Enterprise Cookie and Local Storage Technologies Notice
Rules governing cookies and equivalent technologies used on the public website and secure workspace, based on minimisation and no default advertising profiling.
Regulatory and governance references
- Directive 2002/58/EC and Article 122 of Italian Legislative Decree 196/2003
- Regulation (EU) 2016/679
- Italian DPA Guidelines on cookies and other tracking technologies of 10 June 2021
References indicate the design framework and must be verified against the current legislation, implementing measures, national law and the parties’ actual roles at implementation time.
1. Scope and Definitions
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
2. Strictly Necessary Cookies
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Strictly necessary cookies support sessions, authentication, security and language preference. They are not used for advertising profiles; duration, domain, Secure/HttpOnly/SameSite attributes and purpose must remain proportionate to risk and be described in maintained technical information.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
3. Language and Preference Cookies
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Strictly necessary cookies support sessions, authentication, security and language preference. They are not used for advertising profiles; duration, domain, Secure/HttpOnly/SameSite attributes and purpose must remain proportionate to risk and be described in maintained technical information.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
4. Session and Authentication Cookies
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Strictly necessary cookies support sessions, authentication, security and language preference. They are not used for advertising profiles; duration, domain, Secure/HttpOnly/SameSite attributes and purpose must remain proportionate to risk and be described in maintained technical information.
Two-factor authentication reduces credential-compromise risk and may be made mandatory for roles selected by policy. The Superadmin controls the relevant policy; recovery, reset and disablement must be logged and protected by controls commensurate with the access being restored.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
5. Security, 2FA and Abuse Prevention
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Two-factor authentication reduces credential-compromise risk and may be made mandatory for roles selected by policy. The Superadmin controls the relevant policy; recovery, reset and disablement must be logged and protected by controls commensurate with the access being restored.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
6. Analytics Tools and Activation Criteria
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Analytics are disabled by default unless a documented decision is made. If introduced, UESE assesses whether they may qualify as technical analytics under Italian DPA conditions or require consent; profiling or marketing tools are not activated before a valid user choice where consent is required.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
7. No Default Advertising Profiling
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
The public configuration does not provide automated decisions producing legal or similarly significant effects on data subjects. Any future use case must be separately assessed under the GDPR and AI Act, including human oversight and rules governing clinical decisions.
Analytics are disabled by default unless a documented decision is made. If introduced, UESE assesses whether they may qualify as technical analytics under Italian DPA conditions or require consent; profiling or marketing tools are not activated before a valid user choice where consent is required.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
8. Third-Party Services and Embedded Content
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Documentation is version controlled and may be updated to reflect technical, scientific or regulatory change. Databases imported by the customer remain subject to the rights and restrictions applicable to their source; the existence of an import feature does not grant UESE rights over the content or guarantee that the source may lawfully be reused.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
9. Duration and Retention Criteria
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Retention periods are defined by data category and purpose. Exit must distinguish export, return, logical deletion, storage deletion and backup cycles; legal duties, disputes or legal hold may justify limited segregated retention that is documented and not reused for other purposes.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
10. Preference Management
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Strictly necessary cookies support sessions, authentication, security and language preference. They are not used for advertising profiles; duration, domain, Secure/HttpOnly/SameSite attributes and purpose must remain proportionate to risk and be described in maintained technical information.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
In healthcare or multi-centre projects, the requirement should be linked to the protocol, decision record, DPIA or security file where relevant, avoiding any assumption that a technical configuration replaces legal or scientific assessment.
11. Browser Controls, Blocking and Deletion
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
Retention periods are defined by data category and purpose. Exit must distinguish export, return, logical deletion, storage deletion and backup cycles; legal duties, disputes or legal hold may justify limited segregated retention that is documented and not reused for other purposes.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
Compliance is continuous: changes to purpose, data, suppliers, engines, hosting, integrations or law require impact assessment and, where needed, updates to contracts, controls, instructions and documentation.
12. Technology Evolution and New Categories
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
UESE retains evidence proportionate to function and risk. The customer organisation remains responsible for its authorisations, protocols, legal bases and healthcare or scientific decisions beyond the service scope entrusted to UESE.
13. Privacy and DPO Contacts
The public website and secure workspace use storage technologies only to the extent necessary for security, sessions, language choice and user-requested functions. Any future analytics or third-party technologies that are not strictly necessary are subject to prior assessment and, where required, a compliant consent mechanism.
UESE’s Data Protection Officer is Dr Prof Giuseppe Izzo, contactable at dpo@uese.it. The DPO performs the tasks under GDPR Articles 37–39 independently; where a request concerns data processed on behalf of a customer, UESE will cooperate but may need to direct the data subject to the competent controller.
The technical inventory of storage technologies should be reviewed when the frontend, authentication system or providers change. User choice must not be obtained through deceptive interfaces, and withdrawal must be as accessible as consent where consent is required.
For enterprise deployments, the decision should be translated into a RACI matrix, verifiable evidence, acceptance criteria, technical controls and periodic review; exceptions must be approved, reasoned, time-limited and traceable.
For requests concerning data processed within a customer project, UESE may need to direct the data subject to the competent controller. For commercial or technical enquiries, use the dedicated stakeholder form and do not submit patient data.
Request informationWebsite owner and corporate contacts
UESE ITALIA S.p.A. · Piazza Trivulziana 4/A · 20126 Milano (MI) · Italy · P. IVA / C.F. IT04398760274 · REA MI 2679515 · sales@uese.it · +39 02 5656 8416.