Cookie Policy
CONSOO S.R.L.S. — hice
Edition: English master (international)
Last updated: 3 July 2026
1. Introduction and scope
1.1 This Cookie Policy describes the types of cookies and similar technologies
used on the website https://hice.ai and on the web application of the Service
accessible at https://app.hice.ai (hereinafter, jointly, the "Site" and the
"Service"), as well as the purposes for which they are used and the means by
which the user can manage their preferences.
1.2 This document is provided pursuant to Article 122 of Legislative Decree 196/2003 (the Italian Personal Data Protection Code, the "Privacy Code"), which implements Directive 2002/58/EC (the "ePrivacy Directive"), Regulation (EU) 2016/679 (the "GDPR"), and in accordance with the "Guidelines on the use of cookies and other tracking tools" adopted by the Italian data protection authority (Garante per la protezione dei dati personali) by measure of 10 June 2021 (the "Garante 2021 Guidelines"), referenced here as the EU baseline.
1.3 The controller of the personal data collected through cookies is CONSOO
S.R.L.S. (hereinafter "hice" or the "Provider"), with registered office at
Piazzetta Umberto Giordano 2, 20122 Milan (MI), Italy, VAT/Tax Code
IT13823860963. The Controller's full contact details are set out in §10 and in
the Privacy Notice (informativa-privacy.md).
1.4 This Cookie Policy forms an integral and substantial part, to the extent
applicable, of the Privacy Notice (informativa-privacy.md), to which reference
is made for any aspect concerning the processing of personal data not
specifically governed in this document (in particular: the roles of the
controller and the processor, the data subject's rights, retention periods, and
transfers outside the EEA).
2. What cookies and similar technologies are
2.1 Cookies are small text files that the websites visited send to the user's device (computer, tablet, smartphone), where they are stored and then retransmitted to the same sites on subsequent visits. Cookies allow, among other things, the Site and the Service to function properly, the user's session to be kept active, the preferences expressed to be remembered, and information about the use of the pages to be collected in aggregate form.
2.2 Similar technologies means the further tools that, although not
technically cookies, allow information to be stored on or accessed from the
user's device, or the user's activity to be tracked. This category includes, by
way of example: the browser's local storage tools (localStorage,
sessionStorage, IndexedDB), pixels/web beacons, identifiers associated with
product scripts, and techniques for detecting user interactions (for example,
the recording of browsing sessions). In this document the term "cookie", unless
otherwise indicated, is to be understood as referring both to cookies in the
technical sense and to similar technologies.
2.3 For the purposes of consent, the Garante 2021 Guidelines treat in the same way cookies and other tracking tools capable of storing information on, or accessing information already stored in, the user's device. The rules on consent set out in §4 and §6 therefore apply to all the technologies described in §2.2, and not only to cookies in the strict sense.
3. Classification of the cookies used
Cookies may be classified according to several criteria. The distinctions relevant for the purposes of this Cookie Policy are set out below.
3.1 By the party that installs them
3.1.1 First-party cookies: installed directly by hice through the domains
hice.ai and app.hice.ai.
3.1.2 Third-party cookies: installed, through the Site or the Service, by
parties other than hice (the providers indicated in the table in §7), acting as
independent controllers or as processors as specified in the register of
sub-processors (_foundation.md §5) referenced in §8.
3.2 By duration
3.2.1 Session cookies: automatically deleted when the browser is closed.
3.2.2 Persistent cookies: stored on the device until they expire or until they are removed by the user.
3.3 By purpose (the Garante's categories)
For the purposes of consent, the Garante 2021 Guidelines distinguish two macro categories, described in §4.1 and §4.2:
3.3.1 Technical / necessary cookies — do not require the user's consent.
3.3.2 Analytics and profiling cookies — as a rule require the user's prior consent, save for the exception for anonymized analytics referred to in §4.2.2.
