Nymia · Cookie Policy
Cookie Policy
How Nymia uses cookies, local storage and similar tracking technologies. This document lists only the cookies and tools actually deployed by the Platform and complies with the Italian Data Protection Authority (Garante) guidelines on cookies (Provvedimento no. 231 of 10 June 2021), the GDPR, the ePrivacy Directive and the DSA.
1. Introduction
This Cookie Policy ("Cookie Notice") explains how the Nymia platform — operated by Bull Marketing S.r.l.s. — uses cookies and similar local storage technologies (localStorage, sessionStorage) while Users browse the website www.nymia.me and the related applications.
This Notice is provided pursuant to:
- Art. 122 of Italian Legislative Decree No. 196 of 30 June 2003 ("Privacy Code"), as amended by Legislative Decree No. 101 of 10 August 2018, implementing Directive 2002/58/EC ("ePrivacy");
- Regulation (EU) 2016/679 ("GDPR"), in particular for coordination with the Privacy Policy;
- the "Guidelines on the use of cookies and other tracking tools" adopted by the Italian Data Protection Authority with measure No. 231 of 10 June 2021 (hereinafter, the "2021 Cookie Measure");
- Regulation (EU) 2022/2065 ("DSA") as regards the transparency of interfaces and the absence of dark patterns in the cookie banner;
- the applicable policies of the distribution platforms (Apple App Store Review Guidelines § 5.1.1 and § 5.1.2; Google Play Developer Program Policies — "User Data"; Meta Platform Policies) and the transparency requirements applicable to Stripe integrators.
Nymia adopts an approach of maximum transparency: this Notice describes exclusively cookies, identifiers and local storage technologies that are actually used in the Platform's source code as of the last update date indicated in the header. No technology that is not actually present in the project is indicated as "already active".
In the event of any interpretative divergence between the Italian version and any translation into other languages, the Italian version shall prevail. This Notice must be read together with the Terms and Conditions and the Privacy Policy published on the Platform.
2. Data controller
The Controller of the personal data collected through cookies and similar technologies is:
- Bull Marketing S.r.l.s.
- Registered office: Via Minelli 23, 44042 Cento (FE), Italy
- Tax code and VAT number: IT02178200388
- REA registration: FE-257774
- Dedicated privacy email: privacy@nymia.me
- General support email: support@nymia.me
As of the date of publication of this Notice, Bull Marketing has not appointed a Data Protection Officer ("DPO"), as the conditions making such appointment mandatory under Art. 37 GDPR do not apply. Should such an appointment be made, the contact details will be published in this Section.
For any question relating to this Notice or to exercise the rights granted by the GDPR and by Italian cookie legislation, you can write to privacy@nymia.me.
4. How Nymia handles cookies and local storage
As an architectural choice aimed at minimising the use of cookies, the Nymia Platform — in its first-party code (frontend and backend managed by Bull Marketing) — does NOT set browser cookies for authentication, language, preference persistence or cookie consent.
Nymia instead uses the browser's local storage APIs (localStorage and sessionStorage), which have the following legally relevant characteristics:
- they are not automatically transmitted to the server with each request (unlike cookies);
- they are accessible only to the domain that set them (same-origin isolation);
- they are nevertheless considered "tools similar to cookies" by the Authority when used for tracking; for this reason, first-party local storage is also documented in this Notice, to the extent that it stores data attributable to the User.
The set of cookies actually present on the User's device while browsing Nymia depends on:
- the local storage technologies used by Bull Marketing's code (Section 5);
- any cookies set by third-party scripts loaded by the Platform (Section 10);
- the technical cookies of the hosting/CDN infrastructure used (currently the Emergent environment);
- the consent choices expressed by the User through the Cookie Banner (Section 12).
5. Inventory of technologies actually used
Below is the complete and verified list of local storage technologies and third-party cookies used on the Platform as of the last update date indicated in the header. For each item we indicate: technical name, provider, category, purpose, legal basis, duration and nature (mandatory or optional).
