ERMITS ADVISORY SERVICES - COOKIE & PORTAL POLICY
Effective Date: April 21, 2026
Last Updated: April 21, 2026
This Cookie & Portal Policy explains how ERMITS LLC ("ERMITS," "we," "our," or "us") uses cookies, tracking technologies, and similar storage when you visit the public ERMITS Advisory marketing site at https://www.ermits-advisory.com/ and when you use other ERMITS Advisory web experiences (for example a secure client portal, if offered on a separate host). This policy should be read together with our Advisory Services Privacy Policy.
1. SCOPE AND APPLICABILITY
1.1 Services Covered
This policy applies to:
Advisory Services Website:
- Public marketing site at https://www.ermits-advisory.com/ (services, how it works, sample report, Cyber Exposure Brief, intake)
- Contact and inquiry forms (for example Talk to an advisor)
- Google Analytics 4 on pages that load our analytics script
Client Portal:
- Secure client portal for engagement management (where ERMITS provides portal access; may be hosted separately from the static marketing site)
- Document sharing and collaboration platform
- Project status tracking and communications
- Deliverable access and review
1.2 What This Policy Does NOT Cover
This policy does NOT cover:
- ERMITS software products and SaaS platforms (separate Cookie Policy applies)
- Third-party websites linked from our website
- Email communications (covered by Privacy Policy)
- Engagement deliverables (covered by Terms of Service)
2. COOKIES AND SIMILAR TECHNOLOGIES
2.1 What Are Cookies?
Cookies are small text files stored on your device (computer, tablet, smartphone) when you visit websites. Cookies enable websites to remember your actions and preferences over time.
This policy also covers:
- Local Storage: Browser-based storage (localStorage, IndexedDB)
- Session Storage: Temporary storage cleared when browser closes
- Web Beacons (Pixels): Small graphics that track page views
- SDKs: Software development kits for mobile applications
- Fingerprinting: Device and browser characteristic collection
- Server Logs: Web server access and error logs
- Analytics Tools: Website analytics and performance monitoring
- Session Tokens: Authentication and session management
2.2 How We Use Cookies
We use cookies for the following purposes:
Essential Cookies (Always Active):
Required for basic website and portal functionality:
- Authentication and session management (client portal)
- Security and fraud prevention
- Load balancing and performance
- User preference storage (language, theme selection)
- Form submission and inquiry handling
Performance Cookies (Optional):
Help us improve service performance (may vary by site or application):
- Page load time measurement
- Error tracking and debugging on some applications (for example Sentry)—not loaded on the static www.ermits-advisory.com pages by default
- Feature usage analytics
- Service optimization
Analytics Cookies (Optional):
Help us understand how visitors use our website. On https://www.ermits-advisory.com/, we use Google Analytics 4 (G-VEQXJHYNHG) with IP anonymization. Other ERMITS web properties may use additional tools (for example PostHog).
- Page views and navigation patterns
- Time spent on pages
- Popular content and resources
- Popular features and pages
- User journey analysis
- Conversion tracking
Functional Cookies (Optional):
Enable enhanced functionality:
- Remember your preferences and settings
- Remember form field entries (for convenience)
- Enable resource downloads and content access
- Personalize user experience
- Enable integrations with third-party services
Marketing Cookies (Opt-In Required):
Used for marketing and advertising (with your consent):
- Track conversions from marketing campaigns
- Measure effectiveness of advertising
- Enable targeted content recommendations
- Support retargeting campaigns
We Do NOT Use:
- Third-party advertising networks
- Cross-site tracking for profiling
- Cookies to sell your data
- Tracking cookies for advertising or marketing (Privacy-First Architecture)
3. SPECIFIC COOKIES AND TECHNOLOGIES
3.1 Advisory Services Website Cookies
| Cookie Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| ermits_session | ERMITS | Session management | Essential | Session |
| ermits_consent | ERMITS | Cookie consent preferences | Essential | 1 year |
| ermits_language | ERMITS | Language preference | Functional | 1 year |
| theme | ERMITS | UI theme preference (light/dark) | Functional | 1 year |
| _ga | Google Analytics | Website analytics | Analytics | 2 years |
| _gid | Google Analytics | Website analytics | Analytics | 24 hours |
Note: Cookie names and specifics may change. On the static marketing host, you should expect Google Analytics (_ga, _gid, and related) when analytics is enabled, plus local storage for UI preferences (for example theme). Session cookies such as ermits_session may apply on other ERMITS web apps; PostHog or Sentry may appear on other properties—not on the default static pages of www.ermits-advisory.com.
