Website privacy

Cookie and Similar Technologies Policy

The browser technologies used by ICEQC, their purposes, duration, providers and available controls.

Privacy controls for a secure digital service

1. Scope and relationship to the Privacy Notice

This Policy applies to cookies, local storage and comparable technologies used on the official public website at iceqc.org and describes relevant technologies used on the ICEQC application centre at portal.iceqc.org. It identifies the current public-site configuration, explains the function and duration of each category and states how a visitor can exercise a choice.

The Data Protection and Privacy Notice identifies the controller, personal-data categories, purposes, recipients, international transfers, retention rules and individual rights. This Policy should be read with that Notice. A payment or other provider’s website is governed by that provider’s own cookie and privacy information once the user leaves an ICEQC domain.

2. What these technologies are

Cookie

A small text record that a website asks a browser to store. The browser may return it with later requests to the relevant domain, subject to its attributes and expiry.

Local storage

Browser storage associated with an origin. Unlike a cookie, a local-storage value is not automatically transmitted with every web request; page code reads it when needed.

Session and security token

A value used to maintain an authenticated or transaction state, prevent request forgery, validate a security challenge or bind an action to the correct session.

Pixel, tag or software development kit

Code that can cause information about a page, device or interaction to be sent to another service. The public ICEQC website does not currently deploy advertising pixels, social-media tracking tags or an audience-measurement service.

3. Current public-website position

The public website currently uses only the first-party local-storage item described below and security technologies that Cloudflare may activate when needed to protect the service. ICEQC does not currently use optional audience-measurement, behavioural advertising, cross-site profiling or embedded social-media technologies on the public website.

Because no optional category is active, the English privacy control records acknowledgement of the current notice and provides access to the settings inventory; it does not ask the visitor to consent to a dormant service. If ICEQC later proposes an optional technology, it will identify the provider, purpose and material duration, update the policy version and obtain any choice required by applicable law before activating that technology for the visitor.

4. Strictly necessary first-party storage

Name

iceqc.privacy-choice

Technology and party

First-party local browser storage set for the ICEQC public-site origin.

Data stored

Policy version, necessary-technology status, any category state supported by that policy version, and the date and time at which the choice or acknowledgement was recorded.

Purpose

To remember that the privacy notice has been addressed, restore the applicable settings and avoid presenting the same initial notice on every page.

Duration

Treated by the website as expired 180 days after it is recorded, or earlier when the policy version changes. The browser may retain the physical value until the website overwrites it or the user clears site data.

Legal character

This storage supports the operation of the privacy control. It is not used for advertising, cross-site tracking or audience measurement and is not treated as consent to unrelated personal-data processing.

5. Cloudflare security technologies

ICEQC uses Cloudflare to deliver and protect its websites and application services. When an applicable challenge, bot-management, rate-control or security rule is triggered, Cloudflare may place a strictly necessary cookie such as cf_clearance, __cf_bm or a successor security value. The precise cookie depends on the protection invoked and may not appear during an ordinary visit.

Security challenge state

May retain evidence that a browser successfully completed a challenge so the challenge need not be repeated for every protected request.

Bot and abuse management

May help distinguish legitimate requests from automated or abusive traffic and preserve service availability.

Duration and access

Security values are normally short-lived and are controlled by the applicable Cloudflare product configuration. Cloudflare processes associated network and device signals as an ICEQC provider and, for processing it independently determines, under its own privacy terms.

6. Account and application-centre technologies

The application centre uses security and session mechanisms necessary to authenticate users, preserve the integrity of forms, prevent cross-site request forgery, enforce access permissions and protect application and evidence records. Some values may be held in secure, HTTP-only cookies that page scripts cannot read; others may be carried in a form or request for the limited security purpose for which they were issued.

An authenticated service cannot operate without its necessary session and anti-forgery controls. Disabling them may prevent sign-in, registration, password recovery, form submission, evidence upload or account administration. They are not used to create an advertising profile.

