Cookie Policy
Last updated: July 15, 2026 | Version: 2.0
1. Introduction
This Cookie Policy explains how CyberSpeed LLC ("we," "us," "our") uses cookies and similar tracking technologies on cyberspeedllc.com ("Website"). It should be read alongside our Privacy Policy.
We comply with UAE Federal Decree-Law No. 45 of 2021 (PDPL), the UAE Telecommunications and Digital Government Regulatory Authority (TDRA) guidelines, and reference international standards including the EU ePrivacy Directive (2002/58/EC) and GDPR (EU 2016/679) for visitors from those jurisdictions.
2. What Are Cookies?
Cookies are small text files stored on your device (computer, tablet, mobile) when you visit a website. They enable the website to remember your actions and preferences over time. Similar technologies include:
- Local Storage / Session Storage: Browser-based storage for larger data
- Web Beacons / Pixel Tags: Invisible images tracking page views, email opens
- Fingerprinting: Device/browser configuration profiling (we do not use)
- ETags / Cache: HTTP caching mechanisms
3. Legal Basis for Cookie Use
| Category | Legal Basis (PDPL Art. 6 / GDPR Art. 6) | Consent Required |
|---|---|---|
| Strictly Necessary | Legitimate Interest (PDPL 6(1)(f)) / Contract Performance (6(1)(b)) | No — enabled by default |
| Preferences / Functionality | Legitimate Interest / Consent (PDPL 6(1)(a)) | Yes — opt-in |
| Analytics / Statistics | Legitimate Interest / Consent | Yes — opt-in (anonymised = legitimate interest) |
| Marketing / Advertising | Explicit Consent (PDPL 6(1)(a) / GDPR 7) | Yes — explicit opt-in required |
4. Cookies We Use
4.1 Strictly Necessary Cookies (Always Active)
These enable core functionality: security, authentication, session management, payment processing. Cannot be disabled.
| Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| session_id | CyberSpeed LLC | Session management, CSRF protection, secure login | Session | First-party, HTTP-only, Secure, SameSite=Strict |
| XSRF-TOKEN | CyberSpeed LLC | Cross-site request forgery prevention | Session | First-party, HTTP-only, Secure, SameSite=Strict |
| cookie_consent | CyberSpeed LLC | Stores your cookie preferences (categories accepted/declined) | 12 months | First-party, Secure, SameSite=Lax |
| cf_clearance | Cloudflare | WAF challenge verification, bot mitigation | 30 minutes | Third-party, Secure, SameSite=None |
| __cf_bm | Cloudflare | Bot management, rate limiting | 30 minutes | Third-party, Secure, SameSite=None |
| stripe_sid / stripe_mid | Stripe | Fraud prevention for payment processing | 30 min / 1 year | Third-party, Secure, SameSite=None |
4.2 Preferences & Functionality Cookies (Opt-In)
Remember your choices: language, region, display preferences, chat widget state.
| Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| language_pref | CyberSpeed LLC | Preferred language (en/ar) | 12 months | First-party, Secure, SameSite=Lax |
| theme_pref | CyberSpeed LLC | Dark/light mode preference | 12 months | First-party, Secure, SameSite=Lax |
4.3 Analytics & Statistics Cookies (Opt-In)
Anonymised aggregate data to improve website performance and user experience. IP addresses anonymised.
| Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| _ga | Google Analytics 4 | Distinguish unique users, calculate sessions | 13 months | Third-party, Secure, SameSite=None |
| _ga_XXXXXXXX | Google Analytics 4 | Session state, enhanced measurement | 13 months | Third-party, Secure, SameSite=None |
| _gid | Google Analytics 4 | Distinguish users within 24h | 24 hours | Third-party, Secure, SameSite=None |
| _gat_gtag_UA_XXXXXX | Google Analytics 4 | Throttle request rate | 1 minute | Third-party, Secure, SameSite=None |
| _clck / _clsk | Microsoft Clarity | Heatmaps, session recordings (anonymised) | 1 year / Session | Third-party, Secure, SameSite=None |
Data Processing: Google Analytics 4 configured with anonymize_ip: true, ads_personalization: denied, data_retention: 14 months. Microsoft Clarity masks all text inputs, emails, passwords. No cross-site tracking.