3.2 Client Portal Cookies
| Cookie Name | Provider | Purpose | Duration |
|---|---|---|---|
| sb-access-token | Supabase | Authentication | 1 hour |
| sb-refresh-token | Supabase | Session renewal | 30 days |
| portal_session | ERMITS | Session management | 4 hours |
Security Features:
- All authentication cookies are HTTP-only (not accessible to JavaScript)
- Secure flag set (transmitted only over HTTPS)
- SameSite attribute set to prevent CSRF attacks
- Automatic expiration and renewal
- Encrypted values for sensitive cookie data
3.3 Server Logs
What We Log:
- Timestamp of access
- IP address (anonymized after 90 days)
- HTTP method and requested URL
- HTTP response status code
- User agent (browser and operating system)
- Referrer (previous page)
- Error messages and stack traces (for debugging)
Log Retention:
- Active logs: 90 days
- Archived logs (anonymized): 1 year
- Access restricted to security and engineering teams
Use of Logs:
- Security monitoring and threat detection
- Performance optimization
- Error debugging and troubleshooting
- Usage statistics (anonymized)
- Fraud prevention
4. COOKIE CONSENT AND MANAGEMENT
4.1 Cookie Consent Banner
Some ERMITS sites display a cookie consent banner with options to accept all cookies, reject non-essential cookies, customize categories, and save preferences. The static marketing site at https://www.ermits-advisory.com/ may not show a full interactive banner on every page; you can still control cookies through your browser settings and use Google’s opt-out tools for analytics.
4.2 Managing Cookie Preferences
On ERMITS Website:
- Access cookie preferences anytime via footer link
- Navigate to: Cookie Settings or Preferences
- Toggle cookie categories on/off (except essential)
- Save changes (takes effect immediately)
Browser Controls:
Most browsers allow cookie management:
Block All Cookies:
- May prevent website functionality
- Client portal will not function without essential cookies
Block Third-Party Cookies:
- Reduces third-party tracking
- Recommended for privacy
- May affect some features (analytics, marketing)
Delete Cookies:
- Clear existing cookies
- Resets preferences (consent banner reappears)
4.3 Browser-Specific Instructions
Google Chrome: Settings → Privacy and Security → Cookies and other site data
Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
Safari: Preferences → Privacy → Cookies and Website Data
Microsoft Edge: Settings → Cookies and site permissions → Cookies and data stored
Mobile Browsers: iOS Safari: Settings → Safari → Block All Cookies | Android Chrome: Settings → Site Settings → Cookies
5. THIRD-PARTY SERVICES AND INTEGRATIONS
5.1 Third-Party Service Providers
This static marketing site (www.ermits-advisory.com): Google Analytics 4 (see below); form submissions may be processed by our hosting provider (for example Netlify) under its terms. The list below includes providers that may apply to other ERMITS Advisory experiences (such as a client portal) or other sites.
Supabase (Authentication & Database):
- Purpose: User authentication and session management
- Privacy: Essential for service functionality
- Control: Required for service use; cannot be disabled
- Data Collected: Email, encrypted client data, session information
- Location: US or EU (client choice for portal data residency)
- Privacy Policy: https://supabase.com/privacy
Google Analytics:
- Purpose: Website traffic analysis and visitor behavior
- Data Collected: Page views, sessions, demographics, interests, device info
- Privacy: IP anonymization enabled, data retention set to 26 months
- Opt-Out: Use Google Analytics Opt-out Browser Add-on or disable analytics cookies
- Privacy Policy: https://policies.google.com/privacy
PostHog (Analytics):
- Purpose: Anonymous usage analytics with differential privacy on some ERMITS web properties (not used on the default static pages of www.ermits-advisory.com)
- Privacy: Cannot identify individual users
- Control: Can be disabled in privacy settings (opt-out)
- Privacy Policy: https://posthog.com/privacy
Sentry (Error Tracking):
- Purpose: Monitor application errors and performance on some applications (not loaded on the default static www.ermits-advisory.com pages)
- Privacy: Automatically scrubs PII from error reports
- Control: Can be disabled in privacy settings
