Cookie Policy
Last updated: September 16, 2026
Cookies and Other Tracking Tools
This section describes the types of cookies and other tracking tools (pixel cookies, web beacons, device identifiers, localStorage) used on the Site, implementing the Guidelines of the Italian Data Protection Authority of 10 June 2021 and art. 122 of Legislative Decree 196/2003 as amended.
The cookies and other tracking tools used by the Site fall, according to the purpose pursued, into the following categories; the tools actually active on this Site, with their purpose and duration, are listed in the sections below:
- Technical cookies (necessary): indispensable for the operation of the Site or for the services requested by the user (session, authentication, security, storage of the cookie choice). They are installed by the Controller, either directly or through providers acting as processors, and do not require prior consent under art. 122(1) of the Italian Privacy Code.
- Functionality and experience cookies: they store user choices (language, light/dark theme, interface preferences, embedded media content) in order to offer additional features. They qualify as technical cookies where they give effect to a choice expressed by the user in order to provide the requested service; they require prior consent where they are not strictly necessary for that service.
- Analytics/statistical cookies: they collect information on the use of the Site. They require prior consent, unless the tool is configured so as to be assimilable to technical cookies under the Garante Guidelines of 10 June 2021 (truncated IP address, no cross-linking with other processing, no sharing with third parties, use limited to this Site alone).
- Profiling/marketing cookies: they create profiles on the user to show personalised advertising and targeted content. They require explicit and granular prior consent.
Consent banner: on first access to the Site a banner is displayed allowing the user to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing), with three equally prominent actions (Garante 2021 + EDPB Guidelines 03/2022). The choice made is stored on the user's device for the period indicated in the technical cookies table; in line with the Italian Data Protection Authority's Guidelines of 10 June 2021, the banner is not shown again before six months have elapsed since it was last displayed, unless the user clears their browsing data or changes their preferences.
The user can change or withdraw consent at any time, through the cookie preferences control available on the Site or from the browser settings. For details of each identifier used, including how long the expressed preference is stored, please refer to the tables in the sections below.
First-party Technical Cookies and Identifiers
The Site uses cookies and identifiers strictly necessary for its operation. These technical identifiers are installed by the Controller, either directly or through providers acting as processors, and do not require the data subject's consent, in accordance with Art. 122(1) of Italian Legislative Decree 196/2003 and the Italian DPA Guidelines of 10 June 2021.
The table below describes the technical identifiers by the function they perform: the actual names depend on the platform the Site is built with and on the services enabled, and those shown in brackets are only common examples.
| Identifier | Type | Purpose | Duration |
|---|---|---|---|
| Application session (e.g. session_id, PHPSESSID) | cookie | Ensures the basic operation of the Site while browsing | Browser session |
| Language preference (e.g. locale, lang) | cookie | Stores the language selected by the user | Up to 1 year |
| Theme preference (e.g. theme, color-scheme) | cookie | Stores the light/dark theme preference | Up to 1 year |
| Record of the cookie choice (e.g. cookie_consent, possibly with a Site identifier suffix) | cookie or localStorage | Records the choice expressed by the user in the banner | Until the choice is renewed or manually deleted |
| Technical browser identifier (e.g. visitor_uid) | cookie or localStorage | Random client-side identifier which does not by itself reveal the user's identity and is used to associate the consent record with the visitor: it qualifies as an online identifier under Art. 4(1) GDPR | Until manual deletion |
| Anti-CSRF protection (e.g. csrf_token) | cookie | Protection against cross-site request forgery attacks (security) | Session |
Server-side consent record: where the Site keeps proof of the choice expressed in the banner, the record (accepted or rejected categories, technical visitor identifier, date and time, source) is transmitted to the Controller and stored in its compliance infrastructure for as long as necessary to discharge the burden of proof of consent (Art. 7.1 GDPR), within the periods set out in the section on retention periods. The record contains no directly identifying data, only the technical browser identifier: it is therefore pseudonymous, not anonymous, data.
Note: the table describes the technical identifiers according to the function they perform. The list of the names actually used on the Site at the time of the visit may be requested at any time from the Controller at the contact details set out in this notice.
To disable technical identifiers, the user must act directly on the browser settings. Disabling them may impair the operation of the Site.
Consent management and withdrawal
On first access to the Site, a banner is shown that allows you to accept, refuse or customise the use of non strictly necessary cookies (functionality, analytics and marketing). Strictly technical cookies are installed regardless of consent, in compliance with art. 122(1) of Italian Legislative Decree 196/2003 and the Italian Data Protection Authority guidelines of 10 June 2021.