4. Categories of cookies, purposes, and legal bases
4.1 Technical / necessary cookies
4.1.1 Technical cookies are those used for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or to the extent strictly necessary for the Provider to provide the Service explicitly requested by the user (Article 122(1) of the Privacy Code). They include, in particular:
(a) navigation or session cookies, which ensure the normal navigation and use of the Site and the Service (for example, by enabling authentication and the maintenance of the user's session within the restricted area);
(b) functionality cookies, which allow the user to navigate according to a set of selected criteria (for example, the language) in order to improve the service provided;
(c) security cookies, used to prevent abuse, fraudulent activity, and unauthorized access, as well as for the purpose of protecting the Account and the Tenant.
4.1.2 Given the nature of the Service — a multi-tenant SaaS platform with a restricted area, accessible upon authentication — the technical session and authentication cookies are indispensable for the operation of the Service: disabling them may prevent access to the restricted area, the maintenance of the session, and the proper use of the functionalities.
4.1.3 Legal basis. For technical/necessary cookies the user's consent is not required. The related processing is lawful insofar as it is necessary for the performance of the contract to which the data subject is party or for the performance of pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR), as well as, for security cookies, on the basis of the Controller's legitimate interest in ensuring the security of the network, of the Service, and of the data (Article 6(1)(f) GDPR, also in relation to Recital 49).
4.1.4 Adequate information about technical/necessary cookies is in any case provided by means of this document, consistently with the Garante 2021 Guidelines.
4.2 Analytics and profiling cookies
4.2.1 Analytics cookies are used to collect information, in aggregate or disaggregated form, on the number of users and on how they visit and use the Site and the Service (for example, the most visited pages, navigation paths, errors encountered, interactions with the functionalities). Profiling cookies are aimed at creating profiles relating to the user and are normally used for further purposes.
4.2.2 Analytics treated as technical cookies (the Garante's exception). According to the Garante 2021 Guidelines, analytics cookies may be treated as technical cookies — and therefore installed without consent — only where the following conditions are simultaneously met:
(a) they are used solely to produce aggregate statistics and in relation to a single site or a single mobile application, so as not to allow the monitoring of a person's browsing across different sites or applications;
(b) for their production, at least the fourth component of the user's IP address is masked (reduction of direct identifiability);
(c) the third parties possibly involved refrain from combining the data so minimized with other processing (for example, customer files or statistics relating to other sites) or from transmitting them to further third parties, save the possibility of using them solely for the technical provision of the measurement service, as a person acting under the site operator.
In the absence of even one of those conditions, analytics cookies are subject to the consent regime referred to in §4.2.3.
4.2.3 Legal basis (general rule). For analytics cookies not falling within the exception referred to in §4.2.2 and for all profiling cookies, the legal basis is the user's consent, given in advance, freely, specifically, on an informed basis, and unambiguously (Article 122 of the Privacy Code; Articles 6(1)(a) and 7 GDPR). Such cookies are installed only after the user has given their consent through the dedicated banner (§6). Consent may be withdrawn at any time, as easily as it was given (§6.4).
4.3 Third-party marketing / advertising cookies
4.3.1 At present, hice does not use third-party advertising cookies or behavioural advertising tools on the Site and the Service. Should such tools be introduced in the future, this Cookie Policy will be updated and their use will be subject to the user's prior consent pursuant to §4.2.3.
5. Product analytics tool and session recording
5.1 hice uses a product analytics tool, provided by a sub-processor, to
understand how users interact with the Service, identify malfunctions, and
improve the user experience and the functionalities. The cloud services and the
servers used to provide the Service are located in the reference region of this
edition (European Union / EEA). The product analytics service provider acts as a
sub-processor of hice as indicated in the register of sub-processors
(_foundation.md §5) referenced in §8.