FIRST-PARTY TECHNOLOGIES (nymia.me domain — stored as localStorage/sessionStorage)
- Name: "ig_token" — Provider: Nymia (first party) — Category: strictly necessary — Purpose: authentication token (JWT) that allows the authenticated User to access their reserved areas; without this data it is not technically possible to maintain the login state — Legal basis: Art. 122(1) of the Privacy Code (consent exemption for technical tools) and Art. 6(1)(b) GDPR (performance of the contract) — Duration: persistent until explicit logout, token expiry, server-side revocation or manual deletion by the User — Mandatory.
- Name: "nymia_language" — Provider: Nymia (first party) — Category: strictly necessary / preferences — Purpose: stores the interface language chosen by the User (it/en) to ensure its persistence between sessions and avoid re-presenting the language onboarding at each access — Legal basis: Art. 122(1) of the Privacy Code (feature requested by the User) — Duration: persistent until manually deleted by the User — Mandatory (necessary to provide the service in the chosen language).
- Name: "nymia.cookie_consent_v1" — Provider: Nymia (first party) — Category: strictly necessary — Purpose: stores the choice expressed by the User in the Cookie Banner ("accepted" or "rejected") in order not to re-propose it on each page and to correctly manage the loading of technologies subject to consent — Legal basis: Art. 122(1) of the Privacy Code (compliance with a legal obligation regarding the documentation of consent) — Duration: persistent; the User can reset it at any time by deleting the site data or using the dedicated function in Settings — Mandatory.
- Name: "nymia_sound_muted" — Provider: Nymia (first party) — Category: preferences/functionality — Purpose: stores the User's choice to mute the sounds of in-app notifications — Legal basis: Art. 122(1) of the Privacy Code — Duration: persistent until manually deleted — Optional.
- Name: "nymia.email_banner_dismissed" — Provider: Nymia (first party) — Category: preferences/functionality — Purpose: stores the User's choice to close the email verification banner; it is stored in sessionStorage and is automatically deleted when the browser is closed — Legal basis: Art. 122(1) of the Privacy Code — Duration: current session — Optional.
- Name: "nymia_attribution_session" — Provider: Nymia (first party) — Category: preferences/functionality — Purpose: temporary snapshot (sessionStorage) of the attribution parameters present in the entry URL (UTM, gclid, fbclid, wbraid, gbraid) used to correctly link any registration or transaction to the campaign of origin, as part of the server-side CAPI event described in the Privacy Policy — Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of its own communication), subject to consent when the attribution flows into marketing services — Duration: current session — Optional.
- Name: "nymia_attribution_first_touch" and "nymia_attribution_last_touch" — Provider: Nymia (first party) — Category: statistics/attribution — Purpose: they record respectively the "first touch" (immutable) and the "last touch" (updated at each new visit with parameters) for the purpose of calculating conversion attribution, always as part of the server-side CAPI event — Legal basis: legitimate interest (Art. 6(1)(f) GDPR) subject to consent when the data flow into marketing services — Duration: persistent until manually deleted — Optional.
THIRD-PARTY TECHNOLOGIES (set by scripts loaded from domains other than nymia.me)
- Name: PostHog cookies and localStorage (for example: "ph_[project-key]_posthog", "ph_current_session_id") — Provider: PostHog Inc., 2261 Market St #4008, San Francisco, CA 94114, USA — Category: statistics/analytics and session recording — Purpose: analysis of aggregate browsing behaviour, product analytics and — depending on the configuration — recording of interface interaction sessions (session replay) — Legal basis: Art. 122(1) of the Privacy Code (consent) — Duration: up to 12 months for the distinct-id, session duration for the session identifier — Optional (subject to explicit consent).
- Name: cookies or localStorage set by the script "assets.emergent.sh/scripts/emergent-main.js" — Provider: Emergent Labs (provider of the hosting/deploy infrastructure) — Category: strictly necessary (delivery platform) — Purpose: technical platform tools related to the operation of the production environment (routing, management of the hosting platform's user sessions) — Legal basis: Art. 122(1) of the Privacy Code (technical tools) — Duration: session or as defined by Emergent — The exact composition is reported in Section 19 as it requires technical verification with the provider.
