Noetis — Cookie & Similar Technologies Policy
Version 2.0 · Effective date: to be announced upon release · Last updated: to be announced upon release
This Policy explains the use of cookies, local storage and similar technologies by Noetis.
1. Scope
This Policy primarily governs Noetis's own marketing website and application.
Where Noetis technology operates on a Customer Property, Noetis generally processes relevant information on behalf of the website operator. The operator is responsible for its own cookie notice, consent mechanism and legal basis.
2. Necessary technologies
Technologies strictly necessary to provide functionality expressly requested by a user may be used without consent where permitted by applicable law.
These may support:
- authentication;
- security;
- session continuity;
- load balancing;
- fraud prevention;
- storing privacy choices.
3. Non-essential technologies
Where required by law, non-essential technologies are activated only after valid consent.
These may include technologies used for:
- analytics;
- behavioural measurement;
- Visitor Intelligence;
- cross-session recognition;
- Personalisation;
- experimentation;
- attribution;
- marketing.
4. Visitor Intelligence on Customer Properties
Where Customer has lawfully enabled the relevant functionality, Noetis may use a pseudonymous Visitor Identifier or similar storage technology to associate behaviour across sessions.
This may enable the Customer to:
- recognise a returning Visitor;
- understand prior interactions;
- infer likely interests;
- personalise eligible website content;
- measure experiment outcomes.
A pseudonymous identifier is not necessarily anonymous data.
5. Consent
Where consent is required, it must be obtained before the relevant non-essential technology is activated.
Consent should be:
- freely given;
- specific;
- informed;
- unambiguous;
- based on affirmative action;
- withdrawable.
For processing configured as consent-dependent, only a supported affirmative consent state may activate the relevant technology. An unknown, missing, malformed, rejected or withdrawn consent state does not count as consent.
Customer is responsible for configuring its own consent interface and communicating supported consent signals to Noetis. A technical consent state received by Noetis is distinct from legal evidence of consent, which remains Customer's responsibility to maintain or ensure where required.
6. Refusal
Customer shall not configure Noetis to treat:
- inactivity;
- silence;
- continued browsing alone; or
- an unticked/ignored choice
as an affirmative consent signal where affirmative consent is legally required.
7. Withdrawal
Users must be able to withdraw consent as easily as required by applicable law.
Where a supported withdrawal reaches Noetis, consent-dependent tracking and cross-session Visitor Intelligence shall cease for the relevant identifier in accordance with the DPA: consent-dependent recognition, profile enrichment, inference and Personalisation for that identifier stop; background processes do not silently reactivate the withdrawn processing; historical data is not used to silently reconstruct the withdrawn profile; and a return visit does not by itself reactivate the withdrawn purpose. Where consent is legally required, a new valid affirmative consent is required before that processing may resume.
8. Session recordings
Where enabled, Noetis may provide session-recording functionality.
Noetis may provide masking, blocking, exclusion or similar controls intended to prevent designated sensitive fields, such as password and payment inputs, from being captured.
Customer remains responsible for testing its website, configuring forms, selectors, available exclusion/masking controls and Customer Properties appropriately before enabling recordings in production, and for determining whether recordings may lawfully be used.
Customer must not intentionally configure recording of passwords, payment-card numbers, CVVs or security codes, authentication secrets, government identifiers, special-category Personal Data, criminal-conviction data, or other information whose recording would be unlawful or disproportionate.
9. Customer CMP
Noetis may integrate with Customer consent-management mechanisms.
Noetis is entitled to rely on consent states received through supported technical integrations unless it has reason to know they are invalid.
Noetis does not warrant that Customer's CMP, banner wording or consent design complies with applicable law.
10. No cross-customer advertising tracking
Noetis does not use Visitor Intelligence to create a cross-customer advertising identity graph for targeting individuals across unrelated Customer Properties.
11. Noetis's own cookies
The exact technologies used on Noetis's own Sites, their providers, purposes and retention periods should be maintained in the live cookie-preference interface.
That live list should be treated as the authoritative operational inventory.
12. Changes
Noetis may update this Policy as technology and law change.
Where legally required, Noetis will request renewed consent for materially different processing on its own Sites.
Contact: chris@noetis.nl