5.2 The features of that tool used by hice include the recording of browsing sessions ("session replay"), that is, the visual reconstruction of the user's interaction with the pages of the Service (sequence of screens, clicks, navigation, errors), aimed at identifying malfunctions and improving usability. That feature is configured in masked mode, in accordance with the principles of data minimization and data protection by design (Articles 5 and 25 GDPR). In particular:
(a) all displayed text and all input fields are masked by default during recording: on playback, the textual content and the values entered are not legible, but are replaced by placeholders;
(b) the automatic detection of interactions (autocapture) is configured with removal of the free text associated with the elements, so as not to capture potentially identifying or sensitive content;
(c) the tool does not collect personally identifying data (PII): sessions are associated solely by means of technical identifiers of the User and the Tenant (IDs), not by name, email, or other direct data;
(d) the automatic client-side detection of page views (pageview) is disabled.
5.3 Assessment for the purposes of consent. The product analytics tool is capable of collecting technical identifiers and data relating to the user's interactions with the Service. That tool requires the user's consent pursuant to §4.2.3, since the conditions of the Garante's exception referred to in §4.2.2 are not met in full: in particular, the detection of interactions and the recording of sessions (albeit masked) exceed the mere production of aggregate statistics with an anonymized IP. The tool is therefore activated only after the user's consent, given through the banner (§6); in the absence of consent, the tool is not loaded and does not collect data relating to browsing.
Session recording and product analytics as described in this §5 are subject to the consent given through the banner (§6): the tool remains disabled until the user gives consent and is loaded only after opt-in, with the masking described in §5.2.
5.4 The data collected through the product analytics tool are processed by hice
as controller for the purposes of product analytics, diagnostics, and telemetry
indicated in the Privacy Notice (informativa-privacy.md). For details on the
location of the processing and on any safeguards for transfers, reference is made
to §8.
6. Consent management (banner, granularity, withdrawal)
6.1 Banner and initial information. On first access to the Site or the Service, the user is shown an initial-information banner (cookie banner) which:
(a) informs the user, in a concise manner, of the use of cookies and similar technologies, with a reference to this extended Cookie Policy for all details;
(b) allows the user to accept all cookies subject to consent, or to reject them all (continuing with technical/necessary cookies only), or to customize their choices;
(c) bears a close command ("X") which, consistently with the Garante 2021 Guidelines, does not amount to the giving of consent and keeps only technical/necessary cookies active;
(d) does not use deceptive patterns (so-called dark patterns): the accept and reject commands are presented with equal prominence.
6.2 No preset consent. Until the user expresses a choice, only technical/necessary cookies are installed on the device. The analytics and profiling cookies subject to consent (§4.2.3), including the product analytics tool (§5), are not installed or activated before consent is obtained. Merely continuing to browse (scroll) does not constitute consent.
6.3 Granularity. Through the banner's customization panel, the user can give or refuse consent for each individual category of cookie (and, where technically available, for each individual tool), it being understood that technical/necessary cookies cannot be disabled as they are indispensable for the operation of the Service.
6.4 Withdrawal of consent. The user may modify or withdraw the consent given at any time, as easily as it was given, by accessing the preference management panel again through the dedicated "Cookie preferences" link [to be completed with the actual placement of the link/command — e.g. the footer of the Site and/or the settings of the Service]. Withdrawal does not affect the lawfulness of the processing based on the consent given before withdrawal.
6.5 Re-presentation of the banner. The banner is not re-presented at each access. The user's choice is retained for a period no longer than that indicated by the Garante 2021 Guidelines , at the end of which, or in the event of significant changes to the processing conditions or of changes to the cookies installed, the request for consent is re-presented to the user.
6.6 Management through the browser. In addition to the tools referred to above, the user can also manage their cookie preferences through their browser's settings, as indicated in §9. Please note that disabling technical/necessary cookies through the browser may compromise the proper functioning of the Site and the Service.
6.7 Recording of consent. hice keeps a record of the choices made by the user regarding cookies, in order to be able to demonstrate that consent has been obtained pursuant to Article 7(1) GDPR.
The consent mechanism described in this §6 (banner with accept/reject/ customize, granularity by category, withdrawal as easy as the giving of consent, recording of consent) is implemented at the system level: session recording and product analytics (§5) remain disabled until the user gives consent through the banner, and are loaded only after opt-in.
