Legal document
LEVEL-EST Website Cookie Policy
1. Purpose and Scope
1.1. This LEVEL-EST Website Cookie Policy (the 'Cookie Policy') explains how cookies and similar technologies are used on the public website level-est.com.
1.2. This Cookie Policy applies only to level-est.com and its public pages. It does not govern the LEVEL-EST SaaS platform, the level-est.app web application, user accounts, service connections or other LEVEL-EST systems, which may be subject to separate policies and terms.
1.3. This Cookie Policy should be read together with the LEVEL-EST Website Privacy Policy and the LEVEL-EST Website Terms of Use.
2. Website Operator
2.1. The level-est.com website is administered by LEVEL-EST, whose operator is Sole Proprietor Maryna Volodymyrivna Vasiliva.
2.2. For the purposes of this Cookie Policy, the terms 'LEVEL-EST', 'we', 'us' and 'our' mean the operator of the level-est.com website, which organizes the use of cookies and similar technologies on the website.
2.3. If information processed through cookies or similar technologies is personal data, that processing is carried out in accordance with the LEVEL-EST Website Privacy Policy.
2.4. Questions concerning this Cookie Policy or the use of cookies and similar technologies may be sent to privacy@level-est.com or info@level-est.com.
2.5. Legal information about the LEVEL-EST operator may be provided to the user upon request or as part of a separate contractual service-onboarding process.
3. What Cookies and Similar Technologies Are
3.1. A cookie is a small text file that a website stores in the visitor's browser. Cookies may contain a randomly generated identifier, a preference or other technical information and may be read during later requests to the website.
3.2. Similar technologies include browser storage mechanisms such as localStorage. They do not necessarily use cookie files, but they can store information on or access information from the visitor's device and are therefore covered by this Cookie Policy.
3.3. A first-party technology is set or read by level-est.com. A third-party technology is set or read by an external provider through content, scripts or services integrated into the website.
3.4. Website technologies are divided into the following categories:
- necessary technologies - required to protect the website, provide a function expressly requested by the visitor or remember the visitor's privacy choices;
- optional technologies - analytics, advertising, marketing, profiling or other non-essential third-party integrations that are not necessary for the website's basic operation.
4. Technologies Currently Used
4.1. On the effective date of this Cookie Policy, level-est.com uses only the technologies described below.
| Technology | Classification | Purpose, data and access | Retention period |
|---|---|---|---|
| csrftoken | First-party cookie set by level-est.com. Necessary security technology. | Stores a randomly generated security value used to protect website forms against cross-site request forgery (CSRF). It does not contain data entered in the form. It is created automatically when a visitor opens a page that initializes a protected form or cookie settings. | Up to 364 days from creation or renewal, unless deleted earlier. |
| level-est-theme | First-party localStorage entry. User-requested functional preference. | Stores only the theme selected by the visitor, such as light or dark. It is written only after the theme is changed, remains in that browser and is not sent to LEVEL-EST with network requests. | No automatic expiry; remains until the theme is changed or the visitor clears the website's browser data. |
| level-est-consent | Signed first-party cookie set by level-est.com. Necessary consent-management technology. | Stores a pseudonymous choice identifier, accepted or rejected categories, decision type, relevant policy, technology-inventory and consent-interface versions, and decision and expiry timestamps. It is HttpOnly and does not contain a name, email address, contact-form content or account data. | Up to 12 months, or until earlier replacement after a material change or deletion by the visitor. |
4.2. LEVEL-EST currently does not use analytics cookies, advertising cookies, marketing cookies, social-media trackers, profiling technologies or third-party tracking pixels on level-est.com.
4.3. Website images, fonts, scripts and video materials are currently provided as first-party website resources. The website does not load third-party video players or other embedded third-party media that place optional cookies.
4.4. Ordinary requests to the website may generate technical server or infrastructure logs, such as an IP address, request time and browser information. Such logs are not cookies or browser storage. Their processing is described in the LEVEL-EST Website Privacy Policy.
5. Necessary and User-Requested Technologies
5.1. Necessary technologies may be used without requesting consent where they are required to transmit a communication, protect the website or provide a function expressly requested by the visitor.
5.2. The csrftoken cookie is used to protect website forms and the website against forged requests. Blocking this cookie may prevent a protected form from being submitted correctly.
5.3. The level-est-theme entry is created only after the visitor deliberately selects another website theme. It is used solely to remember that setting.
5.4. The level-est-consent cookie is created only after the visitor records a choice in the cookie notice or settings. It is used to remember and honor that privacy choice.
5.5. LEVEL-EST does not use these technologies for advertising, behavioral profiling, cross-site tracking or measuring individual marketing activity.
6. Optional Technologies and Consent
6.1. On the effective date of this Cookie Policy, no optional technologies are active on level-est.com. The website nevertheless provides a cookie notice and settings interface so visitors can review the current inventory and record their privacy choices.
6.2. A preference recorded while an optional category is inactive is not treated as advance consent for a technology or provider that has not been introduced. LEVEL-EST will update the inventory and ask for a new, specific choice before activating a new or materially changed optional technology.
6.3. Before any optional technology is introduced:
- the technology will remain disabled by default;
- it will not be loaded and will not connect to its provider before the visitor makes an affirmative choice;
- the visitor will receive clear information about the provider, purpose, information used and retention period;
- accepting and rejecting optional technologies will be available through equally prominent and accessible options;
- optional categories will not be preselected;
- closing a notice, remaining inactive, scrolling the page or continuing to browse will not be treated as consent;
- rejecting optional technologies will not prevent access to the website's ordinary public content.
