Cookie Policy · LSSI-CE · RGPD · AEPD

Transparency about
every cookie we use —
and the ones we don't.

This Cookie Policy explains what cookies are, which ones Giroteam Software Studio uses on giroteam.com, what they do, how long they last, who else has access to the data they collect, and exactly how you can accept, reject or revoke consent at any time — in accordance with Spanish Law 34/2002 (LSSI-CE), Regulation (EU) 2016/679 (GDPR) and the Spanish Data Protection Agency (AEPD) Guide on the use of cookies.

§ 01 / What is a cookie

A cookie is a small
file —
and a legal artefact.

A cookie is a small text file that a website stores on the device you use to browse (computer, tablet or mobile). Cookies allow a site to remember your visit, your preferences, your authentication state and how you arrived — across pages and across return visits.

Under Spanish and European law, the term cookie also covers any similar technology that stores information on, or retrieves information from, your terminal device: pixels, local storage, session storage, IndexedDB, browser fingerprints, SDK identifiers and equivalent tracking mechanisms. The same rules apply to all of them.

Cookies are not, on their own, harmful. They cannot read your hard drive, install software, or transmit viruses. What they can do is identify your browser between visits — which is why their use is regulated.

01.
Where they live
On your device, not on our servers. You control them at all times.
02.
What they store
Small identifiers, preferences and state flags — never your hard drive.
03.
Who reads them
Only the domain that set them, plus any third-party domain you authorise.
§ 03 / Types of cookies

Classified by ownership,
duration and purpose.

The AEPD Guide on the use of cookies defines three classification axes. We follow the same structure so you can see at a glance what each cookie does and why it exists.
C · 01 — Ownership

Who sets the cookie

First-party cookies

Set by giroteam.com directly. We are the data controller.

Third-party cookies

Set by external providers (analytics, embedded video, ad networks). They act as independent data controllers or processors.

C · 02 — Duration

How long they last

Session cookies

Deleted automatically when you close your browser. Used to maintain state during a single visit.

Persistent cookies

Remain on your device for a defined period (from a few minutes to a maximum of 24 months, per AEPD criteria) until they expire or you delete them.

C · 03 — Purpose

What they are for

Essential / non-essential

Essential cookies make the site work. Non-essential cookies enable analytics, personalisation or marketing — and require consent.

Granular by use

Technical, preferences, analytics/measurement, behavioural advertising — each managed independently.

purpose.matrix
P · 01
Strictly necessary
Always active

Technical cookies

Strictly necessary cookies enable navigation, session maintenance, security, load balancing, language preferences, accessibility settings and the storage of your cookie consent itself. Without them, the site cannot function correctly.

Legal basisArt. 22.2 LSSI-CE (exempt)
Maximum durationSession – 12 months
ConsentNot required
P · 02
Preferences
Consent required

Preference cookies

Preference cookies remember the choices you make — language, region, layout, accepted notices — so you don't have to set them again on your next visit. They make the site feel familiar but are not essential to its operation.

Legal basisArt. 6.1(a) GDPR · Consent
Maximum durationUp to 12 months
ConsentRequired
P · 03
Analytics
Consent required

Analytics & measurement cookies

Analytics cookies let us understand which pages are visited, how visitors arrive, and where the experience breaks. The data is aggregated and used to improve the site. We use IP anonymisation where the provider supports it.

Legal basisArt. 6.1(a) GDPR · Consent
Maximum durationUp to 24 months
ConsentRequired
P · 04
Marketing
Consent required

Behavioural advertising cookies

Behavioural advertising cookies build a profile of your interests across sites and serve advertising that matches it. They include retargeting pixels and social network cookies. We only set them when you have given explicit consent.

Legal basisArt. 6.1(a) GDPR · Consent
Maximum durationUp to 13 months
ConsentRequired
§ 04 / Cookie inventory

The cookies we actually set, and the providers that set them.

Below is the current inventory of cookies used on giroteam.com. It is updated whenever we add, remove or change a provider. Provider names, retention periods and purposes reflect the latest declarations from each vendor.