- Data Collected: Error messages (PII automatically scrubbed), user actions leading to errors
- Data Retention: 90 days
- Privacy Policy: https://sentry.io/privacy/
Stripe (Payment Processing):
- Purpose: Payment processing and fraud prevention where ERMITS collects payment through Stripe (not used for standard form-only intake on the static marketing site)
- Privacy: Handles payment information securely
- Control: Required for payment functionality
- Privacy Policy: https://stripe.com/privacy
HubSpot (Marketing Automation):
- Purpose: Lead management, form submissions, marketing campaigns where deployed
- Data Collected: Contact information (name, email, company), form submissions, page views
- Privacy: GDPR-compliant, data processing agreement in place
- Opt-Out: Disable marketing cookies, unsubscribe from emails
- Privacy Policy: https://legal.hubspot.com/privacy-policy
Vercel (Hosting & CDN):
- Purpose: Content delivery and performance optimization
- Privacy: Standard web server logs
- Control: Required for service delivery
- Privacy Policy: https://vercel.com/legal/privacy-policy
5.2 Third-Party Cookie Control
We Contractually Require Third Parties To:
- Use data only for specified purposes (supporting our services)
- Implement appropriate security measures
- Comply with applicable privacy laws (GDPR, CCPA)
- Respect user opt-out preferences
- Delete data when no longer needed
You Can Control Third-Party Cookies:
- Use browser settings to block third-party cookies
- Use privacy-focused browser extensions (Privacy Badger, uBlock Origin)
- Opt out via Digital Advertising Alliance: http://optout.aboutads.info
- Opt out via Network Advertising Initiative: http://optout.networkadvertising.org
6. DO NOT TRACK (DNT) AND GLOBAL PRIVACY CONTROL (GPC)
6.1 Do Not Track Support
ERMITS Respects DNT Signals:
- When browser DNT is enabled, we disable optional analytics and marketing cookies
- Essential cookies remain active (required for portal functionality)
- No behavioral tracking or profiling when DNT enabled
Enabling DNT:
- Firefox: Settings → Privacy & Security → Send websites a "Do Not Track" signal
- Safari: Preferences → Privacy → Prevent cross-site tracking (enabled by default)
- Edge: Settings → Privacy, Search, and Services → Send "Do Not Track" requests
- Chrome: Not supported (use cookie controls instead)
6.2 Global Privacy Control (GPC)
GPC Support:
- We honor Global Privacy Control signals as an opt-out preference under CCPA
- GPC automatically disables non-essential cookies
- Available via browser extensions or privacy-focused browsers
Enabling GPC:
- Install GPC browser extension: https://globalprivacycontrol.org
- Use privacy-focused browsers with built-in GPC (Brave, DuckDuckGo, Firefox with extension)
7. CLIENT PORTAL SPECIFIC PROVISIONS
7.1 Client Portal Authentication
Secure Authentication:
- Multi-factor authentication (MFA) required for all portal users
- Strong password requirements (minimum 16 characters)
- Session timeout after 4 hours of inactivity
- Automatic logout after 12 hours maximum
7.2 Portal Data Protection
Encryption:
- All data transmitted over TLS 1.3
- Files encrypted at rest (AES-256)
- End-to-end encryption available for sensitive deliverables
- Zero-knowledge architecture option (client-controlled encryption keys)
7.3 Portal Usage Tracking
What We Track (Client Portal):
- Login/logout events and timestamps
- Document access and downloads
- Page views within portal
- Feature usage (anonymized)
- Error events and performance issues
Purpose:
- Security monitoring and anomaly detection
- Audit trail for compliance
- Portal performance optimization
- User support and troubleshooting
Privacy Protections:
- Tracking limited to portal activity only
- No cross-site tracking or profiling
- Data used only for security and support
- Client administrators may review access logs
7.4 Local Storage and IndexedDB
Privacy-First Local Storage:
ERMITS products extensively use browser local storage (localStorage, IndexedDB) for Privacy-First Architecture:
Purpose:
- Store assessment data locally (never transmitted to servers)
- Enable offline functionality
- Reduce server data storage
- Provide faster performance
Privacy Benefits:
- Data stays local: Your data remains on your device
- No server transmission: ERMITS doesn't access local storage data
- User control: You can clear local storage anytime
