This policy describes the use of cookies and other tools that store or access information on your device through the website and application areas of the Domusify platform. It supplements the Privacy policy, which describes the other personal data processing activities.
1. Controller and scope
The data controller for the tools described in this policy is SFV S.R.L., with registered office at Via Terra di Santa Lucia 56, 95030 Mascalucia (CT), Italy, tax code and VAT number 05881360878.
For information and to exercise your rights concerning personal data, you can use the contact details published on the SFV S.R.L. website or write to the certified email address (PEC) [email protected].
The platform uses two distinct technical contexts:
- the marketing website, available at https://domusify.com, which hosts the landing page and the legal documents;
- the application domain, which hosts registration, sign-in, credential recovery, onboarding, account management and the agencies' administration panels.
The individual agencies' public websites have their own Cookie policy. This policy therefore does not describe the tools used exclusively by agency websites, such as maps, geocoding, enquiry forms and other features specific to those public websites.
2. What cookies and similar tools are
Cookies are small files that a website can store in the browser and receive on subsequent visits. They may be used to keep a session, protect requests, remember a choice or collect information about how the website is used.
Cookies can be:
- first-party, when they are set in the context of the website being visited;
- third-party, when they belong to a different domain;
- session cookies, when their persistence is tied to the browser session;
- persistent, when they have an expiry date or remain until deleted.
Being a first-party cookie does not necessarily mean that the data is processed only by SFV: Google Analytics cookies, for example, are normally set on the website's domain but are used as part of a service provided by Google.
This policy also covers similar tools such as localStorage, sessionStorage, identifiers and other techniques for storing or accessing information on your device. The rules that apply depend on the actual purpose of the tool, not merely on the name of the technology used.
3. Categories and legal bases
| Category | Purpose | Your choice |
|---|---|---|
| Necessary | Operation of the website and the platform, session management, authentication, security, protection of requests, storage of privacy preferences and features expressly requested | No consent is required when they are strictly necessary; blocking them in the browser may prevent some features |
| Statistics | Analysis of marketing website traffic using Google Analytics 4 | Disabled until consent; you may accept or reject them and withdraw consent |
Storing or accessing information that is strictly necessary to transmit a communication, or to provide a service expressly requested by the user, falls within the exemption under Article 122 of Italian Legislative Decree 196/2003.
Optional statistics tools are used only after consent, in accordance with Article 122 of Italian Legislative Decree 196/2003 and Articles 4(11) and 7 GDPR.
The platform does not use advertising, remarketing or commercial profiling cookies and does not use Google Signals.
4. Domains and session separation
The marketing website and the application domain belong to distinct technical contexts.
The marketing domain serves the landing page and the legal pages. Any preferences relating to statistics tools apply to this domain and to the browser you are using.
The application domain handles accounts, authentication and panels. The authenticated session is configured to be shared only within the application namespace, so that signing in on the account pages remains valid in the panels of the agencies you are authorised to access.
The authenticated session of the application domain is not shared with the marketing domain.
Agency websites on custom domains do not receive the platform's authenticated session. The respective Cookie policies apply to the public websites of the agencies.
5. How to set your preferences on the marketing website
The configuration provided for the marketing website keeps Google Analytics 4 disabled on the first visit and until you make a positive choice.
The preference system lets you:
- accept the optional statistics tools;
- reject the statistics tools and continue using only the necessary ones;
- open the settings to check or change your choice.
Closing the banner with the relevant control keeps the optional tools disabled. Scrolling the page, continuing to browse or using the website's links does not amount to giving consent.
The optional options are not pre-selected.
You can change or withdraw your choice at any time through "Cookie preferences", available on the marketing website. Withdrawal stops subsequent transmissions relating to the disabled category, without affecting the lawfulness of processing carried out beforehand.
