Skip to main content
Parousia Group

Legal

Cookie policy

Cookie policy

This site sets one cookie. It holds a language code, it is strictly necessary, and there is nothing else — no analytics, no advertising, no third party.

What this policy covers

This policy is published by Parousia Group, entered in the trade and personal property credit register of Kinshasa/Gombe under number RCCM CD/KNG/RCCM/21-B-02650, whose registered office is at 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. That company operates this site, sets the cookie described below and is the controller for the processing associated with it.

It covers www.parousiagroup.com and the regional sites operated on the same codebase: westafrica, eastafrica, europe, americas, middleeast and apac.parousiagroup.com. It describes everything this site stores on, or reads from, your device — cookies and any equivalent technique, Article 5(3) of the ePrivacy Directive applying to the storage and the access rather than to the name given to them.

It does not cover the sites of the group’s six solutions — NetVox Intelligence, Global Technology Africa, Afrika Plaza, PAGEXPRESS, PAGPay and INTIC — which publish their own. What personal data the group processes, on what legal basis, who receives it and for how long it is kept are set out in the privacy policy; this document deals with what is written to your device.

The cookie this site sets

The table below is the inventory of the cookies set by this site. It states, for each one, its name, the party that sets it, the purpose it serves, its category under Article 5(3) of the ePrivacy Directive and its duration. It is exhaustive: a cookie that does not appear in it is not set by this site.

Cookies set by this site — the list is complete
NameSet byPurposeCategoryDuration
NEXT_LOCALEParousia Group — first-party cookie, set by this site on parousiagroup.com and its regional subdomains. No third party is involvedHolds the two-letter code of the language being served, so that a later visit is served in that language instead of being negotiated again from your browser settingsStrictly necessary — exempt from consent under Article 5(3) of the ePrivacy Directive; Art. 6(1)(f) of the GDPR for the associated processing12 months (Max-Age 31 536 000 seconds), Path=/, SameSite=Lax. Rewritten each time it is used

Its value is one of eleven language codes — en, fr, pt, es, ar, he, zh, hi, am, sw, ln. It is not an identifier: it does not distinguish you from anyone else reading the site in the same language, it is never combined with any other data, and no script on the site reads it. It is written by the server, on a request to an address that carries no language prefix. Browsing addresses that already carry a prefix, such as /fr/about or /ar/contact, writes nothing.

The cookie is sent back to this site alone. It carries the SameSite=Lax attribute, so it is not sent with a cross-site request, and it is served over an encrypted connection pinned by a two-year HTTP Strict Transport Security policy. The processing associated with it is entered in the record of processing operations published in the privacy policy, with its legal basis and its retention period.

Why there is no consent banner

Article 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC, makes consent the rule for storing information on, or gaining access to information already stored in, a user’s terminal equipment. The same provision states two exceptions, and the second is the one that applies here: storage that is strictly necessary in order to provide an information society service explicitly requested by the user.

The service requested is a page served in a language the visitor can read. The Article 29 Working Party classified cookies of this kind as user interface customisation cookies and treated them as exempt (Opinion 04/2012, WP 194, section 3.6); the CNIL exempts, on the same reasoning, trackers used for interface personalisation such as the choice of language, where that personalisation is an intrinsic and expected part of the service (délibération n° 2020-091). The EDPB’s Guidelines 2/2023 confirm that the test bears on the storage and the access themselves, which is why this policy describes both. The same exemption is relied on in the United Kingdom under Regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

The exemption relieves the group of asking for consent; it does not relieve it of informing you. That duty is met by this document and by the privacy policy, which carries the legal basis and the retention period for the associated processing under Article 13 of the GDPR. The twelve-month duration is stated in the inventory above, and it is not extended without a change to this document.

