Version: 2.0 | Effective Date: 2 September 2026 | Last Updated: 2 September 2026
Version 1.x, effective 19 November 2025, was replaced by this version.
Operator: Difinity Pty Ltd (ABN 82 686 692 759), Sydney, NSW, Australia
1. Scope
This Cookie Policy explains how Difinity Pty Ltd ("Difinity", "we", "us" or "our") uses cookies and similar browser technologies on the Difinity.ai website at difinity.ai and supported subdomains that display or receive its Cookie settings. It also explains the necessary authentication storage used on the chat and agent workspace at chat.difinity.ai.
Cookies are small files stored by a browser. Similar technologies include local storage, session storage, software development kits, pixels and scripts that read or write information on a device or send interaction events.
Read this Policy with the Privacy Policy. Website and business vendors are identified in those two policies. The Sub-processors page is a separate list for vendors that process Customer Personal Data for the contracted Services.
Difinity offers Platform hosting in AWS regions in Australia (Sydney), European Union (Frankfurt) and United States. The organisation's hosting region is agreed in the applicable Order Form. Website-vendor processing locations are separate and appear in Sections 7 and 8 and the Privacy Policy.
2. Your choices
Our Cookie settings provide four categories:
- Necessary: storage and processing needed to record and apply a choice, secure the site, authenticate a signed-in person or deliver a feature they request. Necessary technologies cannot be switched off through Cookie settings.
- Functional: optional storage used to remember a preference or provide enhanced functionality.
- Analytics: optional measurement, person profiles and session recording.
- Marketing: optional advertising, attribution and marketing measurement.
On a first visit, you can accept all optional categories, reject them, or choose categories. No PostHog analytics event is captured and no PostHog cookie, local-storage identifier or other PostHog device storage is created before you accept Analytics.
Your saved choice remains valid for up to 12 months or until the consent version changes. The Cookie settings control remains available so you can change the choice at any time.
2.1 Rejecting or withdrawing Analytics
Rejecting or withdrawing Analytics stops PostHog capture and session recording immediately. It clears PostHog local and session storage, including ph_<project_key>_posthog and __ph_opt_in_out_<project_key>, and removes difinity_has_visited. PostHog sets no cookie in this implementation. No further PostHog analytics event is sent unless Analytics is accepted again.
Withdrawing consent does not make earlier processing unlawful. It does stop future processing that depends on that consent. Information already received by a provider remains subject to the server-side retention period in Section 8 and applicable deletion rights.
2.2 Feature configuration before Analytics consent
Before Analytics consent, the Site makes one request per page load through its proxy to PostHog Cloud EU for the project configuration that shapes the page. The request does not repeat while that page stays open. It has no body and no visitor identifier beyond the public project token. As with any web request through the proxy, PostHog Cloud EU receives the IP address, page URL and browser details. No feature-flag evaluation request or analytics event is sent. The request stores nothing on the device. We rely on our legitimate interests in loading the Site's feature configuration.
3. Necessary storage
The first-party key difinity_cross_domain_consent is Necessary storage. It is stored in a cookie, with local storage as a fallback, after you save a choice. It records the selected categories, date and time, consent version and Difinity domain where the choice was made. It applies and synchronises the choice across supported Difinity domains for up to 12 months. Blocking or deleting it can cause the banner to return or prevent the choice applying consistently.
The chat and agent workspace at chat.difinity.ai uses the first-party Supabase Auth cookie sb-<project-ref>-auth-token to keep a signed-in person authenticated. The cookie is split into numbered chunks such as .0 and .1 where needed, is set on .difinity.ai, and is kept for 7 days, refreshed while the active session is renewed. This is necessary for the service the person requests and is separate from optional website Analytics and Marketing. Supabase authentication data is processed in the same region as the organisation's hosting region: Australia (Sydney), European Union (Frankfurt) or United States.
The browser can also use temporary session storage needed to keep an in-progress form or display a result requested by the person. That state ends with the relevant browser session unless the feature explains a different period.