The data subject may modify or withdraw consent at any time:
- by using the cookie preferences control available on the Site;
- by deleting cookies already installed from the browser settings (the procedure varies depending on the browser).
Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before the withdrawal (art. 7.3 GDPR).
Proof of consent (art. 7.1 GDPR): depending on the platform the Site is built with, the choice expressed in the banner may be stored solely on the user's device or also kept server-side for evidentiary purposes. In the latter case the data stored is: random browser identifier (UUID), chosen cookie categories, date and time, cryptographic hash of the user-agent, country of origin (no full IP address). No directly identifying data is stored or shared with third parties (name, email address, IP address): the record relates to the browser only and constitutes pseudonymous, not anonymous, data. It is kept for as long as necessary to discharge the burden of proof, within the periods set out in the section on retention periods, after which it is deleted.
Local Storage (localStorage and sessionStorage)
The Site uses browser-side storage technologies (localStorage and sessionStorage) to provide the requested functionalities and improve the user experience. These technologies are equated with cookies under Art. 122(1) of Italian Legislative Decree 196/2003: where they are not strictly necessary for the service requested by the user, their use requires consent under Art. 6.1.a GDPR and the aforementioned Art. 122.
The keys actually present depend on the platform the Site is built with and on the features enabled; locally stored data typically includes:
- Light/dark theme;
- User selected language;
- Layout and interface arrangement preferences;
- User cookie consent state (where the Site keeps proof of consent, a copy is retained server-side — see the technical cookies section);
- Application session data (partially filled forms, operations in progress);
Most of this data stays on the user device and is not transmitted to the Controller. The only exceptions — expressly declared — are the consent record (where replicated server-side for the burden of proof under Art. 7.1 GDPR) and, where enabled, compliance telemetry (see dedicated clause).
Local data remains stored until it is manually deleted from the browser settings, through the browsing data deletion feature, or, where the Site provides for it, through the dedicated local data deletion control.
Google Tag Manager (GTM)
Provider: Google Ireland Ltd (Ireland) — parent company Google LLC (USA).
Purpose: orchestration and conditional loading of analytics, marketing and functional tags (e.g. GA4, Meta Pixel) on the Site.
Data processed: loading of the GTM container transmits to Google servers the user's IP address, user-agent and page URL, even before activation of specific tags.
Retention: Google Cloud logs as per provider policies (typically 14-30 days for network logs).
Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent of the data subject under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected via the cookie banner before loading the container. The qualification as "technical processing exempt from consent" has been superseded by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231), which require prior consent for any identifier not strictly necessary for Site operation.
Provider privacy policy: business.safety.google/privacy
Google Analytics 4 (Google Ireland Limited)
We use Google Analytics 4 to analyse the use of the Site in aggregated form, identify areas for improvement and optimise user experience.
- Purpose: statistical analysis of traffic and user behaviour
- Data collected: device identifiers, IP address (masked by Google, not stored in clear text for GA4 properties), pages visited, dwell time, interactions, custom events
- Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003: the service is activated only after consent, because not all the minimisation conditions required by the Italian DPA's cookie Guidelines of 10 June 2021 (decision no. 231) in order to treat analytics cookies as technical cookies are met
- Retention: 14 months (GA4 property setting)
- Configuration: single domain, no cross-site tracking; the "Google Signals" and "Data Sharing > Modeling" options are disabled, to avoid mixing with advertising profiling purposes that would require separate consent
- Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
- Provider privacy policy: policies.google.com/privacy
Meta Pixel (Facebook / Instagram)
Provider: Meta Platforms Ireland Limited (Ireland) — parent Meta Platforms Inc. (USA).
Purpose: remarketing, conversion measurement, Facebook/Instagram Ads campaign optimisation.
Data collected: cookie identifiers (_fbp, _fbc), pages visited, conversion events, IP address.
Retention: 90 days (cookie _fbp); data processed by Meta is retained according to the provider's policies.
Roles: for the collection and transmission of data through the pixel, the Controller and Meta act as joint controllers pursuant to art. 26 GDPR (see CJEU, case C-40/17, Fashion ID); Meta's subsequent processing for its own purposes remains its exclusive responsibility. The essence of the joint controllership arrangement is made available to the data subject by the provider.
Transfer: data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent pursuant to art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003, collected through the cookie banner before the pixel is activated. Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7(3) GDPR).