7. Payment-service technologies

Where online card payment is available, selecting the payment action redirects the user to a Stripe-hosted Checkout page. Stripe may use cookies and similar technologies required to provide the payment page, authenticate the transaction, prevent fraud, remember transaction state and comply with legal duties. Stripe’s website and processing are governed by its current privacy and cookie information.

ICEQC does not load Stripe Checkout invisibly on the public website and does not receive the full card number or card security code. The return to the ICEQC application centre does not itself establish that payment succeeded; the invoice record is updated only after the payment event is securely confirmed and reconciled.

8. Optional audience measurement

No audience-measurement service is currently active on the public website. ICEQC therefore does not set an analytics cookie, create a visitor identifier for measurement or permit a measurement provider to collect public-site interactions under this category.

If this category is introduced, its sole stated function will not be assumed from the category name. The updated inventory will identify the provider, data, purpose, duration, recipients and applicable transfer information. It will remain inactive until the legally required choice has been obtained, and access to public information will not be conditional on accepting it unless the law permits and the service genuinely requires it.

9. Optional external content

No optional third-party media, social feed, map or comparable external-content service is currently embedded on the public website. Ordinary external links do not cause the destination provider to set its cookies on iceqc.org. The destination’s technologies apply only after the visitor follows the link or otherwise requests that external service.

If optional embedded content is introduced, ICEQC will block the provider connection until the applicable choice is made, unless loading is strictly necessary for a service expressly requested by the user or another lawful exception applies. The control will identify the consequence of enabling the content, including transfer to the provider.

10. No advertising or sale of browser data

ICEQC does not use public-site cookies or local storage to deliver behavioural advertising, sell browser histories, participate in cross-site advertising auctions or permit a social-media platform to build an interaction profile through an embedded tracking pixel. This statement describes the current ICEQC configuration and does not govern information that an external website independently receives after a visitor chooses to leave iceqc.org.

11. Legal basis and consent standard

Strictly necessary technologies are used to deliver a service expressly requested by the user, secure the service, prevent misuse, maintain an authenticated or transaction state and remember the privacy control. ICEQC relies on the applicable statutory permission and its proportionate interest in secure service operation rather than presenting these functions as optional consent.

For a non-essential technology, ICEQC obtains prior consent where required by the law applicable to the visitor or processing. Consent must be specific, informed, freely given and capable of withdrawal. Continuing to browse, silence or failure to change a browser default is not treated as affirmative consent where affirmative consent is required.

12. Using Cookie settings

  • Open Cookie settings from the footer of any public page to review the current categories and status.
  • The English control currently shows that optional audience measurement and external content are not in use; there is therefore no optional activation switch to save.
  • Acknowledging the notice stores the current policy version and time for 180 days. It does not waive a data-protection right or approve future optional technologies.
  • If an optional category is later introduced, refusing it will be as accessible as accepting it, category controls will not use preselected consent, and withdrawal will stop future optional use for that browser.
  • A choice applies to the browser and site origin in which it is stored. It does not automatically follow the person to another browser, device or cleared browsing profile.

13. Browser and device controls

A user can inspect, block or delete cookies and local storage through browser or device settings. Private-browsing modes may remove values when the session ends. Browser controls may not distinguish an essential security value from an optional value by purpose, and blocking all storage can prevent protected or authenticated services from functioning.

Global privacy signals and browser preference mechanisms are assessed according to their technical meaning and applicable law. A signal cannot disable a technology that is strictly necessary to provide a specifically requested secure function, but it is not ignored merely because the website also offers an on-page control.

The current first-party record can be inspected in the browser’s storage or developer tools under the iceqc.org origin. Its contents should correspond to the inventory in this Policy and should not contain a name, email address, application number or advertising identifier. An unexpected ICEQC-domain value may be reported using the contact route below; a screenshot should conceal unrelated browsing or account information.

14. International processing and provider information

Cloudflare and Stripe operate internationally. Associated device, security and transaction data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States and other locations identified in their current service and subprocessor information. ICEQC applies the transfer safeguards described in the Data Protection and Privacy Notice for processing under its control.

