Cookie Policy & Inventory
This Cookie Policy and Inventory explains how AITA World, S.L. ("AITA", "we", "us", or "our"), with registered office at Sabino Arana 8, 2º, 48013 Bilbao, Bizkaia, Spain, tax identification number (CIF) B75859744, uses cookies and similar client-side tracking technologies on the website aita.world and its sub-domains (the "Website").
This Policy is issued in compliance with Article 22.2 of Spanish Law 34/2002 on Information Society Services and E-Commerce (LSSI-CE), Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), and Spanish Organic Law 3/2018 (LOPDGDD), following the guidelines of the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD).
It complements our Privacy Policy and Website Terms of Use.
1. What Are Cookies and Similar Technologies
A cookie is a small text file placed on your device by a website to store information about your visit. We treat as "cookies" — subject to the same legal rules — comparable technologies, including:
- HTML5 local storage and session storage;
- pixels, web beacons, and tracking GIFs;
- fingerprinting based on device, browser, network, or hardware characteristics;
- software development kits (SDKs) embedded in our content;
- external network resources (such as external webfont CDNs) that receive your IP address upon request.
2. Why We Use Cookies
We use cookies and client-side storage to:
- Ensure Website Operation: Load pages, route network traffic, remember UI language choices, and secure restricted areas.
- Remember Preferences: Store your cookie consent choices and display settings.
- Analytics and Performance: Understand how visitors interact with the Website in aggregate to optimize user experience and fix technical errors.
- Security: Detect and prevent bot traffic, fraud, and security incidents.
- Marketing and Attribution: Measure the performance of our professional communication and B2B marketing campaigns (loaded strictly after explicit consent).
We do not sell personal data collected through cookies to third parties.
3. Categories of Cookies We Use
3.1. Strictly Necessary
Required for the Website to function securely and properly (e.g., bot protection, edge routing, storing cookie consent options). These do not require user consent under Art. 22.2 LSSI-CE.
3.2. Analytics and Product Improvement
Help us analyze visitor statistics, session behavior, and error logs (e.g., Microsoft Clarity). Loaded only after explicit consent.
3.3. Marketing and Attribution
Placed by third-party tools to measure campaign performance and conversion attribution (e.g., LinkedIn Insight Tag, Google Ads). Loaded only after explicit consent.
3.4. External Resources Transmitting Personal Data
Third-party hosted resources (e.g., Google Fonts) that transmit your IP address to external servers when requested. Loaded only after explicit consent; if consent is refused, the Website automatically falls back to self-hosted assets (fonts.css).
4. Legal Basis
- Strictly Necessary Cookies: Legitimate interest in operating a secure and functional website (Art. 6(1)(f) GDPR) and exemption under Art. 22.2 LSSI-CE.
- Analytics, Marketing & External Resources: Explicit user consent (Art. 6(1)(a) GDPR) obtained via the cookie banner prior to script execution.
5. Cookie Consent Mechanics and Your Rights
5.1. Cookie Banner: On your first visit, the banner displays three equally prominent options: Accept all, Reject all, and Configure. Prior to your choice, only Strictly Necessary cookies are active.
5.2. No Pre-ticked Boxes: Granular preferences do not use pre-checked boxes.
5.3. No Cookie Walls: Access to public website content is never restricted if you refuse non-essential cookies.
5.4. Withdrawing Consent: You can change or withdraw consent at any time via the "Cookie preferences" link located in the Website footer.
5.5. Consent Record: We retain a record of your consent choices (categories accepted/refused, timestamp, policy version) for up to 24 months for compliance and evidentiary purposes.
5.6. Global Privacy Control (GPC): We automatically honor browser-level Sec-GPC: 1 signals as an opt-out choice for non-essential cookies.
6. Itemised Cookie Inventory
The table below lists the specific client-side technologies deployed across aita.world and its sub-domains. The identity of each third-party provider acting as a processor or subprocessor is listed at aita.world/legal/subprocessors.
6.1. Strictly Necessary (Always Active)
| Name | Provider | Type | Purpose | Duration | Safeguard / Transfer |
|---|---|---|---|---|---|
__cf_bm |
Cloudflare, Inc. (USA) | cookie | Bot management and security evaluation | 30 minutes | DPF + SCC (USA) |
cf_clearance |
Cloudflare, Inc. (USA) | cookie | Records completion of security challenges | 30 days | DPF + SCC (USA) |
_vcrcs |
Vercel Inc. (USA) | cookie | Deployment edge-routing and caching | Session | DPF + SCC (USA) |
aita_consent |
AITA World, S.L. | cookie / localStorage | Stores user cookie consent choice and log | 24 months | EEA (No transfer) |
6.2. Analytics and Performance (Opt-in Only)
| Name / Tag | Provider | Type | Purpose | Duration | Safeguard / Transfer |
|---|---|---|---|---|---|
_clck |
Microsoft Corp. (USA) — Clarity | cookie | Persists user ID across sessions (v4y0cwaq68) |
1 year | DPF + SCC (USA) |
_clsk |
Microsoft Corp. (USA) — Clarity | cookie | Connects session events into a unified stream | 1 day | DPF + SCC (USA) |
CLID / MUID |
Microsoft Corp. (USA) — Clarity | cookie | Anonymous identifier for system health & analytics | 1 year | DPF + SCC (USA) |
Clarity configuration: Sensitive form inputs are masked by default. Data retention on Microsoft servers is 13 months.
6.3. Marketing and Campaign Attribution (Opt-in Only)
| Name / Tag | Provider | Type | Purpose | Duration | Safeguard / Transfer |
|---|---|---|---|---|---|
li_sugr / UserMatch |
LinkedIn Corp. (USA) — LinkedIn Insight Tag | cookie / pixel | B2B ad campaign measurement and conversion tracking | 90 days | DPF + SCC (USA) |
_gcl_au |
Google LLC (USA) — Google Ads | cookie / pixel | Conversion attribution for commercial inquiries | 90 days | DPF + SCC (USA) |
6.4. External Network Resources (Opt-in Only)
| Resource | Provider | Purpose | Fallback if Refused | Safeguard / Transfer |
|---|---|---|---|---|
Google Fonts (fonts.googleapis.com) |
Google LLC (USA) | Brand webfonts (Inter, Golos Text) | Self-hosted fonts.css (No data transfer) |
DPF + SCC (USA) |
6.5. Client-side Storage on Platform (app.aita.world)
Platform zone — strictly necessary authentication & operational state only.
| Key | Storage | Purpose | Duration | Category |
|---|---|---|---|---|
accessToken |
localStorage |
Short-lived JWT session authentication token | Session | Strictly Necessary |
refreshToken |
localStorage |
Long-lived refresh token for authorization | Persistent | Strictly Necessary |
aita-lang |
localStorage |
User UI language preference | Persistent | Strictly Necessary |
7. International Data Transfers
Where third-party cookie providers process data outside the European Economic Area (EEA), transfers are conducted under European Commission adequacy decisions (including the EU–U.S. Data Privacy Framework) or standard contractual clauses (SCCs) pursuant to Commission Decision (EU) 2021/914.
8. Contact Information
If you have questions regarding this Cookie Policy or wish to exercise your data rights:
privacy@aita.world — AITA World, S.L., Sabino Arana 8, 2º, 48013 Bilbao, Bizkaia, Spain.Supervisory authority: Agencia Española de Protección de Datos (AEPD) (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid).