, the Controller uses in particular the personal data provided by the data subject in their Account and when joining or registering for a competition, promotion, programme or other campaign. Detailed information is provided in each case in the terms of participation of the relevant competition, promotion, programme or campaign.
Legitimate interest of the Controller: where personal data is processed for the above purposes, the legitimate interest pursued by the Controller consists of the ability to handle complaints lawfully and to respond to users’ comments or questions, as well as raising the level of the services provided and building positive relationships with users.
5. Legal obligations (tax and accounting)
Legal basis: where processing is necessary for compliance with a legal obligation to which the Controller is subject, i.e. on the basis of Article 6(1)(c) GDPR, in particular the Controller’s legal obligations under tax and accounting laws, including in connection with settling competitions, promotions, loyalty programmes or similar campaigns. For this purpose, the Controller processes above all the personal data provided in order to place and settle an order for a service and to perform the contract, as well as the data provided by the user or customer when joining a loyalty programme, competition, promotion or similar campaign, in accordance with its rules.
Other purposes and legal bases of processing personal data
1. Social media profiles
Legal basis: the performance of a contract and, where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (legitimate interest of the controller), i.e. on the basis of Article 6(1)(f) GDPR and Article 6(1)(b) GDPR (for the performance of a contract and in order to take steps at the request of the data subject prior to entering into a contract).
Purpose and scope: for this purpose, the Controller processes personal data (in particular identifiers, the content of comments and opinions) of persons (users) who visit profiles run by the Controller on social media or other platforms (for example Facebook, YouTube, TikTok, Instagram and Google). Personal data is processed in order to run such profiles, to inform people about the Controller’s activities and to share opinions expressed about the Controller.
Legitimate interest of the Controller: building the Controller’s image, informing people about its activities, building positive relationships with users, and the ability to pursue or defend against possible claims, provided that this Privacy policy does not govern the processing of personal data by the controllers of the above platforms or social media.
2. Staff of contractors, partners or customers
Legal basis: the performance of a contract and, where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (legitimate interest of the controller), i.e. on the basis of Article 6(1)(f) GDPR and Article 6(1)(b) GDPR.
Purpose and scope: processing the personal data of staff members of contractors, partners or customers who work with the Controller. In connection with concluding contracts as part of its business, the Controller obtains data and also receives from customers or contractors the data of persons involved in performing such contracts (e.g. persons authorised to make contact, persons cooperating in providing services, etc.). The scope of the data transferred is in each case limited to what is necessary to perform the contract and usually does not include information other than first name and surname and contact details (business email or telephone number).
Legitimate interest of the Controller: the above personal data is processed to pursue the legitimate interest of the Controller and of its contractor (where processing is based on this ground), consisting of enabling the proper and efficient performance of the contract. Such data may be disclosed to third parties involved in performing the contract.
3. Business contacts
Legal basis: the performance of a contract and, where processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party (legitimate interest of the controller), i.e. on the basis of Article 6(1)(f) GDPR and Article 6(1)(b) GDPR.
Purpose and scope: processing data collected through business contacts. In connection with its business, the Controller also collects personal data in other situations, e.g. during business meetings, for purposes related to initiating and maintaining business contacts. Personal data collected in such cases is processed only for the purpose for which it was collected, and the Controller ensures its appropriate protection.
Legitimate interest of the Controller: building a network of contacts, building relationships and maintaining a positive image in connection with its business.
IV. Personalised advertising and social plug-ins
The Controller may use personal data to prepare and show personalised advertising to users visiting the Service, including by using tools and cookies of third parties. Further information on this can be found in the provisions on cookies later in this Policy.
Because the Website may use so-called social plug-ins and other similar social tools, including tools that allow users to share content with other users of those platforms or to recommend it through their account with the provider of the relevant platform, the providers of these platforms may also process Users’ personal data as independent controllers. Detailed rules on how the controllers of social networks process personal data can be found on the websites of the individual platforms.
When a user visits the pages of the Service, the browser they use may connect directly to the servers of the entities that provide these plug-ins or tools, so that these entities receive information about the user’s use of the pages of the Service and, among other things, their IP address. Such information may be sent regardless of whether the user has an account with that entity and whether they are currently logged in to it. If the user has an account with such an entity and is logged in to it, this information may additionally be linked to and assigned to their social media account. Certain content may also be published on the user’s social media profile and be visible to other users of those platforms, in particular those they are connected with.
