Back to Home

Cookie Policy

Last updated: April 8, 2026

Introduction

This Cookie Policy explains how CoreITsm ("we", "us", "our") uses cookies and similar tracking technologies on our enterprise IT service management platform (the "Platform"). It covers what cookies are, how we use them, your choices regarding cookies, and your rights under applicable privacy laws.

Our Commitment

We are committed to transparency in our use of cookies and providing you with meaningful control over how your data is collected and used through tracking technologies.

What Are Cookies and Tracking Technologies?

Cookies

Cookies are small text files stored on your device (computer, tablet, or mobile) when you visit our Platform. They allow us to recognize your device and remember information about your visit.

Similar Tracking Technologies

We also use similar technologies including:

  • Web Beacons/Pixels: Tiny transparent images used to track user interactions
  • Local Storage: Browser storage for maintaining user preferences and session data
  • Session Storage: Temporary storage for data during a single session
  • Device Fingerprinting: Collecting device characteristics for security purposes
  • Tracking URLs: Specialized URLs that track user engagement and campaign effectiveness

How We Use Cookies and Tracking Technologies

Essential Cookies

Required for basic Platform functionality, authentication, security, and core features. These cookies cannot be disabled as they are necessary for the Platform to operate.

  • Session management and user authentication
  • Security token storage and CSRF protection
  • Load balancing and server routing
  • Platform stability and performance optimization
  • Multi-factor authentication (MFA) session management
  • API rate limiting and abuse prevention

Performance and Analytics Cookies

Help us understand how visitors interact with our Platform to improve performance, user experience, and service quality through aggregated, anonymized data.

  • Page load time optimization and performance monitoring
  • Error detection, reporting, and debugging
  • Platform performance metrics and uptime monitoring
  • User experience analytics and journey mapping
  • Feature usage statistics and adoption rates
  • A/B testing and feature rollout monitoring

Functional Cookies

Remember your preferences, settings, and customizations to provide a personalized experience and enhanced functionality.

  • Language and regional preferences
  • Dashboard layout and widget arrangements
  • Theme, display, and accessibility preferences
  • Feature usage preferences and custom settings
  • Recent activity and navigation history
  • Personalized content recommendations

Marketing and Advertising Cookies

Used to deliver relevant advertisements, measure marketing campaign effectiveness, and personalize marketing communications based on your interests.

  • Campaign performance tracking and attribution
  • Cross-device user journey analysis
  • Interest-based advertising and retargeting
  • Marketing effectiveness measurement
  • Social media integration and sharing analytics
  • Email campaign tracking and optimization

Security and Fraud Prevention Cookies

Used to detect, prevent, and respond to security threats, fraudulent activities, and malicious behavior.

  • Bot detection and automated attack prevention
  • Fraud detection and prevention systems
  • Account takeover protection
  • Security incident monitoring and response
  • Device fingerprinting for authentication
  • Geolocation verification and access control

Detailed Cookie Inventory

Cookie NameTypePurposeDurationCategoryLegal Basis
coreitsm_sessionHTTPAuthentication session management and securitySessionEssentialLegitimate Interest
coreitsm_preferencesHTTPUser preferences, dashboard layout, and settings1 yearFunctionalConsent
coreitsm_analyticsHTTPPlatform usage analytics and performance metrics30 daysAnalyticsConsent
coreitsm_performanceHTTPPerformance monitoring, error tracking, optimization24 hoursPerformanceLegitimate Interest
coreitsm_securityHTTPSecurity token, CSRF protection, fraud preventionSessionSecurityLegitimate Interest
coreitsm_marketingHTTPMarketing campaign tracking and attribution90 daysMarketingConsent
coreitsm_ab_testingHTTPA/B testing and feature rollout managementSessionAnalyticsLegitimate Interest

Third-Party Cookies and Integrations

We use third-party services that may place cookies on your device for various purposes. These services are carefully vetted for security and privacy compliance:

Google Analytics 4

Platform usage analytics, performance monitoring, and user behavior analysis with aggregated, anonymized data.

