Skip to content
Get a quote

Legal document

Cookie policy

Which cookies we use, which ones need consent and how you can change your choice.

The cookie banner on the site has to be translated natively into all three languages, not just into the English version; Korean law (PIPA) treats cookie consent as a separate act, not as a formality translated automatically.

This is not legal advice. The exact list of cookies (technical name, provider, lifetime) has to be generated automatically by the chosen consent management platform (CMP) or documented manually at the time of the actual launch; the list below describes the categories and tools confirmed by the site’s technical specification, not a technical audit of individual cookies, which cannot exist before the site is live.

This source document was last updated: 5 September 2026.


1. What cookies are

Cookies are small text files, saved by your browser when you visit a site, that allow the site to remember information about your visit (for example, the language you chose) or to send data about your browsing to third parties (for example, analytics or advertising tools). The same legal umbrella also covers similar technologies: local storage in the browser (localStorage), identifiers from tracking pixels and so on. We treat them all the same way in this policy.


These cookies are indispensable to the basic functioning of the site and cannot be switched off from the consent banner; they can only be blocked from your browser settings, in which case some features of the site will no longer work correctly.

Cookie / technology Purpose Lifetime Provider
Language preference (RO/EN/KO) Remembers the language you chose, so you do not have to select it on every visit Persistent, ~12 months First party (the site itself)
Form session / CSRF token Protects the contact forms against cross-site request forgery attacks Session (deleted when the browser closes) First party
Anti-bot verification (Cloudflare Turnstile) Confirms that the form is submitted by a person rather than an automated script A few minutes, per verification Cloudflare, Inc.; it sets no cross-site tracking cookie

2.2 Traffic analytics, the cookieless layer, active by default

We use a cookieless analytics tool ([TO BE COMPLETED Plausible, Fathom or the equivalent chosen by the technical team]) that places no cookies, collects no personal data and cannot identify you individually or track you across different sites; it provides only aggregate statistics (visitor numbers, popular pages, traffic sources). Being a tool with no personal data and no persistent identifier, it does not require your consent under the current interpretation of ePrivacy/GDPR for this type of technology, and it stays active whatever you choose in the banner.

These tools are switched off by default and are activated only after you explicitly choose “Accept” for the corresponding category in the cookie banner. Nothing in this category runs before your decision.

Cookie / technology Purpose Typical lifetime Provider
Google Analytics 4 (_ga, _ga_* and other cookies issued by gtag.js) Detailed traffic statistics, on-site behaviour, conversion attribution Up to 2 years Google Ireland Limited / Google LLC
Google Tag Manager / Google Ads (conversion and remarketing cookies, if we run paid campaigns) Measuring the effectiveness of advertising campaigns, remarketing Variable, up to 13 months for advertising cookies Google Ireland Limited / Google LLC
Microsoft Clarity Interaction maps (heatmaps) and anonymised session recordings, to understand how you navigate the site; form fields are masked automatically, so anything typed in is not visible in the recordings Up to 1 year Microsoft Corporation

For visitors from the European Economic Area, we activate these tools through Google Consent Mode v2: your browser transmits four consent signals (ad_storage, analytics_storage, ad_user_data, ad_personalization), and the Google scripts behave accordingly; they do not load fully until you make a choice.

The exact list of individual cookies (full technical name, issuing domains, precise lifetimes) will be generated automatically by the consent management platform (CMP) chosen at implementation and displayed dynamically in the banner or the cookie settings page; the tables above describe the confirmed categories and providers, not a full technical audit, which cannot exist before the site actually launches. [TO BE COMPLETED at launch].


  • Strictly necessary cookies (2.1) rest on the technical necessity of providing the service you explicitly requested (for example, submitting a form); they require no consent, under ePrivacy (transposed in Romania through Law No. 506/2004).
  • The cookieless analytics tool (2.2) processes no personal data, so it does not fall under the cookie consent requirement.
  • All other cookies (2.3) rest exclusively on your explicit consent (Art. 6(1)(a) GDPR plus Art. 4-5 of Law 506/2004), not on legitimate interest. Legitimate interest may justify subsequent processing of data under GDPR, but it never replaces the obligation to ask for consent before placing the cookie.

On your first visit, you see a banner that lets you:

  • accept all optional cookie categories;
  • reject all optional cookie categories, an option just as visible and as accessible as “Accept”, never hidden in a small link or several clicks away;
  • customise, switching each category on or off individually (detailed analytics, advertising, interaction maps).

No cookie from category 2.3 is placed before you make a choice. The banner is translated natively for each language version of the site (Romanian, English, Korean); it is not simply the English banner shown with translated labels.

You can change your choice at any time, through the permanent “Cookie settings” link, available in the site footer, on every page, in all three languages. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, but it stops any further collection immediately.

How to disable cookies in your browser

Independently of our banner, you can block or delete cookies in the settings of the browser you use (Chrome, Safari, Firefox, Edge and others); see your browser’s help section. Blocking cookies entirely may affect the correct functioning of parts of the site (for example, remembering your language preference).


5. Cookies and visitors from South Korea

The Korean (KO) version of the site follows the same principles of prior, granular and explicit consent, under Korean personal data protection law (PIPA), which has its own consent regime, similar in principle to GDPR but treated as a separate process rather than as a translation of the European version. The cookie banner is served correctly, in Korean, with non-essential cookies blocked by default until explicit acceptance. [LAWYER VALIDATION by local Korean counsel] on any additional requirement for granular consent per purpose, specific to PIPA, beyond the general structure described here; Korean data law was amended substantially in 2025-2026 (including an amendment applying from September 2026 that raises the cap on penalties significantly), so we recommend a fresh check right before launch, not only when this document was drafted.


6. Contact

For questions about this policy or about the cookies used on the site:

  • Email: [TO BE COMPLETED dedicated data protection email]
  • General email: office@alucard.ro

For details of how we process the personal data resulting from the use of accepted cookies, see the Privacy Policy.


What has to be completed before publication

Company and technical details ([TO BE COMPLETED]), 3 markers:

  1. The cookieless analytics tool finally chosen (Plausible, Fathom or equivalent), Sections 2.2 and 2.3
  2. The exact and complete list of individual cookies (technical name, domain, precise lifetime), generated by the chosen CMP or documented manually, at the time of the actual launch, Section 2.3
  3. The dedicated data protection email, Section 6

Points for legal validation ([LAWYER VALIDATION]), 1 marker:

  1. Additional granular consent requirements specific to PIPA for the KO version of the banner, checked with local Korean counsel, taking into account the recent 2025-2026 amendments to Korean data protection law (Section 5)

Technical note for the implementation team: this document assumes a CMP that natively supports Google Consent Mode v2 and Korean as a language in its own right (not generically as “other languages”); that is a functional requirement, not a choice of a specific vendor.