TECHNICAL GOVERNANCE & TELEMETRY

Comprehensive Enterprise Cookie Policy

Effective Date: July 28, 2026 | Last Updated: July 28, 2026 | Document Control Version 3.4

Fraoula LLC ("Fraoula", "we", "us", or "our"), headquartered in Newark, Delaware, USA, establishes this Cookie Policy to provide complete transparency regarding the HTTP cookies, browser local storage objects, session tokens, and telemetry mechanisms utilized across our enterprise websites and software products.

1. Introduction, Legal Scope & Entity Governance

Fraoula LLC ("Fraoula", "Company", "we", "us", or "our") operates as an enterprise AI software product company incorporated under the laws of the State of Delaware, United States of America, with operational engineering teams active across the United States, Europe, and India. This Cookie Policy applies to all site visitors, registered enterprise tenants, software engineers, data architects, and corporate partners accessing our primary web properties, including www.fraoula.co, our specialized product subdomains data-audit.fraoula.co (Fraoula Data Auditor) and marketing.fraoula.co (Fraoula Marketing Intelligence Platform), our software APIs, SDKs, and associated cloud services (collectively, the "Services").

This Policy explains the precise technical nature, operational purpose, lifespan, security parameters, and legal governance of HTTP cookies, HTML5 local storage objects (LSOs), session storage objects, web beacons, and edge telemetry tags deployed across our network infrastructure. This document operates in direct conjunction with our Comprehensive Privacy Policy and aligns strictly with global data protection directives, including the European Union ePrivacy Directive (Directive 2002/58/EC as amended by Directive 2009/136/EC), the EU General Data Protection Regulation ( Regulation [EU] 2016/679), the UK Privacy and Electronic Communications Regulations (PECR), the California Consumer Privacy Act / California Privacy Rights Act (/CPRA), the W3C Tracking Preference Expression (DNT), and the Global Privacy Control (GPC) specification.

By interacting with our digital properties or configuring enterprise tenant connections, you acknowledge the storage and access of cookies and browser telemetry objects as detailed herein. You maintain full legal authority and technical capability to modify, restrict, or block cookies through browser preferences or Global Privacy Control (GPC) signals, subject to the essential operational requirements detailed in Section 8 below.

2. Technical Taxonomy of Tracking & Storage Technologies

Modern enterprise web applications leverage various browser storage and network signaling mechanisms to maintain user authentication, secure edge network connections, and store local session state. Fraoula utilizes the following distinct categories of storage technology across our production infrastructure:

A. HTTP Cookies (Header-Based Storage Objects)

An HTTP cookie is a small cryptographic text file containing alphanumeric key-value strings transmitted by a web server to your web browser upon accessing a URL endpoint. Your browser stores the file locally and returns the cookie header string with subsequent HTTP/S requests directed to the issuing domain. Cookies are categorized by lifetime and issuing origin:

  • Session Cookies: Temporary memory tokens stored strictly in volatile browser RAM during an active browsing session. Session cookies expire automatically upon closing the web browser tab or executing an explicit sign-out command. They are utilized by Fraoula primarily for single sign-on (SSO) authentication and Cross-Site Request Forgery (CSRF) token validation.
  • Persistent Cookies: Durable text files stored on your local disk drive with explicit cryptographic expiration timestamps (ranging from several hours up to twelve months). Persistent cookies survive browser restarts to recall user preferences (such as language selection or dark mode UI states).
  • First-Party Cookies: Issued directly by Fraoula’s primary host domains (www.fraoula.co, data-audit.fraoula.co, marketing.fraoula.co). First-party cookies are readable exclusively by Fraoula servers.
  • Third-Party Cookies: Issued by authorized enterprise subprocessors (e.g., Cloudflare, Stripe, Auth0) operating under contract with Fraoula to deliver edge security, bot protection, and financial payment checkout gateways.

B. HTML5 Web Storage (LocalStorage & SessionStorage APIs)

HTML5 Web Storage provides client-side key-value database storage directly within the web browser interface. Unlike HTTP cookies, web storage data is not automatically appended to every outbound HTTP server header, reducing network bandwidth overhead:

  • LocalStorage API: Persistent client-side data storage without automatic expiration dates. Fraoula utilizes LocalStorage to cache non-sensitive application UI configurations, user workspace layout preferences, and documentation state parameters.
  • SessionStorage API: Volatile client-side storage isolated strictly to the active browser tab. Data stored in SessionStorage is automatically destroyed when the tab is closed. Fraoula uses SessionStorage for transient form draft holding and temporary telemetry state buffers.

