Privacy Policy
How TONSEC handles personal data and cookies.
This page describes what data we collect when you visit this website, why we collect it, and how you can control it.
Who is the data controller
The data controller for this website is:
- Esprito Tech QFZ LLC
- Registered at: Qatar Financial Zone, Doha, Qatar
- Contact for privacy matters: info@esprito.com
We have not appointed a Data Protection Officer because our processing does not meet the criteria set out in Article 37 GDPR (no large-scale monitoring, no processing of special categories of data).
Cookies and similar technologies
We use a small number of cookies and local storage entries. They fall into two categories:
- Strictly necessary. Used for core features such as keeping your theme preference (light/dark) and your cookie consent decision itself. These cannot be disabled because the site would not work correctly without them.
- Analytics (optional). When you give consent, we load Google Analytics 4 (GA4) to understand aggregated traffic patterns — page views, navigation flow, clicks on key buttons, and outbound links to our GitHub repository. We do not run advertising, profiling, or remarketing tags.
We implement Google Consent Mode v2. This means that until you accept, GA4 is loaded in a restricted mode that does not set tracking cookies. If you reject analytics, no GA cookies are set at all.
The main cookies you may encounter:
| Name | Purpose | Duration | Category |
|---|---|---|---|
tonsec.cookie-consent.v1 | Stores your cookie preferences | 1 year | Strictly necessary |
theme | Stores your light/dark theme preference | 1 year | Strictly necessary |
_ga, _ga_<container-id> | Google Analytics client identifier | up to 13 months | Analytics |
Data we collect through analytics
When analytics is enabled, GA4 processes:
- A randomly generated client identifier stored in a first-party cookie.
- Page URLs, page titles, referrer and basic device information (browser, OS, approximate geolocation by IP at country/city level).
- Custom events we defined to measure interest in our product (for example, clicks on Quick Start, navigation to documentation, opens of the GitHub repository).
Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive). Providing this data is entirely voluntary. If you refuse, every feature of the site remains fully available.
All data is stored on Google's infrastructure. We do not sell or share this data with third parties for advertising purposes.
International data transfers
Google Analytics is operated by Google LLC (United States) and Google Ireland Limited. When analytics is enabled, your data may be transferred to servers located in the United States.
We rely on the following safeguards for these transfers, as required by Chapter V GDPR:
- Standard Contractual Clauses (SCCs) included in Google Analytics' Data Processing Terms (link).
- EU–U.S. Data Privacy Framework: Google LLC is certified under the Framework (verification), which was recognised as providing an adequate level of protection by the European Commission in July 2023.
- IP anonymisation and no-ad-features settings inside our GA4 property.
Your rights under the GDPR
Subject to the conditions set out in the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erase your data ("right to be forgotten", Art. 17).
- Restrict processing (Art. 18).
- Port your data to another controller (Art. 20).
- Object to processing (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, email us at info@esprito.com. We reply within 30 days as required by Art. 12(3) GDPR.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), typically the data protection authority in your country of residence or place of the alleged infringement. A list of EU authorities is available on the EDPB website.
Your choices on this site
- Click Reject all in the cookie banner to disable analytics.
- Click Customize to toggle individual categories.
- Use the Manage cookies link in the footer at any time to change your mind.
- You can also block analytics at the browser level by using any standard privacy extension, or by enabling "Do Not Track".
Data retention
- Consent record (
tonsec.cookie-consent.v1): kept until you change it or clear your browser storage. - Analytics events in GA4: retained according to our property settings (default: 14 months). Aggregated reports may be kept longer.
- Cookies set by GA4: expire automatically after 13 months.
You can request deletion of analytics data associated with your client identifier by contacting us at the email address above.
Changes to this policy
We may update this policy to reflect changes in the site or in applicable law. Material changes will be announced in the cookie banner so that you can re-confirm your consent.
Last updated: 2026-04-24.