_ga_gid_ga_*_ga_*_*

Privacy Policy: https://policies.google.com/privacy

Intercom

Customer support, live chat functionality, and user communication management.

intercom-session-*intercom-id-*intercom-device-id-*

Privacy Policy: https://www.intercom.com/legal/privacy

Stripe

Payment processing, billing management, and financial transaction security.

__stripe_session__stripe_mid__stripe_sid

Privacy Policy: https://stripe.com/privacy

HubSpot

Marketing automation, lead tracking, and customer relationship management.

hubspotutk__hstc__hssrc__hssc

Privacy Policy: https://legal.hubspot.com/privacy-policy

Cloudflare

Content delivery network, security services, and performance optimization.

__cfduid__cfruidcf_clearance

Privacy Policy: https://www.cloudflare.com/privacypolicy/

Consent Management and Your Choices

Cookie Consent Banner

When you first visit our Platform, you'll see a cookie consent banner where you can:

  • Accept All: Enable all cookie categories for optimal functionality
  • Accept Essential Only: Enable only essential cookies required for Platform operation
  • Customize Preferences: Select specific cookie categories to enable or disable
  • View Details: Access detailed information about each cookie category and specific cookies

Granular Consent

Our consent system allows you to accept or reject specific cookie categories independently, giving you fine-grained control over tracking technologies.

Cookie Preference Center

You can access our cookie preference center at any time to:

  • Review and modify your current cookie preferences
  • Withdraw consent for non-essential cookies
  • View detailed cookie information and third-party services
  • Access privacy settings and data management tools
  • Download your consent history and preferences

Browser and Device Controls

You can control cookies through your browser settings:

  • Accept/Reject All Cookies: Global cookie acceptance or rejection settings
  • First-Party Only: Accept only cookies set by our Platform
  • Block Third-Party: Prevent external services from setting cookies
  • Delete Existing Cookies: Clear all stored cookies from your device
  • Site-Specific Settings: Configure cookie preferences for our Platform only

Important Notice

Blocking essential cookies may prevent you from using core Platform features, including authentication, security, and basic functionality.

Cross-Device and Cross-Domain Consent

Our consent management system:

  • Synchronizes consent across all your devices and browsers
  • Applies your preferences consistently across our Platform domains
  • Remembers your choices for future visits
  • Provides unified consent management across integrated services

Legal Basis for Cookie Usage

We process cookies and tracking technologies based on appropriate legal foundations depending on the type, purpose, and regulatory requirements:

Essential Cookies

Legal Basis: Legitimate Interest

Required for Platform operation, security, and provision of services. Cannot be disabled without affecting core functionality.

GDPR Art. 6(1)(f) - Legitimate interests

Performance Cookies

Legal Basis: Legitimate Interest

Used to improve Platform performance, security, and user experience with minimal privacy impact.

GDPR Art. 6(1)(f) - Legitimate interests

Functional Cookies

Legal Basis: Consent

Used to remember preferences and provide personalized features. Requires explicit user consent.

GDPR Art. 6(1)(a) - Consent

Marketing Cookies

Legal Basis: Consent

Used for advertising and marketing purposes. Requires explicit user consent under GDPR and opt-out under CCPA.

GDPR Art. 6(1)(a) - Consent

Security Cookies

Legal Basis: Legitimate Interest

Used for fraud prevention, security monitoring, and protection against malicious activities.

GDPR Art. 6(1)(f) - Legitimate interests

Your Rights Regarding Cookies

Right to Information

You have the right to know what cookies we use, why we use them, and how long they are stored. This policy provides comprehensive information about all tracking technologies.

Right to Control

You can control which cookies are stored on your device through our consent banner, preference center, and browser settings.

Right to Withdraw Consent

You can withdraw consent for non-essential cookies at any time through our preference center. Withdrawal is as easy as giving consent.

Right to Object

You can object to the use of certain cookies for specific purposes, particularly marketing and advertising cookies.

Right to Access and Portability

You can request access to your cookie preferences and consent history, and export this data in a machine-readable format.

