AqNova Marketplace Policies & Disclosures
Global Legal Footer Framework
Comprehensive Compliance & Platform Governance Reference
"Cookie": A small text file placed on a User's device by a web server when the User visits a website. Cookies are stored in the User's browser and enable the website to recognize the device on subsequent visits or page loads.
"Similar Tracking Technologies": Any technology that performs a function analogous to a cookie, including: pixel tags (web beacons); local shared objects (Flash cookies); HTML5 local storage and session storage; IndexedDB; device fingerprinting; fingerprint hashing; browser cache tracking; CNAME cloaking; and any future technology with equivalent tracking functionality. All references to "cookies" in this Policy include similar tracking technologies unless the context requires otherwise.
"Essential Cookies" ("Strictly Necessary Cookies"): Cookies that are technically necessary for the Platform to function and to deliver a service explicitly requested by the User. These cookies cannot be refused without impairing core Platform functionality.
"Non-Essential Cookies": All cookies that are not essential — including performance, analytics, functionality, advertising, and social media cookies — which require the User's prior, affirmative consent before being set.
"Consent": A freely given, specific, informed, and unambiguous indication of the User's agreement to the processing of their personal data through non-essential cookies, expressed by a clear affirmative action (e.g., clicking an "Accept" button). Consent by inaction, pre-ticked boxes, continued browsing, or implied acceptance is not valid consent for the purposes of this Policy.
"Consent Record": The complete, timestamped log of a User's cookie consent choices, including: the date and time of consent; the consent version identifier; the specific categories accepted or rejected; the mechanism through which consent was given or withdrawn; and the User's identifier (hashed where technically feasible to protect privacy).
"First-Party Cookie": A cookie set by the AqNova Platform (aqnova.co or aqnova.co) directly, readable only by AqNova.
"Third-Party Cookie": A cookie set by a domain other than AqNova's own domains (e.g., analytics providers, advertising networks, social media platforms), typically readable by the third party across multiple websites.
"Cookie Preference Center" ("CPC"): The granular, user-accessible interface provided by AqNova that allows Users to view all cookie categories, read descriptions of each category's purpose, and accept, reject, or customize their consent choices at any time.
"Cookie Banner": The initial notification displayed to new visitors or returning visitors without valid current consent, informing them of cookie use and directing them to the CPC.
AqNova implements a technical and procedural guarantee that withdrawing consent for any cookie category is never more difficult, time-consuming, or obscure than giving consent. This equal-ease requirement is implemented as follows:
The "Reject All" option on the cookie banner requires exactly one click — the same number as "Accept All."
The CPC is accessible from a persistent link in the footer of every Platform page, including during active shopping sessions, without requiring login.
Changes made in the CPC take effect immediately upon saving. Cookies for rejected categories are deleted from the User's browser within 30 seconds of saving updated preferences.
Consent withdrawal does not require the User to provide a reason, to contact customer support, or to navigate through any additional screens beyond the CPC.
Withdrawing consent from a non-essential cookie category does not affect the User's account standing, order history, or shopping experience beyond the features that rely on the rejected cookies (which will be disclosed clearly in the CPC toggle description).
AqNova maintains a comprehensive, tamper-evident audit trail of all cookie consent interactions. Each Consent Record contains:
| Data Field | Content | Retention Period |
|---|---|---|
| Consent Timestamp | UTC date, time (millisecond precision), and timezone offset of the consent interaction | Minimum 3 years; longer if required by applicable law |
| Policy Version ID | Unique identifier of the Cookie Policy version in effect at the time of consent | 3 years minimum |
| CPC Version ID | Unique identifier of the Cookie Preference Center version in effect at time of consent | 3 years minimum |
| Consent Signal | Categorical record: 'Accept All,' 'Reject All,' or 'Custom' (with per-category binary flags) | 3 years minimum |
| Category Choices | Per-category boolean flags: Essential (always true), Analytics, Functionality, Advertising, Social Media | 3 years minimum |
| Individual Cookie Choices | Where user exercises individual cookie-level controls, per-cookie boolean record | 3 years minimum |
| Consent Method | How consent was given: banner click / CPC toggle / API signal / third-party CMPrecord | 3 years minimum |
| User Identifier | Pseudonymized user ID (SHA-256 hash); not linked to PII in the audit log itself | 3 years minimum |
| IP Address (hashed) | SHA-256 hash of truncated IP address (last octet masked). Never stored in plain text. | 3 years minimum |
| Browser / Device Signal | User-agent string hash (not full UA string), screen resolution category | 3 years minimum |
| Withdrawal / Update Record | Complete history of all updates, including prior state, new state, and timestamp of change | 3 years minimum |
| Jurisdiction Tag | Country/region code detected at time of consent for jurisdiction-specific compliance record | 3 years minimum |
Consent records are stored in an immutable, append-only audit log system maintained by AqNova's Consent Management Platform (CMP). Records may not be retroactively modified. Any update to a User's consent choices generates a new record appended to the log; prior records are preserved. AqNova will produce consent records in response to valid regulatory requests, subject to applicable data protection law.
