Çerez Politikası

Art Persona · Cookie Policy · v1.0 · Effective 30 July 2026

FieldValue
OperatorGromeFeet OÜ
Company number17348635
Registered officePärnu mnt 12, Kesklinna linnaosa, 10148 Tallinn, Harju maakond
Trading name / brandSanat Kişiliği
Websitehttps://art-persona.com
Contact emailinfo@art-persona.com
Support / complaintsinfo@art-persona.com (Monday-Friday, 09:00-17:00 Estonia time, excluding public holidays)
Governing lawEstonia, subject to mandatory consumer protections
Document versionv1.0
Effective date30 July 2026
Important: Strictly necessary technologies support security, checkout and consent records. Analytics, preference and marketing technologies are used only under the consent model required by applicable law, and users can change their choices at any time.

1. Introduction and scope

This Cookie Policy applies to art-persona.com and related checkout or account pages controlled by GromeFeet OÜ. It should be read with the Privacy Policy. Technologies placed directly by a payment provider or other independent service may also be governed by that provider’s notice.

2. What cookies and similar technologies are

Cookies are small text records stored by a browser. Similar technologies include local storage, session storage, software development kit identifiers, tags and pixels. They can remember a session, secure a form, record consent, measure performance or associate a visit with an advertising campaign.

3. Why we use cookies

Art Persona uses technology to keep the website secure, preserve checkout state, remember language and consent choices, diagnose errors, understand aggregate use and evaluate marketing where permission has been given. Data is not used to create a biometric identity profile from avatar images.

4. Cookie categories

Technologies are grouped as strictly necessary, functional or preference, analytics or performance, and marketing. Classification follows the purpose actually served. A technology used for more than one purpose is treated according to the purpose requiring the highest level of user choice.

CategoryPurposeConsent requiredEffect if disabled
Strictly necessarySecurity, session continuity, checkout, load balancing and consent storageNo, where strictly necessaryLogin, upload, checkout or preference storage may fail
Functional / preferencesRemember language, interface and non-essential user choicesYes, where requiredSettings may reset and convenience features may be reduced
Analytics / performanceMeasure aggregate traffic, errors and feature performanceYes, where requiredCore service remains available; improvement data is reduced
PazarlamaMeasure campaigns and limit or attribute promotional messagesYesNo behavioural marketing technology is activated

5. Lawful basis and consent

Strictly necessary technologies operate because they are required to provide a requested service or secure the website. Non-essential cookies rely on consent where European privacy rules require it. Consent is specific by category, recorded, and not bundled with acceptance of the Terms.

Non-essential technologies remain off until a valid choice is recorded where consent is required.

6. Cookie inventory and example technology

The inventory below identifies the main technologies used by the current service architecture. A payment provider may generate additional short-lived security identifiers during checkout. Their exact technical names can vary by provider, device and risk-control path, while the stated purpose and category remain controlling.

Cookie / technologyTypePurposeDurationProvider
ap_sessionStrictly necessaryMaintains secure website and account sessionSessionSanat Kişiliği
ap_csrfStrictly necessaryPrevents unauthorised form and checkout requestsSessionSanat Kişiliği
ap_cookie_consentStrictly necessaryStores category choices and notice version12 monthsSanat Kişiliği
ap_localeFunctional / preferencesRemembers language and regional display choice6 monthsSanat Kişiliği
payment_sessionStrictly necessaryConnects the checkout to authentication and transaction statusSession to 24 hoursPayment provider displayed at checkout
ap_analytics_idAnalytics / performanceCounts visits and measures aggregate feature use13 monthsArt Persona analytics service
ap_campaignPazarlamaAttributes a consented campaign visit to an Order90 daysArt Persona marketing service

7. Third-party cookies and embedded services

Third-party providers may set technology when their content or payment frame loads. Art Persona limits such integrations, contractually restricts processors where applicable and blocks non-essential tags before consent. Independent third parties can determine additional purposes and should provide their own notices.

8. Managing preferences

The cookie settings interface allows category choices to be changed at any time. Users may also block or delete cookies in browser settings. Blocking essential cookies can prevent login, secure upload, checkout, fraud checks or preservation of a partially completed order.

9. Retention and expiry

Session cookies expire when the browsing session ends or shortly afterwards. Persistent identifiers use the duration shown in the inventory and are refreshed only where justified. Consent records are retained long enough to demonstrate the choice and then renewed at reasonable intervals or after a material change.

10. Do-Not-Track and browser signals

Because browser Do-Not-Track signals are not implemented consistently, the Service does not rely on them as a universal consent mechanism. Where a legally recognised opt-out signal applies, GromeFeet OÜ will honour it for the relevant processing. The cookie settings interface remains the primary control for European users.

Withdrawal must be as accessible as the original consent choice.

11. Children and age

The Service is directed to adults. Art Persona does not knowingly use behavioural advertising cookies to profile children. An adult arranging an avatar involving a minor must control the session and ensure that no child independently submits information or changes consent preferences.

12. International data flows

Cookie and analytics providers may process identifiers outside the European Economic Area. Transfers are handled under the safeguards described in the Privacy Policy. Users may refuse non-essential categories to prevent the related technology from being activated where consent is the legal basis.

13. Changes to this policy

The inventory is updated when providers, durations, names or purposes materially change. A new non-essential purpose will not be treated as covered by an unrelated prior consent. The effective date shows the current version, and the settings interface may request renewed choice where appropriate.

14. Contact and complaints

Questions about cookies, consent records or providers may be sent to info@art-persona.com. A privacy complaint can also be made to the Estonian Data Protection Inspectorate or another competent supervisory authority. Technical problems with the settings interface should be reported with browser and device details but without unnecessary personal information.

