Purpose and scope
This Notice covers cookies, local storage, session identifiers, server logs, measurement, and security technologies used on the Website, portals, forms, dashboards, and external content. The final version will list only tools actually in use.
What is a cookie?
A small text file stored through a browser on a computer or telephone to remember a session, device, or choice. It does not necessarily contain a name but may link with other information when a user signs in or submits a form.
Similar technologies
- Local and session storage.
- Pixels and web beacons.
- Device and session identifiers.
- Security tokens and server logs.
- Measurement links and consent tools.
- Bot protection and login identifiers.
First and third parties
First-party technologies are placed by the Center domain for pages, language, sessions, and security. External providers may place technologies for analytics, video, maps, meetings, forms, protection, or subscriptions. Nonessential services should not activate before the required choice.
Strictly necessary cookies
These support operation and a requested service, including secure connections, navigation, form submission, anti-forgery, bot prevention, login, and preference storage. The service may not work without them.
- Session identifier.
- Language.
- Login state.
- Security token.
- Privacy choice.
- Session expiry.
Functional cookies
These remember nonessential choices such as language across visits, display, search filters, dashboards, date format, or accessibility settings. Rejection may remove preferences without blocking core content.
Analytics and performance
These may measure visits, pages, duration, paths, devices, referral, form completion, errors, speed, and downloads. Aggregation and minimized identification are preferred, and advertising and unnecessary features should be disabled.
Marketing cookies
These are not necessary for the Center’s core services. Future introduction requires updated notice, provider and purpose details, duration, sharing, choice, and rejection. They should not support undisclosed political targeting.
Social and embedded content
Video, posts, sharing buttons, maps, or forms may allow a platform to set cookies. Content may load only after user action, or use static previews and external links to reduce tracking.
Duration
Session cookies usually end on browser close, session expiry, or logout. Persistent cookies remain until expiry, deletion, preference change, or service closure and should not last longer than purpose requires.
Cookie register
After implementation an accurate register should be published; hypothetical names must not be presented as active.
| Cookie or technology | Provider | Category | Purpose | Duration | Party |
|---|---|---|---|---|---|
| [To be confirmed] | [Center or provider] | Necessary | [Purpose] | [Duration] | First/third |
| [To be confirmed] | [Center or provider] | Functional | [Purpose] | [Duration] | First/third |
| [To be confirmed] | [Center or provider] | Analytical | [Purpose] | [Duration] | First/third |
Preference panel
- Accept optional categories.
- Reject all nonessential categories.
- Select categories.
- Read detail.
- Save and later change choices.
- Provide equally clear Arabic and English accept and reject controls.
Suggested short notice
Consent
Where required, consent is freely given, clear, specific, affirmative, withdrawable, and separate from unrelated terms. Continued browsing alone is not sufficient where an explicit choice is required.
Recording choices
A necessary record may store accepted and rejected categories, date, notice version, and region. A renewed choice may be requested when categories, providers, purposes, or retention change.
Changing preferences
A persistent Manage Cookie Preferences link should appear in the footer and policies. Updated choices stop new optional cookies; existing cookies may also require browser deletion.
Effect of rejection
Rejecting nonessential cookies should not block public pages, policies, research, contact, complaints, or privacy forms. It may affect remembered language, display, embedded media, dashboard preferences, or performance measurement.
Browser controls
Browsers can view, delete, block, or clear cookies and restrict third parties or storage. Complete blocking may affect login, forms, language, security, and dashboards.
Automated privacy signals
Browsers may send Do Not Track or Global Privacy Control. The Website should not claim support until implementation, testing, and legal treatment are confirmed.
Privacy-respecting analytics
- Aggregate information.
- Minimized network addresses.
- Disabled advertising identifiers and provider sharing.
- Shorter retention.
- No advertising-account linkage.
- More controlled hosting.
- Respect for rejection.
Network addresses
Addresses may appear in security, analytics, and bot-protection logs for error diagnosis, attack prevention, general location, and session management. They are not used for undisclosed political or commercial targeting.
Form protection
A protection service may assess interaction timing, device, network, tokens, or challenges. Selection should consider data collection, accessibility, Arabic support, processing location, and alternatives.
Dashboards and accounts
Dashboards may use sessions, local storage, filters, security tokens, and downloads. Accounts require session verification, permissions, and timeouts. Deletion may sign the user out or remove settings.
Email subscriptions
Subscription services may confirm registration, record consent, manage unsubscribe, and measure opens or clicks. Actual measurement and choices should be disclosed.
Personal information and basis
Cookie identifiers may be personal information depending on linkability and law. Necessary technologies may rely on service delivery, security, or contract; nonessential technologies may require consent. Final wording depends on jurisdiction and tools.