A rejection or partial consent choice is kept for six months. Consent to all optional tools may be kept for up to twelve months, without prejudice to your ability to change or withdraw your choice at any time. A new choice may be requested before it expires when the conditions of processing change significantly or the required consent version changes. The banner is not shown again insistently after a rejection. A new request may also be needed when:
- the configuration of the tools changes substantially;
- new purposes requiring a choice are introduced;
- the previous preference can no longer be recognised;
- the relevant period has elapsed.
The six- and twelve-month periods concern the storage of your choice on the device and do not constitute a universal legal duration for any consent or any cookie.
Preferences apply to the marketing domain and to the browser you are using. Different browsers, devices or profiles may require separate choices.
Consent is collected and managed in accordance with the Italian Data Protection Authority's guidelines on cookies and other tracking tools.
6. Technical cookies of the platform
The platform uses Laravel and Filament. Some cookie names are generated automatically by the framework or depend on the production environment configuration.
In the table, the asterisk indicates a variable part of the name, not a character necessarily present in the cookie.
The durations shown as standard come from the application configuration and the software components used; they are not the result of a browser scan on a specific device.
| Name or functional identifier | Purpose | Scope and standard duration |
|---|---|---|
Laravel session cookie, with the name configured through SESSION_COOKIE or derived from APP_NAME |
Keeps the application session, the temporary state of requests and, on the application domain, the user's authentication | First-party; 120 minutes of inactivity in the current standard configuration, renewed based on activity |
XSRF-TOKEN, when issued |
Protects requests and forms against cross-site forgery and lets application components send the security token | First-party; duration tied to the session, normally 120 minutes in the current standard configuration |
remember_*, only if you select "Remember me" when signing in |
Allows the authorised user to be recognised again even after the ordinary session expires | First-party, application domain; Laravel standard duration 400 days, unless invalidated, logged out or deleted earlier |
| Storage of the marketing website's privacy preferences, through a cookie or other technical browser storage | Remembers acceptance, rejection and the status of the Statistics category | First-party, marketing domain; six months, up to twelve months for consent to all optional tools |
The actual name of the session cookie may therefore vary according to the value configured in the environment. This variability does not change its purpose.
The Laravel session cookie may have a time-based expiry and therefore does not necessarily disappear simply because the browser is closed.
By its very function, the XSRF-TOKEN cookie is accessible to code running in the browser so that its value can be sent back in protected requests; the session cookie, on the other hand, is configured as HttpOnly in the application's standard configuration.
On the application domain, the session is configured to be available on the apex and on the platform's technical subdomains, which are needed to let an authenticated user access the panels of the agencies they are authorised for. On the marketing domain, however, the session remains limited to that domain.
Signing out, changing credentials, invalidating the session or other security events may make the authentication cookies ineffective before their formal expiry on the device.
Technical references: Laravel session configuration, CSRF request protection and handling of the "Remember me" cookie.
7. Cloudflare protection
Cloudflare delivers content and protects the website and the platform from harmful traffic.
Using the Cloudflare network does not automatically mean that every cookie documented by the provider is set. The cookies depend on the security features actually enabled and on the events encountered while browsing.
The cookies Cloudflare may use in the relevant security services include:
| Cookie | Function and conditions of use | Documented duration |
|---|---|---|
__cf_bm |
Assessment of automated traffic when the relevant Bot Management or Bot Fight Mode products are active | 30 minutes of continuous inactivity |
cf_clearance |
Records that a Cloudflare verification has been passed and avoids immediately repeating the same challenge | 30 minutes in the default Challenge Passage configuration; duration configurable |
cf_ob_info and cf_use_ob |
Support for the Always Online feature, when used | 30 seconds |
__cflb |
Origin server affinity when the relevant load balancing service is enabled | From a few seconds up to 24 hours, depending on the configuration |
When these tools are actually used to protect the service, manage traffic or ensure technical continuity, they are treated as necessary.
The platform currently does not use Google Cloud reCAPTCHA on the marketing, registration or authentication pages described in this policy. Any use of reCAPTCHA on the agencies' public websites is governed by their respective Cookie policies.
Further details are available in the Cloudflare cookie catalogue and the Challenge Passage documentation.
