Cookie Policy
This Policy explains the cookies and similar browser technologies used by Avidni's public website and signed-in services, their purposes, duration, and controls.
On this page
1. About cookies and similar technologies
1.1 Cookies are small text records a website asks a browser to store and return. Similar technologies include local storage, session storage, pixels, server logs, and authentication tokens. They can keep a service secure, remember a choice, maintain a session, or measure use.
1.2 This Policy covers technologies used on avidnifirm.com and Avidni's signed-in web services. A client project hosted under another domain may use a different inventory and notice controlled by that client.
1.3 The public site currently uses browser storage for consent and optional first-party analytics. Signed-in services also use strictly necessary authentication and security technologies. We do not currently deploy third-party advertising cookies on the public website.
2. Current technology inventory
2.1 avidni.cookie-consent.v2026-06 is a local-storage record set by Avidni. It stores accepted, rejected, or preferences so the site can respect the visitor's choice. It remains until the visitor clears site data or Avidni changes the consent version. Category: strictly necessary preference and consent record.
2.2 avidni.analytics-session.v1 is a session-storage record set by Avidni only when optional analytics has been accepted and an analytics event is sent. It contains a random session identifier used to group events during the browser session. It is removed when the browser session ends. Category: analytics.
2.3 Avidni first-party analytics sends the requested path, referral source, event time, consent version, random session identifier, and limited call-to-action properties to Avidni's configured analytics endpoint. It does not intentionally send inquiry field contents. The event record is stored server-side under Avidni's analytics retention process. Category: analytics.
2.4 Supabase authentication may set cookies or equivalent browser records with names based on the configured Supabase project, commonly including an auth-token identifier. They maintain a signed-in session, refresh authentication, support recovery, and protect authorised routes. Duration can be session-based or persistent according to the authentication configuration and token expiry. Category: strictly necessary.
2.5 Cloudflare may use strictly necessary security, routing, bot-management, or challenge technologies when a security rule or challenge is triggered. The exact technology and duration depend on the active Cloudflare service and risk event. Category: strictly necessary security.
3. Strictly necessary technologies
3.1 Necessary technologies provide functions a user requests or protect the service. They include consent storage, authentication, session refresh, access control, load routing, fraud and abuse prevention, file-transfer authorisation, and security challenges.
3.2 These technologies do not require optional analytics consent where applicable law permits them because the service cannot securely provide the requested function without them. Blocking them may prevent sign-in, account recovery, secure forms, payments, uploads, or preference storage from working.
3.3 We limit necessary technologies to their operational purpose and do not use them for third-party behavioural advertising.
4. Preference technologies
4.1 Preference technologies remember a choice that changes how the site behaves. The current public site uses local storage to remember the cookie-consent decision and version.
4.2 A preferences control may temporarily reopen the consent interface without changing the stored decision until the visitor selects a new option. Future language, display, or accessibility preferences will be added to the inventory before or when deployed.
5. Analytics technologies
5.1 Optional first-party analytics is disabled unless the stored consent decision is accepted. On acceptance, the site records page views and selected internal call-to-action clicks to understand navigation, content usefulness, and technical performance.
5.2 The analytics design uses a random session identifier rather than an advertising identifier. It does not intentionally collect form answers, message contents, payment details, or account credentials as event properties.
5.3 Rejecting optional analytics does not reduce access to public content or signed-in services. Events that occurred lawfully before consent was withdrawn may remain in aggregated or retained records under the Privacy Policy.
6. Marketing and advertising technologies
6.1 Avidni does not currently deploy third-party advertising, cross-site behavioural profiling, retargeting, or social-media tracking cookies on the public website.
6.2 If Avidni introduces a marketing technology, it will remain disabled until the required consent is obtained. We will update this inventory with the provider, purpose, data, and duration and provide a separate marketing choice before use.
6.3 An ordinary link to a social network or external website does not itself set that provider's cookies through Avidni. The provider may use technologies after you follow the link under its own notice.
7. Providers and duration
7.1 Avidni controls the public consent and analytics storage listed above. Supabase supports authentication and application services. Cloudflare supports edge delivery, security, workers, and file storage. Vercel may support application deployment. Their network logs and necessary technologies follow their services and contractual settings.
7.2 Browser storage remains for the duration stated in section 2 or until the user clears it. Server-side logs and analytics records follow the retention criteria in the Privacy Policy. A provider may retain security, billing, or diagnostic records for its own legally permitted period.
7.3 Technology names and durations can change after browser, provider, or security updates. We review the inventory when the consent version or deployed services materially change.
8. Giving and refusing consent
8.1 On a first visit without a current decision, the public site displays a consent control. You can accept optional technologies, reject non-essential technologies, or open preferences. Rejecting is intended to be as accessible as accepting.
8.2 Avidni records the choice and consent version in local storage. Acceptance triggers optional analytics from that point. Rejection prevents the analytics component from sending optional events.
8.3 Consent is specific to the browser and profile. A different device, private window, browser profile, cleared storage, or new consent version may show the control again.
9. Changing or withdrawing consent
9.1 You can reopen Cookie Preferences from the website footer and replace your current choice. Withdrawal takes effect for future optional events on that browser.
9.2 You can also clear avidnifirm.com site data in the browser. Clearing data removes the stored choice, so the consent control will appear again. It may also sign you out and remove other preferences.
9.3 Withdrawing consent does not affect the lawfulness of earlier consent-based processing. You may separately exercise privacy rights described in the Privacy Policy.
10. Browser and device controls
10.1 Most browsers let you view, delete, or block cookies and site storage for all sites or a selected domain. Browser help documentation explains the available controls.
10.2 Blocking all cookies or storage can prevent authentication, security, consent memory, payments, uploads, and account functions. A browser's do-not-track signal does not have a single legally defined effect in every jurisdiction; Avidni instead uses the explicit consent control described above.
10.3 Security software, privacy extensions, and network filters may also block scripts or endpoints. If a requested function fails, review those controls before sending any sensitive troubleshooting information.
11. Updates and contact
11.1 We update this Policy and its inventory when technologies, providers, purposes, or legal requirements materially change. The effective date and version identify the current document. A new consent version may ask visitors to decide again.
11.2 Questions about cookies or similar technologies may be sent to services@avidnifirm.com. For access, deletion, objection, or another personal-data request, use the procedure in the Privacy Policy.
11.3 You can also review the Terms of Service for service rules and the Privacy Policy for processing purposes, lawful bases, sharing, transfers, retention, and rights.