Dec 2027EU AI Act compliance

    Cookie Notice

    Version 2026.1 · Effective from 2026-09-15

    This Cookie Notice explains which cookies and similar technologies we use on the LandingRed website and Platform, what each one does, how long it is kept, and how you can accept, refuse or withdraw your consent. It also explains what our own servers record when you open a page. It supplements our Privacy Policy, in particular section 11, and should be read together with it.

    1. Who we are and what this notice covers

    The data controller is AB Corporate Advisory S.r.l. ("LandingRed", "we", "us"), with registered office at Corso del Popolo 39/A, 31100 Treviso (TV), Italy; registered with the Companies Register of Treviso-Belluno under no. 05406430263; VAT and tax code 05406430263; REA TV-441553; certified e-mail (PEC) abcorporateadvisory@pec.it. For data-protection matters you can contact us at privacy@landingred.com or, for formal communications, at the PEC address above.

    This notice covers the pages served at landingred.com: our public website, including its free tools, the LandingRed Platform that you use after signing in, and the pages for developers and staff described in sections 6 and 7.

    2. What cookies and similar technologies are

    Cookies are small text files that a website asks your browser to store and to send back with later requests. Websites can also keep information in your browser in other ways: local storage keeps it until it is deleted, and session storage normally keeps it until the browser tab is closed. The rules on storing information on your device, or gaining access to information already stored on it, are set out in Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive), as amended by Directive 2009/136/EC, and in Italy in Article 122 of the Personal Data Protection Code (Legislative Decree No 196/2003). This notice covers cookies, local storage and session storage alike. Our pages do not store information on your device through any other browser storage, such as IndexedDB, the Cache API or service workers.

    3. The two categories, how we group them, and the legal bases

    We place each item in a category according to its purpose. An item is Essential only if it is needed for something you have asked for — signing in, keeping a form you are filling in, applying a setting you picked, or recording your cookie choice — and we do not use it for anything else. An item that records how you reached us is Analytics, and it is used only if you switch Analytics on. We do not use any item to build a profile of you or for advertising, and none of them is set by another company.

    Essential (always on)

    Essential cookies and similar technologies are the ones we consider strictly necessary to provide the website and the Platform as you use them: for example, to keep you signed in, to protect your account against forged requests, to keep a form you are filling in, to remember settings such as your language, and to record your cookie choice. For that reason we do not ask for your consent before using them, and they cannot be switched off in the cookie choices window. Section 6 lists each of them, with what it does and how long it is kept. Where they involve personal data, we process it to provide the Service and your account (Article 6(1)(b) GDPR) and to keep the Service secure and prevent abuse (Article 6(1)(f) GDPR), as set out in section 4 of the Privacy Policy.

    Analytics (only with your consent)

    Analytics records which campaign or website brought you to us (section 4), so that we can see which of our campaigns and which other websites bring us visitors, sign-ups and users of our free tools. When you submit a form or sign up, that information is stored with your submission, together with the date and time of your choice and the e-mail address you enter, or with your new workspace. Analytics stays off until you switch it on, and this information is stored on your device and sent to us only while it is on. Your consent is the legal basis for it (Article 6(1)(a) GDPR).

    Page visits are counted for every visitor, whatever their choice, and nothing is stored on your device for it. Section 5 explains what our servers record when you open a page.

    4. Analytics: where your visit came from

    When a page loads, our code reads two pieces of information about how you reached us: the campaign tags in the address of the link you followed (utm_source, utm_medium and utm_campaign), which are chosen by whoever created the link, and the domain of the website that sent you to us, if it is not our own.

    If Analytics is switched on, we store this information in your browser under the name lr_attribution the first time a visit has a source; a later source does not replace it. It is then sent to our own server with the page-visit messages described in section 5 and with the forms you submit: sign-up, the free EU AI Act self-assessment, the AI usage scan and the Article 50 disclosure notice generator. When you submit one of these forms, the source is stored with your submission, together with the date and time of your Analytics choice; the submission also holds the e-mail address you enter and the IP address of the request; for sign-up it is stored with a record linked to your new workspace. Submitting one of these forms also creates an entry in our audit log, the record we keep of changes to the data in our systems: that entry holds the e-mail address you entered and the IP address and browser details of the request, it cannot be changed, and it is deleted after 10 years. We keep the source stored with a form submission for as long as we keep that submission, which is 24 months, and the source recorded with a sign-up for 24 months.