TECHNOLOGIES NOT USED AND NEGATIVE DECLARATIONS
In order to avoid any ambiguity, we expressly declare that as of the last update date:
- Nymia does NOT load the Meta Pixel (fbevents.js script) on the client side. The measurement of Meta conversions takes place exclusively server-side through the Conversions API ("CAPI") described in Section 17 of the Privacy Policy, subject to the User's consent. Consequently, the first-party cookies "_fbp" and "_fbc" are NOT set by the Platform on the nymia.me domain; if present on the User's device, they are pre-existing cookies set by other sites that loaded the Meta pixel.
- Nymia does NOT use Google Analytics or Google Tag Manager as of the last update date. The cookies "_ga", "_gid", "_gat", "_ga_*" or similar are therefore not present.
- Nymia does NOT use Hotjar, Clarity, Mixpanel, Segment, Amplitude, TikTok Pixel, LinkedIn Insight Tag, Snap Pixel, Reddit Pixel or Pinterest Tag.
- Nymia does NOT use Cloudflare or other CDNs that set the "__cf_bm" cookie on the nymia.me domain as of the last update date; should a CDN be introduced in the future, this Notice will be updated before its activation.
- Stripe does not set cookies on the nymia.me domain because the Platform does not host Stripe.js in-page: payment takes place via redirection to Stripe Checkout, on the checkout.stripe.com domain, where Stripe's cookies apply (Section 10).
- LiveKit does not set cookies: Live sessions and Calls use a WebRTC/WebSocket connection authenticated via token and do not require cookies on the User's device.
- Wasabi (S3) does not set cookies: media content is served via temporary signed URLs without trackers.
- No social plugin SDKs are used (share buttons from Meta, X, TikTok, LinkedIn) that could set third-party cookies.
6. Strictly necessary category
Strictly necessary (or "technical") cookies and technologies enable the provision of the Platform's essential features and are released or used without the need for consent, as they fall within the exemption provided for by Art. 122(1) of the Privacy Code and by Recital 66 of the ePrivacy Directive.
This category includes:
- "ig_token" (JWT authentication — Section 5);
- "nymia_language" (interface language — Section 5);
- "nymia.cookie_consent_v1" (recording of the consent choice — Section 5);
- the technical identifiers set by the "emergent-main.js" script functional to the deploy infrastructure (Section 5).
Refusing these technologies would make it impossible to use the essential features of the Platform (account access, storage of the cookie choice, correct delivery of content in the chosen language). It is therefore not technically possible to deactivate them while keeping the service operational, other than by ceasing to use Nymia.
7. Preferences and functionality category
Preference/functionality cookies and technologies allow the choices made by the User to be remembered in order to personalise their browsing experience. They typically fall within the exemption of Art. 122(1) of the Privacy Code when strictly necessary for the service requested by the User.
This category includes:
- "nymia_sound_muted" (muting of audio notifications — Section 5);
- "nymia.email_banner_dismissed" (closing of the email verification banner — Section 5);
- any preferences saved locally in relation to themes, layouts, search filters.
The User can delete these preferences at any time from the "Clear site data" section of their browser or by using the self-service functions available on the Platform.
8. Statistics and analytics category
Analytics cookies and technologies are intended to measure the use of the Platform in aggregate form, identify any malfunctions, optimise the user experience and evaluate the effectiveness of navigation paths.
As of the last update date, the Platform uses the PostHog service for product analytics purposes and — if enabled by the configuration — session replay. In compliance with the Authority's 2021 Cookie Measure and Opinion No. 4/2012 of the Article 29 Working Party, PostHog is NOT classified strictly as a technical cookie but as an analytics cookie subject to consent, since:
- it uses persistent identifiers (distinct-id);
- it enables session recording activity that makes it possible to reconstruct the individual behaviour of the User;
- it operates under a data transfer regime to the United States.
For these reasons, PostHog is activated only if the User has given consent through the Cookie Banner or after expressing an equivalent preference in the Settings.
Nymia does NOT use Google Analytics as of the last update date. Should it be integrated in the future, this Notice will be updated before its activation and notice will be given via the cookie banner and email communication.