C. Web Beacons, Pixel Tags & Server-to-Server Telemetry

Web beacons (also known as clear GIFs, tracking pixels, or single-pixel images) are minute electronic graphics embedded within web pages or HTML emails. Unlike traditional third-party tracking pixels used by advertising networks, Fraoula utilizes zero third-party behavioral advertising pixels on primary corporate pages. Instead, our software products leverage server-to-server API webhooks and SHA-256 cryptographic digests to transmit anonymized conversion metrics directly between enterprise servers without exposing raw personal identifiers.

3. Statutory Framework & Consent Governance Standards

Fraoula enforces rigorous compliance with international privacy statutes governing electronic communications and automated data collection:

A. EU ePrivacy Directive (2002/58/EC) & (2016/679)

Under Article 5(3) of the EU ePrivacy Directive and Recital 32, storing cookies or accessing information stored on a user's terminal equipment requires prior, freely given, specific, informed, and unambiguous opt-in consent, except where the cookie is strictly necessary for the delivery of a service explicitly requested by the user ("Strictly Necessary Exemption"). Fraoula enforces the following consent rules:

  • Strictly Necessary Exemption: Essential security tokens, load balancing cookies, and CSRF protection cookies execute immediately upon site load without requiring opt-in consent.
  • Opt-In Consent Requirement: All non-essential analytical or functional preference storage mechanisms require affirmative opt-in click action prior to script execution.
  • Prohibition of Forced Cookie Walls: Access to primary website content and documentation is never blocked if a user rejects non-essential cookies.
  • Granular Consent Management: Users maintain the right to accept or reject specific cookie categories independently without all-or-nothing constraints.

B. UK Privacy and Electronic Communications Regulations (PECR)

In full compliance with UK PECR regulations enforced by the Information Commissioner’s Office (ICO), Fraoula applies identical opt-in consent requirements for all UK-based site visitors, maintaining explicit consent records for legal auditing.

C. California / CPRA & U.S. State Opt-Out Frameworks

Under California Civil Code Section 1798.120 (/CPRA), consumers possess the statutory right to opt-out of the "sale" or "sharing" of personal information. Fraoula does NOT sell consumer personal information or share personal data with third-party advertising networks for cross-context behavioral advertising. Furthermore, we recognize Global Privacy Control (GPC) opt-out signals automatically at the web server layer.

4. Detailed Classification of Cookies Deployed by Fraoula

Every cookie and storage object utilized across Fraoula digital properties falls strictly into one of four functional categories. Below is an exhaustive audit of each category:

Category 1: Strictly Necessary / Essential Security & Operations Cookies

These cookies are indispensable for enabling website navigation, securing edge network endpoints, authenticating user login credentials, preventing Cross-Site Request Forgery (CSRF), and enforcing Web Application Firewall (WAF) bot mitigation. Because these cookies are essential to provide the service requested by the user, they cannot be turned off in our system settings. Essential cookies do not store any personally identifiable information in unencrypted form.

Category 2: Functional & Preference Local Storage

Functional storage objects allow Fraoula websites to remember choices you make during your visits (such as your preferred color theme, code editor settings, active documentation tab, or language preference) to deliver a personalized, seamless workspace experience. Disabling preference storage will revert your workspace display settings to default values upon every page navigation.

Category 3: Performance & Technical Telemetry Cookies

Performance telemetry cookies collect anonymized, aggregated information regarding server response times, edge network cache hit rates, page load latency, and JavaScript execution errors. This data is utilized exclusively by Fraoula systems engineering teams to optimize cloud delivery infrastructure and fix technical defects. Telemetry data contains zero personal identifiers and cannot be used to trace individual user browsing activity across non-Fraoula sites.

Category 4: Enterprise Marketing & Conversion Telemetry

Utilized exclusively on product landing pages to measure corporate campaign effectiveness. Identifiers are hashed client-side using SHA-256 cryptographic digests prior to transmission. Fraoula does not sell marketing data, purchase third-party enrichment profiles, or participate in third-party ad retargeting networks.