- Encryption option: Sensitive data can be encrypted locally
Managing Local Storage:
- Clear Local Storage: Account Settings → Data → Clear Local Data
- Browser Settings: Developer Tools → Application → Storage → Clear
- Warning: Clearing local storage deletes locally-stored assessments and data
- Backup: Export data before clearing: Account Settings → Export Data
8. PRIVACY BY DESIGN FOR ADVISORY SERVICES
8.1 Minimal Data Collection
Website:
- Anonymous browsing supported (no account required)
- Contact forms collect only necessary information
- No tracking of individual browsing behavior for marketing
- Resource downloads do not require email (for public content)
Client Portal:
- Data collection limited to engagement-related activities
- No unnecessary profiling or behavioral tracking
- Client controls data retention and deletion
- Export all portal data anytime (JSON, CSV)
8.2 Data Minimization Practices
We Do NOT Collect:
- Browsing history across other websites
- Granular location data (only country-level for analytics)
- Personal data from cookies (authentication tokens only)
- Sensitive personal information via website forms
- PII in cookies (names, emails, addresses not stored in cookies)
- Sensitive data in cookies (passwords, financial info, CUI/FCI)
We Do Collect (Minimally):
- Contact information you provide via forms (name, email, company, phone)
- Aggregated website analytics (page views, popular content)
- Client portal activity for security and audit purposes
- Technical information (browser, OS, device type) for support
- Session tokens only for authentication
- Hashed identifiers for analytics (cannot be reverse-engineered)
8.3 Privacy-First Architecture
Due to Privacy-First Architecture:
- No tracking cookies for advertising or marketing
- No cross-site tracking or profiling
- Minimal essential cookies only for functionality
- Local processing reduces need for server-side cookies
- Pseudonymized analytics cannot identify individual users
8.4 Transparency and Control
You Can:
- View and manage cookie preferences anytime
- Access all data we hold about you
- Export your data in machine-readable format
- Delete your account and data
- Opt out of marketing and analytics
- Contact us with privacy questions: privacy@ermits.com
9. INTERNATIONAL PRIVACY CONSIDERATIONS
9.1 GDPR Compliance (EU/UK/Switzerland)
For visitors and clients in the European Economic Area, United Kingdom, or Switzerland:
Cookie Consent:
- Explicit consent required before setting non-essential cookies
- Granular control over cookie categories
- Easy withdrawal of consent anytime
- Pre-checked boxes prohibited (opt-in required)
Legal Basis for Cookies:
- Essential Cookies: Necessary for service provision (GDPR Art. 6(1)(b))
- Analytics Cookies: Legitimate interests (GDPR Art. 6(1)(f)) or consent
- Marketing Cookies: Explicit consent (GDPR Art. 6(1)(a))
Rights:
- Access cookie data collected about you
- Request deletion of cookie data
- Object to cookie-based processing
- Lodge complaint with supervisory authority
Data Protection Authority:
- Contact your local DPA: https://edpb.europa.eu/about-edpb/board/members_en
- ERMITS DPO: privacy@ermits.com
9.2 CCPA Compliance (California)
For California residents:
Right to Know:
- Categories of personal information collected via cookies
- Categories of third parties with whom we share cookie data
- Business purposes for cookie use
Right to Opt-Out:
- Opt out of "sale" of personal information (we do not sell)
- Opt out of sharing for targeted advertising (disable marketing cookies)
- Use GPC to automatically signal opt-out preference
Right to Limit:
Limit use of sensitive personal information (none collected via cookies)
Non-Discrimination:
- Equal service regardless of cookie preferences
- No penalty for disabling optional cookies
Submit Requests:
- Email: privacy@ermits.com (Subject: "CCPA Request - Cookies")
- Online: Cookie Settings → Exercise Your Rights
9.3 Other Jurisdictions
Canada (PIPEDA): Express consent for non-essential cookies. Opt-out available anytime. Office of the Privacy Commissioner: https://www.priv.gc.ca
Brazil (LGPD): Cookie consent required similar to GDPR. Rights to access, delete, and object.
Australia (Privacy Act): Australian Privacy Principles (APPs) apply. Reasonable notice and opt-out for cookies.