Cookie consent given by a User remains valid until: (a) the User withdraws or modifies their consent through the CPC; (b) the consent expires (AqNova seeks re-consent after 12 months maximum, or 6 months for advertising cookies); (c) a material change to the Cookie Policy or the list of cookies requiring fresh consent is made (see Section 3.3.9); or (d) applicable law requires earlier re-consent.
Re-consent is triggered and the Cookie Banner is re-displayed under the following circumstances:
AqNova deploys a new third-party cookie provider that does not fall within an existing consent category for which the User has given consent.
AqNova expands the purposes for which an existing cookie category is used.
The User clears their browser cookies, which deletes the consent record from their browser (server-side records are preserved, but the User will be prompted again upon next visit).
12 months have elapsed since the User's last active consent interaction (6 months for advertising/targeting cookies).
A major new version of the Cookie Policy is published (version number changes in the first decimal place, e.g., v1.0 to v2.0).
While AqNova applies the GDPR standard as its global baseline, each jurisdiction imposes its own specific requirements for cookie consent, disclosure, and enforcement. The following sections detail the jurisdiction-specific compliance posture maintained by AqNova.
Primary Legal Framework
General Data Protection Regulation (GDPR — Regulation (EU) 2016/679): Governs the processing of personal data associated with cookie-based tracking.
ePrivacy Directive (2002/58/EC as amended by 2009/136/EC — the 'Cookie Law'): The primary instrument governing the storage and access of information on terminal equipment (i.e., cookies). Requires prior informed consent for non-essential cookies.
EU ePrivacy Regulation (pending): The forthcoming ePrivacy Regulation will replace the Directive upon adoption. AqNova monitors developments and will update compliance posture upon enactment.
IAB Europe Transparency & Consent Framework (TCF) v2.2: AqNova implements the TCF to standardize consent signals with advertising technology vendors in the EU ecosystem.
EDPB Guidelines on Consent (05/2020, updated 2021) and Cookies (5/2019, updated 2023): AqNova's CPC design and consent management practices comply with all adopted EDPB guidelines.
| EU/EEA Compliance Requirements — Confirmed Implementation Consent Standard: Freely given, specific, informed, unambiguous (Art. 6(1)(a) + Art. 7 GDPR) Mechanism: Affirmative action only. No pre-ticking. No consent by browsing. Granularity: Category-level and individual cookie-level controls available. Equal Prominence: Accept and Reject buttons are visually and functionally equivalent. No Cookie Wall: Platform access is not conditioned on acceptance of non-essential cookies. Withdrawal: One-click rejection from footer CPC link. Immediate effect. TCF 2.2: Full vendor list with individual vendor consent toggles. DPO Contact: privacy@aqnova.co EU Representative: [EU Art. 27 Representative — to be designated] GDPR Legal Basis: Consent (Art. 6(1)(a)) for non-essential cookies; Legitimate Interests (Art. 6(1)(f)) for essential security/fraud cookies — with LIA conducted. |
|---|
Member State Specifics
Several EU Member States have issued national guidance or regulations that go beyond the minimum requirements of the ePrivacy Directive:
France (CNIL): AqNova's banner complies with CNIL recommendations (Délibération n° 2020-091), including equal prominence for accept/refuse and a functional 'Continue without accepting' option on the banner level.
Germany (DSK / State DPAs): AqNova's CPC complies with German State DPA guidance, including prohibiting dark patterns and providing transparency on data flows to US-based providers (Schrems II implications fully disclosed).
Italy (Garante): AqNova's banner includes the cookie wall prohibition and complies with Garante's 2021 guidelines on cookie usage.
Netherlands (AP): AqNova complies with Autoriteit Persoonsgegevens guidance on cookie consent and social media button tracking.
Spain (AEPD): AqNova complies with AEPD's March 2023 cookie guidelines, including specific banner design requirements and legitimate interest restrictions for cookies.
Denmark (Datatilsynet): Compliant with Datatilsynet guidelines, including scroll/swipe tracking restrictions.