    If Analytics is off, this information stays only in the memory of the open page and is gone when you leave or reload it. It is not stored on your device, it is not added to the page-visit messages or to the forms you submit, and any lr_attribution already stored is deleted. Your browser still sends the full address of the page you open, including any campaign tags in it, and usually the domain — sometimes the full address — of the page that sent you, with the request for the page itself; section 5 explains how our web server logs those requests.

    You can withdraw your consent at any time, as explained in section 8. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. It deletes lr_attribution from your browser at once. Because a withdrawal is never sent to us, we do not learn that you have withdrawn it, so a source, and the date and time of your choice, already stored with a form you submitted, or with your sign-up, stay with us for the period given above unless you ask us to erase them: write to privacy@landingred.com from the e-mail address you entered. A source sent with a page-visit message is stored without anything that identifies you, so we cannot find it to erase it.

    5. Counting page visits, and what our servers log

    When you open a page that can be used without signing in, your browser sends a short message to our own server so that we can count visits. These pages are our public website and its free tools, the sign-in, sign-up, password-reset, invitation and two-factor sign-in pages, the page an external auditor opens from an access link, and the page shown for an address that does not exist. This happens for every visitor, whatever the cookie choice, including when you open one of these pages while signed in. Nothing is stored on your device for it, and pages that require you to sign in are not counted. Browsers that declare themselves automated send no message.

    The message states which page was opened, in a general form that leaves out any personal access code contained in the address; the language of the page; and whether it is a page view, the first page shown after the site was loaded in your browser, or a template download. If Analytics is switched on, it also carries the source described in section 4; otherwise those fields are empty. The message contains no identifier that we created for you. Your browser attaches to it the cookies it already holds for our site, so the request can carry your sign-in cookie, but the visit record keeps neither that cookie nor anything derived from it.

    Our server records the event with the date and time. That record holds no IP address, no browser details, no account and no identifier for you or your device, and it is not linked to anything else we hold about you. The server reads the user-agent string that your browser sends with every request, which names the browser and its version, only to leave out automated visitors such as search-engine crawlers; the visit record does not keep it.

    Like any website, our web server keeps a technical log of the requests it receives, whatever your cookie choice. Each entry holds the date and time, your IP address, the address requested, including any campaign tags in it, the answer our server gave, and the request details your browser sends, such as the browser and its version and, where your browser sends it, the address of the page the request came from. The cookies your browser sends are not written to the log. We use this log to run the website and the Platform and to keep them secure (Article 6(1)(f) GDPR). The log is limited in size: when it is full, the oldest entries are overwritten by newer ones, so we do not keep it for a fixed period.

    As with any request to a website, our server receives your IP address. To prevent abuse, it keeps a counter linked to your IP address, which limits how many of these messages it accepts from one address. The counter is deleted one hour after the last message from that address.

    Visit records are deleted 24 months after they are created.

    We count visits only to produce aggregated statistics about the use of our public website, such as how many visits each page receives and in which language. We produce those statistics with our own systems: we do not use an outside measurement service, and page-visit records are not combined with other information we hold about you. Where counting involves personal data, such as the IP address our server receives with each request, we rely on our legitimate interest in understanding how our website is used and in keeping it secure (Article 6(1)(f) GDPR).

    Your right to object

    You have the right to object at any time, on grounds relating to your particular situation, to the processing described in this section that is based on our legitimate interest (Article 21 GDPR). To object, write to privacy@landingred.com. Visit records do not identify you, so unless you give us information that lets us find the records concerned we may not be able to act on your objection; if that is the case, we will tell you.

    6. List of cookies and similar technologies

    The table below lists the cookies and similar technologies that our website and the Platform store in your browser on the date of this notice. All of them are set by LandingRed itself; none is set by another company. Each one is created only when you use the feature it relates to, as the table describes.

