This notice describes the use of cookies and other tools for storing or accessing information on your device through the Agency’s website. It supplements the Privacy policy, available on the website, which explains the other personal data processing activities.
1. Controller and contacts
The data controller is Immobiliare Etna, with its registered office at {{agency_registered_address}}, tax code {{agency_tax_code}} and VAT number {{agency_vat_number}}.
For information and to exercise your rights concerning personal data, you can write to {{agency_privacy_email}}.
SFV S.R.L. provides the platform and manages its technical operation on behalf of the Agency, as described in the Privacy policy.
2. What cookies and similar tools are
Cookies are small files that a website can store in your browser and receive on subsequent visits. They can be used to maintain a session, protect forms, remember a choice or collect information on how the website is used.
Cookies may be:
- first-party, where they are set in the context of the website visited;
- third-party, where they belong to a different domain, such as that of an embedded service;
- session, where their persistence is linked to the browser session;
- persistent, where they have an expiry date or remain until deleted.
Classification as a first-party cookie does not mean that the data are processed only by the Agency: GA4 cookies, for example, are normally set on the website’s domain but are used for a service provided by Google.
This notice also covers technologies such as localStorage, sessionStorage, identifiers, pixels and other means of accessing information on the device. localStorage has no inherent automatic expiry: any duration must be managed by the application; sessionStorage is normally linked to the browser tab’s session. The rules depend on the actual purposes, not merely on the name of the technology.
3. Categories and legal bases
| Category | Purpose | User choice |
|---|---|---|
| Necessary | Website operation, sessions, security, storing privacy preferences and expressly requested features. To protect the forms the Agency uses Google Cloud reCAPTCHA (Google): the verification script is loaded from www.recaptcha.net even before consent |
Do not require consent because they are needed to provide the requested service and to protect the forms from automated submissions; they can be blocked through the browser, which may cause malfunctions |
| Statistics | Traffic analysis with Google Analytics 4 | Disabled before consent; can be accepted and consent withdrawn separately |
| Functional | Loading features and external content, such as the embedded map (OpenStreetMap) | Disabled before consent: the map is loaded only after consent to the category |
Storage or access strictly necessary for transmitting a communication or providing an expressly requested service falls under the exemption in Article 122 of Italian Legislative Decree 196/2003. Optional tools require consent under that provision and Articles 4(11) and 7 GDPR. The legal bases described in the Privacy policy apply to further processing of personal data.
The Agency does not use GA4 for advertising, remarketing or Google Signals. Independent processing by functional content providers is described in their respective notices and must not be confused with the Agency’s statistical purposes.
Protecting the forms from automated submissions is a necessary service: the Google Cloud reCAPTCHA check is active even without consent, because without it a legitimate request could not be told apart from spam. It does not depend on the optional categories and is not switched off by a refusal; the data processed by Google is described in its own notice. No optional tool — statistics, external content or marketing — is loaded before the user makes a choice.
4. How to express your preferences
On your first visit, the website keeps optional tools disabled. The banner allows you to:
- accept all optional tools offered;
- reject all optional tools and continue with necessary ones;
- customise your choices, accepting external features, statistics and marketing separately.
On your first visit, closing the banner using the designated control keeps optional tools disabled. When the panel is reopened, closing it without saving changes instead preserves the last recorded choice: to withdraw consent already given, you must disable the category and save your choice, or use the command to reject all optional tools. Scrolling the page, continuing to browse or using forms does not constitute consent. Optional choices are not preselected.
You can reopen the panel at any time through “Cookie preferences”, available on the website. Refusal does not prevent you from viewing listings or contacting the Agency; it may prevent optional external content from loading.
Banner choices do not include the specific consent to email tracking described in section 9.
Preferences apply to the Agency’s website and the browser used. The Analytics property shared across the platform does not automatically extend consent to other agencies’ websites.
A refusal or partial consent is stored for six months. Consent to every optional tool may be stored for up to twelve months, and the choice can be changed or withdrawn at any time. A new choice may be requested before it expires when the processing conditions change significantly or when the version of the consent requested changes. The banner is not persistently displayed again after refusal. A new request may also be necessary if the tools change substantially, if the previous choice can no longer be recognised or once the period has elapsed. Six and twelve months are not a universal statutory expiry period for all consent or all cookies.
The methods for obtaining and requesting consent again follow the Italian Data Protection Authority’s Guidelines on cookies and other tracking tools.
5. Technical application cookies
The website uses Laravel and the administration panel uses Filament. Names generated by the application may contain variable prefixes, identifiers or suffixes. In the table, the asterisk indicates a variable part of the name, not a character necessarily present in the cookie.
The public website, the one visitors browse, uses no cookies: the visitor’s preferences — acceptance, refusal and selected categories — are kept in the browser’s local storage (localStorage, or sessionStorage where the duration has to remain tied to a single tab), under a key dedicated to the consent of the visited website, with the same purpose and the same durations as a first-party technical cookie and without the server reading them. This notice keeps the name “Cookie policy” for clarity: the rules do not change with the name of the technology. The cookies listed below concern the session, the administration panel and the Agency’s reserved area.