4.4 Marketing & Advertising Cookies (Explicit Opt-In Required)
Used only with your explicit consent for personalised advertising and conversion tracking.
| Cookie Name | Provider | Purpose | Expiry | Type |
|---|---|---|---|---|
| _fbp | Meta (Facebook) | Conversion tracking, audience building, ad delivery | 3 months | Third-party, Secure, SameSite=None |
| _fbc | Meta (Facebook) | Click ID for attribution | 3 months | Third-party, Secure, SameSite=None |
| _gcl_au | Google Ads | Conversion tracking, ad personalisation | 3 months | Third-party, Secure, SameSite=None |
| _gcl_aw | Google Ads | Ad click tracking | 90 days | Third-party, Secure, SameSite=None |
| li_gc / li_rm | Conversion tracking, retargeting (B2B) | 6 months | Third-party, Secure, SameSite=None | |
| ttclid / _ttp | TikTok | Conversion tracking, audience insights | 13 months | Third-party, Secure, SameSite=None |
4.5 Third-Party Embedded Content Cookies
Pages with embedded content (YouTube, Vimeo, Calendly, Typeform) may set cookies from those providers. We use privacy-enhanced modes where available (youtube-nocookie.com, Vimeo dnt=1).
5. Your Cookie Choices & Controls
5.1 Cookie Consent Banner
On first visit, a banner allows you to:
- Accept All: Enable all categories
- Reject All (Non-Essential): Only strictly necessary cookies
- Customise: Toggle Preferences, Analytics, Marketing individually
Your choice is stored in cookie_consent (12 months). You can change preferences anytime via the "Cookie Settings" link in the footer.
5.2 Browser Controls
All modern browsers allow you to:
- Block all cookies / third-party cookies
- Delete existing cookies
- Set per-site exceptions
- Use "Do Not Track" (DNT) signal — we respect DNT for analytics
Links: Chrome | Firefox | Safari | Edge
5.3 Opt-Out Tools
6. International Data Transfers
Some third-party cookies involve data transfers outside UAE/GCC:
- Google (Analytics, Ads): USA/EU — Standard Contractual Clauses (SCCs) + Supplementary Measures
- Meta (Facebook/Instagram): USA — SCCs + Data Processing Addendum
- Microsoft (Clarity, LinkedIn): USA/EU — SCCs + UK Addendum
- TikTok: Singapore/USA — SCCs
We only engage subprocessors providing adequate safeguards per PDPL Articles 22–24. Transfer impact assessments conducted for high-risk transfers.
7. Data Retention for Cookie Data
| Category | Max Retention | Deletion Trigger |
|---|---|---|
| Strictly Necessary | Session + 30 min | Browser close / session end |
| Preferences | 12 months | User changes preference / manual clear |
| Analytics (GA4) | 14 months | Auto-expiry / user deletion request |
| Analytics (Clarity) | 13 months / Session | Auto-expiry / session end |
| Marketing | 13 months | Consent withdrawal / auto-expiry |
8. Children's Privacy
Our Website and Services are not directed at children under 18. We do not knowingly collect Personal Data from minors. If a parent/guardian becomes aware a child has provided data, contact dpo@cyberspeedllc.com for immediate deletion.
9. Policy Updates
We may update this Cookie Policy to reflect changes in technology, law, or our practices. Material changes will be indicated by an updated "Last updated" date and a prominent notice on the Website. Continued use after changes constitutes acceptance.
Version history:
- v2.0 — July 15, 2026: Full PDPL alignment, detailed cookie tables, explicit consent flows
- v1.0 — January 2025: Initial publication
10. Contact & Your Rights
For cookie-related inquiries, consent withdrawal, or to exercise your PDPL rights (access, rectification, erasure, restriction, portability, objection):
Data Protection Officer: [CLIENT ACTION: Insert DPO Name]
Email: dpo@cyberspeedllc.com
Postal: CyberSpeed LLC, FOAM2399 Compass Building, Al Shohada Road, AL Hamra Industrial Zone-FZ, Ras Al Khaimah, UAE — Attn: DPO
Phone: +971 4 200 0000
You also have the right to lodge a complaint with the UAE Data Office (Federal Authority for Identity, Citizenship, Customs & Port Security) or relevant Free Zone authority (DIFC Commissioner, ADGM Registrar).