Following the UK's exit from the EU, cookie regulation in the UK is governed by:
Privacy and Electronic Communications Regulations 2003 (PECR, as amended) — the primary cookie consent instrument.
UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 — governs personal data processing associated with cookies.
ICO's Cookies guidance (most recently updated 2023) — AqNova's implementation follows all ICO practical recommendations.
UK Data Reform / DPDI Bill (in progress): AqNova monitors developments and will update implementation accordingly.
| UK Compliance Summary Consent Standard: Freely given, specific, informed, unambiguous (mirrors GDPR standard). No implied consent: Browsing/continued use does not constitute consent. ICO-aligned banner: Accept/Reject equal prominence. No deceptive design. 'Legitimate Interests' for analytics: Not accepted by ICO for analytics cookies — consent required. US Data Transfers: Chapter V UK GDPR adequacy/safeguard disclosures in CPC. ICO Registration: [ICO Registration No. — to be filed] UK GDPR Rep: [UK Art. 27 Representative — to be designated] |
|---|
Switzerland applies the revised Federal Act on Data Protection (revFADP / nDSG, in force 1 September 2023). Cookie consent requirements mirror the GDPR standard. Norway, Iceland, and Liechtenstein (EEA non-EU members) apply the GDPR directly as incorporated into the EEA Agreement. AqNova's GDPR-standard CPC satisfies all requirements in these jurisdictions. Switzerland: AqNova designates a representative per nDSG Art. 14 as required.
Federal Landscape
The United States does not have a single comprehensive federal cookie consent statute. However, several federal frameworks apply:
Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.): AqNova does not target users under 13 and does not knowingly deploy tracking cookies on users who identify as minors. AqNova's CPC blocks all non-essential cookies for any session where a minor's age is indicated.
Electronic Communications Privacy Act (ECPA): Relevant to the interception of electronic communications through certain cookie-based tracking methods.
FTC Section 5 (15 U.S.C. § 45): The FTC's unfair and deceptive practices authority applies to misleading cookie disclosures and deceptive consent interfaces.
FTC Endorsement Guides & Digital Advertising Alliance (DAA): AqNova participates in the DAA's AdChoices program for interest-based advertising opt-out where applicable.
California — CCPA / CPRA
California provides the most comprehensive US state-level cookie governance framework under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act (CPRA) and the California Privacy Protection Agency (CPPA) regulations:
| California CCPA/CPRA Cookie Compliance Do Not Sell or Share: Prominent 'Do Not Sell or Share My Personal Information' toggle in CPC. Also accessible via dedicated page at [aqnova.co/do-not-sell]. Opt-Out of Sharing: Advertising/targeting cookies that 'share' data with third parties for cross-context behavioral advertising are off by default. Global Privacy Control (GPC): AqNova honors GPC browser signals. If a user's browser transmits a GPC signal, AqNova treats it as a valid opt-out of sale/sharing. Sensitive Data: Special category data (health, race, precise geolocation) is never processed via cookies without explicit opt-in consent. Authorized Agent: Users may designate authorized agents to submit opt-out requests. No Financial Incentive for Consent: AqNova does not offer discounts, loyalty points, or other incentives in exchange for acceptance of advertising cookies. |
|---|
Other US State Privacy Laws
The following US state privacy laws impose obligations relevant to cookie management. AqNova complies with all of these laws for residents of the applicable states:
| State / Law | Cookie-Relevant Requirements | Effective Date |
|---|---|---|
| Virginia — VCDPA (Va. Code § 59.1-571) | Opt-out of targeted advertising via cookies. Opt-out signals must be honored. | Jan 1, 2023 |
| Colorado — CPA (C.R.S. § 6-1-1301) | Universal opt-out mechanism (including GPC) must be honored for targeted advertising. | Jul 1, 2023 |
| Connecticut — CTDPA | Opt-out of processing for targeted advertising. Dark patterns prohibited. | Jul 1, 2023 |
| Utah — UCPA | Opt-out of sale of personal data and targeted advertising. | Dec 31, 2023 |
| Texas — TDPSA | Opt-out of processing for targeted advertising and sale of personal data. | Jul 1, 2024 |
| Florida — FDBR (for large controllers) | Opt-out of targeted advertising. Sensitive data processing restrictions. | Jul 1, 2024 |
| Montana — MCDPA | Opt-out of targeted advertising and sale of personal data. | Oct 1, 2024 |
| Oregon — OCPA | Opt-out of targeted advertising. Additional transparency requirements. | Jul 1, 2024 |
| New Hampshire — NHPA | Opt-out of targeted advertising and sale of personal data. | Jan 1, 2025 |
| New Jersey — NJDPA | Opt-out of processing for targeted advertising. | Jan 15, 2025 |
| All other states | AqNova monitors all enacted state privacy legislation and updates compliance posture upon effective date. | Ongoing |
AqNova's GPC honor commitment means that Users whose browsers transmit a valid Global Privacy Control opt-out signal will automatically have all advertising, targeting, and data-sale-related cookies disabled, without the need to manually adjust CPC settings. This applies to all US states that have enacted GPC-honor requirements, and as a matter of AqNova's global privacy policy beyond those states.
