Cookie Policy
Document ID: FDT-COOKIE-2026-v1.2-EN
Version: 1.2
Last updated: 13 July 2026
1. Controller and scope
This Cookie Policy applies to Freeze-drying.tech and, in the corresponding language versions, to Liofilizacion.es and Liofilizacao.pt.
Controller: Jan Panek, autónomo
Spanish NIF: Y2362080V
EU VAT number: ESY2362080V
Address: Rotonda de Versalles 23, 28512 Villar del Olmo, Madrid, Spain
Contact: [email protected]
It forms part of the Privacy Policy.
2. Cookies and similar technologies
Cookies are small files stored on a device. Similar technologies include pixels, tags, local storage, browser identifiers, device signals and session-replay technologies. They may be set by us or by a provider whose service we use.
Non-essential storage or access technologies are used only after prior consent. Strictly necessary technologies may be used without consent where required to transmit a communication, provide a service expressly requested by the user, secure the service or remember privacy choices.
3. Your choices
On the first visit, you can:
- Accept all non-essential categories;
- Reject all non-essential categories; or
- open Settings and choose separately between:
- Analytics
- Session replay
- Advertising
Non-essential categories are off by default. There are no preselected options.
You can change or withdraw consent at any time through the permanent Cookie settings link in the footer. Withdrawal prevents future loading and removes first-party identifiers where technically possible. You can also remove cookies in your browser.
Rejecting optional technologies does not prevent access to the website, enquiry forms or B2B ordering functions.
4. Categories and expected technologies
The exact active technologies are shown in the consent panel. Names and durations may vary by browser, geography, provider configuration or service update.
| Category | Purpose | Provider and examples | Typical duration | Default |
|---|---|---|---|---|
| Strictly necessary | Security, bot mitigation, load balancing, saved privacy choice, requested form/session state and B2B checkout operation | Cloudflare: __cf_bm, cf_clearance; first-party consent preference such as site_consent; necessary application/session identifiers |
__cf_bm: about 30 minutes; cf_clearance: configured challenge period; consent choice: about 6 months; session: session duration |
Always active |
| Analytics | Measure aggregate traffic, performance, navigation and page use | Google Analytics 4: _ga, _ga_<container-id>, and _gid if deployed |
_ga and _ga_<container-id>: up to 2 years; _gid: up to 24 hours |
Off until Analytics consent |
| Session replay | Diagnose usability through masked clicks, scrolling and navigation replay | Microsoft Clarity: _clck, _clsk, CLID, MUID, ANONCHK and related identifiers |
From minutes/session to about 13 months, depending on identifier | Off until Session replay consent |
| Advertising | Measure campaigns, attribution and, where enabled, create or personalise advertising audiences | Google Ads: _gcl_au; Meta: _fbp, fr; Microsoft Advertising/UET where enabled: _uetvid, _uetsid, MUID |
Commonly 1 day to 13 months depending on provider | Off until Advertising consent |
5. Payment checkout on Stripe
When a Business Buyer chooses card payment, the buyer is redirected to Stripe’s hosted checkout on a Stripe domain.
Stripe may use cookies and device signals on its own domain for authentication, payment processing, fraud prevention, security and regulatory compliance, including identifiers such as __stripe_mid, __stripe_sid and Radar-related technologies.
These technologies are used in connection with the payment service expressly requested by the buyer and are governed by Stripe’s own privacy and cookie information. Full card data is entered on Stripe’s hosted environment and does not pass through our website servers.
6. Google implementation
We use a consent-first configuration equivalent to Basic Consent Mode:
- Google Analytics and Google advertising tags do not load before the relevant consent;
- no Advanced Consent Mode or pre-consent cookieless measurement pings are used;
- Analytics consent does not enable Advertising;
- withdrawal stops future loading.
7. Microsoft Clarity safeguards
Clarity is used only after separate Session replay consent and must be configured with:
- strict masking;
- no deliberate unmasking;
- exclusion from contact, quote, checkout and all other form-bearing pages;
- no capture of form fields, free text, email, telephone, VAT number, lead/order identifiers or payment information;
- restricted access and retention controls.
If those safeguards are not operating, Clarity must remain disabled.
8. Advertising safeguards
Advertising technologies are used only after Advertising consent.
Unless the Privacy Policy and consent interface are specifically updated, we do not enable:
- Meta Advanced Matching;
- Meta Conversions API;
- Google Enhanced Conversions;
- customer-list uploads;
- Customer Match;
- custom or lookalike audiences based on lead/customer data.
9. Strictly necessary security and consent records
Cloudflare, Turnstile, application security and consent records may process IP address, browser information and security results without optional-cookie consent where necessary to protect the service, transmit communications or remember privacy choices.
The GDPR lawful basis for security and consent-proof records is normally legitimate interest and/or compliance with legal obligations. Session state necessary for a user-requested form or checkout may also be required to perform requested pre-contractual steps.
10. Providers and international transfers
Google, Microsoft, Meta, Stripe and other providers may process data outside the EEA. Where required, transfers rely on adequacy decisions, the EU–US Data Privacy Framework for certified entities, Standard Contractual Clauses or another lawful safeguard.
More information is provided in the Privacy Policy.
11. Browser controls and updates
Browser settings can block or delete cookies, but blocking strictly necessary technologies may prevent security, form or checkout functions.
We update this Policy and the consent inventory when providers, purposes or technologies materially change.
12. Contact
Questions or requests: [email protected]