Providers and international processing
Provider and server location, subprocessors, contract, encryption, deletion, retention, and rights are assessed and actual details added after selection.
Children and no sale
The general Website should not use marketing cookies to track children. The Center does not sell cookie-derived information to advertisers or data brokers.
No manipulative design
- Do not make acceptance much easier than rejection.
- Do not hide reject or use misleading colors or text.
- Do not block core content unnecessarily.
- Do not repeatedly pressure after rejection.
- Do not describe marketing as necessary.
- Do not condition complaints or privacy on tracking consent.
Implementation and testing
- Inventory every technology.
- Classify and remove unnecessary items.
- Identify purpose, provider, and duration.
- Block optional cookies before choice.
- Test acceptance, rejection, and changes.
- Test mobile, Arabic, and English.
- Publish and review the register.
- Confirm forms work without optional cookies.
- Remove obsolete cookies.
- Document latest testing.
Questions and changes
Undocumented cookies, difficulty rejecting, continued tracking, or panel problems may be reported to [Privacy email]. The Notice changes when tools, providers, services, retention, law, or audit findings change.
| Item | Value |
|---|---|
| Effective date | [To be added after approval] |
| Latest update | [To be added when revised] |
| Version | 1.0 – launch draft |
Session and persistent storage
- Session cookies
- Normally end when the browser closes, the session expires, or the user logs out.
- Persistent cookies
- Remain until a defined date, deletion, preference change, or service termination.
- Local storage
- May retain language, settings, or dashboard state in the browser until cleared by the user or application.
- Security tokens
- May verify a session or prevent forged requests and are not ordinarily used for marketing.
Social and embedded content
A video, map, or social platform may set cookies when embedded content loads and may connect the visit with a user account. A static preview and user-initiated loading are preferred, with an external link or alternative where possible.
Minimum cookie register
| Name | Provider | Category | Purpose | Duration | Party |
|---|---|---|---|---|---|
| [Confirmed after scan] | [Center or provider] | Necessary | [Purpose] | [Duration] | First/third |
| [Confirmed after scan] | [Center or provider] | Functional | [Purpose] | [Duration] | First/third |
| [Confirmed after scan] | [Center or provider] | Analytical | [Purpose] | [Duration] | First/third |
Prior blocking
An analytical or marketing tool should not send a request or place an identifier before user choice where consent is required. Network and storage behavior must be tested rather than relying only on a banner displaying a “reject” button.
Removing prior cookies
Withdrawal stops new optional storage. A consent tool may delete cookies it controls, while others may require browser or provider controls. The interface should not imply that stopping future storage automatically removes every prior record.
Do Not Track and Global Privacy Control
Support for Do Not Track or Global Privacy Control should not be claimed before implementation is tested. Once supported, the Website explains which signals are honored and their effect on categories and prior data.
Network addresses and location estimation
Network addresses may appear in hosting, security, and analytical records and support attack prevention, diagnosis, and general regional estimation. They should not create undisclosed political or commercial profiles or precise location without necessity and notice.
Bot-protection tool
- Select a provider minimizing data and supporting screen readers.
- Provide an alternative where a challenge fails.
- Review Arabic support and processing location.
- Do not enable marketing tracking under the pretext of form protection.
- Identify the provider in the cookie register and notice.
Dashboards and accounts
A dashboard or account may need storage for filters, sessions, permissions, and downloads. Necessity is classified, the system explains what remains locally or is sent to a provider, and deleting session cookies will ordinarily sign the user out.
Email measurement
Where newsletters use pixels or links to measure opens or clicks, this is disclosed with available choices. Nonessential measurement may be disabled or aggregated and is not enabled merely because the mailing provider offers it.
Basis by category
| Category | Expected basis |
|---|---|
| Necessary | Requested service, security, or session operation under applicable law. |
| Nonessential functional | Choice or consent where required. |
| Analytical | Consent or another specifically lawful basis with a clear rejection option. |
| Marketing | Ordinarily express consent before activation. |
Technical test checklist
- Open the Website in a clean browser.
- Reject optional categories before interaction.
- Inspect cookies, storage, and network requests.
- Accept one category and test it alone.
- Change preference and withdraw consent.
- Test forms and accounts without optional cookies.
- Test Arabic, English, mobile, and keyboard use.
- Reconcile the published register with actual behavior.
Register review
The register is reviewed when a tool, provider, dashboard, video, newsletter, or account is added; duration or purpose changes; an undocumented cookie is found; or an incident occurs. The date of the latest technical scan should be recorded.
Current package status
Contact and dates
| Item | Status |
|---|---|
| Privacy email | [Approved privacy email] |
| Effective date | [To be added after approval] |
| Latest update | [To be added when revised] |
| Version | 1.0 on first approval |
| Latest cookie scan | [To be added after live-server testing] |