Logo
Logo

Cookies Policy

Published:

This document lists every cookie that may be stored on a visitor's device when using the system, the purpose of each cookie, its storage duration, and the consent category it belongs to.

A separate Lithuanian-language version of this document is available at (here).

Consent categories

The system asks for consent in three categories. Visitors can accept all, reject non-essential, or choose individually via the cookie consent banner. The choice is remembered for 12 months and can be re-opened from the page footer.

CategoryRequiredDescription
NecessaryYesRequired for the site to function (session, security, consent state). Cannot be disabled.
FunctionalNoOptional features that improve usability and personalization.
AnalyticsNoHelp us understand how visitors use the site so we can improve it.

If the visitor has not yet made a choice, only Necessary cookies are loaded. Analytics scripts are blocked at the browser level (via the script-blocking layer) until consent is granted.

Cookies set by this system

Necessary cookies

CookieProviderPurposeLifetimeType
cookieConsentThis siteStores the visitor's cookie consent choices per category as JSON.12 monthsFirst-party
SSESS<hash> / SESS<hash>Drupal (CMS)Maintains an authenticated session for users who log in to the CMS or admin areas. Not set for anonymous portal visitors.Up to 23 daysFirst-party
XSRF-TOKEN / CSRF tokenDrupalCSRF protection for authenticated form submissions and API calls. Issued only when a session is active.SessionFirst-party

Analytics cookies

These cookies are loaded only after the visitor accepts the Analytics category. The exact set depends on the analytics scripts configured by the administrator. The system supports Google Analytics / Google Tag Manager out of the box.

CookieProviderPurposeLifetimeType
_gaGoogle AnalyticsDistinguishes unique visitors.2 yearsThird-party
_ga_<container-id>Google Analytics (GA4)Persists session state for the GA4 property.2 yearsThird-party
_gidGoogle AnalyticsDistinguishes visitors over a 24-hour window.24 hoursThird-party
_gat_gtag_<property-id>Google AnalyticsThrottles request rate to the analytics endpoint.1 minuteThird-party
_gac_<property-id>Google Ads (linked)Stores campaign attribution information for conversions imported into Google Ads.90 daysThird-party

How consent is enforced technically

  1. On first page load, the browser reads the cookieConsent cookie. If absent or invalid, the consent banner is shown and only Necessary cookies are written.
  2. Analytics scripts are wrapped in a script-blocking layer (yett) and are not executed until the Analytics category is accepted.
  3. When the visitor saves their choice, cookieConsent is written and the page is refreshed so blocked scripts can initialize.
  4. The visitor can change their choice at any time by re-opening the consent banner from the footer.

Visitor rights

Under the GDPR, visitors can:

  • Withdraw consent at any time via the consent banner.
  • Request a data export via POST /api/gdpr/export (authenticated users).
  • Request data deletion via POST /api/gdpr/forget (authenticated users).
  • Update consent records via POST /api/gdpr/consent (authenticated users).

Maintenance

This document must be updated whenever:

  • A new cookie is set by the application.
  • An administrator adds, removes, or changes tracking scripts in the CMS cluster settings (tracking_scripts.head_start, head_end, body_start, body_end).
  • A new GDPR consent category is added in mm_gdpr.settings.yml.

This website uses cookies

We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking 'Accept', you consent to our use of cookies.