If a user does not want the providers of plug-ins or tools, or social networks, to assign the data collected during their visit to the Service to their profile with that provider, they should log out of that social network before visiting the Service. The user can also prevent plug-ins from loading on the page by using the relevant mechanisms of the browser they use, in accordance with its settings.
The Controller makes every effort to choose only software, including the above plug-ins, from reputable entities that set out their personal data protection rules in detail.
The purposes, scope and rules of the collection and further processing of personal data by these entities can be found in their privacy policies. The Controller encourages you to read them, including at the following addresses:
V. Categories of personal data concerned
The Personal Data Controller processes the following categories of personal data:
- contact details,
- data about activity on the Service,
- data about Orders on the Service,
- data about Orders or Services being fulfilled,
- billing and payment data,
- data about complaints, grievances and requests,
- data about marketing services,
- data about users’ activity on social networks where the Controller has profiles or accounts,
- data about contractors and partners working with the Controller.
VI. Voluntary provision of personal data
Providing the required personal data is voluntary for the data subject and is a condition for the Controller to provide Services or perform the Contract.
Providing certain data is a condition for using particular services and features of the Website. The system automatically marks mandatory data. If this data is not provided, the Service cannot provide the relevant services and features. Apart from the data marked as mandatory, providing other personal data is voluntary.
VII. Data processing period
The period for which the Controller processes data depends primarily on the type of Service provided and the purpose of processing. The processing period may also result from generally applicable laws where they form the basis for processing. Where data is processed on the basis of the Controller’s legitimate interest, for example for security reasons, it is processed for the period that allows that interest to be pursued or until an effective objection to the processing is raised. Where processing is based on consent, data is processed until consent is withdrawn. Where processing is necessary to conclude and perform a contract, data is processed until the contract is terminated or expires. Personal data will be deleted in the following cases:
- when the data subject requests its deletion or withdraws the consent given,
- when the data subject has taken no action for more than 10 years (inactive contact),
- upon obtaining information that the stored data is out of date or inaccurate.
Some data may be processed for as long as it may be necessary to pursue possible claims or to defend against claims, for evidential purposes in relation to the services provided by the Controller, and to handle complaints, grievances or other requests, until the claims become time-barred. The Controller will not use this data for marketing purposes.
The Controller stores data collected through cookies, other online identifiers and similar mechanisms for a period corresponding to the life cycle of the cookies stored on devices, or until the user deletes them from their device. Details about the lifetime of each cookie can be found in the provisions on cookies later in this document.
VIII. Recipients of personal data
Under Article 4 GDPR, a recipient means a natural or legal person, public authority, agency or another body to which personal data is disclosed, whether a third party or not.
Given the purposes of processing specified by the Controller, the personal data processed by the Controller may be transferred to the following categories of recipients:
- state authorities, for example the public prosecutor’s office, the police or a data protection supervisory authority, if they request it from the Controller and indicate the legal basis for their request,
- service providers the Controller works with, in particular to deliver Products and Services, including processing payments and deliveries, and to provide the Service and its features, i.e. in the scope of providing Services, providers responsible for the proper operation of the Controller’s IT resources and ICT systems, as well as other external entities working with the Controller in its business. These providers include in particular:
- Hetzner Online GmbH (Germany): hosting of application servers and databases,
- Cloudflare, Inc.: CDN and DNS services and bot protection,
- Stripe Payments Europe, Ltd. (Ireland): payment processing,
- PayPal: payment processing,
- Amazon Web Services (Amazon SES) and Elastic Email: email sending infrastructure,
- Google Ireland Ltd., registered in Ireland: analytics services (Google Analytics 4), if enabled, only with the user’s consent,
- entities providing accounting services to the Controller.
- personal data may be transferred to other entities, namely providers of tools whose cookies are used. Information about these entities and the purposes for which cookies are used is set out later in this document.
The Controller may provide a detailed list of providers at the request of the data subject.