Canadian cookie compliance is governed by a combination of federal and provincial legislation:
PIPEDA (Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5): PIPEDA requires meaningful consent for the collection of personal information through cookies. The OPC's Guidelines for Obtaining Meaningful Consent (2018) provide detailed implementation guidance.
Canada's Anti-Spam Legislation (CASL, S.C. 2010, c. 23): CASL's computer programs provisions (Section 8) may apply to certain cookie deployments. AqNova ensures CASL compliance through its consent-first approach.
Quebec — Law 25 (An Act to Modernize Legislative Provisions as Regards the Protection of Personal Information, effective September 22, 2023): The most prescriptive Canadian cookie consent framework. Requires a cookie banner with clear accept/refuse options in French and English, prior to any non-essential cookie activation. Requires disclosure of use of profiling for advertising purposes. Requires designation of a Privacy Officer and a privacy policy accessible in French.
Alberta — PIPA (Personal Information Protection Act, S.A. 2003, c. P-6.5): Requires meaningful consent for the collection of personal data through cookies.
British Columbia — PIPA (Personal Information Protection Act, S.B.C. 2003, c. 63): Equivalent consent standards to federal PIPEDA with BC-specific guidance.
| Canada / Quebec Law 25 Compliance Summary Bilingual CPC: Cookie Preference Center available in both English and French. Prior Consent: Non-essential cookies blocked prior to consent activation (Quebec Art. 8.1). Profiling Disclosure: Explicit disclosure of any profiling for advertising purposes (Law 25, Art. 9). French-language Policy: This Cookie Policy is available in French at [aqnova.co/fr/cookies]. Privacy Officer: Designated Quebec Privacy Officer — privacy@aqnova.co CAI: AqNova cooperates with the Commission d'accès à l'information (CAI). |
|---|
Brazil's Lei Geral de Proteção de Dados (LGPD — Law 13,709/2018) governs cookie-related personal data processing. The National Data Protection Authority (ANPD) has issued guidance on consent and legitimate interest that applies to cookie deployments. Key requirements:
Legal Basis Disclosure: AqNova discloses the specific LGPD legal basis (Art. 7) for each cookie category. Non-essential cookies use Art. 7(I) — consent — as the legal basis.
Consent Quality: LGPD Art. 8 requires specific, informed, and unambiguous consent. Pre-ticked boxes are not valid. The CPC includes Portuguese-language disclosures for all Brazilian users.
Right of Withdrawal: Brazilian users may withdraw cookie consent at any time through the CPC, consistent with LGPD Art. 8(5).
7-Day Right of Regret: Where applicable, AqNova ensures that the LGPD's online consumer protections (in conjunction with CDC Art. 49) are honored.
ANPD Cooperation: AqNova cooperates with the Autoridade Nacional de Proteção de Dados (ANPD) and will comply with ANPD guidance on cookie consent as it develops.
Portuguese-Language CPC: The CPC is fully available in Brazilian Portuguese for all Brazilian users.
While comprehensive cookie-specific legislation is less mature in most Latin American jurisdictions compared to the EU, the following frameworks apply to AqNova's cookie practices:
| Country | Applicable Framework | Cookie-Relevant Standard |
|---|---|---|
| Colombia | Ley 1581 de 2012 (Habeas Data); Decreto 1377/2013 | Informed consent required for personal data processing. Cookie disclosures in Spanish. SIC oversight. |
| Chile | Ley 19.628 sobre Vida Privada (reform pending — Ley Marco de Datos Personales) | Consent for personal data processing via cookies. Spanish-language disclosures. SERNAC oversight. |
| Argentina | Ley 25.326 Protección Datos Personales; Disposición AAIP 4/2019 | Consent required for non-essential cookies. Spanish-language disclosures. AAIP oversight. |
| Mexico | Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) 2010 | Arco rights apply to cookie data. Consent required. Spanish-language Aviso de Privacidad required. |
| Peru | Ley 29733 de Protección de Datos Personales | Consent for personal data collection via cookies. ANPD (Peru) oversight. |
| Uruguay | Ley 18.331 de Protección de Datos Personales (LPDP) | Uruguay has EU adequacy. GDPR-equivalent standard applies. URCDP oversight. |
| Costa Rica | Ley N° 8968 Protección de la Persona frente al Tratamiento de sus Datos Personales | Consent for personal data processing. PRODHAB oversight. |
| All other countries | AqNova applies GDPR baseline as default where no specific local framework exists. | GDPR-standard consent. Spanish/Portuguese language CPC available. |
African data protection law is rapidly maturing. AqNova applies GDPR-baseline consent practices for all African users while specifically complying with enacted national legislation. The African Union's Convention on Cyber Security and Personal Data Protection (Malabo Convention) provides a regional framework that several countries are progressively implementing.