5. Comprehensive Technical Inventory Table of Cookies & Storage Objects

The following audit table provides complete technical transparency regarding the specific cookies, issuing domains, categories, operational purposes, and retention lifespans across Fraoula web properties:

6. Absolute Strict Non-Tracking & Privacy-First Commitment

Fraoula operates as an enterprise software product vendor serving privacy-sensitive Fintech, Healthtech, and industrial organizations. We enforce a strict privacy-first architecture across our entire digital infrastructure:

  • ZERO Third-Party Behavioral Ad Pixels: We do NOT place Meta Pixels, Google Remarketing Tags, TikTok Pixels, or third-party ad network tracking scripts on our primary corporate properties.
  • ZERO Data Sale or Cross-Context Sharing: We do NOT monetize browser data, sell visitor profile data, or share personal information with data brokers, ad networks, or credit agencies.
  • ZERO Cross-Site Fingerprinting: Fraoula codebases contain zero canvas fingerprinting, audio context sniffing, WebGL rendering probes, or font enumeration scripts designed to track users across non-affiliated domain names.
  • Client-Side Hashing Safeguards: Any conversion data processed for marketing optimization undergoes SHA-256 cryptographic hashing prior to outbound network transmission.

7. Global Privacy Control (GPC) & Do-Not-Track (DNT) Technical Specifications

Fraoula web servers automatically process and honor automated privacy signals transmitted by modern web browsers:

  • Global Privacy Control (GPC) Signal Enforcement: When your browser transmits the Sec-GPC: 1 HTTP request header (supported by Brave, Firefox, DuckDuckGo, and privacy extensions), Fraoula edge servers instantly process this request as a legally binding opt-out signal. Optional performance telemetry scripts are automatically suppressed, and the fraoula_gpc_acknowledged key is stored to confirm server compliance.
  • Do-Not-Track (DNT) Header Specification: Fraoula honors the W3C DNT: 1 HTTP header. When detected, optional client-side performance logging is immediately disabled for the session duration.
  • Automated Opt-Out Verification: Site visitors can verify GPC signal acknowledgment by inspecting response headers for X-GPC-Status: Honored on all Fraoula endpoints.

8. Managing, Disabling & Controlling Cookies Across Browsers & Operating Systems

You maintain full legal authority and technical capability to manage, block, or clear cookies and local storage objects deployed on your device through various technical mechanisms across desktop and mobile platforms:

A. Desktop Browser Controls

Most modern web browsers permit users to view, manage, restrict, or block cookies through detailed security and privacy settings menus:

  • Google Chrome (Windows / macOS / Linux): Settings > Privacy and security > Third-party cookies > Select "Block third-party cookies" or "See all site data and permissions" to delete specific domain entries.
  • Mozilla Firefox (Windows / macOS / Linux): Preferences > Privacy & Security > Enhanced Tracking Protection > Select "Strict" mode or custom cookie restrictions.
  • Apple Safari (macOS): Settings > Privacy > Select "Prevent cross-site tracking" and check "Block all cookies" if complete restriction is desired.
  • Microsoft Edge (Windows / macOS): Settings > Cookies and site permissions > Manage and delete cookies and site data.
  • Brave Browser (Desktop): Shields menu > Set Shields to "Aggressive" to block all cross-site cookies, trackers, and fingerprinting attempts automatically.

B. Mobile Operating System Controls (iOS & Android)

Mobile device users can control web storage and cookie behavior directly within operating system system settings:

  • Apple iOS / iPadOS (iPhone & iPad): Settings > Safari > Enable "Prevent Cross-Site Tracking" and toggle "Block All Cookies" or clear "Advanced > Website Data".
  • Google Android (Mobile Devices): Open Chrome App > Settings > Site settings > Cookies > Select "Block third-party cookies" or "Block all cookies".

C. Clearing LocalStorage & SessionStorage Objects

HTML5 LocalStorage and SessionStorage objects can be cleared manually at any time using your web browser’s Developer Tools panel (Press F12 or Cmd+Option+I > Application / Storage tab > Select Local Storage / Session Storage > Right-click domain > Select "Clear").

D. Operational Consequences of Disabling Essential Cookies

Please note that if you choose to block strictly necessary cookies (such as fraoula_session_id, fraoula_csrf_token, or __cf_bm), essential website functionalities will be impaired. You will be unable to log into enterprise product consoles, Single Sign-On (SSO) authentication will fail, and API form submissions will be rejected by our Web Application Firewall for security protection.