Provider privacy policy: facebook.com/privacy/policy
YouTube (embedded videos)
Provider: Google Ireland Limited (Ireland) — parent: Google LLC (USA).
Purpose: playback of YouTube videos embedded in Site pages.
Data collected: IP address, video viewing data, cookie identifiers (VISITOR_INFO1_LIVE, YSC, PREF), user-agent. If the user is logged into Google, additional data may be associated with the account.
Retention: VISITOR_INFO1_LIVE 180 days, YSC session, PREF up to 24 months, per provider policy.
Transfer: United States (Google LLC). Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: prior consent under art. 6(1)(a) GDPR and art. 122(1) of Italian Legislative Decree 196/2003; without consent the video is not loaded. The Site uses privacy-enhanced mode (youtube-nocookie.com) where possible.
Privacy policy: policies.google.com/privacy
Vercel (hosting platform)
Provider: Vercel Inc. (USA).
Purpose: Site hosting, content delivery via CDN, prevention of abusive traffic (rate limiting, anti-DDoS).
Data processed: IP address, user-agent, HTTP request logs. No tracking cookies installed on the browser.
Retention: access logs kept for a period normally not exceeding 30 days, according to the hosting provider's settings.
Transfer: data may be transferred to the United States. Where the provider adheres to the EU-US Data Privacy Framework, the transfer is based on the relevant adequacy decision of the European Commission (Article 45 GDPR); otherwise, or should that decision cease to apply, the Standard Contractual Clauses under Article 46 GDPR with supplementary measures apply.
Legal basis: legitimate interest of the Data Controller in the provision, security and stability of the service (art. 6.1.f GDPR, see Recital 49).
Provider privacy policy: vercel.com/legal/privacy-policy
Brevo SAS (formerly Sendinblue)
We use Brevo as a provider for transactional emails (confirmations, service notifications) and, subject to consent, for email marketing and newsletters. Brevo acts as Data Processor under art. 28 GDPR.
- Purpose: sending transactional emails and, with consent, promotional communications and newsletters
- Data collected: email address, name, opening and click events of the messages sent
- Tracking pixels in emails: messages may contain tracking pixels, i.e. invisible images that detect the opening of the message and clicks on links, in order to measure the effectiveness of the communications and interest in the content offered. Storing and reading them on the recipient's device requires consent under art. 122(1) of the Italian Privacy Code (Legislative Decree 196/2003)
- Legal basis: performance of the contract for sending transactional emails (art. 6.1.b GDPR); consent for promotional communications (art. 6.1.a GDPR); consent for the tracking of openings and clicks (art. 6.1.a GDPR and art. 122(1) of the Italian Privacy Code)
- Withdrawal of consent: Consent may be withdrawn at any time and as easily as it was given, and withdrawal does not affect the lawfulness of processing carried out before it (art. 7.3 GDPR). Withdrawal may also cover tracking alone, while still receiving the messages: simply write to the Data Controller at the contact details given in this notice; to stop all mailings, the unsubscribe link is available at the bottom of every email
- Retention: until unsubscription and in any case no longer than the term set out for marketing purposes in the section of this notice devoted to retention periods; the record evidencing the consent given (art. 7.1 GDPR) is kept in minimised form for the period indicated in the section of this notice devoted to retention periods
- Transfer: The provider states that it processes data on infrastructure located in the European Union; any transfers to third countries are covered by the safeguards under Chapter V GDPR.
- Provider privacy policy: brevo.com/legal/privacypolicy
How to manage preferences
You can manage your cookie preferences in two ways:
- From the Site: use the cookie preferences control available on the Site to reopen the choice panel.
- From your browser settings (the paths indicated may vary depending on the version installed):
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings (or Preferences) → Privacy → Cookies and website data
- Microsoft Edge: Settings → Privacy, search and services → Cookies
For newsletters and promotional emails: use the unsubscribe link at the bottom of every message, or write to the Controller at the contact details given in this notice.
Note: disabling first-party technical cookies may prevent the Site from functioning correctly (e.g. language persistence, cart session).
Additional opt-out tools for advertising networks:
- EDAA advertisers: youronlinechoices.eu
- Google Ads: adssettings.google.com
- Meta (Facebook/Instagram): facebook.com/settings/ads
Contacts for cookie questions
For any question about cookie usage on this site:
- Email: social@detassis.it
- Address: Via IV Novembre 93/1, 38121 Trento (TN)
For more details on data processing collected via cookies, see the Privacy Policy of the site.