First-party cookies (set by Giroteam)

Name Provider Purpose Type Duration
session_id Giroteam Maintains your authenticated session and CSRF state during the visit. Technical Session
XSRF-TOKEN Giroteam Cross-site request forgery (CSRF) protection for form submissions. Technical Session
cookie_consent Giroteam Stores your cookie consent choices so the banner is not shown again. Technical 12 months
locale Giroteam Remembers your selected language (EN / ES / DE). Preferences 12 months

Third-party cookies

The cookies below are set by external providers. Each provider acts as an independent data controller for the data collected through its cookies, and its own privacy notice applies.

Name Provider Purpose Type Duration
_ga Google Ireland Ltd. Distinguishes unique users for Google Analytics 4 measurement. Analytics Up to 24 months
_ga_* Google Ireland Ltd. Persists session state for the Google Analytics 4 property. Analytics Up to 24 months
_gid Google Ireland Ltd. Distinguishes users over a 24-hour window for legacy GA properties. Analytics 24 hours
_fbp Meta Platforms Ireland Ltd. Meta Pixel — measures conversions and enables retargeting on Facebook / Instagram. Marketing Up to 90 days
li_sugr / bcookie LinkedIn Ireland U.C. Insight Tag — measures LinkedIn campaign performance and enables retargeting. Marketing Up to 12 months
VISITOR_INFO1_LIVE Google Ireland Ltd. (YouTube) Set by embedded YouTube videos to estimate bandwidth and serve video. Marketing Up to 6 months
__cf_bm Cloudflare, Inc. Bot mitigation and DDoS protection by Cloudflare; no profiling. Technical 30 minutes
Important

If your consent settings have not authorised analytics or marketing cookies, the corresponding third-party scripts are not loaded, and the cookies listed in those categories are not set. This inventory therefore reflects the maximum scope of what may be present, not what is necessarily active in your session.

§ 05 / International transfers

Some cookie data
leaves the EU.

Some of the third-party providers listed above are established outside the European Economic Area, mainly in the United States. Where this happens, the activation of their cookies entails an international transfer of personal data subject to chapter V of the GDPR.

We rely on the safeguards offered by each provider, which include one or more of the following mechanisms:

Transfer safeguards in place

  • Adequacy decision of the European Commission (for example, the EU–US Data Privacy Framework, where applicable).
  • Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organisational measures.
  • Binding Corporate Rules (BCRs) within the provider's corporate group, where applicable.

You can request a copy of the safeguards applicable to each transfer by contacting us at privacy@giroteam.com. Withdrawing consent to the corresponding cookie category stops the transfer for future visits.

§ 06 / Manage your cookies

Accept, reject or revoke — at any time, in two clicks.

You decide which cookie categories to authorise. Your choices can be reviewed and changed whenever you want, with the same ease as the original decision.

Preferences

Open the preferences panel

The preferences panel lets you grant or revoke consent by category — technical, preferences, analytics and marketing — without affecting your access to the site. Your last decision is stored for 12 months.

Block or delete cookies in your browser

You can also configure your browser directly to block or delete cookies for any site. Each browser has its own settings; the official documentation is linked below.

B · 01

Google Chrome

Settings → Privacy and security → Cookies and other site data → choose your blocking or deletion options.

Official help article →
B · 02

Mozilla Firefox

Settings → Privacy & Security → Cookies and Site Data → manage stored data and exceptions.

Official help article →
B · 03

Apple Safari

Preferences → Privacy → Cookies and website data → block all, or manage by website.

Official help article →
B · 04

Microsoft Edge

Settings → Cookies and site permissions → Manage and delete cookies and site data.

Official help article →
B · 05

Opera

Settings → Advanced → Privacy & security → Cookies and other site data.

Official help article →
B · 06

iOS & Android

On mobile, cookie controls live in the privacy section of each browser app. The advertising identifier (IDFA / GAID) can additionally be reset or disabled in your device's privacy settings.

device-level controls available

Third-party opt-out tools

Each major third-party provider also offers its own opt-out interface, which works regardless of the consent you have given on giroteam.com.