6.4. If several optional purposes are introduced, visitors will be able to select each relevant category separately in cookie settings.
6.5. Visitors can review, change or withdraw their recorded choice through the persistently available 'Cookie settings' link on the website. Where optional technologies are active, withdrawing consent will be as easy as giving it.
6.6. Withdrawal of consent will apply to future use of the relevant optional technologies. It will not affect the lawfulness of processing carried out before consent was withdrawn. LEVEL-EST will stop future optional loading and delete first-party optional data that the website can delete directly. A visitor may also need to clear browser data where deletion is controlled by the browser or an external provider.
6.7. LEVEL-EST may ask the visitor to make a new choice after consent expires or where purposes, providers or technologies change materially. A materially changed optional technology will not be activated on the basis of an earlier choice that did not cover that change.
7. Consent-Preference Record
7.1. The public website uses the following first-party record to remember and verify the visitor's cookie-setting choice.
| Field | Details |
|---|---|
| Name and status | level-est-consent - active after the visitor records a choice in the cookie notice or settings. |
| Type and provider | Signed first-party cookie created and verified by level-est.com. |
| Purpose and data | Remembers and confirms a visitor's choice. It may contain a pseudonymous random choice identifier, accepted or rejected categories, decision type, relevant policy, technology-inventory and consent-interface versions, and decision and expiry timestamps. It will not contain a name, email address, contact-form content or account data. |
| Classification | Necessary consent-management record used only to remember and honor privacy choices and confirm the recorded decision. |
| When created | Only after the visitor records an accept, reject or customized choice in the cookie interface. |
| Duration | Up to 12 months, or until earlier withdrawal, replacement after a material change or deletion by the visitor. |
7.2. The consent-preference record is stored in the visitor's browser and is not used as a permanent consent history linked to an account. If the visitor deletes browser data or uses another browser or device, the website may no longer recognize the previous choice and may ask the visitor to make it again.
7.3. A digital signature on the record helps the website detect unauthorized changes. The signature is an integrity control and does not mean encryption.
8. Managing and Deleting Browser Data
8.1. Visitors can use their browser settings to inspect, block or delete cookies and localStorage data.
8.2. Instructions differ depending on the browser and its version. Visitors should consult the privacy or website-data settings of the browser they use.
8.3. Deleting level-est-theme will reset the saved website theme. Deleting level-est-consent will reset the recorded cookie choice and cause the website to ask again. Blocking or deleting csrftoken may prevent protected website forms from working correctly.
8.4. Clearing browser data will not delete information that has already been lawfully received through a submitted contact form or information retained in technical server logs. Such data is governed by the LEVEL-EST Website Privacy Policy.
9. Third Parties and International Data Transfers
9.1. LEVEL-EST currently does not allow analytics, advertising, marketing or social-media providers to place or read optional technologies through level-est.com.
9.2. Playing self-hosted media does not cause the visitor's browser to connect to a third-party media platform solely for the purpose of playing that media.
9.3. Hosting, security and communications providers may process ordinary network requests or technical logs on LEVEL-EST's behalf. Such processing does not mean that those providers are allowed to place optional tracking technologies. Further information about recipients and data transfers is provided in the LEVEL-EST Website Privacy Policy.
9.4. If a third-party optional service is introduced, LEVEL-EST will update this Cookie Policy before activating it and, as applicable, will identify:
- the provider and relevant domains;
- the purpose and category;
- the cookies or similar technologies used;
- the information accessed or stored;
- the retention period;
- the relevant recipients;
- any international data transfers;
- a link to the provider's relevant privacy information.
9.5. If cookie-related personal data is transferred outside Ukraine or the European Economic Area, as applicable, LEVEL-EST will use a lawful transfer mechanism and appropriate safeguards required by applicable data-protection law.
10. Personal Data and Security
10.1. A cookie identifier or other technical information may be personal data where it identifies or can reasonably be linked to a person or device.
10.2. LEVEL-EST limits the information stored through website technologies to what is reasonably required for their stated purposes and applies appropriate technical and organizational security measures.
10.3. No method of storing or transmitting information is completely secure. LEVEL-EST therefore cannot guarantee absolute security but takes reasonable measures proportionate to the nature and risk of the information processed.
10.4. Information about the purposes and legal bases for processing personal data, retention periods, recipients, international transfers and visitors' data-protection rights is provided in the LEVEL-EST Website Privacy Policy.
10.5. Requests concerning personal-data rights may be sent to privacy@level-est.com or info@level-est.com.
11. Changes to this Cookie Policy
11.1. LEVEL-EST may update this Cookie Policy where the website, technologies, legal requirements or LEVEL-EST practices change.
11.2. The updated version, version number and effective date will be published on level-est.com.
11.3. If a change materially affects a visitor's previous consent, LEVEL-EST will ask the visitor to make a new choice before the changed optional technology is activated.
11.4. Visitors are encouraged to review this Cookie Policy periodically.
12. Contact Details
12.1. Questions, requests or complaints concerning cookies and similar technologies on level-est.com may be sent to LEVEL-EST at privacy@level-est.com or info@level-est.com.