aumatex.
Contact

Last update May 15, 2026

Cookie and Tracking Technologies Policy

This policy describes the use of cookies and similar technologies on aumatex.it in accordance with Regulation (EU) 2016/679 (GDPR), Article 122 of Legislative Decree 196/2003 (Italian Privacy Code) and the Italian Data Protection Authority Cookie Guidelines of June 10, 2021 and subsequent clarifications (May 2025). This notice is provided pursuant to Article 13 GDPR by the Data Controller Aumatex SRLS.

1. What cookies and similar technologies are

  • Cookies are small text files that the website or third parties may store on the user's device during browsing.
  • Similar technologies include: localStorage, sessionStorage, indexedDB, web beacons/pixel tags, SDK identifiers, fingerprinting, iframe tracking, cache storage and system logs.
  • Key distinction: strictly necessary technical cookies do NOT require consent; analytics cookies (even anonymized), non-essential preferences, profiling/marketing cookies require prior INFORMED consent under Article 122 Italian Privacy Code.
  • Preventive blocking principle: Third-party scripts that install non-technical cookies are BLOCKED by default and activated only after explicit consent.

2. Cookie categories used and current status

  • NECESSARY TECHNICAL (Art. 122 co. 1 Italian Privacy Code): Essential for security (CSRF, XSS protection), website delivery, load balancing, consent management, rate limiting, abuse prevention. NO consent required; blocked only if disabled by browser.
  • PREFERENCES/FUNCTIONAL: CURRENTLY NOT PRESENT on the site (no embedded third-party widget or content). Any future implementation will require prior consent.
  • ANALYTICS: Google Analytics 4 configured in privacy-safe mode. REQUIRES prior INFORMED consent; GA4 script BLOCKED until consent. Configuration: IP anonymized, Google Signals OFF, ads personalization OFF, max 14 months retention.
  • MARKETING/PROFILING: Currently NOT PRESENT on the site. Any future implementations will require specific prior consent with separate notice.
  • Equal prominence principle: "Reject" button has IDENTICAL visual weight (size, color, contrast, position) to "Accept" button. No UX manipulation (dark patterns) to steer toward acceptance.

3. Cookie and tracking technologies inventory

  • Table updated as of May 15, 2026. Periodically verify via DevTools > Application/Storage that no undeclared cookies are present.
  • WARNING: Before consent, GA4 and third-party widgets MUST be completely inactive (verify absence of network calls to google-analytics.com and googletagmanager.com).
Name / technologyProviderGDPR categorySpecific purposeDurationLegal basisPre-consent status
aumatex_cookie_consent (first-party cookie)Website / Aumatex SRLSNecessary technicalStores user choice, policy version, timestamp. No tracking.180 daysArt. 122 co. 1 Italian Privacy CodeActive (first-party, no third-party)
__cf_bm, __cfruidCloudflare Inc.Necessary technical (security)Bot management, rate limiting, DDoS protection. No commercial profiling.30 minutes - 24 hoursArt. 122 co. 1; legitimate interest securityActive
cf_clearanceCloudflare Inc.Necessary technical (security)Verification of CAPTCHA turnstile challenge completion. Only if activated.Session - 1 yearArt. 122 co. 1; legitimate interest securityConditional
_ga, _ga_<container-id>Google Ireland Ltd.Analytics (non-technical)Distinguishes users/sessions, measures site interactions. ONLY with consent.2 years maxInformed consent Art. 122 co. 1 bisBLOCKED - script not loaded
_gid (if active)Google Ireland Ltd.Analytics (non-technical)Daily session identifier for GA4.24 hoursInformed consentBLOCKED
_gat (if active)Google Ireland Ltd.Analytics (non-technical)GA4 request throttling.1 minuteInformed consentBLOCKED
Vercel/Edge logsVercel Inc.Necessary technical (logs)HTTP request logs for troubleshooting and security. IPs anonymized where possible.1-7 daysArt. 6(1)(f) GDPR - securityActive (server-side)

4. Google Analytics 4 - Privacy-safe configuration

  • Default status: GA4 is COMPLETELY DISABLED until specific consent to Analytics category.
  • Technical implementation: gtag.js / G-Tag loaded dynamically ONLY after analytics consent; no static inclusion in initial HTML.
  • Mandatory verified configuration: (1) IP anonymization active (ip_anonymization: true), (2) Google Signals DISABLED, (3) Remarketing/Ads Personalization DISABLED, (4) Data retention 14 months, (5) No cross-device User-ID, (6) No data sharing with Google advertising products.
  • Data transfer: Google Ireland Ltd. is EU responsible; Google LLC USA is sub-processor with Data Privacy Framework certification (adequacy decision 2023/1795).
  • Withdrawal: Upon analytics consent withdrawal, site (a) stops sending GA4 hits, (b) deletes _ga and _ga_* cookies via JavaScript, (c) reloads page without GA4 script.
  • User verification: Can verify absence of pre-consent tracking via DevTools > Network and check absence of calls to google-analytics.com.

5. Third-party content

  • The site embeds no third-party calendars, videos, maps or widgets: no external content is loaded in the user’s browser except Google Analytics 4, and only after consent.
  • Links to external sites (social networks, GitHub) leave the website and processing occurs under the respective provider’s notices.

6. Consent management - Legal requirements

  • Equal prominence: "Reject" button has IDENTICAL visual weight (size, color, contrast, position) to "Accept" button. No UX manipulation (dark patterns) to steer toward acceptance.
  • First display: Banner shown immediately on first access, partially blocking interaction until choice is made (modal preferred) or in prominent position.
  • Granularity: Separate consent per category (necessary/preferences/analytics). Necessary always active and non-disableable.
  • Preliminary information: Banner includes immediate links to Privacy Policy and Cookie Policy; brief but clear description of purposes.
  • Consent proof: Recorded in first-party cookie (aumatex_cookie_consent, 180 days, SameSite=Lax, Secure): (a) choice made, (b) timestamp, (c) policy version, (d) accepted categories. No server-side storage required for non-sensitive cookies.
  • Withdrawal: "Cookie preferences" link always accessible in footer of every page; banner reopening with ability to change choice. Withdrawal immediately effective.
  • Post-withdrawal deletion: Upon analytics withdrawal, GA4 script removed and _ga/_ga_* cookies deleted via JavaScript (document.cookie with past expires).

7. Browser settings

  • Users may delete or block cookies in browser settings. Blocking technical cookies may impair some website functions.
  • Useful guides are available in Chrome, Safari, Firefox, Edge and other browser settings.

8. Cookies to verify manually

  • Before go-live and after each change to Cloudflare, Vercel, GA4 or forms, check DevTools > Application/Storage > Cookies and update this table if new names, providers, purposes or durations appear.

We build digital systems together.

Websites, software, infrastructure and automation for companies that want to operate better.

Contact

Aumatex

  • Home
  • About us
  • Case studies
  • Blog
  • Tech stack
  • Careers
  • Contact

Services

  • Custom software
  • iOS apps
  • Web Apps & PWA
  • Business platforms
  • Websites
  • E-commerce
  • UX/UI Design
  • AI, chatbots & automation
  • Cloud & infrastructure
  • Public tenders & MEPA

Products

  • View all products
  • Native Apps
  • Web App & PWA
  • Business Platforms
  • Websites
  • E-commerce

Legal

  • Privacy policy
  • Cookie policy
Aumatex
aumatex.
Aumatex SRLS · Via Umberto Biancamano 25, 00185 Roma (RM), Italy© 2026 Aumatex SRLS · VAT IT15617831001•Privacy policy•Cookie policy•