Overview
This Cookie Policy explains how Finomics ("we," "our," or "us") uses cookies and similar tracking technologies when you visit our website or use our FinOps platform. It should be read alongside our Privacy Policy.
We are committed to transparency about the data we collect and how it is used. If you have questions or concerns about our use of cookies or other data-collection practices, please contact us before using the platform.
What Are Cookies
Cookies are small text files stored on your device when you visit a website. They allow the site to remember your actions and preferences (such as login state or display settings) over time, so you do not have to re-enter them every time you return.
Similar technologies — such as local storage, session storage, and pixel tags — may be used for the same or related purposes. This policy covers all such technologies collectively referred to as "cookies."
Cookies We Use
The table below summarises the categories of cookies used on the Finomics platform:
| Category | Purpose | Consent Required |
|---|
| Strictly Necessary | Authentication, session management, security | No — required for the service to function |
| Functional | User preferences, UI settings, language | Depends on jurisdiction |
| Analytics | Usage patterns, performance monitoring | Yes — opt-in where required |
Strictly Necessary Cookies
These cookies are essential for the platform to operate securely. They cannot be disabled without affecting core functionality. We use them to:
- • Maintain your authenticated session after login
- • Store and rotate authentication tokens (including refresh-token reuse detection)
- • Protect against cross-site request forgery (CSRF)
- • Enforce session timeouts and re-authentication when required
- • Enable single sign-on (SSO) flows where applicable
FinOps Insight: Authentication Cookies
Our authentication cookies are HttpOnly and Secure, meaning they cannot be accessed by JavaScript and are only transmitted over HTTPS. They are classified as strictly necessary and do not require separate consent under most privacy regulations, including GDPR.
Functional Cookies
Functional cookies remember choices you make to improve your experience. Examples include:
- • Dashboard layout and column preferences
- • Date range and filter selections
- • Notification and display settings
- • Language and time-zone preferences
Analytics Cookies
We use analytics cookies to understand how users interact with our platform so we can improve it. These cookies collect aggregated, anonymised data and may include:
- • Pages visited and time spent on each page
- • Features used and workflows triggered
- • Error rates and performance metrics
- • Device type, browser, and operating system
Where required by law (e.g. under GDPR or ePrivacy Directive), analytics cookies are only set after you provide explicit consent via our cookie-consent mechanism.
IP Address Collection & Audit Logging
In addition to cookies, we collect and process certain server-side data for security and compliance purposes:
IP Address Logging
We record the IP address associated with each authenticated request. This data is used to:
- • Detect anomalous login activity and potential account compromise
- • Identify and block abusive or suspicious access patterns
- • Support refresh-token reuse detection (a security control that flags stolen tokens)
- • Fulfil legal obligations under applicable regulations
Security Audit Logging
Our audit logs capture the following for each session event:
- • Timestamp and event type (login, logout, token refresh, permission change)
- • IP address and approximate geolocation (country/region)
- • User-agent string (browser/OS details)
- • User identifier and organisation
FinOps Insight: Legal Basis for IP & Audit Data
IP address collection and security audit logging are processed under our legitimate interest in securing the platform and protecting user accounts, and where required by law for compliance purposes. We retain this data for up to 1 year. Where applicable regulations require disclosure or consent for IP-level tracking, we will obtain it through our consent-management mechanism prior to rollout in those regions.
Your Consent
For cookies that are not strictly necessary, we will seek your consent before setting them. Where applicable law (such as GDPR or the ePrivacy Directive) requires it:
- • A cookie-consent banner will appear on your first visit
- • You may accept all cookies, reject non-essential cookies, or customise your preferences by category
- • Your consent choices are stored and respected for future visits
- • You may withdraw consent at any time by updating your cookie preferences in the platform settings or by clearing your browser cookies
Withdrawing consent for non-essential cookies will not affect the lawfulness of processing that occurred before withdrawal, and will not prevent you from using core platform features.
Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to:
- • View cookies that have been set and delete them individually
- • Block all cookies or block cookies from specific sites
- • Set your browser to alert you before a cookie is stored
Please note that blocking strictly necessary cookies will prevent you from logging in and using the Finomics platform. Disabling functional cookies may degrade your experience by resetting your preferences on each visit.
For browser-specific instructions, refer to your browser's help documentation (e.g. Chrome, Firefox, Safari, Edge).
Third-Party Cookies
Some third-party services integrated with our platform may set their own cookies. These are governed by the respective third party's cookie and privacy policies. We do not control third-party cookies. Where we use third-party analytics or monitoring providers, we ensure they operate under appropriate data processing agreements and, where required, obtain your consent before their cookies are loaded.
Policy Updates
We may update this Cookie Policy from time to time to reflect changes in technology, regulation, or our data practices. When we make material changes, we will:
- • Update the effective date at the top of this page
- • Display a notice on the platform or via email where required
- • Re-request consent where the changes affect cookies that require it