Heads up — Blocking all cookies (including technical ones) may degrade the site experience: features like form submissions, language selection and login will stop working correctly. Blocking only non-essential cookies has no functional impact on giroteam.com.

§ 07 / Your rights

Eight rights —
guaranteed by the GDPR.

As a data subject, you have the following rights at any time, free of charge, regarding the personal data processed through cookies.

R · 01

Access

Know what personal data we process about you, why, and to whom we communicate it.

R · 02

Rectification

Have inaccurate or incomplete data corrected without undue delay.

R · 03

Erasure

Request deletion of your data, including the right to be forgotten, where the legal grounds apply.

R · 04

Objection

Object to processing based on legitimate interests, including profiling for direct marketing purposes.

R · 05

Restriction

Limit processing of your data in specific circumstances foreseen by the GDPR.

R · 06

Portability

Receive your data in a structured, commonly used and machine-readable format.

R · 07

Withdraw consent

Revoke previously granted consent at any time, without affecting the lawfulness of prior processing.

R · 08

Lodge a complaint

File a claim with the Spanish Data Protection Agency (AEPD) if you believe your rights have been infringed.

Supervisory authority

You may lodge a complaint with the Spanish Data Protection Agency (AEPD) — C/ Jorge Juan, 6 · 28001 Madrid — or through its electronic registry at www.aepd.es.

§ 08 / Retention, security & updates

We keep the data only
for as long as it's useful.

B · 01 — Retention

How long the data stays

Cookie-derived data is kept for the duration declared in the inventory above and, in any case, no longer than 24 months from the last interaction, in line with the AEPD's criterion. After that, consent is requested again.

B · 02 — Security

How we protect it

All traffic is served over HTTPS / TLS 1.3. Cookies with sensitive purposes use the Secure, HttpOnly and SameSite=Lax attributes by default. Access to backend logs is restricted to authorised personnel under confidentiality agreements.

B · 03 — Changes

How updates work

We may update this Cookie Policy to reflect changes in legislation, technology or our own services. Substantial changes will trigger a new consent request the next time you visit, and the version history is preserved internally.

§ 09 / Frequently asked

Questions people
actually ask us.

Short, direct answers to the most common questions about cookies, consent and Spanish law. If your question isn't here, write to privacy@giroteam.com and a real person will reply.

Can I use giroteam.com without accepting any cookie?

+

Yes. Technical cookies are the only ones strictly necessary, and they do not require your consent under article 22.2 LSSI-CE. Rejecting analytics and marketing cookies does not block any content on the site.

What happens if I close the banner without choosing?

+

Closing the banner without an explicit decision is treated as a rejection of all non-essential cookies. No analytics, preferences or marketing cookies will be set until you make an explicit choice in the preferences panel.

How can I withdraw my consent later?

+

Open the preferences panel from the link in the website footer or from the dedicated button in section 6 of this policy. You can also clear the cookie_consent cookie in your browser, which will cause the banner to appear again.

Are cookies personal data?

+

Cookies themselves are storage mechanisms. The data they collect — IP address, device identifier, browsing patterns — is considered personal data under the GDPR when it allows you to be directly or indirectly identified, which is why this policy applies.

Do you sell cookie data to third parties?

+

No. We do not sell, rent or trade cookie-derived data. Third-party providers receive data only for the specific purpose declared for each cookie (for example, measurement or advertising), under their own terms.

What about Do Not Track or Global Privacy Control signals?

+

When your browser sends a Global Privacy Control (GPC) signal, we treat it as a withdrawal of consent for non-essential cookies for the corresponding session, in line with current AEPD criteria. Do Not Track headers are also respected where technically reliable.

We answer privacy enquiries within one working day

Questions about a cookie,
a provider, or your rights?

Write to our privacy team at any time. We respond in English, Spanish or German, normally within one working day, and always before the legal deadline of one month for GDPR requests.