The above providers are based mainly in countries of the European Economic Area (EEA). The Personal Data Controller may commission specific activities to recognised subcontractors operating outside the EEA. Personal data transferred outside the EEA will be protected by appropriate legal safeguards so that the receiving providers guarantee a high level of personal data protection. These safeguards result in particular from an obligation to apply the standard contractual clauses adopted by the European Commission or binding corporate rules duly approved by a supervisory authority within the meaning of the GDPR. The way data is protected complies with the rules set out in Chapter V GDPR. The data subject may ask the Controller for additional information about the safeguards applied, obtain a copy of them and information about where they have been made available. In addition, the Controller will inform you of any intention to transfer personal data outside the EEA at the time the data is collected. In some cases, the transfer of personal data may also be based on relevant decisions or agreements concluded with the competent EU bodies.
IX. Automated decision-making
Within the Service, the Controller takes steps to monitor the activity of its users (visitors to the Service) and to analyse these actions, but it does not engage in automated decision-making with significant effects within the meaning of the GDPR, including profiling. Information about personalised advertising can be found later in this document, in the part on cookies.
X. Rights of the data subject
Under the GDPR, the data subject has the right to:
- request access to their personal data,
- request rectification of their personal data,
- request erasure of their personal data,
- request restriction of the processing of their personal data,
- object to the processing of their personal data,
- request the portability of their personal data,
- withdraw consent to the processing of their personal data, and
- lodge a complaint with a supervisory authority.
Details of the individual rights:
1. Right of access to personal data (Article 15 GDPR)
The data subject may obtain from the Controller information as to whether their data is being processed and, if it is, they have the right to:
- access the data,
- obtain information about the purposes of processing, the categories of personal data processed, the recipients or categories of recipients of the data, the planned period for which the data will be stored or the criteria used to determine that period, the rights available under the GDPR and the right to lodge a complaint with a supervisory authority, the source of the data, automated decision-making, including profiling, and the safeguards applied in connection with transferring the data outside the European Union,
- obtain a copy of their personal data.
2. Right to rectification of personal data (Article 16 GDPR)
If personal data is inaccurate, the data subject may request the Controller to rectify it without undue delay. They may also request the Controller to complete the data. If they have an Account on the Service, they can also rectify and complete their personal data themselves after logging in to their Account, in line with its features.
3. Right to erasure of personal data, the so-called “right to be forgotten” (Article 17 GDPR)
The data subject may request this when:
- their personal data is no longer necessary for the purposes for which it was collected or otherwise processed,
- they have withdrawn a particular consent, to the extent that the personal data was processed on the basis of their consent,
- their personal data was processed unlawfully,
- they have objected to the processing of personal data for direct marketing purposes, including profiling, to the extent that the processing of personal data is related to direct marketing,
- they have objected to the processing of their personal data in connection with processing necessary for the performance of a task carried out in the public interest or processing necessary for the purposes of the legitimate interests pursued by the Controller or by a third party.
Despite a request for erasure of personal data, the Controller may continue to process the data in order to establish, exercise or defend claims, and the person who made the request will be informed of this.
4. Right to request restriction of the processing of personal data (Article 18 GDPR)
The data subject may request this when:
- they contest the accuracy of their personal data: the Personal Data Controller will restrict the processing of their personal data for a period that allows the accuracy of the data to be verified,
- the processing of their data is unlawful and, instead of erasure of the personal data, they have requested restriction of the processing of their personal data,
- their personal data is no longer needed for the purposes of processing, but it is needed to establish, exercise or defend claims,
- they have objected to the processing of personal data: until it is determined whether the legitimate grounds of the Personal Data Controller override the grounds given in their objection.
5. Right to object to the processing of personal data (Article 21 GDPR)
The data subject may object at any time to the processing of their personal data, including profiling, in connection with:
- processing necessary for the performance of a task carried out in the public interest or processing necessary for the purposes of the legitimate interests pursued by the Controller or by a third party,
- processing for direct marketing purposes, where this takes place.
6. Right to data portability (Article 20 GDPR)
The data subject has the right to receive their personal data from the Controller in a structured, commonly used and machine-readable format and to transmit it to another personal data controller, or to request that the Controller transmit their personal data directly to another controller (where technically feasible).
7. Right to withdraw consent to the processing of personal data
The data subject may do so at any time. This does not affect the lawfulness of processing carried out on the basis of their consent before its withdrawal.
8. Right to lodge a complaint with a supervisory authority
If the data subject considers that the processing of their personal data infringes the GDPR, they have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work or the place of the alleged infringement.
You have the right to lodge a complaint with the data protection supervisory authority competent for you.
How to exercise your rights
You can exercise all your rights by contacting the Controller at the contact details given in this Policy.