Categories of data processed: anonymous visitor identifier, URLs visited, timestamps, resolution, device type, referrer and — in the case of session replay — video of the interactions on the interface (mouse, tap, scroll, input). Sensitive input fields are masked by default by the tool; where such masking is not configured, this is indicated in Section 19.
9. Marketing and profiling category
Marketing and profiling cookies and technologies are aimed at showing personalised commercial communications to the User based on their interactions with the Platform or with connected third-party services (in particular, Meta platforms).
As of the last update date, the Platform does NOT load the Meta Pixel client-side on the nymia.me domain. The measurement of Meta events takes place exclusively through the server-side Conversions API (CAPI) described in Section 17 of the Privacy Policy, subject to the User's consent. In this scenario:
- the event is generated by the Nymia backend in reaction to a User action (registration, purchase);
- the "fbp" and "fbc" identifiers possibly present on the User's device (set by other sites loading the Meta pixel) may be read by the Platform to be included as "user_data" in the CAPI event, in order to improve matching;
- Nymia itself does NOT set "_fbp" or "_fbc" cookies on its own domain.
Any first- or third-party cookies set in the future for re-targeting activities or personalised advertising campaigns would fall into this category. In such a case, loading will take place exclusively subject to the User's specific and granular consent through the Cookie Banner and will be preceded by an update of this Notice.
11. Legal basis of processing
The processing of personal data collected through cookies and similar technologies is based on different legal bases, depending on the category of the technology used:
- Strictly necessary cookies and tools (Section 6): Art. 122(1) of the Privacy Code (consent exemption) and Art. 6(1)(b) and (f) GDPR (performance of the service contract and legitimate interest in operational continuity and IT security).
- Preference and functionality cookies (Section 7): Art. 122(1) of the Privacy Code (feature requested by the User) or consent pursuant to Art. 6(1)(a) GDPR where personalisation exceeds what is strictly requested.
- Analytics and statistics cookies (Section 8): consent pursuant to Art. 122 of the Privacy Code and Art. 6(1)(a) GDPR, unless they are "first-party analytics cookies with masked IP and no cross-referencing with other processing", for which the Authority allows a consent exemption pursuant to para. 3.2 of the 2021 Cookie Measure (a condition not fully met by PostHog).
- Marketing cookies and technologies (Section 9): consent pursuant to Art. 122 of the Privacy Code and Art. 6(1)(a) GDPR.
- Aggregate processing of anonymous statistical data: legitimate interest pursuant to Art. 6(1)(f) GDPR, subject to irreversible anonymisation.
Consent, where required, is collected through the Cookie Banner described in Section 12, in accordance with EDPB Guidelines 5/2020 on consent (version 1.1 of 4 May 2020) and the Authority's 2021 Cookie Measure.
13. How to change or withdraw consent
The User can at any time modify or withdraw the consent given in relation to cookies using the following tools:
- clearing the nymia.me site data from their browser (Settings → Privacy and security → Clear browsing data);
- deleting the "nymia.cookie_consent_v1" key from the browser's local storage: on the next access, the Cookie Banner will be shown again;
- using the dedicated "Cookie settings" function in the account Settings area (when available for their profile);
- writing to privacy@nymia.me: we will handle the request manually and delete the stored identifiers.
The withdrawal of consent does not affect the lawfulness of the processing based on the consent given before withdrawal (Art. 7(3) GDPR). Nymia will stop loading the technologies subject to consent as soon as the withdrawal is recorded.
14. Browser settings
The User can also configure their browser to block or delete cookies and local storage technologies. The procedures vary depending on the browser used; below are the official references for the main browsers:
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop
- Apple Safari (macOS): https://support.apple.com/guide/safari/sfri11471/mac
- Apple Safari (iOS): https://support.apple.com/en-us/HT201265
- Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
- Opera: https://help.opera.com/en/latest/web-preferences/#cookies
The User can also activate the following system settings to protect their privacy:
- "Do Not Track" / Global Privacy Control: Nymia respects GPC signals when transmitted by the browser, considering them a valid opt-out from non-essential processing;
- App Tracking Transparency (iOS): any future mobile applications will respect the choices expressed by the User via ATT pursuant to the Apple App Store Review Guidelines;
- Advertising ID (Android): any future mobile applications will not process the Advertising ID without explicit consent pursuant to the Google Play Developer Program Policies.