Durations labelled as standard are those documented by the software: they do not represent the results of a browser scan. Tools that depend on a feature are used only where that feature is active and relevant to the visit.
| Name or functional identification | Purpose | Scope and standard duration |
|---|---|---|
Laravel session cookie, normally with a name ending in _session |
Links requests to the session; manages temporary state, messages and authentication where provided | First-party; standard Laravel configuration: 120 minutes of inactivity, renewed according to session activity |
XSRF-TOKEN, where issued by the applicable middleware |
Protection against forged requests and support for forms and application requests | First-party; duration linked to the session, normally 120 minutes in the standard configuration |
Persistent login cookie remember_*, only where the “Remember me” feature is available and selected |
Keeps an authorised user logged in to the panel | First-party, administration area; the standard value in the Laravel 13 authentication component is 400 days, unless invalidated or deleted earlier |
| Website privacy preference storage, kept in the browser’s local storage and not in a cookie | Remembers acceptance, refusal and selected categories | Visitor’s browser, on the visited host; six months, up to twelve months for consent to every optional tool, according to the configuration described in section 4 |
The application session cookie may have a time-based expiry and therefore does not necessarily disappear when the browser is closed. Logging out of the panel and invalidating credentials may end the effectiveness of authentication cookies before they expire on the device.
The panel may also store preferences strictly related to interface functionality, such as the selected theme or component state, when the relevant feature is used. If stored in localStorage, they persist until removed by the application or the user; they are not used to measure traffic or for commercial profiling. The public website does not require visitors to have an account: administration authentication cookies are not necessary simply to view listings.
References: Laravel session configuration, CSRF protection, Laravel authentication component.
6. Cloudflare and reCAPTCHA protection
Cloudflare delivers content and protects the website against malicious traffic. Cookies depend on the controls actually enabled: using the CDN does not automatically mean that all cookies in the Cloudflare catalogue are installed.
| Cookie | Function and condition of use | Documented duration |
|---|---|---|
__cf_bm |
Assessment of automated traffic on websites protected by the relevant Bot Management or Bot Fight Mode products | 30 minutes of continuous inactivity |
cf_clearance |
Records that a Cloudflare check has been passed | 30 minutes in the default Challenge Passage configuration; configurable by the operator |
cf_ob_info and cf_use_ob |
Support for retrieving pages through Always Online, where the feature is used | 30 seconds |
__cflb |
Affinity with the origin server, only where the relevant load balancing service is enabled | From a few seconds up to 24 hours, depending on configuration |
These tools, where necessary for the security or continuity function actually provided, are treated as technical tools.
Protection of the forms against automated submissions is provided by Google Cloud reCAPTCHA (Google), which tells human requests apart from automated ones. The service may set the cookie the verification needs:
| Cookie | Function and condition of use | Documented duration |
|---|---|---|
_GRECAPTCHA |
Anti-bot verification of the forms, when the verification is executed | Six months according to the provider’s documentation |
reCAPTCHA also processes browser and connection signals to distinguish people from bots: the absence of a cookie does not mean that no processing takes place. Google processes this data on behalf of the controller, under the Google Cloud data processing terms.
Cloudflare also acts as an independent controller to improve bot detection. Further details are available in the Cloudflare cookie catalogue and the Challenge Passage documentation.
7. Google Analytics 4
GA4 is activated only after consent to the Statistics category. Before acceptance, the website sends no events or measurement signals to GA4, including through cookieless transmissions. Blocking cookies alone would not be sufficient to prevent all transmissions by the service.
| Cookie | Provider and domain on which it is set | Purpose | Documented standard expiry |
|---|---|---|---|
_ga |
Google; normally set on the website’s domain | Distinguishes browsers using an identifier | Two years |
_ga_<identificativo> |
Google; normally set on the website’s domain | Maintains information on the Analytics session state | Two years |
Browsers may impose shorter limits. The tag’s standard settings may update the expiry on subsequent visits; the user can withdraw consent before that time. The suffix of the second cookie identifies the container used.
Cookie durations do not match the two months specified in the Privacy policy for GA4 user-level and event-level data subject to the relevant setting. Expired data are deleted through monthly processing; any reset due to new activity concerns user-level data, as explained in the Privacy policy. Aggregated reports are subject to further distinct rules.
Management of the GA4 property is entrusted to SFV. Each agency receives only aggregated reports for its own website. The configuration does not provide for advertising, Google Signals or recognition of visitors across different agencies’ websites. Names, email addresses, telephone numbers and messages from forms are not transmitted to Analytics.
References: GA4 cookies and their durations, cookies and user identification, data retention.
8. OpenStreetMap, Nominatim and Google Maps
The website may use OpenStreetMap or Google Maps. The service enabled for the page determines which requests are made: today OpenStreetMap is active, while Google Maps is not used. The choice of the service belongs to the website configuration, not to consent: with the Functional category off, no map is loaded, whatever the configured service.