    Versions of our website published before this notice took effect also saved the colour theme on every visit, saved the language chosen by a link, and kept the free self-assessment draft in local storage rather than only for the browser tab. Anything saved that way stays in your browser until you clear this site’s data, and our pages still read the theme and language values. The old self-assessment draft is moved into the tab, and removed from local storage, the next time you open the self-assessment.

    Where a name below contains a descriptive part such as “workspace number”, the stored name contains the actual value instead.

    All visitors

    • landingred.consent.v1

      Type
      Local storage
      Category
      Essential
      Purpose
      Records your cookie choice and when you made it, so that the banner is not shown again and Analytics runs only if you switched it on. Written when you make a choice, and when a refusal saved by an earlier version of the banner is converted to the current format.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it. See section 9.
      Set by
      LandingRed (first party)
    • lr_attribution

      Type
      Local storage
      Category
      Analytics
      Purpose
      Records the first known source of your visits: the campaign tags of the link you followed, or the domain of the website that sent you to us. Sent with page-visit messages and with the forms you submit. Stored only if you switch Analytics on (section 4).
      How long it is kept
      No expiry date: kept until you withdraw consent or clear this site’s data. Deleted as soon as you withdraw consent.
      Set by
      LandingRed (first party)
    • locale

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers the language of the interface. Set when you switch language on the website or in the Platform, and also each time you sign in, or open a page while signed in, from the language saved in your account. On the website, a stored language other than English normally takes you to the pages in that language.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • landingred-announce-dismissed

      Type
      Local storage
      Category
      Essential
      Purpose
      Keeps the announcement bar at the top of the website hidden after you close it.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • csrftoken

      Type
      Cookie
      Category
      Essential
      Purpose
      Protects against forged requests sent from other websites: our pages send it back with each change you make, so that our server can check the request comes from us. Set when you sign in, when you open the staff administration sign-in page, and when you open an address under /api/ that shows a page in your browser, such as /api/docs/. The last two do not need you to sign in.
      How long it is kept
      364 days from when it was last set; a new one is set each time you sign in. Signing out does not delete it.
      Set by
      LandingRed (first party)

    Free tools

    • public-assessment-draft

      Type
      Session storage
      Category
      Essential
      Purpose
      Keeps your progress in the free EU AI Act self-assessment so that a page refresh does not lose it: your answers and, once you enter them, your e-mail address and company name.
      How long it is kept
      Normally until you close the browser tab. Removed when you submit the assessment.
      Set by
      LandingRed (first party)
    • ai-usage-scan-handoff

      Type
      Session storage
      Category
      Essential
      Purpose
      Passes the summary produced by the AI usage scan to the EU AI Act self-assessment when you choose to continue there. The summary holds counts, categories and months, not the text of your conversations.
      How long it is kept
      Removed when the self-assessment reads it; otherwise normally until you close the browser tab.
      Set by
      LandingRed (first party)
    • ai-usage-scan-quota

      Type
      Local storage
      Category
      Essential
      Purpose
      Counts the AI usage scans run in this browser today, to hold the free scan to 5 a day. The scan itself runs in your browser, so this count does not protect our servers: it is a usage limit we set for the free tool.
      How long it is kept
      No expiry date. The count applies only to the current day (UTC) and starts again the next day.
      Set by
      LandingRed (first party)

    Signing in and the Platform

    • sessionid

      Type
      Cookie
      Category
      Essential
      Purpose
      Keeps you signed in. It holds a random code that our server links to your account, and scripts on our pages cannot read it. Set when you sign in, and when you start single sign-on.
      How long it is kept
      Normally until you close your browser, and at most 8 hours after your browser last contacted the Platform while you were signed in. Deleted when you sign out.
      Set by
      LandingRed (first party)
    • theme

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers the colour theme (light, dark or system) you pick in the Platform’s menu. The Platform writes it only when you pick one; the staff administration pages write to the same name (see below).
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • landingred.tour.completed.v1

      Type
      Local storage
      Category
      Essential
      Purpose
      Stops the product tour from starting again once it has been closed or finished. The tour starts by itself the first time the Platform is opened in this browser after the workspace’s setup is complete. It applies to everyone who signs in with this browser.
      How long it is kept
      No expiry date: kept until you clear this site’s data, or removed when you start the tour again from the menu.
      Set by
      LandingRed (first party)
    • security_banner.dismissed_until