West Africa
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| Nigeria | Nigeria Data Protection Act 2023 (NDPA); NDPR 2019; NITDA Guidelines | Informed consent required for personal data processing via cookies. Data Controller registration with NDPC. Cookie disclosures in English. AqNova appointed local representative (Sahara Eagle Ltd — Reg: 1957145). |
| Ghana | Data Protection Act 2012 (Act 843); Data Protection Commission (DPC) | Consent-based processing for non-essential cookies. DPC registration required. English-language disclosures. |
| Senegal | Loi n° 2008-12 sur la Protection des Données à Caractère Personnel; CDP oversight | Consent required. French-language disclosures. CDP (Commission de Protection des Données Personnelles) oversight. |
| Ivory Coast | Loi n° 2013-450 relative à la protection des données à caractère personnel; ARTCI | Consent for personal data processing via cookies. French-language disclosures. |
| Cameroon | Loi n° 2010/012 relative à la cybersécurité et à la cybercriminalité au Cameroun | Cookie consent governed under broader data protection provisions. Bilingual (French/English) disclosures. |
East Africa
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| Kenya | Data Protection Act 2019 (DPA); Office of the Data Protection Commissioner (ODPC) | Lawful processing basis required for cookie data. Consent is the primary basis for non-essential cookies. ODPC registration. English-language disclosures. |
| Ethiopia | Computer Crime Proclamation; Personal Data Protection Proclamation (draft/emerging) | AqNova applies GDPR-baseline consent pending full legislative enactment. English-language disclosures. |
| Tanzania | Electronic and Postal Communications Act; Personal Data Protection Act (in development) | GDPR-baseline consent applied. English-language disclosures. |
| Uganda | Data Protection and Privacy Act 2019 (DPPA); PDPO oversight | Consent required for personal data processing. PDPO (Personal Data Protection Office) compliance. English-language disclosures. |
| Rwanda | Law No. 058/2021 Governing the Protection of Personal Data; NCSA oversight | Consent-based framework. GDPR-influenced standard. English/French/Kinyarwanda disclosures. |
North Africa
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| Egypt | Personal Data Protection Law No. 151 of 2020; PDPO | Informed consent required for personal data processing via cookies. Arabic-language disclosures available. PDPO oversight. |
| Morocco | Loi 09-08 relative à la protection des personnes physiques à l'égard du traitement des données à caractère personnel; CNDP | Consent required. French and Arabic language disclosures. CNDP registration and oversight. |
| Tunisia | Loi organique n° 2004-63 portant sur la protection des données à caractère personnel; INPDP | Consent required. French and Arabic disclosures. INPDP oversight. |
Southern Africa
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| South Africa | Protection of Personal Information Act (POPIA — Act 4 of 2013); Information Regulator | POPIA's eight conditions for lawful processing apply to cookie data. Condition 1 (Accountability) and Condition 4 (Participation) are most relevant. Consent-based processing required for targeted advertising cookies. Information Regulator cooperation. English-language disclosures with multilingual accessibility. |
| Zambia | Electronic Communications and Transactions Act; Data Protection Act (emerging) | GDPR-baseline consent applied. English-language disclosures. |
| Zimbabwe | Cyber and Data Protection Act 2021; Postal and Telecommunications Regulatory Authority (POTRAZ) | Consent-based processing for cookie data. English-language disclosures. |
Pan-African Implementation Note
For all African jurisdictions where national data protection legislation is still developing or has not yet fully addressed cookie-specific consent, AqNova applies its GDPR-baseline standard. AqNova's local representative in West Africa (Sahara Eagle Ltd, Nigeria) supports compliance activities across the West African region. AqNova maintains multilingual CPC capability including English, French, Arabic, and Portuguese across the African platform.