8. Google Analytics 4 on the marketing website
When enabled on the marketing website, Google Analytics 4 is used only after consent to the Statistics category.
Before consent is given, the website must not send GA4 any measurement events or signals, not even through cookie-free modes. Blocking cookies alone would not in fact be enough to prevent any possible transmission by the service.
| Cookie | Provider and setting domain | Purpose | Documented standard expiry |
|---|---|---|---|
_ga |
Google; normally set on the marketing domain | Distinguishes browsers by means of an identifier | Two years |
_ga_<identifier> |
Google; normally set on the marketing domain | Keeps information about the state of the Analytics session | Two years |
Browsers may impose shorter durations. The tag's standard settings may update the expiry on subsequent visits, and the Analytics configuration allows the default durations to be changed.
The configuration provided does not use advertising features, remarketing or Google Signals.
Names, email addresses, passwords, credentials and data entered in restricted areas are not transmitted to Analytics.
GA4 is not used on the sign-in, registration or credential recovery pages or in the administration panels described in this policy.
The duration of Analytics cookies on the device does not coincide with the retention period for user- and event-level data on Google's servers. The configuration adopted provides for two months for data subject to the relevant GA4 setting; aggregated reports are subject to different rules, as stated in the Privacy policy.
References: GA4 cookies and their durations, data collected by Analytics and data retention.
9. Service emails and server-side services
Elastic Email. Communications needed for the account, such as email address verification, credential recovery and other operational emails, are sent through a server-side service and do not require the cookies used on the provider's commercial website to be installed in the browser.
Any tools for measuring opens and clicks operate within the emails and are not part of the cookie consent given on the marketing website. For the platform's service emails, those tools are not used in the absence of a suitable legal basis and, where processing requires consent, of specific separate consent.
DigitalOcean. The hosting and database infrastructure is used server-side and, merely because the service is used, does not involve installing in the browser the cookies found on DigitalOcean's commercial website.
Google Search Console. Verifying ownership of the website and consulting its reports does not, in itself, introduce additional cookies or tracking tools into visitors' browsers.
The personal data processing connected with these services is described in the Privacy policy.
10. Withdrawal, deletion and browser settings
You can change or withdraw your consent to statistics tools through "Cookie preferences" as easily as you gave it.
After withdrawal, the website stops subsequent loads and transmissions of the disabled category and removes, where technically possible, the optional cookies it manages directly.
SFV cannot directly delete from your device all cookies belonging to third-party domains. To remove them, you can use your browser settings.
Withdrawing consent does not automatically amount to deleting data already collected on servers. For any requests concerning personal data, the rights described in the Privacy policy apply.
Your browser lets you view, delete or block cookies and other website data. Official instructions are available for Chrome, Firefox, Safari and Microsoft Edge.
Deleting browser data may also erase your rejection preference and make it necessary to express it again.
Blocking necessary cookies may prevent authentication, session state recovery, request protection or correct operation of the panel.
11. Personal data, recipients and transfers
Cookies and similar tools may involve identifiers, IP addresses, device information, preferences and interactions. The absence of the user's name does not automatically make this data anonymous.
The data may be processed by SFV, by authorised persons and by the providers named in the Privacy policy according to their respective roles.
Some providers may involve processing or access from countries outside the European Economic Area. The applicable safeguards, the roles of the providers and the retention criteria on servers are described in the Privacy policy.
You can exercise the rights provided for by the GDPR, where applicable, using the contact details given in the Privacy policy. You may also lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority.
12. Updates and correspondence with the actual configuration
This policy concerns the tools and configurations described for the marketing website, the application domain and the platform's panels.
Introducing new statistics or advertising tools, external content or other tracking technologies requires this policy to be updated and, where necessary, consent to be obtained before they are enabled.
The names, durations or technical behaviour of some cookies may change as a result of updates to the framework, the browser or the providers. The website configuration must be kept consistent with what is stated in this policy.
Updating the text does not constitute consent to new optional tools.
Last updated: 20 September 2026