The Controller will provide information on the action taken on a request without undue delay, and in any event within one month of receiving the request. Where necessary, the one-month period may be extended by a further two months, taking into account the complexity of the request or the number of requests. In any case, the Controller will inform the person of any such extension within one month of receiving the request, together with the reasons for the delay.
Information on the use of cookies on the Website
I. General information
When you browse the Website, “cookies” are used (hereinafter: “Cookies”), i.e. small pieces of text information stored on the user’s end device in connection with their use of the Website. They are used, among other things, to make the pages of the Website work correctly.
In particular, these files make it possible to identify the software used by the user of the Service and to tailor the Website to their individual needs.
Cookies usually contain the name of the domain they come from, how long they are stored on the device and an assigned value.
II. Security and types of files
The Cookies used by the Controller are safe for the user’s devices. In particular, viruses or other unwanted or malicious software cannot reach the user’s devices through Cookies.
Two types of Cookies are used on the Service:
- Session cookies: these are stored on the user’s device and remain there until the browser session ends. The stored information is then permanently deleted from the device’s memory. The session cookie mechanism does not allow any personal data or confidential information to be collected from the user’s device.
- Persistent cookies: these are stored on the user’s device and remain there until they are deleted. Ending the browser session or switching off the device does not remove them from the user’s device. The persistent cookie mechanism does not allow any personal data or confidential information to be collected from the user’s device.
III. Purposes of using Cookies
The Controller may also use third-party Cookies. The Cookies used by the Controller fall into the following categories, which match the choices in the cookie banner: 1. Necessary, 2. Functional, 3. Analytics and 4. Marketing.
The purposes for which they are used, and the entities that use them, are set out in detail below. Each of these entities also sets its own privacy rules; links to the rules of the individual providers can also be found in this document. The Controller encourages you to read them.
The following Cookies are used:
| Cookie name | Lifetime | Purpose | First-party or third-party | Provider | Category |
|---|---|---|---|---|---|
| heyhey-session | 2 hours | Maintaining the user session and making the Service work correctly. | First-party | heyhey (heyhey.ae, the heyhey dashboard) | Necessary |
| XSRF-TOKEN | 2 hours | Protecting forms against CSRF attacks. | First-party | heyhey (heyhey.ae, the heyhey dashboard) | Necessary |
| remember_web_* | Up to 1 year | Remembering a logged-in user (the “remember me” feature). | First-party | heyhey (the heyhey dashboard) | Functional |
| heyhey_consent | 1 year | Remembering the user’s cookie consent preferences. | First-party | heyhey (heyhey.ae) | Necessary |
| __cf_bm | 1 hour | Supporting bot protection by Cloudflare Bot Management. | Third-party | Cloudflare | Necessary |
| _ga | 2 years | Distinguishing users for Google Analytics 4 statistics (if enabled, only with the user’s consent). | Third-party | Analytics | |
| _ga_* | 2 years | Maintaining the state of the Google Analytics 4 measurement session (if enabled, only with the user’s consent). | Third-party | Analytics |
Detailed information on the options for, and ways of, handling Cookies is available in the settings of the software (web browser) used by each user of the Service. Additional information about cookie categories and managing consent can also be found in the Cookie policy.
Personalised advertising
Cookies may be used by advertising networks, in particular the Google network, to display ads tailored to the preferences of the user (a visitor to the Service), including personalised ads. For this purpose, information may be retained, in particular about how the user moves around the web, the search terms they use and when they used the website.
Personalised ads (sometimes also called interest-based ads) are tools that can make ads better matched to the user’s preferences and interests.
Editing, enabling and blocking Cookies
To view and edit information about preferences collected by the Google advertising network, each user can use the tools available at google.com/ads/preferences and policies.google.com/technologies/partner-sites.
Using the settings of the web browser they use, or through the configuration of the service, the user can change the Cookie settings themselves at any time, specifying the conditions for storing Cookies and for Cookies accessing their device. The user can change these settings to block the automatic handling of Cookies in the web browser settings or to be informed each time Cookies are placed on their device. On the Service, cookie preferences can be changed at any time using the “Cookie settings” link in the website footer.
The user can also disable or withdraw consent to the use of Cookies of external providers, as well as remarketing pixels, using the Network Advertising Initiative tool at: optout.networkadvertising.org.