      Type
      Local storage
      Category
      Essential
      Purpose
      Hides the reminder to set up two-factor sign-in for 7 days after you close it.
      How long it is kept
      No expiry date: kept until you clear this site’s data. The reminder returns after 7 days.
      Set by
      LandingRed (first party)
    • whatsnew:lastSeenId:‹workspace number›

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers the latest product announcement you closed in a workspace, so that it is not shown again. The name contains the workspace’s internal number.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • datatable:filters:‹workspace number›:inventorydatatable:filters:‹workspace number›:reports-historydatatable:filters:‹workspace number›:vendor-list-filters

      Type
      Local storage
      Category
      Essential
      Purpose
      Restores the search text, filters and sort order you last used in the inventory, the reports history and the vendor list. The name contains the workspace’s internal number, and the value can contain words you typed in the search box.
      How long it is kept
      Removed when you return the table to its default view; otherwise kept until you clear this site’s data. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • riskWizard.modeconformityWizard.mode

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers whether you prefer the guided or the expert mode of the risk classification and conformity wizards. Set when you switch mode.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • inventory.create_mode

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers whether you prefer the guided or the expert mode when you add a system to the inventory. Set when you switch mode.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • editor.ai_panel_openeditor.subsection_panel_open

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers whether you left the AI panel and the subsection panel of the section editor open or closed.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • sidebar.expanded-sections

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers which regulation sections of the Platform’s sidebar (Data Act, CRA, DORA, NIS2) you have expanded.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • eu_comply.regulation_qa.disclosure_seen_v1

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers that you closed the notice explaining that answers in the Ask the EU AI Act window are generated by AI, so that it is shown only once in this browser. Each answer keeps its own AI label.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • conformity.route_explainer_dismissed.‹route type›

      Type
      Local storage
      Category
      Essential
      Purpose
      Keeps the explanation of a conformity route hidden after you close it, separately for each of the two route types.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • onboarding-draft-‹user number›onboarding-draft-anon

      Type
      Local storage
      Category
      Essential
      Purpose
      Keeps your progress while you set up a new workspace, including the e-mail address for incident notifications, whether your organisation is an SME and its annual turnover. The name contains your account’s internal number.
      How long it is kept
      Removed when you finish setting up the workspace. If you leave it unfinished, it is kept until you clear this site’s data; signing out does not delete it.
      Set by
      LandingRed (first party)

    Staff administration and API pages

    • messages

      Type
      Cookie
      Category
      Essential
      Purpose
      Carries a one-time confirmation message from one page of the staff administration area to the next. That area requires a staff account. The message can contain the name of a record, such as a user’s e-mail address.
      How long it is kept
      Removed once the message has been shown; otherwise when you close the browser.
      Set by
      LandingRed (first party)
    • tabstyle

      Type
      Cookie
      Category
      Essential
      Purpose
      Remembers which tab (HTML form or Raw data) you last chose on a page of our API opened directly in a browser. Written only when you click one of those tabs.
      How long it is kept
      Until you close the browser.
      Set by
      LandingRed (first party)
    • theme

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers the colour theme of the staff administration pages (light, dark or automatic). Written each time one of those pages is opened, including their sign-in page, which anyone can reach. It shares its name with the Platform’s theme setting above, so each can change the other.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • django.admin.navSidebarIsOpen

      Type
      Local storage
      Category
      Essential
      Purpose
      Remembers whether the navigation sidebar of the staff administration pages is open. Written when staff open or close it.
      How long it is kept
      No expiry date: kept until you clear this site’s data in your browser. Signing out does not delete it.
      Set by
      LandingRed (first party)
    • django.admin.navSidebarFilterValue

      Type
      Session storage
      Category
      Essential
      Purpose
      Keeps the text typed into the filter box of the staff administration sidebar.
      How long it is kept
      Normally until you close the browser tab.
      Set by
      LandingRed (first party)
    • django.admin.filtersState

      Type
      Session storage
      Category
      Essential
      Purpose
      Remembers which filters are expanded on the list pages of the staff administration area.
      How long it is kept
      Normally until you close the browser tab.
      Set by
      LandingRed (first party)

    7. What we do not use

    We do not use cookies or similar technologies for advertising, and none of the information they hold is passed to advertising networks.

