Home / Cookie Policy
LegalCookie Policy.
What is set, why, for how long — and what we deliberately do not do.
This site currently sets no cookies and makes no third-party requests. The consent banner described below still has to be implemented before measurement is activated.
Purpose and scope of this policy
This policy explains which cookies and equivalent technologies this site uses, what each one is for, how long it lasts, and how you control them. It complements our Privacy Policy, which covers personal data more broadly.
It applies to eshay-advisory.com and its subdomains. It does not apply to third-party sites you may reach from here, nor to client environments we assess under a separate contract.
What we mean by cookie
A cookie is a small file placed on your device by a website and returned to it on subsequent requests.
We treat equivalent technologies under this same policy — local storage, session storage, pixels, beacons, software development kits and any similar identifier — because the legal obligation follows the function performed, not the technical format used. A tracker that avoids the word "cookie" is still a tracker.
Our position: no third-party requests
This site loads nothing from a third-party domain. Typefaces, stylesheets, scripts, icons and images are all served from our own origin.
This is deliberate. Loading a font, a map or an analytics script from an external provider transmits your IP address and your user agent to that provider before you have consented to anything — a transfer that European courts have repeatedly held to require consent. A cybersecurity advisory firm that made that mistake on its own site would be difficult to take seriously.
The practical consequence for you: visiting this site does not expose you to any company other than ours.
Legal framework
Placing or reading information on your device requires your prior consent under Article 5(3) of Directive 2002/58/EC (ePrivacy), transposed in France by Article 82 of the Data Protection Act, with the exception of what is strictly necessary to deliver a service you have expressly requested.
Where a cookie also involves processing personal data, Regulation (EU) 2016/679 (GDPR) applies in addition, and consent must be free, specific, informed and unambiguous.
We follow the French supervisory authority's guidance: refusing must be as simple as accepting, continued browsing is not consent, and consent is requested again after a reasonable period.
Cookies set by this site
As at the date of this document, this site sets no cookies at all and requests nothing from any external domain. It is a static site with no measurement deployed. The table below documents the three cookies that will exist once the consent banner and aggregate measurement are activated, so that this policy is already accurate on the day they ship.
| Name | Purpose | Category | Type | Retention |
|---|---|---|---|---|
| esh_consent | Stores the choice you made in the consent banner, so you are not asked again on every page. | Strictly necessary | First-party | 6 months |
| esh_session | Maintains the integrity of a form submission and protects it against cross-site request forgery. | Strictly necessary | First-party | Session |
| esh_stat | Aggregate measurement: pages viewed, entry and exit points, technical performance. No cross-site tracking and no profile. | Measurement — consent required | First-party | 13 months |
This inventory is updated whenever a cookie is added, changed or removed.
Strictly necessary cookies
These are required for the site to function and for the security of your interaction with it: recording your consent choice, protecting a form submission against cross-site request forgery, and maintaining session integrity.
They are exempt from consent because without them the service you asked for cannot be delivered. They carry no identifier usable for tracking, and they are never read for any purpose other than the one stated.
Measurement cookies
Used only to understand which pages are read, where visitors arrive from and leave, and how the site performs technically.
They are set only after you accept, they are first-party, the data is aggregated, IP addresses are truncated before storage, and no profile is built. They are not used to identify you, to retarget you, or to enrich any commercial database.
Retention is capped at thirteen months, after which the data is deleted rather than renewed silently.
What we deliberately do not do
- No advertising or retargeting cookies, and no advertising network integrations.
- No cross-site or cross-device tracking, and no device fingerprinting.
- No social network pixels, share widgets or embedded players.
- No data broker or lead-enrichment integrations.
- No sale, rental or exchange of any data collected here.
- No dark patterns in the banner: refusing takes exactly one click, like accepting.
Server logs are not cookies
Independently of cookies, our servers keep technical logs — IP address, timestamp, resource requested, response status and user agent. These are necessary to operate the service and to detect abuse, and they rest on our legitimate interest in the availability and integrity of our systems rather than on your consent.
They are not used to analyse your behaviour, they are not cross-referenced with any other source, and they are kept for a short operational period before deletion.
Managing your choice here
On your first visit, a banner lets you accept everything, refuse everything, or decide category by category. Nothing beyond the strictly necessary is set before you choose.
You can change your decision at any time from the same panel, reachable from the footer. Withdrawing consent is as immediate as giving it, and takes effect on the next page load.
Managing cookies in your browser
Independently of our banner, your browser lets you view, block or delete cookies. The relevant settings are:
- Chrome — Settings › Privacy and security › Third-party cookies
- Firefox — Settings › Privacy & Security › Cookies and Site Data
- Safari — Preferences › Privacy › Manage Website Data
- Edge — Settings › Cookies and site permissions
Blocking all cookies at browser level may affect sites that genuinely need them. It will not affect this one, beyond your consent choice being asked again on each visit.
Do Not Track and Global Privacy Control
We honour the Global Privacy Control signal: if your browser sends it, we treat it as a refusal of measurement cookies and no banner interaction is required from you.
The older Do Not Track header has no agreed legal meaning and is inconsistently implemented; we nonetheless treat it as a refusal, on the principle that an expressed preference should be respected rather than argued with.
What refusing changes
Nothing. Every page, every document and every function of this site remains fully available if you refuse measurement cookies. No content is gated, no feature is degraded, and you are not asked again on every page.
Transfers outside the EEA
The cookies described here are first-party and the data they generate is hosted within the European Economic Area.
Should a future measurement tool require a transfer outside the EEA, it would be implemented only under an adequacy decision or Standard Contractual Clauses together with a transfer impact assessment, and this policy would be updated before that tool was activated — not after.
How long your choice is kept
Your consent decision is stored for six months. After that period you are asked again, in line with supervisory authority guidance, so that a choice made once does not bind you indefinitely.
Proof of consent — the choice made, its date and the version of the policy in force — is retained for the period required to demonstrate compliance.
Changes and version
This policy is updated whenever the cookies in use change. Material changes are published here with a new version number and date, and where the change affects the basis of your consent, we ask for it again.
Current version 1.0, dated 5 August 2026.
Contact
Questions about this policy, or about how a specific cookie behaves: privacy@eshay-advisory.com.
You also have the right to lodge a complaint with your supervisory authority. In France, that is the Commission Nationale de l'Informatique et des Libertés (CNIL).