European Cookie & Privacy Policy — Full Legal Version (GDPR & ePrivacy Compliant)
Comprehensive, Formal, Lawyer-Level Draft
1. Introduction
This European Cookie & Privacy Policy (“Policy”) describes how we collect, process, store, and safeguard personal data when you access or use our website (“Website”).
We are committed to full compliance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)
- Directive 2002/58/EC (ePrivacy Directive)
- Applicable national data protection laws within the European Economic Area (EEA)
This Policy forms part of our general Terms of Service.
By using our Website, you acknowledge and agree to the terms of this Policy unless you choose to modify your consent preferences.
2. Data Controller Information
We act as the Data Controller for all personal data processed through this Website.
Company Name: [Insert legal entity]
Registered Address: [Insert address]
Email for Data Protection Inquiries: [Insert email]
Data Protection Officer (if applicable): [Insert DPO name/contact]
Where legally required, we maintain a Register of Processing Activities (ROPA) pursuant to Article 30 of the GDPR.
3. Categories of Personal Data Processed
3.1 Data Provided Directly by Users
This includes, but is not limited to:
- Full name
- Email address
- Phone number
- Company or organization name
- Inquiry details submitted via forms or email
- User-generated content
3.2 Automatically Collected Data
When you visit the Website, we may collect:
- IP address (with anonymization where applicable)
- Browser type and version
- Device type
- Operating system
- Referrer URLs
- Date and time of access
- Pages viewed and interactions
- Session identifiers
3.3 Cookies, Pixels & Tracking Technologies
We use:
- HTTP cookies
- Local storage
- Session storage
- Tracking pixels
- Analytics scripts
- Advertisement identifiers
A detailed list is available in Section 4: Cookie Categories.
4. Cookie Categories & Definitions
4.1 Strictly Necessary Cookies
Essential for core Website functionality (security, authentication, session management).
These cookies do not require consent under the ePrivacy Directive.
4.2 Performance & Analytics Cookies
Used to understand user behavior and improve Website functionality.
Examples include:
- Google Analytics with IP anonymization
- Server-side analytics
Requires user consent in the EU.
4.3 Functional Cookies
Support features such as:
- Remembering language preferences
- Saving login sessions (user-initiated)
- Enhancing user interface behavior
Requires consent unless strictly necessary.
4.4 Advertising & Marketing Cookies
Used for:
- Behavioral advertising
- Audience segmentation
- Conversion tracking
- Retargeting campaigns
Examples:
Meta Pixel, Google Ads, TikTok Pixel, programmatic ad trackers.
Explicit opt-in consent required.
4.5 Third-Party Cookies
Placed by:
- Analytics platforms
- Social media networks
- Advertising networks
- Embedded content providers (e.g., YouTube, Maps)
Third parties act as Independent Controllers or Joint Controllers, depending on the service.
5. Legal Basis for Processing (GDPR Art. 6)
We process personal data based on:
- Consent — user-initiated consent for analytics and marketing
- Legitimate Interest — Website optimization, security, fraud prevention
- Contract Performance — when responding to contact requests
- Legal Obligation — compliance with EU or national regulations
- Vital Interest — rare and only for safety-related situations
For cookies and tracking technologies, consent is required except for strictly necessary cookies.
6. Purposes of Processing
Personal data may be used for:
- Providing and maintaining the Website
- Enhancing user experience and Website performance
- Conducting analytics and statistical reporting
- Preventing fraud and ensuring security
- Responding to inquiries and support requests
- Running marketing, advertising, and remarketing campaigns (with consent)
- Legal compliance and dispute resolution
We do not sell personal data.
7. Data Retention Policy
We retain personal data only as long as necessary for the purposes described in this Policy:
- Contact form submissions: up to 24 months
- Analytics data: 14–26 months (depending on provider settings)
- Marketing data: until consent withdrawal
- Technical logs: 30–180 days
- Cookie identifiers: per cookie lifespan (see Cookie Settings)
We apply data minimization and pseudonymization where appropriate.
8. Data Sharing & International Transfers
We may share personal data with:
- Hosting providers & cloud infrastructure
- Analytics platforms
- Marketing & advertising partners
- Security and anti-fraud services
- CRM or email delivery platforms
If data is transferred outside the EEA, we safeguard it under:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions (e.g., UK, Canada)
- Binding Corporate Rules (BCRs)
- Other GDPR-approved protection measures
We require all processors to sign a Data Processing Agreement (DPA).
9. Profiling & Automated Decision-Making
We may use automated tools for:
- Personalized content
- Advertisement targeting
- Audience segmentation
We do not engage in automated decision-making that produces legal or significant effects on users as defined by GDPR Article 22.
10. Your Rights Under GDPR
You may exercise the following rights at any time:
- Right to Access personal data
- Right to Rectification of inaccurate data
- Right to Erasure (“Right to be Forgotten”)
- Right to Restrict Processing
- Right to Data Portability
- Right to Object to processing
- Right to Withdraw Consent at any time
- Right to Lodge a Complaint with an EU Supervisory Authority
To exercise these rights:
Email: [Insert data protection email]
We respond within 30 days, extendable to 90 days for complex cases.
11. Cookie Consent Banner & Management
A cookie banner is displayed upon first visit, allowing users to:
- Accept all cookies
- Reject all non-essential cookies
- Customize preferences by category
Consent is stored in compliance with:
- GDPR
- ePrivacy Directive
- CNIL guidelines (France)
- ICO recommendations (UK)
- EDPB guidelines
Users can modify consent at any time via Cookie Settings.
12. Security Measures
We implement industry-standard safeguards, such as:
- SSL/TLS encryption
- Firewalls & monitoring systems
- Access control & authentication
- Data pseudonymization and hashing
- Secure data backups
- Regular security audits & DPIA (where required)
13. Updates to This Policy
We may modify this Policy at any time to reflect:
- Legal changes
- Industry standards
- Technical updates
- New services or features
Latest revision date: 11/12/2025