    Apart from the pages for developers described below, no other company places cookies or similar technologies through our website or the Platform, and our pages load code, styles, fonts, images and video from our own servers only. Links to other websites, such as our LinkedIn page, load nothing from those websites until you follow them; after that, the other website’s own rules apply.

    We do not use cookies or similar technologies to recognise you from one visit to the next for statistics or advertising, and we do not record what you do on other websites. The sessionid and csrftoken cookies hold random codes that we use only to keep you signed in and to protect against forged requests (section 6). With your consent, the only thing we record about another website is the domain of the one that sent you to us (section 4).

    If your organisation has set up single sign-on, signing in takes your browser to your organisation’s own sign-in service, which may use its own cookies under its own rules.

    Our pages for developers, at /api/docs/ and /api/redoc/, do not show the cookie banner. Their code asks your browser to load files from cdn.jsdelivr.net and, for /api/redoc/, fonts from Google (fonts.googleapis.com and fonts.gstatic.com) and an image from cdn.redoc.ly; if your browser loads them, those services receive your IP address and browser details. /api/docs/, like the other addresses under /api/ that show a page in a browser, also sets the csrftoken cookie without you signing in; /api/redoc/ does not.

    8. How to give, change or withdraw consent

    When you have not yet made a choice, a banner asks for it. Reject all and Accept all are shown side by side, with the same size and style. Closing the banner with × or pressing Escape in it has the same effect as Reject all. Choose cookies opens a window where you can switch Analytics on or off and save your choice.

    You can change your choice at any time with the button. It is at the foot of this page, in the footer of our website and of the Platform, and on the sign-in, sign-up and free tool pages, next to a link to this notice. In the window it opens, choose Reject all or Accept all, or switch Analytics on or off and choose Save choices. Closing that window with × changes nothing.

    To withdraw your consent, open that window and choose Reject all, or switch Analytics off and choose Save choices. It is the same window in which you can give consent, and the change takes effect at once. Refusing or withdrawing consent does not limit your use of the website or the Platform.

    Your choice applies to this browser only. It is kept in this browser, not in your account, and does not follow you to other browsers or devices. The record of your choice is not sent to us on its own — although a message that carries a visit source shows that Analytics was on. When you submit one of the forms named in section 4, or sign up, while Analytics is on, the date and time of your choice are stored with that submission, so that we can show that you consented (Article 7(1) GDPR).

    9. How long we remember your choice

    We keep your choice in this browser under the name landingred.consent.v1, with the date and time you made it. It has no expiry date: it stays until you clear this site’s data in your browser, and signing out does not delete it.

    The banner is shown again if this browser no longer holds a valid choice, for example after you clear this site’s data, and it is shown in any other browser or on any other device you use. If we add a category, or change what a category is used for, we will show the banner again so that you can choose again. If your browser does not let our site store your choice, for example because site data is blocked, the choice applies only until you leave or reload the page, and the banner then appears again.

    10. Browser settings

    Most browsers let you see, delete and block cookies and other site data, usually in their privacy or site settings. Deleting this site’s data signs you out, deletes your cookie choice so that the banner appears again, and removes saved settings, drafts and filters. Signing in needs the sessionid cookie, so if you block cookies for our site you cannot stay signed in to the Platform.

    Signing out does not delete what our site keeps in your browser’s local storage. On a shared computer, delete this site’s data in your browser when you have finished.

    11. Your rights

    Our Privacy Policy explains how we process personal data, who receives it, whether it is transferred outside the European Economic Area and how long we keep it, and describes your rights, including the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with a supervisory authority — in particular in the EU Member State where you live or work, or where you believe the infringement took place; in Italy this is the Garante per la protezione dei dati personali. For any question about this notice, contact us at privacy@landingred.com.

    12. Changes to this notice

    We will update this notice when the cookies and similar technologies we use change. The version number and date at the top of this page identify the current version.