Cookies Declaration
Last updated: 28/09/2026
Version: 1.2
Introduction
This Cookies Declaration explains how Ibernia LLC ("Ibernia", "we", "us" or "our") uses cookies and similar technologies on the Ibernia website, on our sign-in and account pages, and in the Ibernia web platform (together, the "Platform"). It should be read together with our Privacy Policy, which explains how we handle personal data more generally.
We use cookies and similar technologies that are strictly necessary to operate the Platform, in particular for authentication, security and basic preferences. We do not use cookies for third-party advertising. The one exception to "strictly necessary" on our public website is Apollo, described below, which only runs if you accept it on the cookie banner.
The Ibernia web platform can also use product-analytics storage (provided by PostHog), but only if you have turned analytics on in your account settings. Analytics is switched off by default, and no analytics data is captured until you choose to enable it.
The Ibernia website uses Cloudflare Web Analytics to count visits and see which pages are viewed. It does not set cookies, does not use local storage and does not track you across websites, so it is not listed in the tables below.
We may update this Cookies Declaration from time to time, for example if we introduce a new cookie or change an existing one. When we do, the "Last updated" date at the top of this page will change.
What are cookies and similar technologies?
Cookies are small text files that a website stores on your device so that it can recognise your browser, keep you signed in, or remember a preference. Similar technologies include browser localStorage and sessionStorage, which work in much the same way but store information in your browser rather than sending it back to us with every request. The Ibernia web platform uses both, mainly to hold authentication and preference data.
Where we describe a cookie or key as "essential" below, we mean that the Platform cannot function correctly without it. Blocking essential cookies will normally prevent you from signing in.
Sign-in and account pages (identity.ibernia.it)
The following cookies may be set when you sign in, register, use multi-factor authentication, or manage your account.
| Name | Purpose | Duration | Essential |
|---|---|---|---|
| .AspNetCore.Identity.Application | Keeps you signed in (authentication cookie). | Session, or for the length of the authentication session where "remember me" is used. | Yes |
| .AspNetCore.Antiforgery.* | Protects forms against cross-site request forgery (CSRF). | Session, or short-lived | Yes |
| .AspNetCore.Correlation.* and .AspNetCore.OpenIdConnect.Nonce.* (and similar) | Secures the sign-in flow by verifying that a login request and its response belong together. | Short-lived | Yes |
| Ibernia.AdvisorDevice | Recognises your browser as a known device, so that we can apply limits on how many sessions are open at once and detect unusual sign-in activity. | Up to 400 days | Yes |
| Ibernia.PortalPostLogout | Remembers a safe page to return you to after you sign out. | Up to 8 hours | Yes |
| iber_mfa_grace_flow | Supports the multi-factor authentication setup and grace flow. | Session, or short-lived | Yes |
| .AspNetCore.Culture | Remembers your language preference, for example English or Italian. | 1 year | Yes |
| Application.Theme | Remembers your appearance preference on sign-in and account pages. | 1 year | Yes |
| cookieconsent_status | Remembers that you have dismissed the cookie information banner, so it is not shown again. | Around 1 year | Yes |
The Ibernia web platform (ibernia.it)
Once you are signed in, the Ibernia web platform stores most authentication and preference information in your browser rather than in cookies. The following may be present.
| Name or key | Stored in | Purpose | Essential |
|---|---|---|---|
| oidc.user:{authority}:{clientId} | sessionStorage | Holds the sign-in tokens and basic profile that keep you signed in to the platform. | Yes |
| iber_device_id | localStorage | A stable identifier for your browser, used to apply limits on concurrent device sessions. | Yes |
| Sign-in return keys, for example the page to return to after login | sessionStorage | Returns you to the page you were trying to reach after you sign in. | Yes |
| ibernia-user-display:* and language preference keys | sessionStorage | Holds your display name and language so the interface does not have to reload them on every page. | Yes |
| PostHog cookies and localStorage keys | Cookie and localStorage | Product analytics, used to understand how the platform is used so we can improve it. Only used if you turn analytics on in your account settings. Off by default. | No, opt-in |
Our public website (ibernia.app)
When you first visit our website, a banner asks whether you accept marketing cookies. If you accept, we load Apollo (Apollo.io), which helps us understand which companies visit our website and, for some visitors, who they are, so that our team can follow up with interested firms. To do this Apollo loads a script from LiveIntent, which tries to match your browser to a hashed (scrambled) email address it already knows. If you reject, or do not choose, neither Apollo nor LiveIntent is loaded and nothing is stored apart from your choice.
| Name or key | Stored in | Purpose | Essential |
|---|---|---|---|
| ibernia-consent | localStorage | Remembers whether you accepted or rejected marketing cookies, and when. We ask again after six months. | Yes |
| ibernia-language | localStorage | Remembers the language you chose for the website. | Yes |
| apolloAnonId and keys beginning with Apollo's site identifier (event queue, tracking check) | localStorage | Apollo: a random identifier for your browser, plus visits waiting to be sent to Apollo. | No, only if you accept |
| liveIntentData | localStorage | Apollo: holds the hashed email address LiveIntent matched to your browser, if any. Kept for up to one day. | No, only if you accept |
| LiveIntent cookies, for example _lc2_fpi and _li_dcdm_c | Cookie | LiveIntent: recognises your browser so it can be matched to a hashed email address. Set by LiveIntent, not by us. | No, only if you accept |
The website also uses Cloudflare Web Analytics to count visits, as described above. It stores nothing on your device.
Managing your cookies
You can change your choice for our public website at any time using the Cookie settings link at the bottom of every page. If you withdraw consent, we stop loading Apollo and remove the Apollo data stored in your browser. Cookies that LiveIntent has already set can be cleared in your browser settings.
You can turn product analytics on or off at any time in your account settings, where that option is available to you. Turning it off stops any further analytics data being collected.
You can also clear or block cookies and site data in your browser settings. Every browser handles this slightly differently, so we suggest looking at the privacy or security section of your browser's own help pages. Please note that blocking essential cookies will normally prevent you from signing in or will stop parts of the Platform working correctly.
If you have any questions about this Cookies Declaration or about how we use cookies, you can contact us at [email protected].
See also our Privacy Policy and our Terms and Conditions.