7. List of cookies and tools used
7.1 The tables below set out the cookies and the storage and tracking tools used on the Site and the Service, indicating their type, purpose, duration, and the party concerned. The list reflects the technical inventory of the Service; the technical names, the number, and the durations of third-party cookies (in particular those of the product analytics tool) may vary and are subject to periodic verification (§7.2).
7.1.1 Technical / necessary cookies (no consent — §4.1)
| Name / Tool | Type | Purpose | Duration | Party (functional category) |
|---|---|---|---|---|
sb-<project>-auth-token (and related chunks .0 / .1 / .2) | Technical / necessary cookie (httpOnly, Secure) | Authentication of the User and maintenance of the session in the restricted area of the Service | Session duration | Cloud infrastructure, hosting, database, authentication, and storage provider (sub-processor, European Union / EEA; see _foundation.md §5) |
hice-platform-auth | Technical / necessary cookie | Authentication to the platform administration area | Session duration | hice (first party) |
hice-platform-login-day | Technical / necessary cookie (security) | Monitoring of access and prevention of abuse on the administration area | 24 hours | hice (first party) |
hice_oauth_nonce | Technical / necessary cookie (security) | Anti-CSRF protection in the connection flows of external integrations | Less than 10 minutes | hice (first party) |
hice_pp_portal_token | Technical / necessary cookie | Access to the projects client portal | Per the Service's configuration | hice (first party) |
7.1.2 Similar technologies — technical / necessary local storage (localStorage / sessionStorage) (no consent — §4.1)
| Name / Key | Type | Purpose | Duration | Party |
|---|---|---|---|---|
calendarSidebarOpen, calendarHideWeekend | localStorage — technical / functional | Storing the calendar's display preferences | Persistent (until deleted by the user) | hice (first party) |
calendarVisibleOwners, calendarHiddenCalendars | localStorage — technical | Identifiers of calendars shown or hidden | Until logout | hice (first party) |
hice.mail.layout.<id> | localStorage — technical | Layout preferences for the integrated mail client | Until logout | hice (first party) |
hice.chat.* | localStorage / sessionStorage — technical | Technical identity and lifecycle of the current conversation | Until logout | hice (first party) |
SID | sessionStorage — technical | Session identifier for product telemetry | Session duration | hice (first party) |
hice_chat_conversation_id | sessionStorage — technical | Maintaining the context of the conversation with the assistant | Session duration | hice (first party) |
7.1.3 Tools subject to consent (§4.2.3 and §5)
| Name / Tool | Type | Purpose | Duration | Party (functional category) |
|---|---|---|---|---|
| Cookies/identifiers of the product analytics tool, with masked session recording (session replay) | Analytics / product — subject to consent (§5) | Analysis of interactions with the Service, diagnostics, improvement of the experience and of the functionalities; session recording with masking of all text and all inputs, without PII (§5.2) | Indicatively up to 12 months, in accordance with the provider's retention policy | Product analytics service provider (sub-processor, European Union / EEA; see _foundation.md §5) |
7.1.4 Third-party cookies at the payment stage
| Name / Tool | Type | Purpose | Duration | Party (functional category) |
|---|---|---|---|---|
| Technical cookies of the payment-processing provider (set at the checkout stage) | Technical / necessary for the payment operation (e.g. anti-fraud, 3-D Secure authentication) | Carrying out and securing the payment requested by the user; fraud prevention | Duration set by the payment-processing provider | Payment-processing provider (sub-processor / independent controller for anti-fraud aspects; see _foundation.md §5) |
At present, hice does not use generalist third-party web analytics tools (for example Google Analytics or Google Tag Manager), nor geographic-map cookies. The fonts are hosted directly by hice (self-hosted) and do not entail the installation of any cookie or requests to third-party domains.
7.2 The technical names of the cookies, their number, and their duration may vary over time depending on updates to the Site, the Service, and third-party tools. hice periodically updates this table following the outcome of inventory checks.