Because provider names, security cookie specifications and subprocessors can change, the provider’s current official documentation should be consulted together with this inventory. A provider document does not authorise ICEQC to introduce a materially different optional purpose without updating this Policy and the relevant choice.

15. Storage scope, expiry and deletion mechanics

A cookie is scoped by domain, path, security attributes and, where applicable, partitioning rules. A value set for the public website is not automatically available to the application centre or an external payment page. Secure and HTTP-only attributes reduce particular risks but do not make a technology anonymous or remove the need for an appropriate purpose, retention period and access control.

A stated duration is the intended maximum or functional expiry for the value, not a promise that every physical copy disappears from every device at that instant. A browser may delete it earlier, preserve a local-storage value until site data is cleared, restore browser state from a backup or apply vendor-specific retention behaviour. ICEQC configures its own code to disregard an expired privacy-choice record and to replace a record whose policy version is no longer current.

Deleting a browser value prevents future use of that copy but does not retrospectively delete server security logs, payment records or consent evidence already created for a separate lawful purpose. Those records are governed by the Privacy Notice and applicable retention rules. Conversely, closing an account does not necessarily clear site data stored in the user’s browser; the user may clear it through the browser controls.

16. Responsibility for strictly necessary technologies

ICEQC classifies a technology as strictly necessary only where the relevant function cannot reasonably be supplied in a secure and compliant manner without it. The classification is made from the actual purpose and deployment, not from a provider’s marketing label. Typical necessary purposes are authentication, session continuity, request integrity, load and security management, privacy-choice storage and completion of a transaction expressly initiated by the user.

Necessary status is not permission to reuse the resulting data for audience measurement, advertising or unrelated profiling. Access, duration and onward disclosure remain limited to the operational or security purpose. If a single technology would combine a necessary purpose with an optional purpose, the optional component must be separated or remain inactive until the required choice has been obtained.

A user may object to or question necessary processing under the Privacy Notice. Depending on the technology, ICEQC may be unable to provide the protected function without it, but will consider whether an alternative method can provide equivalent identity, transaction or security assurance. Public information that does not require authentication is not intentionally conditioned on acceptance of an optional technology.

17. Standard for introducing an optional category

Before an optional technology is enabled, ICEQC identifies the specific purpose, controller and provider roles, data and identifiers involved, triggering pages or actions, duration, access recipients, processing locations, transfer safeguards, interaction with other services, withdrawal method and effect of refusal. A broad description such as ‘improving experience’ is not sufficient where it fails to explain the material operation.

The control must prevent non-essential storage and provider requests until the legally required affirmative action occurs. Categories are not preselected, acceptance and refusal are presented without a materially deceptive imbalance, and a visitor can revisit the choice from the footer. Consent for one stated purpose does not activate a different provider or purpose, and consent obtained under one policy version is not silently extended after a material change.

Withdrawal applies prospectively from the time the website can implement the instruction. ICEQC disables the relevant tags or connections and, where technically supported, deletes its optional first-party identifiers. A third party that previously received data may need to retain a limited record under its own legal obligations; its notice and the rights process under the Privacy Notice apply to that retained processing.

18. Consent evidence and preference records

Where consent is required, ICEQC may retain evidence of the policy version, categories presented, choice, time, site origin and technical information reasonably needed to demonstrate that the control operated. The evidence is not used to infer interests or build a browsing profile. A minimal withdrawal or refusal record may be retained so that the website can honour the instruction and demonstrate that no optional category should be activated for that browser.

The current public implementation stores the choice locally and does not create a named, cross-device preference account. ICEQC therefore cannot ordinarily retrieve or change a public-site choice by a person’s name or email address. Clearing site data removes the browser’s local record and causes the notice to be presented again; it does not mean that a previous choice was invalid when made.

If a future account-linked preference service is introduced, the Policy will explain the link, its scope across devices, the data stored on the server and how account closure affects it before the feature is used. Optional consent will not be bundled into general account terms where a separate choice is legally required.

