Cookie Policy
Last updated: 21 September 2026
This Cookie Policy explains cookies and similar technologies used on Rooklyn-operated sites and how to accept, reject, configure or withdraw preferences. Last updated: 21 September 2026.
1. Controller and scope
Geetanjali Dubey, trading as Rooklyn, NIF/NIE/CIF Z0680759X; geet29.dubey@gmail.com; https://rooklyn.co. This policy applies where relevant to rooklyn.co, clima.rooklyn.co and aureaclima.rooklyn.co. Third-party sites linked from them have their own policies.
2. Legal framework
Cookies and device storage are governed, among other rules, by Article 22.2 of Spain's Law 34/2002 (LSSI). The GDPR and Spanish data-protection law also apply where personal data is processed. Strictly necessary technologies may be exempt from consent; non-essential technologies are activated only on a valid legal basis and, where required, after valid consent.
3. What cookies are
Cookies are small text files stored in a browser or device. Similar technologies include local storage, pixels, technical identifiers and embedded scripts. They can support site operation, preferences, security, sessions, usage measurement or, where consent applies, personalised content and marketing.
4. Types by purpose
Strictly necessary technologies support navigation, security, load balancing, fraud and bot prevention, sessions, consent choices and expressly requested functions. Functional technologies may remember language or interface choices, subject to consent where required.
Analytics technologies measure use, errors, visited pages and performance and are not enabled before consent when consent is required. Marketing technologies may measure campaigns, limit repeated ads, create audiences or personalise advertising, subject to required prior consent. Embedded forms, calendars, CRM, chat, video, maps and captchas may have their own technologies and consent requirements.
5. First- and third-party cookies
First-party technologies are managed on Rooklyn-controlled domains or components; third-party technologies are managed by integrated providers. Actual use varies by domain, page, component, technical setup and the user's consent choice.
6. Technology inventory
Necessary — Rooklyn consent manager: technical operation and storage of choices; session or configured retention; only as required. Necessary/security — Cloudflare, when active: secure delivery, bot protection and load balancing; possible __cf_bm, cf_clearance or _cflb; generally session or short duration.
Functional/CRM/booking — HighLevel / LeadConnector, only where forms, calendars, chat or integrations load: processing requested interactions and component sessions; identifiers and duration depend on the component, with some published durations of up to one year; non-essential technologies remain subject to consent.
Preferences — Rooklyn or component provider, if implemented: language or other chosen settings; until expiry, deletion or changed preference. Analytics/performance — any future analytics provider: usage and performance; no specific cookie-based analytics tool is declared active by default, and it remains disabled until configured and consented to where required. Marketing/advertising — any future ad platform: campaign measurement or personalised ads; none is declared active by default and it remains disabled until configured and consented to where required.
The precise deployed inventory of names, providers, purposes and expiry periods must match each domain. The consent panel should remain current, and this section should be reviewed before activating new third-party technologies.
7. Consent and settings
The initial banner offers clear, equally visible options to accept, reject or configure non-essential technologies. No boxes are preselected; merely continuing to browse is not consent. Technologies requiring consent remain blocked until a valid choice is made.
8. Withdrawing or changing consent
Preferences can be changed or withdrawn at any time using the permanent cookie settings link or consent manager. Withdrawal does not affect earlier lawful processing. Rejected categories will stop loading on later visits, apart from strictly necessary technologies or those retained by legal obligation.
9. Browser controls
Browsers can also allow, block, limit or delete cookies. Blocking technical cookies may prevent requested features from working. Chrome, Edge, Firefox and Safari provide controls in their privacy settings; steps vary by version and device.
10. Third-party services
Rooklyn may integrate hosting, security, CRM, forms, calendars, booking, messaging, chat, video, maps, analytics or marketing services. Cloudflare may supply technical security cookies; HighLevel / LeadConnector may supply CRM and embedded-component technologies. Inclusion here does not mean all such cookies operate on every page.
11. International transfers
Some providers may process data outside the EEA. Where personal data is transferred internationally, an applicable safeguard such as an adequacy decision, the EU–US Data Privacy Framework (where the provider and transfer qualify), or standard contractual clauses is used. HighLevel states that it and LeadConnector participate in the EU–US framework; the applicable mechanism for a particular processing operation is described in provider documents and Rooklyn's Privacy Policy.
12. Retention
Session cookies are generally removed when the browser closes. Persistent cookies last for their configured period or until deleted. Rooklyn uses periods proportionate to the purpose and periodically reviews active technologies.
13. Updates
This policy may change with technologies, providers, domains or legal obligations. The last-update date appears above; please review this page periodically.
14. Contact
For cookie or privacy-setting questions, email geet29.dubey@gmail.com.