9. Third-Party Edge Infrastructure Subprocessors

Fraoula utilizes specialized third-party cloud infrastructure providers to host edge networks, execute security WAF rules, and process financial checkout payments. These subprocessors may issue technical cookies to deliver service functionality:

  • Cloudflare Inc.: Issues security and bot mitigation cookies (__cf_bm, cf_clearance). Read Cloudflare Privacy Policy at cloudflare.com/privacypolicy.
  • Stripe Inc.: Issues fraud detection cookies (__stripe_mid, __stripe_sid) during checkout. Read Stripe Privacy Policy at stripe.com/privacy.
  • Auth0 / Okta Inc.: Issues identity tokens during OAuth 2.0 login flows. Read Auth0 Privacy Policy at auth0.com/privacy.
  • Amazon Web Services (AWS) & Google Cloud: Issues load balancing session cookies for server routing. Read AWS Privacy at aws.amazon.com/privacy.

10. Enterprise Security Controls Applied to Storage Objects

Fraoula implements robust technical security safeguards to prevent cookie hijacking, session eavesdropping, and Cross-Site Scripting (XSS) attacks:

  • HttpOnly Flag: All sensitive session authentication cookies are marked with the HttpOnly attribute, preventing client-side JavaScript code from reading or extracting cookie contents, neutralizing XSS credential theft.
  • Secure Flag: All cookies are marked with the Secure attribute, instructing web browsers to transmit cookies strictly over encrypted HTTPS connections utilizing TLS 1.3 encryption.
  • SameSite Attribute Enforcement: Authentication and CSRF cookies enforce SameSite=Strict or SameSite=Lax policies to prevent browser transmission during cross-site requests, immunizing endpoints against CSRF attacks.
  • Cryptographic Payload Encryption: Session tokens stored within cookies are encrypted server-side utilizing AES-256-GCM algorithms prior to client delivery.
  • Automatic Token Rotation: Session identifiers are regenerated automatically upon privilege escalation, login authentication, or password modification to mitigate session fixation attacks.

11. International Regulatory Mandates & Compliance Verification

This Cookie Policy complies with jurisdiction-specific regulatory mandates worldwide:

  • European Union & UK: Fully compliant with Article 7 opt-in requirements, ePrivacy Directive 2002/58/EC, and UK PECR guidelines enforced by the ICO.
  • United States (California /CPRA, VA CDPA, CO CPA, CT CTDPA, UT UCPA): Compliant with /CPRA opt-out requirements and automated GPC signal parsing under Section 1798.120.
  • Brazil (LGPD): Compliant with Lei Geral de Proteção de Dados (LGPD Law No. 13,709/2018) Articles 7 and 9 regarding transparent cookie notice and legal processing bases.
  • Canada (PIPEDA & Quebec Law 25): Compliant with meaningful consent standards and mandatory opt-in rules for tracking technologies in Quebec.
  • Australia (Privacy Act 1988): Compliant with Australian Privacy Principles (APPs) regarding transparent disclosure of personal data storage mechanisms.

12. Cookie Lifecycle & Retention Governance

Fraoula enforces strict retention boundaries for all client-side storage objects. Session cookies are automatically purged from volatile browser RAM immediately upon tab closure. Persistent preference cookies maintain a maximum legal lifespan of twelve (12) months, after which they automatically expire and require renewed user consent. Performance telemetry logs stored server-side undergo automated cryptographic destruction after ninety (90) days.

13. Policy Revision & Versioning Control

Fraoula reserves the right to modify this Cookie Policy periodically to reflect infrastructure modifications, new software capabilities, or statutory amendments. When material updates occur, we will update the "Effective Date" and "Document Control Version" at the top of this policy and publish the revised version at https://www.fraoula.co/cookie-policy. For significant modifications impacting user privacy rights or cookie collection scope, we will provide additional notice, such as displaying a refreshed consent banner upon your next visit.

14. Contact Information & Data Protection Officer

If you have technical questions regarding the cookies, local storage objects, or telemetry mechanisms deployed on Fraoula Services, or wish to exercise your data privacy rights, please contact our Data Governance team:

  • Legal Entity Name: Fraoula LLC
  • Headquarters Address: Newark, Delaware, United States of America
  • Data Protection Officer (DPO) Email: info@fraoula.co
  • Corporate Website: https://www.fraoula.co

© 2026 Fraoula LLC. All rights reserved. Enterprise AI Products. Built for Scale.