If a tracker requiring consent is ever setA tracker that does not fall within an exception under Article 5(3) of the ePrivacy Directive will not be set until consent has been obtained. That consent will be free, specific, informed and unambiguous within the meaning of Article 4(11) of the GDPR and of the EDPB’s Guidelines 05/2020: an explicit choice, made before any storage, in which refusing is as easy as accepting and which can be withdrawn at any time by the same means. This document will describe the tracker, its purpose, its issuer and its duration before it is set. The Data Protection Office is responsible for that assessment, at contact@parousiagroup.com.

What this site does not use

No cookie or equivalent storage other than NEXT_LOCALE is set by this site. It sets no audience measurement or analytics cookie, no advertising or retargeting cookie, no tag manager, no social network plug-in or pixel, no session replay or heat map, and it applies no fingerprinting technique. It writes nothing to localStorage, to sessionStorage, to IndexedDB or to a service worker cache.

No request is made from a page of this site to a third-party domain. Fonts and images are served from this origin, and the office map is drawn from data held in the site itself.

The site is served with a content security policy that allows scripts, styles, images, fonts and network connections from its own origin only, and framing is denied outright. A third-party tracker added in error would be blocked by the browser before it ran.

Refusing or deleting the cookie

Every browser lets you view, delete and block cookies, site by site, from its privacy or content settings. You may delete NEXT_LOCALE at any time, or refuse cookies from this site altogether, without applying to the group and without informing it. No consent is recorded, so there is none to withdraw.

The site remains usable without the cookie. In its absence, the language of a page requested without a prefix is negotiated from the Accept-Language header your browser already sends, and the negotiation runs again on the next visit. The negotiation can be avoided entirely by using an address that carries the language, such as /fr/contact; no cookie is written on those addresses.

Effect of deleting the cookieOn a shared device whose browser is configured for a language other than yours, deleting the cookie means the site serves that browser language again on your next visit to an address without a prefix. That is the only consequence, and it is the purpose the cookie serves. No feature of the site depends on it, and no page is refused to a browser that blocks it.

If this ever changes

This document carries a version number, a review date and an effective date, and all three are displayed. Adding a cookie, changing the purpose of the one described here or lengthening its duration raises the version number and is published before it takes effect. Where the addition is not exempt under Article 5(3) of the ePrivacy Directive, it will not be set until consent has been obtained, and refusing will be as easy as accepting.

The Data Protection Office reviews this document at least once a year and whenever the storage carried out by the site changes. Earlier versions are kept by the Group Secretariat, and a copy of the version in force on a given date is sent on request to contact@parousiagroup.com.

Questions and complaints

Questions about this document are addressed to the Data Protection Office at contact@parousiagroup.com, or by post to Parousia Group, Data Protection Office, 157, avenue du Livre, Quartier Révolution, Commune de la Gombe, Kinshasa, Democratic Republic of the Congo. Where you consider that this site stores something it has not declared here, state what you observed and how; the Data Protection Office examines the report and corrects this document where the observation is confirmed.

You may also complain to a supervisory authority without applying to the group first. The authority competent for each jurisdiction is listed in the privacy policy; in the European Union, Article 5(3) of the ePrivacy Directive is enforced by the authority designated by the Member State concerned, and in the United Kingdom by the Information Commissioner’s Office under Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003.

Regulatory basis

  • Directive 2002/58/EC (ePrivacy) as amended by Directive 2009/136/EC — Article 5(3)
  • Regulation (EU) 2016/679 (GDPR) — Articles 4(11), 6, 7 and 13
  • EDPB Guidelines 05/2020 on consent under Regulation 2016/679
  • EDPB Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive
  • Article 29 Working Party — Opinion 04/2012 on Cookie Consent Exemption (WP 194)
  • CNIL — délibération n° 2020-091 du 17 septembre 2020 portant lignes directrices relatives aux cookies et autres traceurs
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (United Kingdom) — Regulation 6
  • République démocratique du Congo — ordonnance-loi n° 23/010 du 13 mars 2023 portant code du numérique