4. Analytics
4.1 Before a choice and after rejection
PostHog does not capture page views, exits, clicks, scroll depth, engagement timing, consent decisions or session recordings before Analytics consent. It also does not capture them after Analytics is rejected or withdrawn. There is no PostHog device storage in those states. Section 2.2 describes the separate project-configuration request.
4.2 After Analytics consent
If you accept Analytics, PostHog can:
- store
ph_<project_key>_posthogand__ph_opt_in_out_<project_key>in local storage and useph_<project_key>_posthogfor session state in session storage, but not in a cookie; - capture page path, referrer, screen dimensions, user agent, clicks, scroll depth, page exits and engagement timing;
- send the full page URL, including any query string, with click and copy events; a click event can also send the element's ID, classes, selector and page section;
- include up to 50 characters of text from a clicked interface element; record that text was copied, its length and whether it looked like code; and never include the copied text itself;
- create or update an analytics profile; and
- record configured page interactions for session replay, with form input masking configured by the site.
The first-party local-storage key difinity_has_visited can be written only after Analytics consent. It distinguishes a first visit from a return visit since Analytics was accepted, not the person's first visit ever. It contains no name, email address or account identifier.
The PostHog local-storage keys and difinity_has_visited have no fixed expiry. They are kept until you withdraw consent or clear browser storage. The PostHog session-storage entry lasts for the browser session unless you withdraw consent first.
Google Analytics, when enabled, loads only after Analytics consent is given. If Analytics consent is withdrawn after Google Analytics has been enabled, the site sets Google analytics storage to denied and removes the named first-party analytics cookies within its control. Browser controls may be needed to remove remaining vendor storage.
5. Marketing technologies
Apollo loads when Marketing consent is active. It is used for website visitor attribution and marketing measurement.
Meta Pixel, when enabled, loads only after Marketing consent is given. It is used for advertising measurement and attribution.
If Marketing consent is withdrawn, the site removes the Apollo script and stops subsequent Apollo loading. Apollo does not publish the name of its identifier, so the site cannot remove it by name. Apollo's identifier persists until you clear browser storage.
For Meta Pixel when enabled, the site applies the configured consent revocation and clears named marketing cookies within its control. Browser controls may be needed to remove remaining vendor storage. A provider may retain information it received before withdrawal under its published retention and legal obligations.
6. Functional technologies
The consent interface keeps Functional separate from Analytics and Marketing. No optional Functional cookie or local-storage key is currently listed in the verified inventory below. The project-configuration request is described in Section 2.2 and does not depend on Functional or Analytics consent.
If an optional Functional technology is added, we will add it to the inventory and obtain consent where required before it is stored or accessed.
7. Current browser-technology inventory
Google Analytics and Meta Pixel rows describe their behaviour when enabled. Apollo loads after Marketing consent.
| Technology or key | Provider | Purpose and category | First or third party | When used | Browser lifetime | Destination |
|---|---|---|---|---|---|---|
difinity_cross_domain_consent cookie and local storage |
Difinity | Record and synchronise Cookie settings. Necessary. | First party | After a choice is saved | Up to 12 months or until the consent version changes | Supported Difinity domains |
sb-<project-ref>-auth-token cookie, split into numbered chunks such as .0 and .1 where needed |
Supabase Auth | Authenticate a signed-in Platform person. Necessary. | First-party cookie on .difinity.ai supporting a third-party service |
After sign-in | 7 days, refreshed while the active session is renewed | Supabase Auth in the same region as the organisation's hosting region: Australia (Sydney), European Union (Frankfurt) or United States |
| One PostHog project-configuration request per page load | PostHog | Load the feature configuration that shapes the page. Legitimate interests. No analytics event or device storage. The request has no body or visitor identifier beyond the public project token; the proxy forwards the IP address, page URL and browser details. | Third-party remote configuration | Once per page load, including before Analytics consent | No browser storage | PostHog Cloud EU in the European Union (Frankfurt) |