International Data Transfers

Some cookies and tracking technologies may transfer data to countries outside your region. We implement appropriate safeguards for international data transfers:

  • EU-US Data Privacy Framework: Certified adherence to DPF Principles for EU-US data transfers
  • UK Extension to DPF: Certified for UK-US data transfers under the UK Extension
  • Standard Contractual Clauses: EU Commission-approved model clauses for other transfers
  • Adequacy Determinations: Transfers to countries with adequate data protection
  • Binding Corporate Rules: Internal data protection policies for intra-organizational transfers
  • Supplementary Measures: Additional technical and organizational safeguards where required

Data Localization

Where possible, we process data within your region and use local data centers to minimize international transfers.

Regional Compliance and Legal Requirements

GDPR (European Union)

We comply with GDPR requirements for cookie consent and data protection:

  • Prior consent before placing non-essential cookies (opt-in requirement)
  • Granular consent options for different cookie categories
  • Detailed consent documentation and audit trails
  • Easy withdrawal of consent through preference center
  • Clear information about cookie purposes and third parties
  • Data protection by design and by default principles

ePrivacy Directive (EU/EEA)

We obtain explicit consent for non-essential cookies as required by the ePrivacy Directive:

  • Explicit consent for electronic communications tracking
  • Information about storage duration and access to stored information
  • Right to refuse tracking technologies
  • Clear and comprehensive cookie information
  • Regular review and updating of consent mechanisms

CCPA/CPRA (California, USA)

We respect California residents' rights regarding cookies and personal information:

  • "Do Not Sell or Share" opt-out mechanism for data sharing
  • Clear disclosure of third parties receiving personal information
  • Right to opt-out of cross-context behavioral advertising
  • Accessible privacy rights and consumer controls
  • Financial incentives disclosure for data sharing
  • Authorized agent mechanisms for exercising rights

LGPD (Brazil)

We comply with Brazilian data protection laws for cookie usage:

  • Explicit consent for cookie processing in Portuguese language
  • Clear purpose limitation and data minimization
  • Data subject rights for cookie-related personal data
  • National data protection authority compliance
  • International transfer safeguards for Brazilian data

PIPEDA (Canada)

We follow Canadian privacy principles for cookie usage:

  • Meaningful consent for cookie collection and use
  • Appropriate security safeguards for cookie data
  • Open policies and practices regarding cookies
  • Individual access to cookie-related personal information
  • Challenge compliance with privacy commissioner

Cookie Lifespan and Data Retention

Session Cookies

Automatically deleted when you close your browser. Used for temporary data like authentication tokens, session state, and security context.

Duration: Until browser closure

Persistent Cookies

Remain on your device for a specified period. Used for preferences, analytics, and remembering user choices across sessions.

Duration: 24 hours to 1 year depending on purpose

First-Party Cookies

Set directly by our Platform. Used for core functionality, user preferences, and essential Platform operations.

Control: Managed through our consent system

Third-Party Cookies

Set by external services like analytics, support, and payment providers. Used for specialized functionality and services.

Control: Subject to third-party privacy policies

Updates to This Cookie Policy

We may update this Cookie Policy to reflect changes in our practices, technology, legal requirements, or to improve clarity and transparency. We will notify you of material changes through:

  • Website Posting: Updated policy with prominent "Last updated" date
  • Cookie Banner Notice: Display of changes in consent banner for significant updates
  • Email Notifications: Direct email for material changes affecting your rights
  • In-Platform Notifications: Alerts within the Platform for policy updates
  • Preference Center Updates: Highlighted changes in cookie preference center

Version Control

Previous versions of this Cookie Policy are available upon request. We maintain a complete archive of policy changes and effective dates.

Contact Information

If you have questions about our use of cookies, this Cookie Policy, or wish to exercise your rights, please contact us:

Support:

Info@coreitsm.xyz

Technical support and cookie preference assistance

Mailing Address:

Rua Dr Antonio Jose de Almeida Nº2 9ºF 2780-089 Oeiras Portugal

Response Times:

We will respond to cookie-related inquiries within 5 business days and resolve requests within applicable legal timeframes.

Additional Resources

Related Policies

External Resources