10. WEBSITE ANALYTICS AND REPORTING
10.1 Analytics Data Collection
What We Track:
- Page Views: Which pages are visited and how often
- Traffic Sources: How visitors find our website (search, referral, direct)
- Demographics: Country, language, browser, device type (aggregated)
- User Flow: Navigation patterns through website
- Conversions: Form submissions, resource downloads, contact requests
- Performance: Page load times, errors, bounce rates
Privacy Protections:
- IP Anonymization: Last octet removed before storage
- Data Minimization: No granular personal data collected
- Aggregation: Reports show aggregate trends, not individual behavior
- Retention Limits: Analytics data retained 26 months maximum
10.2 How We Use Analytics
Website Optimization:
- Improve user experience and navigation
- Identify popular content and resources
- Fix broken links and errors
- Optimize page performance and load times
Content Strategy:
- Understand which topics are most valuable to visitors
- Develop new resources based on interest
- Tailor messaging to audience needs
Marketing Effectiveness:
- Measure campaign performance
- Understand lead sources and quality
- Optimize marketing spend and strategy
We Do NOT Use Analytics For:
- Individual profiling or targeting
- Behavioral manipulation
- Selling data to third parties
- Invasive tracking or surveillance
11. SECURITY OF COOKIES AND WEBSITE DATA
11.1 Cookie Security Measures
Technical Safeguards:
- HTTPS Only: All cookies transmitted over encrypted connections
- Secure Flag: Cookies sent only over HTTPS
- HTTP-Only Flag: Authentication cookies inaccessible to JavaScript (prevents XSS)
- SameSite Attribute: Cookies sent only to same-site requests (prevents CSRF)
- Short Expiration: Session cookies expire quickly (1-4 hours)
- Encrypted Values: Sensitive cookie values are encrypted
Cookie Security Risks:
Be aware of cookie-related security risks:
- Session Hijacking: Attackers stealing session cookies
- XSS Attacks: Malicious scripts accessing cookies
- CSRF Attacks: Unauthorized actions using your cookies
Protect Yourself:
- Use strong, unique passwords for client portal
- Enable multi-factor authentication (MFA)
- Log out when finished (especially on shared devices)
- Clear cookies on public/shared computers
- Keep browser and OS updated
- Use antivirus and security software
- Be cautious of phishing emails
11.2 Portal Security
Infrastructure Security:
- SOC 2 Type II compliant hosting (Supabase)
- DDoS protection and Web Application Firewall (WAF)
- Regular vulnerability scanning and penetration testing
- 24/7 security monitoring and alerting
- Intrusion detection and prevention (IDS/IPS)
Application Security:
- Secure coding practices (OWASP Top 10)
- Input validation and output encoding
- SQL injection prevention (parameterized queries)
- XSS protection (Content Security Policy)
- CSRF protection (anti-CSRF tokens)
- Regular security updates and patches
11.3 Protecting Yourself
Best Practices:
- Use strong, unique passwords for client portal
- Enable multi-factor authentication (MFA)
- Log out when finished (especially on shared devices)
- Clear cookies on public/shared computers
- Keep browser and OS updated
- Use antivirus and security software
- Be cautious of phishing emails
- Report suspicious activity immediately
12. CHILDREN'S PRIVACY
ERMITS Advisory Services are business-to-business professional services not directed at children under 18. We do not knowingly collect information from children under 18 via our website or portal.
If we learn we have inadvertently collected information from a child under 18, we will delete it immediately. Parents or guardians may contact privacy@ermits.com if they believe a child has provided information to us.
13. UPDATES TO THIS POLICY
13.1 Policy Changes
We may update this policy to reflect:
- New website features or technologies
- Changes in cookie usage
- Legal or regulatory developments
- Industry best practices
- User feedback
13.2 Notification of Changes
Material Changes:
- 30 days' advance notice via website banner
- Email notification to active clients
- Updated cookie consent banner on first visit
- Opportunity to review and adjust preferences
Non-Material Changes:
- Update "Last Updated" date
- Effective immediately upon posting
- Notice in footer of website
13.3 Version History
Previous versions available upon request: privacy@ermits.com
Current Version: 1.1 (April 2026)
14. CONTACT INFORMATION
Cookie and Website Privacy Questions:
Email: privacy@ermits.com
Subject: "Website Cookie Policy Inquiry"
Cookie Preferences:
Use your browser’s cookie controls. Where a Cookie Settings link is available in the footer of an ERMITS site, you may use it to adjust preferences.
Data Protection Officer (EU/UK/Swiss):
Email: privacy@ermits.com
Subject: "Cookie GDPR Inquiry - Advisory Services"
Mailing Address:
ERMITS LLC - Advisory Services
[Physical Address to be inserted]
Attn: Privacy Team
15. EFFECTIVE DATE AND ACCEPTANCE
Effective Date: April 21, 2026
Last Updated: April 21, 2026
By using the ERMITS Advisory Services website or client portal, you acknowledge that you have read and understood this Cookie & Portal Policy.
You can manage your cookie preferences at any time via the Cookie Settings link in the website footer or by contacting privacy@ermits.com.