Contract effective date: September 18, 2024. Audit release: July 9, 2026. Runtime consent and session timestamps are recorded when users actually interact with NEXQ systems.
Cookie and Tracking Technologies Policy
Template and counsel-review notice. This document is a website/app integration template, not a legal opinion. Before publication, replace bracketed placeholders, confirm actual data flows, obtain advice from qualified counsel for each jurisdiction and regulated workflow, and approve final wording through privacy, security, product, marketing, health/clinical, and executive stakeholders. Do not promise controls, certifications, response times, retention periods, or legal rights unless they are actually implemented and operationally supported.
Effective date: September 18, 2024
Last reviewed: July 9, 2026
Last material web integration: July 10, 2026
Organization: NEXQ Inc.
Services covered:
NEXQ websites, web applications, protected workspace surfaces, mobile app surfaces, APIs, secure healthcare and healthtech workflow demonstrations, security and post-quantum readiness planning, diagnostics-workflow support concepts, oncology workflow research, cardiovascular longevity research, research collaboration, support, and related services
Privacy contact: hello@nexq.us
Security contact: hello@nexq.us
Mailing address: Irvine, CA, United States — contact hello@nexq.us for legal notices
1. Scope
This Cookie Policy covers cookies, mobile SDKs, pixels, local storage, tags, session replay, device identifiers, software development kits, beacons, and similar technologies used on our websites, web apps, mobile apps, and embedded services.
2. Technology categories
| Category | Default status | Examples | Governance rule |
|---|---|---|---|
| Strictly necessary | May load without optional consent | security, authentication, load balancing, consent preference storage | Document vendor and purpose. |
| Functional | Load only where lawful basis and notice support it | language, region, accessibility settings | Do not collect sensitive data unless necessary. |
| Analytics | Block until consent or valid legal basis where required | aggregated usage analytics, performance monitoring | Must honor GPC/UOOM where applicable. |
| Advertising / targeted advertising | Block by default until valid consent/opt-in or lawful opt-out regime is satisfied | ad pixels, retargeting, conversion APIs | Prohibited on regulated sensitive flows without written approval. |
| Session replay / heatmaps | Treat as high risk | keystrokes, clicks, form interactions | Must mask fields, minimize capture, and complete DPIA/PIA. |
| Mobile SDKs | Treat as tracking technologies | attribution SDKs, analytics SDKs, crash logs | Must align with Apple/Google privacy disclosures. |
3. Prior opt-in gating
Optional analytics, advertising, retargeting, fingerprinting, session replay, heatmap, attribution, and marketing technologies are blocked by default unless a legally valid consent or documented lawful basis applies. GPC and applicable universal opt-out signals must be honored where required. A rejected, missing, expired, or GPC opt-out state must prevent optional scripts from loading.
4. Global Privacy Control and universal opt-out mechanisms
Where legally required, browser or device-based opt-out signals must be recognized as opt-outs from sale/share/targeted advertising. Test this in staging and production using real browsers and document evidence.
5. Regulated-flow prohibition
Do not deploy advertising pixels, retargeting tags, session replay, heatmaps, or non-essential third-party analytics on patient portals, hospital portals, telehealth rooms, symptom checkers, appointment pages, medication pages, lab results, insurance/payment portals, children’s services, school-directed services, financial-account workflows, or regulated-data forms without written legal, privacy, security, and product approval.
6. Records and renewal
Maintain a tracking-technology inventory with vendor, domain, script, purpose, category, data collected, recipient country, retention, consent basis, app-store label impact, and opt-out mechanism. Save network-test evidence showing optional scripts are blocked by default, GPC is honored, and regulated routes do not leak sensitive data to third parties. Re-review after each new SDK, tag manager change, product launch, acquisition, or vendor contract change.