The tables in §7.1 reflect the technical inventory of the first-party cookies and of the local storage tools of the Service. The names and durations of third-party cookies — in particular those of the product analytics tool (indicative duration of up to 12 months) and those of the payment-processing provider — are provided on an indicative basis and may vary depending on the third-party provider's policies; hice periodically updates the table following the outcome of inventory checks.
8. Data transfers and sub-processors
8.1 Some of the tools described in this Cookie Policy entail processing carried
out by third-party providers acting as sub-processors of hice. The updated
list of sub-processors, indicating the service provided, the categories of data
processed, the location of the processing, and the safeguards adopted for any
transfers to third countries (outside the EEA), is contained in the register
of sub-processors (_foundation.md §5) and referenced in the Privacy Notice
(informativa-privacy.md) and in the Data Processing Agreement
(dpa-trattamento-dati.md).
8.2 The cloud services and the servers used to provide the Service are located in the reference region of this edition (European Union / EEA). Should a processing operation exceptionally require a transfer outside that region, it is carried out by adopting adequate safeguards under the applicable law (Chapter V of the GDPR — Standard Contractual Clauses or an adequacy decision). With specific regard to the tools mentioned in this Cookie Policy:
(a) the product analytics tool (§5) operates through a product analytics service provider on infrastructure located in the European Union / EEA, with the safeguards indicated in the register of sub-processors;
(b) the technical session/authentication cookies depend on the database, authentication, and storage services provided by the cloud infrastructure, hosting, database, authentication, and storage provider, with the location in the European Union / EEA and the safeguards indicated in the register of sub-processors.
8.3 Where a processing operation entails the transfer of personal data to third
countries that do not have an adequacy decision from the European Commission,
hice adopts adequate safeguards under Chapter V of the GDPR (in particular the
Standard Contractual Clauses — SCCs and/or the provider's adherence to
recognized transfer frameworks), as specified in the register of sub-processors.
For any details, reference is made to the Privacy Notice (informativa-privacy.md).
9. How to manage cookies through the browser
9.1 Independently of the tools made available by hice (§6), the user can manage, limit, or disable cookies by changing their browser's settings. The methods vary depending on the program used; below are the references to the guides of the main browsers:
(a) Google Chrome — ;
(b) Mozilla Firefox — ;
(c) Microsoft Edge — ;
(d) Apple Safari — .
9.2 The total or partial disabling of cookies may affect the usability of the Site and the Service. In particular, disabling technical/necessary cookies may prevent access to the restricted area and the use of the Service's functionalities (§4.1.2).
9.3 It is further noted that most browsers allow the activation of an anonymous/private browsing mode and the periodic deletion of cookies already stored.
10. Data controller and contacts
10.1 The data controller is CONSOO S.R.L.S., with registered office at Piazzetta Umberto Giordano 2, 20122 Milan (MI), Italy — VAT/Tax Code IT13823860963 — REA MI-2745733 — certified email (PEC) consoo@pec.it.
10.2 For any request concerning this Cookie Policy or the exercise of the rights
granted by Articles 15–22 GDPR, the user may write to info@hice.ai.
10.3 The data subject has, in any event, the right to lodge a complaint with the
competent supervisory authority (in Italy, the Garante per la protezione dei dati
personali — www.garanteprivacy.it).
10.4 For any further information on the processing of personal data — including
the roles of the controller and the processor, the categories of data, the
purposes, the legal bases, the retention periods, the data subject's rights, and
transfers outside the EEA — reference is made to the Privacy Notice
(informativa-privacy.md).
11. Changes to this Cookie Policy
11.1 hice reserves the right to modify or update this Cookie Policy at any time, including as a consequence of regulatory changes, measures of the Garante, or changes to the cookies and tools used. The version in force is the one published on the Site, indicating the effective date and the date of last update set out in the header.
11.2 In the event of significant changes relating to cookies subject to consent, the request for consent will be submitted to the user again as provided for in §6.5.