Data protection regulation in the Middle East has advanced significantly since 2021, with several GCC countries enacting comprehensive privacy laws. AqNova maintains jurisdiction-specific compliance for all operating countries in the region.
Gulf Cooperation Council (GCC)
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| United Arab Emirates (UAE) | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL); UAE Data Office; ADGM Data Protection Regulations 2021; DIFC Data Protection Law 2020 | Lawful basis required for personal data processing via cookies. Consent is the primary basis for non-essential cookies. UAE Data Office registration. CPC available in Arabic and English. AqNova designates a UAE local representative. |
| Saudi Arabia | Personal Data Protection Law (PDPL — Royal Decree M/19, 2021, effective September 2023); NDMO oversight | Consent required for collection and processing of personal data including via cookies. Arabic-language cookie disclosures mandatory. NDMO (National Data Management Office) cooperation. Sensitive personal data restrictions apply. |
| Qatar | Personal Data Privacy Protection Law No. 13 of 2016; Ministry of Transport and Communications | Consent required for personal data processing. CPC available in Arabic and English. Cross-border transfer restrictions apply. |
| Kuwait | Draft Data Protection Law (advancing through legislative process); existing protections under Law No. 20/2014 (electronic transactions) | GDPR-baseline applied pending full legislative enactment. Arabic and English CPC. |
| Bahrain | Personal Data Protection Law 2018 (Law 30 of 2018); PDPB oversight | Consent required for personal data collection. PDPB (Personal Data Protection Bureau) registration. CPC in Arabic and English. |
| Oman | Personal Data Protection Law (Royal Decree 6/2022, effective February 2023); ITA oversight | Informed consent required for non-essential cookie processing. CPC in Arabic and English. ITA (Information Technology Authority) oversight. |
Levant & Other Middle East
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| Jordan | Cybercrime Law No. 27 of 2015; Draft Personal Data Protection Law (in progress) | GDPR-baseline consent applied. Arabic and English CPC. |
| Israel | Privacy Protection Act 1981; Privacy Protection (Data Security) Regulations 2017; PPA 2023 Amendment | Israel has EU adequacy status. GDPR-equivalent standard applies. Privacy Protection Authority (PPA) oversight. Hebrew and English CPC. |
| Turkey | Kişisel Verilerin Korunması Kanunu (KVKK — Law No. 6698, 2016); KVKK Authority | Explicit consent required for processing of personal data including via cookies. Turkish-language cookie disclosures required. KVKK registration and oversight. Data localization requirements apply. |
| Lebanon | Draft Data Protection Law (advancing); Consumer Protection Law (Law 659/2005 and its amendments) | GDPR-baseline consent applied. Arabic and English CPC. |
| Egypt | (Listed above under North Africa — see Section 3.3.4.H) | See North Africa table above. |
| Middle East Implementation Notes Arabic-Language CPC: AqNova's Cookie Preference Center is available in Modern Standard Arabic for all users in MENA-region countries. Right-to-left (RTL) interface design is implemented. Local Representatives: AqNova designates local data protection representatives in UAE and Saudi Arabia as required under UAE PDPL and Saudi PDPL respectively. Data Localization: Where applicable law requires data to be stored within national territory (e.g., Saudi Arabia PDPL Article 29), cookie-related personal data processing infrastructure complies with applicable localization requirements. Cross-Border Transfers: Cookie-related data transferred to AqNova servers outside the GCC is covered by AqNova's Standard Contractual Clauses and adequacy documentation. |
|---|
China (People's Republic of China)
China has one of the most complex digital data governance frameworks globally, relevant to AqNova's cookie practices:
Personal Information Protection Law (PIPL — effective November 1, 2021): Requires informed consent as the primary legal basis for processing personal information, including via cookies. Consent must be independent, specific, and voluntary. Bundled consent is prohibited.
Data Security Law (DSL — effective September 1, 2021): Governs data classification and security obligations, including for cookie-related data.
Cybersecurity Law (CSL — effective June 1, 2017): Requires network operators to have cybersecurity policies and to protect user information.
GB/T 35273-2020 (Personal Information Security Specification): Technical standard requiring explicit consent mechanisms for cookies; prohibits tracking cookies without consent.
Internet Information Service Algorithmic Recommendation Management Regulations (2022): Relevant to AqNova's personalization and recommendation algorithms powered by cookie data.
Data Localization: Personal information of Chinese users processed or stored in China must comply with cross-border data transfer requirements, including security assessments for specified data volumes.