OpenStreetMap and Nominatim. Map tiles are loaded in the browser only with the Functional category on: before consent, the property page shows an invitation to enable it in place of the map, and no request is made to the mapping service. Addresses are converted into coordinates (Nominatim) on the Controller’s servers, not in the visitor’s browser, so that activity does not depend on the consent given. Loading map tiles may disclose the IP address, browser information, referring page and requested area to OpenStreetMap or its delivery network. These communications do not, by themselves, amount to installing statistical cookies. Cookies used by the openstreetmap.org website are not attributed to all maps: visiting that website and loading only its map tiles are different operations. Processing is described in the OpenStreetMap Foundation Privacy policy.
Google Maps. The embedded map remains blocked until consent is given to the Functional category. Without consent, an invitation to manage preferences is shown without loading Google content. Accepting GA4 statistics does not automatically enable the map, and accepting the map does not enable GA4. Enabling the map is not informed consent to a mapping provider different from the one configured when the choice was made: if the service changes, the version of the consent requested is updated and the choice is asked again.
Activation may allow Google to receive connection data, device information and interactions with the map, and to read or set its own cookies subject to browser settings. Cookies may vary depending on the type of integration, whether the user is signed in to a Google account, preferences already expressed with Google and browser restrictions.
Google documents the following cookies among those used by its services; this is not a list of cookies necessarily installed by every map:
| Cookie documented by Google | Purposes stated by the provider | Documented duration |
|---|---|---|
NID |
Preferences and further Google service functions, including personalisation, analytics and advertising in the contexts described by the provider | Six months from last use |
SOCS |
Stores cookie choices for Google services | 13 months |
AEC |
Protection against spam, fraud and abuse in the services concerned | Six months |
These cookies belong to Google domains where present. Their use by Google must not be confused with the Agency running advertising campaigns, which is not envisaged. The choice made on the website governs the loading of embedded content; it does not automatically change Google account preferences.
References: Google cookies, Google Privacy policy, controller-to-controller terms.
9. Emails, server-side services and social links
Elastic Email. The service’s standard settings include open-tracking pixels and tracked links for clicks. These tools operate in emails and do not constitute cookies necessarily placed during a website visit. Their use is subject to specific consent, separate from GA4 and Google Maps preferences. Without that consent, including where the choice is unknown to the provider, service emails must be sent without open or click tracking. Refusal does not prevent the enquiry from being sent or handled. To withdraw consent, you can write to the Controller’s contact address. Technical data necessary for delivery and abuse prevention remain distinct. See the website’s Privacy policy and the Elastic Email documentation.
DigitalOcean, Amazon S3 and FLUX/BFL. Hosting, file delivery and photograph processing through server-side API calls do not, in themselves, involve installing in the browser the cookies used on these providers’ commercial websites. Any connection data and transmitted content are processed as described in the Privacy policy. This notice does not attribute BFL cookies to the website merely because it uses the FLUX APIs.
Google Search Console. Property verification and viewing reports do not, in themselves, introduce an additional measurement cookie on the website.
WhatsApp and social networks. References are simple links, not embedded social components. Following them takes you to external services, to which their respective notices apply. The mere presence of a link does not provide prior authorisation for cookies from the destination service.
10. Withdrawal, deletion and browser settings
You can withdraw or change preferences through “Cookie preferences” as easily as you can express them. After withdrawal, the website stops subsequent loading and transmissions for the disabled category and removes, where technically possible, the optional cookies it manages directly.
The Agency cannot directly delete all cookies belonging to third-party domains. Browser settings can be used to remove them. Withdrawing consent does not automatically mean that data already collected on servers are deleted: the rights described in the Privacy policy apply to such a request.
The browser allows you to view, delete or block cookies and other website data. Official instructions are available for Chrome, Firefox, Safari and Microsoft Edge.
Deleting data may also remove a refusal preference, making it necessary to express it again. Different browsers, devices and private browsing sessions may require separate choices. Blocking all cookies may affect forms, security checks or administrative access.
11. Personal data, recipients and transfers
Cookies and similar tools may involve identifiers, IP addresses, device information, preferences and interactions. The absence of the user’s name does not automatically make these data anonymous.
Data are processed by the Agency, authorised persons, SFV and the providers described, according to their respective roles. Some services may involve transfers outside the European Economic Area even where the website’s main server is in Europe. The applicable safeguards, providers’ roles and server-side retention criteria are described in the website’s Privacy policy and the official notices referenced.
You can exercise the rights provided for by the GDPR, including access, rectification, erasure, restriction, portability where applicable, objection and withdrawal of consent, by writing to {{agency_privacy_email}}. You can also lodge a complaint with the Italian Data Protection Authority or the competent authority.
12. Updates and scope of durations
This notice covers the services described and their standard configurations, subject to the stated choices for the consent system. The tables distinguish tools linked to specific features from variable names and cookies generally documented by providers.
Changes to services, the introduction of additional tools or substantial changes in purposes require the notice to be updated and, where necessary, a new choice by the user before activation. An update to the text does not constitute consent.
Expiry periods may be shortened by device settings or early deletion. Cookies may be invalidated before the browser physically deletes the file. The notice must remain consistent with the tools actually enabled on the website.
Last updated: 3 October 2026