Deactivating strictly necessary technical cookies could make it impossible to access the Platform or for certain features to function correctly.
15. Transfers outside the EEA
Some of the third-party providers used by the Platform process personal data outside the European Economic Area, in particular in the United States of America. In all cases, the transfer is covered by adequate safeguards pursuant to Chapter V of the GDPR:
- adherence to the "EU-U.S. Data Privacy Framework" pursuant to the European Commission's adequacy decision of 10 July 2023 for certified providers (e.g. Emergent, where certified);
- signature of the Standard Contractual Clauses adopted by the European Commission with Decision (EU) 2021/914 of 4 June 2021 for providers not certified under the DPF;
- supplementary technical measures (TLS 1.2+ encryption in transit, pseudonymisation of identifiers) and organisational measures (Data Processing Agreement, procedures for handling government requests).
An updated list of sub-processors and applicable safeguards can be requested by writing to privacy@nymia.me.
16. Retention period
Personal data collected through cookies and similar technologies are kept for the time strictly necessary to achieve the purposes for which they were collected:
- technical session cookies: deleted when the browser is closed;
- "ig_token": until explicit logout, technical expiry of the token, server-side revocation or manual deletion by the User;
- "nymia_language", "nymia_sound_muted", "nymia.cookie_consent_v1": persistent until manual deletion, with a maximum retention limit of 12 months for the purposes of consent renewal;
- attribution identifiers ("nymia_attribution_*"): 90 days, in alignment with the typical attribution window of marketing platforms;
- PostHog cookies and related identifiers: up to 12 months for the distinct-id; session recordings are kept by PostHog according to its own policies (currently 30 days for the standard plan, unless configured otherwise);
- Emergent technical cookies: duration defined by the provider, typically coinciding with the session or with the duration of the platform tokens.
Pursuant to the Authority's 2021 Cookie Measure, upon expiry of the retention period the data are deleted or irreversibly anonymised.
17. Data subject rights
As a data subject, the User can exercise at any time vis-à-vis Bull Marketing the rights referred to in Articles 15-22 of the GDPR:
- access to the personal data processed through cookies;
- rectification or erasure of the same;
- restriction of or objection to processing;
- data portability;
- withdrawal of consent, with non-retroactive effect;
- lodging a complaint with the Italian Data Protection Authority (www.gpdp.it), without prejudice to recourse to the judicial authority pursuant to Art. 79 GDPR.
To exercise these rights, the User can write to privacy@nymia.me or use the self-service features integrated into the Platform. For a detailed description of the rights and how to exercise them, please refer to Section 22 of the Privacy Policy.
18. Changes to this Cookie Policy
Bull Marketing reserves the right to amend this Cookie Policy to adapt it to:
- supervening regulatory changes;
- new measures of the Italian Data Protection Authority or the European Data Protection Board;
- the introduction of new third-party technologies or the decommissioning of those currently in use;
- updates of the providers indicated in the list in Section 5.
Substantial changes (introduction of new profiling cookies, change of analytics provider, extension of processing purposes) will be communicated in advance by means of:
- re-proposal of the Cookie Banner at the first access following the change;
- publication of the updated version on this page;
- update of the "Last updated" date in the header;
- where appropriate, email communication to registered Users.
Non-substantial changes (typographical corrections, updates of regulatory references, editorial rewording) will be published without any obligation of prior notice.
19. Items to verify before publication
In line with the accountability principle (Art. 5(2) GDPR), we set out below the elements which, at the time of publication, require further technical verification by the technical department and the appointed DPO/privacy consultant before final publication. This section will be removed as soon as all verifications have been completed.
1. PostHog — detailed configuration
- The exact list of cookies/localStorage set by the snippet must be confirmed (for example: "ph_[project-key]_posthog", "posthog", "ph_current_session_id", "ph_persistent_[project-key]"), verifying the SDK version currently loaded from us-assets.i.posthog.com.