19. Global privacy signals and automated preference mechanisms

Browser signals vary in legal meaning and technical specificity. ICEQC evaluates a recognised signal according to the jurisdiction and processing to which it applies, the user agent’s transmission and the purpose the signal is capable of expressing. A signal directed at sale, sharing or cross-context behavioural advertising has no separate operational effect where ICEQC does not conduct those activities, but that absence is documented rather than treated as permission to introduce them.

A general ‘do not track’ header does not have a universally settled effect. ICEQC does not use that uncertainty to override an explicit refusal recorded through the site control. If law requires recognition of a particular universal opt-out mechanism for a future optional activity, the mechanism will be implemented for that activity and the inventory will state the resulting behaviour.

Security and authentication values may continue notwithstanding an opt-out signal where they are strictly necessary and not repurposed. The signal does not authenticate the sender for access, deletion or correction of server records; those requests follow the verification process in the Privacy Notice.

20. External domains, links and embedded resources

A normal hyperlink identifies a destination but does not, by itself, load that destination’s code or cookies on the ICEQC page. Once the visitor follows it, the destination receives the request and may process the referring address, network information and its own cookie state under its terms. Users should check the destination domain before entering credentials, payment information or personal data.

An embedded resource differs because the browser may contact the external provider while the ICEQC page is open. For optional maps, media, fonts, social content or similar resources, ICEQC will use a locally hosted alternative, a click-to-load mechanism or prior category control where required. The provider name and consequence of loading will be disclosed with sufficient specificity for the visitor to decide.

A provider required for security, hosting or an expressly requested transaction may receive a request without optional consent where the applicable exemption or lawful basis applies. That necessary role does not amount to ICEQC endorsing all processing on the provider’s unrelated public services.

21. Shared devices, private browsing and children

A browser choice is associated with a browser profile and origin, not reliably with a natural person. On a shared device, one person’s acknowledgement or preference may therefore be visible to the next user of the same profile. Users who require separate choices should use separate browser profiles or clear the site data after the session. Private-browsing mode may discard the value and cause the notice to reappear on the next visit.

ICEQC public services are directed principally to organisations and adult representatives and do not deploy advertising or behavioural profiling directed at children. Where a child or vulnerable person accesses public information, the necessary technologies described in this Policy operate for delivery and security only. An optional technology materially affecting children would require a separate assessment of applicable age, authority, transparency and consent requirements before deployment.

A parent, guardian, school or employer should not alter another person’s browser choice while representing that it is the person’s own decision unless authorised to act for that person. Accessibility assistance may be provided without taking control of optional privacy choices that the user can make with an accessible method.

22. Inventory assurance and release control

ICEQC reviews the public website, application centre and relevant provider configurations to reconcile deployed browser technologies with this inventory. Review may include source and configuration inspection, browser storage and network observation, authenticated workflow testing and comparison with provider documentation. Automated scanners assist discovery but are not treated as complete because conditional security cookies, regional behaviour and authenticated functions may not appear in a single scan.

A release that introduces or materially changes a tag, software development kit, embedded resource, authentication method or payment integration must identify its browser storage and outbound connections before production use. Unknown or unjustified optional technology is disabled pending classification and documentation. Necessary security values that are generated conditionally are described by function even when a particular visit does not trigger them.

If the observed configuration differs materially from this Policy, ICEQC investigates the source, limits the technology where appropriate, corrects the inventory and determines whether a new choice, deletion instruction, provider notification or personal-data incident assessment is required. Reports from users and security researchers are considered through the contact route below.

23. Changes and re-consent

ICEQC maintains a policy-version value in the public-site privacy record. A material change to an optional purpose, provider or category invalidates the earlier version and causes the website to request a new choice. A merely editorial correction that does not affect the processing or choice may be published without seeking consent again.

The English version is the authoritative version of this Policy.

24. Contact and complaints

Questions about a technology, its current status or a privacy choice may be sent to contact@iceqc.org. Include the domain, approximate date, browser and the name of the value shown by the browser, but do not send passwords, full payment-card information or confidential certification evidence.

A concern about personal-data processing may be raised through the complaint route stated in the Data Protection and Privacy Notice. A person may also approach a competent supervisory authority as provided by applicable law.