Simplified Chinese-Language CPC: The CPC is available in Simplified Chinese for all users accessing from China.
India
Digital Personal Data Protection Act 2023 (DPDPA): India's comprehensive privacy framework came into force in August 2023. Consent is a primary legal basis ("valid consent" must be free, informed, specific, unconditional, and unambiguous — i.e., GDPR-equivalent standard).
IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011: Existing SPDI rules require consent for collection of sensitive personal data; may apply to certain cookie-collected data categories.
CPC available in English and Hindi. AqNova designates an Indian Data Protection Officer where required by DPDPA Rules.
Cross-border transfer: AqNova complies with DPDPA transfer restrictions as notified by the Central Government.
Hong Kong SAR, Macau SAR & Taiwan
Hong Kong: Personal Data (Privacy) Ordinance (PDPO, Cap. 486) applies. Data Protection Principle 1(3) requires prior consent for data collection. PCPD guidance on cookies applies. CPC in Traditional Chinese and English.
Macau: Personal Data Protection Act (Law 8/2005) applies. GDPR-influenced standard. Portuguese and Traditional Chinese CPC.
Taiwan: Personal Information Protection Act (PIPA, as amended 2023). Consent required for collection of personal data via cookies. PPC (Personal Data Protection Commission) oversight. Traditional Chinese CPC.
| Country | Primary Framework | Cookie Compliance Standard |
|---|---|---|
| Australia | Privacy Act 1988 (Cth); Australian Privacy Principles (APPs); OAIC guidance on online tracking | APP 3 requires collection notice and consent for sensitive information. OAIC has confirmed cookies can collect personal information triggering APP obligations. Opt-out of targeted advertising. CPC in English. OAIC cooperation. |
| New Zealand | Privacy Act 2020 (NZ); Information Privacy Principles (IPPs); OPC oversight | IPP 3 requires notification; IPP 4 limits collection. Consent-based approach for non-essential cookies. CPC in English. OPC cooperation. |
| Japan | Act on the Protection of Personal Information (APPI — amended 2022); PPC oversight; PPC Cookie Guidelines (2023) | PPC's 2023 guidelines on cookies require: consent for cross-site tracking; mandatory opt-out mechanism for targeted advertising; transparency about third-party cookie providers. CPC in Japanese. PPC cooperation. |
| South Korea | Personal Information Protection Act (PIPA — amended 2023); Act on Promotion of Information and Communications Network Utilization; PIPC oversight | Separate consent required for each processing purpose. Consent cannot be bundled. Written (electronic) consent mechanism required. CPC in Korean. PIPC registration. Cross-border transfer consent required. |
| Singapore | Personal Data Protection Act 2012 (PDPA, amended 2020); PDPC Advisory Guidelines on Use of Cookies | PDPC's Advisory Guidelines confirm cookies that collect personal data require consent. Deemed consent and opt-out consent available in limited circumstances. Mandatory Data Breach Notification. CPC in English. PDPC cooperation. |
| Malaysia | Personal Data Protection Act 2010 (PDPA); PDPC Malaysia | Consent required for processing personal data via cookies. Data User registration. Bahasa Malaysia and English CPC. |
| Thailand | Personal Data Protection Act 2019 (PDPA — effective June 2022); PDPC Thailand | Explicit consent required for non-essential cookies. CPC in Thai and English. PDPC registration. Cross-border transfer safeguards. |
| Indonesia | Personal Data Protection Law No. 27 of 2022 (UU PDP, effective Oct 2024); Kominfo Regulation No. 20/2016 | Explicit consent required for non-essential cookie processing. CPC in Bahasa Indonesia and English. Kominfo cooperation. |
| Philippines | Data Privacy Act 2012 (R.A. 10173); National Privacy Commission (NPC) Circulars | Consent must be freely given, specific, informed, evidenced. CPC in Filipino/English. NPC registration. DPO designation required for significant processing. |
| Vietnam | Cybersecurity Law 2018; Decree 13/2023/ND-CP on Personal Data Protection (effective July 2023) | Consent required for personal data processing including cookies. CPC in Vietnamese and English. Sensitive data special protections apply. |
| Pakistan | Personal Data Protection Bill (advancing through Parliament) | GDPR-baseline consent applied pending full enactment. Urdu and English CPC. |
| Bangladesh | Digital Security Act 2018; Draft Data Protection Act (in progress) | GDPR-baseline consent applied pending enactment. Bengali and English CPC. |
| Asia-Pacific Regional Implementation Notes Multilingual CPC: The Cookie Preference Center is available in: Japanese, Korean, Simplified Chinese, Traditional Chinese, Thai, Bahasa Indonesia, Bahasa Malaysia, Vietnamese, Filipino, Hindi, Bengali, Urdu, and English across the Asia-Pacific region. Cross-Border Transfers: Cookie-related personal data transferred to non-local servers is covered by Standard Contractual Clauses (EU SCCs), Binding Corporate Rules, or applicable jurisdiction-specific safeguards (e.g., Korea's Standard Clauses, Japan's BCRs). Data Localization: Where applicable law requires local storage of user data (Vietnam Cybersecurity Law; China CSL/PIPL), cookie-related data processing infrastructure complies. DPO Network: AqNova maintains designated Data Protection Officers or representatives in all jurisdictions requiring local DPO designation. |
|---|
AqNova enters into Data Processing Agreements (DPAs) or equivalent contractual arrangements with all third-party cookie providers that process personal data on AqNova's behalf as data processors, consistent with GDPR Article 28, UK GDPR Article 28, and equivalent requirements under applicable national law. These agreements require processors to: (a) process personal data only on documented instructions from AqNova; (b) implement appropriate technical and organizational security measures; (c) assist AqNova in fulfilling data subject rights; (d) delete or return personal data upon termination; and (e) provide audit rights to AqNova.