- It must be confirmed that session recording is deactivated for Users who have not given consent, or that the initialisation of the script is conditioned on the value returned by "hasOptedIn()" in the "choose" function of the CookieBanner: the script is currently inserted statically in public/index.html and is initialised on page load, even before the User makes a choice in the Cookie Banner. It is therefore necessary to: (i) remove the static script and load PostHog only after positive consent; (ii) alternatively, set "loaded: (ph) => { if (!hasOptedIn()) ph.opt_out_capturing(); }"; (iii) evaluate the configuration "autocapture: false" and "disable_session_recording: true" by default.
- The activation of automatic masking of sensitive inputs must be confirmed (parameter "session_recording.maskAllInputs" / "maskTextSelector").
- The conclusion of the DPA with PostHog Inc. and the availability of Standard Contractual Clauses or EU-U.S. DPF certification must be confirmed.
2. Emergent script ("assets.emergent.sh/scripts/emergent-main.js")
- The provider must be asked for the exhaustive list of cookies and identifiers set by the script on the hosting domain, together with their nature (necessary vs statistical) and duration.
- The signature of the DPA must be confirmed and it must be verified whether the provider adheres to the EU-U.S. Data Privacy Framework.
- Where the script sets non-strictly-necessary cookies, it will need to be moved behind consent or replaced with self-hosted equivalents for production.
3. Meta CAPI + client-side attribution
- It must be confirmed that CAPI events (Privacy Section 17) are sent exclusively if the User has consented to the "marketing" category in the Cookie Banner. Currently the backend calls the CAPI in reaction to conversion events: the banner choice must be propagated to the backend via a consent flag.
- The use of Meta's "Limited Data Use" (LDU) parameter should be evaluated for Users residing in jurisdictions with CCPA/CPRA legislation.
4. Google Fonts
- In light of the guidance of the Munich Court (LG München, 20 January 2022 — Az. 3 O 17493/20) on connections to Google domains, evaluate migrating to self-hosting of the Inter font to eliminate the systematic transfer of the IP address to Google. Alternatively, include Google Ireland Limited among the providers in the list of sub-processors and — if deemed appropriate by the DPO — move the font loading behind consent.
5. Possible DPO appointment and adherence to ADR bodies
- This Notice and the Privacy Policy currently declare that no DPO has been appointed. The existence of the conditions of Art. 37 GDPR must be reassessed in light of the growth in the number of Users and — if applicable — the appointment must be made before the official launch.
- Adherence to an out-of-court dispute resolution body pursuant to Art. 141-decies of the Italian Consumer Code, referred to in Section 26 of the Terms, should be evaluated.
6. Consent register
- The cookie choice is currently stored only client-side in "nymia.cookie_consent_v1". The implementation of a server-side register associating each consent choice with the authenticated account and a timestamp should be evaluated, in compliance with the demonstrability principle of Art. 7(1) GDPR.
7. Unified CMP
- The current banner is functional but does not offer granular management by category: consider adopting a Consent Management Platform (CMP) compliant with IAB Europe's TCF 2.2 if services adhering to the framework are introduced in the future (e.g. client-side Meta Ads).
Until the verifications listed above are completed, Bull Marketing undertakes to refrain from loading non-strictly-necessary third-party scripts on an "always-on" basis and to punctually document any deviations. This Notice therefore constitutes a "living" document, updated whenever the actual behaviour of the Platform changes.
20. Contacts
For any request relating to this Cookie Policy or to the processing of personal data collected through cookies and similar technologies, you can contact the Data Controller at the following addresses:
- Bull Marketing S.r.l.s.
- Registered office: Via Minelli 23, 44042 Cento (FE), Italy
- VAT number and tax code: IT02178200388
- REA registration: FE-257774
- Dedicated privacy and cookies email: privacy@nymia.me
- General support email: support@nymia.me
Competent supervisory authority: Garante per la protezione dei dati personali — Piazza Venezia n. 11, 00187 Rome — Tel. +39 06 696771 — Email: garante@gpdp.it — Certified email (PEC): protocollo@pec.gpdp.it — Website: www.gpdp.it.
Pursuant to Art. 77 GDPR and Articles 141 et seq. of the Privacy Code, the User has the right to lodge a complaint with the competent supervisory authority if they believe that the processing of their personal data violates the applicable legislation.