difinity_has_visited local storage |
Difinity | Distinguish first and return visits since Analytics was accepted. Analytics. | First party | Only after Analytics consent | Until consent is withdrawn or browser storage is cleared; no fixed expiry | Difinity's project in PostHog Cloud EU |
ph_<project_key>_posthog and __ph_opt_in_out_<project_key> local storage |
PostHog | Event measurement, analytics profiles and session recording. Analytics. | First-party storage used by a third-party service | Only after Analytics consent | Until consent is withdrawn or browser storage is cleared; no fixed expiry | PostHog Cloud EU in the European Union (Frankfurt) |
ph_<project_key>_posthog session storage |
PostHog | Browser-session state for consented Analytics. | First-party storage used by a third-party service | Only after Analytics consent | Until the browser session ends, Analytics consent is withdrawn or browser storage is cleared | PostHog Cloud EU in the European Union (Frankfurt) |
_ga and _ga_*; _gid; _gac_* when Google Ads is linked |
Google LLC | Website measurement. Analytics. | First-party storage used by a third-party service | When enabled and after Analytics consent | _ga and _ga_*: 2 years; _gid: 24 hours; _gac_*: 90 days |
United States and other countries where Google operates under its Data Processing Terms |
| First-party browser identifier set by the Apollo tracker; exact key name not published | ZenLeads, Inc. d/b/a Apollo.io | Visitor attribution and marketing measurement. Marketing. | First-party storage used by a third-party service | After Marketing consent | Persists until you clear browser storage; Apollo publishes no fixed lifetime | United States and other countries under the Apollo Privacy Policy; SCCs and the applicable Data Privacy Framework where available |
_fbp; _fbc when a visit includes a Meta Pixel ad click identifier |
Meta Platforms Ireland Limited | Advertising measurement and attribution. Marketing. | First-party storage used by a third-party service | When enabled and after Marketing consent | As set by Meta Platforms; see the Meta Platforms Cookie Policy | United States and other locations described in the Meta Platforms Privacy Policy and Meta Platforms Business Tools Terms |
Vendor policies are linked in the table. These website vendors are not Services sub-processors merely because they support Difinity's controller activity.
8. Retention
| Record | Retention |
|---|---|
| Cookie choice | Up to 12 months or until the consent version changes |
| PostHog project-configuration request | No browser storage |
PostHog local-storage identifiers and difinity_has_visited |
Kept until you withdraw consent or clear browser storage; no fixed expiry |
| PostHog session storage | Until the browser session ends, you withdraw consent or you clear browser storage |
| PostHog analytics events and session recordings | 12 months |
| Google Analytics browser identifiers, when enabled | _ga and _ga_*: 2 years; _gid: 24 hours; _gac_*: 90 days |
| Google Analytics event data, when enabled | 2 months by default, configurable to 14 months for event data used in Explorations; see Google Analytics retention controls |
| Apollo browser identifier | Persists until you clear browser storage |
| Apollo server data | As set by the vendor; see the Apollo Privacy Policy |
| Meta Pixel browser identifiers, when enabled | As set by Meta Platforms; see the Meta Platforms Cookie Policy |
| Meta Pixel Event Data, when enabled | Up to 2 years under the Meta Platforms Business Tools Terms |
Clearing cookies or site data in the browser may remove the consent record and cause the site to ask again. Clearing browser data does not itself delete data already received by a provider. Contact privacy@difinity.ai to exercise an applicable deletion right.
9. Managing browser storage
Use Cookie settings on the Site to accept, reject or change optional categories. You can also block or delete cookies and site data in browser settings. Blocking all browser storage can affect saved preferences, forms and authenticated Services.
Difinity does not currently respond automatically to browser Do Not Track signals. Where a legally recognised browser opt-out signal applies, Difinity will handle it as required by the applicable law. The clearest way to control optional site technologies is Cookie settings.
10. Changes to this policy
We may update this Policy when our technologies, providers or legal duties change. The version and Last Updated date at the top identify the current text. We will ask for a new choice when a consent change requires it.
11. Contact
- Privacy enquiries: privacy@difinity.ai
- Legal enquiries: legal@difinity.ai
- Postal address: Difinity Pty Ltd, Sydney, NSW, Australia
© 2026 Difinity Pty Ltd. All rights reserved.