Operational Maintenance Checklist

1. Inventory owners review active cookies, local storage and embedded tags at least quarterly and before each material release.

2. A new non-essential technology is blocked until its purpose, provider, retention, lawful basis and consent category are documented.

3. The production website is scanned after deployment to compare actual names and durations with the published inventory.

4. Consent logs are tested for category accuracy, withdrawal, expiry and version linkage.

5. Expired providers and unused tags are removed from code, consent configuration and this policy.

6. Material discrepancies are corrected promptly and renewed consent is requested where a new purpose is introduced.

15. Governing law and mandatory rights

This Cookie Policy is governed by Estonian law and applicable European privacy law. It does not limit a user’s right to withdraw consent, object to unlawful processing, complain to a competent supervisory authority or use any other mandatory remedy. Mandatory local rules apply where they provide stronger protection.

Deployment and consent controls

Before release, engineering maintains a tag register linking every cookie, local-storage key, pixel or embedded component to an owner, provider, trigger, purpose, category, retention period and consent state. The release is blocked when a non-essential tag can load before the relevant consent choice or when a necessary identifier is used for an unrelated purpose.

Quality assurance tests a first visit with no choice, rejection of all optional categories, selective category acceptance, withdrawal, expiry, refreshed consent after a material change and checkout through the payment-provider interface. Tests also confirm that rejection does not disable ordinary browsing or a requested purchase except where a strictly necessary security function cannot operate.

After deployment, the production website is scanned and compared with the published inventory. Unknown technologies are disabled or investigated, obsolete tags are removed from code and the consent platform, and provider documentation is checked for changed names or durations. A purpose change is not treated as a routine update: it requires a lawful-basis assessment and renewed consent where required.

Consent evidence records the policy version, categories presented, user action, timestamp and relevant technical context without creating an unnecessary behavioural profile. Access to these records is limited, retention is proportionate to demonstrating compliance, and a withdrawal takes effect for future non-essential processing without making the previous lawful use invalid.

Ownership and approval: The named operational owner confirms that the customer-facing rule, production workflow and support script describe the same outcome before publication.

Change control: A material product, provider or checkout change is assessed for legal impact and deployed only after the affected wording, controls and training have been updated.

Customer evidence: Staff rely on the minimum relevant Order, communication, delivery and payment evidence and do not request unrelated identity, image or card information.

Exception handling: An unusual case is escalated to a competent reviewer rather than resolved through an undocumented promise that conflicts with the published terms or mandatory law.

Quality assurance: Sample cases are tested from customer request through final outcome, including the status visible to support and the records needed to explain the decision.

Access control: Systems and provider dashboards use role-based access, strong authentication and prompt removal of credentials when responsibilities change.

Customer communication: Notices state what happened, what the customer must do, the expected next step and the available escalation route without overstating technical or legal certainty.

Provider alignment: The configuration and contractual scope of each processor or platform are checked against the functions attributed to it in this policy.

Incident response: A security, delivery, payment or rights incident is contained, documented and routed to privacy, consumer, payment or legal response procedures as applicable.

Training: Personnel who operate the relevant workflow receive concise instructions, prohibited practices and escalation examples before handling live Orders.

Monitoring: Material failure patterns, complaints and reversals are reviewed for root cause and corrective action rather than treated only as isolated customer-service cases.

Retention discipline: Operational evidence is retained for the applicable legal or dispute period and then deleted or anonymised when no continuing purpose justifies it.

Version integrity: The effective version accepted or presented for an Order can be identified, while the website clearly presents the current version for future transactions.

Remediation: A confirmed control gap is corrected promptly, affected processing or fulfilment is paused where necessary, and impacted customers receive the remedy required by law.

Management review: Senior management periodically reviews whether the policy remains accurate for the live commercial model, risk appetite and acquiring arrangements.

Auditability: A reviewer can reconstruct the material decision and execution status without relying on private memory, informal chat or inaccessible personal files.

User journey review: The desktop and mobile journeys are checked from entry page through consent, checkout, fulfilment and post-purchase support for accuracy and accessibility.

Data minimisation: Forms, logs and case templates collect only fields needed for the stated purpose and avoid free-text requests for sensitive information where structured evidence is sufficient.

Supplier exit: Replacement or termination of a provider includes export or deletion of relevant records, revocation of access and removal of obsolete code, links and policy references.

Complaint learning: Substantiated complaints are mapped to the control that failed, assigned a corrective-action owner and retested after remediation.

Business continuity: Contingency steps preserve customer communications, secure evidence and lawful remedies when a critical provider or internal system is unavailable.

Legal watch: Material changes in consumer, privacy, payment or digital-content requirements are assessed against the live policy and implementation without waiting for a complaint.

Accessibility: Customer notices, controls and support routes remain understandable and operable across common devices and assistive technologies.

Localisation: Translated or localised customer text is checked against the controlling English version so that material rights, deadlines and restrictions are not altered.

Test environment hygiene: Test accounts and sample files are segregated from live Customer Materials and do not use real payment credentials or unnecessary personal data.

Escalation timing: Urgent safety, fraud or security cases are prioritised immediately, while ordinary questions follow published response standards and are not left without ownership.

Metrics integrity: Service metrics distinguish acknowledged, resolved, refunded, corrected and appealed cases so performance reporting does not conceal unresolved customer harm.

Art Persona · Cookie Policy · v1.0 · Effective 30 July 2026. Published on the website; subject to update; the current published version governs.

Sepet (0 ürünü)

Hesabınızı oluşturun