AqNova's Consent Management Platform must meet the following technical and operational standards:
Server-Side Consent Logging: All consent signals must be recorded server-side in an immutable, timestamped, audit-compliant log system. Browser-side consent storage (cookies alone) is insufficient for compliance purposes.
Pre-Consent Blocking: All non-essential JavaScript tag firing and cookie drops must be technically blocked until valid consent is confirmed. This applies to all tags managed through the Tag Management System (TMS).
Consent Signal Propagation: Upon consent update (either granting or withdrawing), the updated consent signal must propagate to all integrated third-party systems within 30 seconds.
Cookie Deletion on Withdrawal: When a User withdraws consent for a cookie category, all non-essential cookies in that category must be deleted from the User's browser within 30 seconds of the withdrawal signal being processed.
GPC Signal Detection: The Platform must detect and honor the Global Privacy Control (GPC) HTTP header signal (Sec-GPC: 1) as an opt-out signal for all US users in applicable states, and for all users globally as a matter of policy.
Consent Versioning: Each version of the Cookie Policy and CPC must be assigned a unique version identifier. Consent records must be linked to the specific version under which they were collected.
Cross-Device Consent: Where a User is logged in to their AqNova account, consent choices made on one device are applied to the User's account and propagated to all logged-in sessions on other devices.
Accessibility: The cookie banner and CPC must comply with WCAG 2.1 Level AA accessibility standards, including full keyboard navigation, screen reader compatibility, and sufficient color contrast ratios.
The cookie banner and CPC must function correctly across:
All major desktop browsers: Chrome, Firefox, Safari, Edge, Opera (latest 3 major versions of each).
All major mobile browsers: Chrome for Android, Safari for iOS/iPadOS, Samsung Internet, Firefox Mobile.
Both iOS and Android mobile operating systems.
Screen sizes from 320px (small mobile) to 2560px (large desktop).
Right-to-left (RTL) layouts for Arabic, Hebrew, and Urdu language interfaces.
Both dark mode and light mode display settings.
This Cookie Policy is assigned a unique version identifier (currently: Version 1.0, effective April 7, 2026). Each published version is maintained in a publicly accessible Policy Version Archive at [aqnova.co/legal/cookie-policy-archive], with the effective date, version number, and a plain-language changelog entry for each update.
A material change requiring re-consent from affected Users occurs when:
A new third-party cookie provider is added to the Platform that introduces new data flows to a third party not previously disclosed.
The purpose of an existing cookie category is expanded beyond what was disclosed at the time of original consent.
A new cookie category is introduced beyond the five categories listed in Section 3.3.1.B.
The data retention period for a cookie or cookie category is extended beyond what was previously disclosed.
Cookies begin to process special category (sensitive) personal data not previously processed.
For material changes, AqNova will: (a) publish the updated Cookie Policy with the new version number and effective date at least 30 days before the change takes effect (14 days for regulatory-required changes); (b) display a re-consent banner to all affected Users; and (c) block any new or expanded cookie processing until valid re-consent is obtained.
Non-material changes (e.g., clarification of existing descriptions, updated contact information, correction of typographical errors, addition of a new essential cookie, or removal of an existing cookie) do not require re-consent but must be: reflected in an updated Policy version with a changelog entry; published with the new effective date; and accessible in the Policy Version Archive.