Skip to content
Quantum Secure Labs

Cookie Policy

Last updated: 2026-09-24

1. What are cookies?

Cookies are small text files that are downloaded and stored on the user's device when they access a website. They allow the site to store and retrieve information about the user's browsing habits or device, in order to improve the browsing experience and provide personalised services.

2. Regulations and scope

This policy forms part of the Privacy Policy of Quantum Secure Labs SL. It complies with the following regulations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
  • Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights (LOPDGDD).
  • Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector (ePrivacy Directive).

3. Types of cookies

By managing entity

  • First-party cookies: managed directly by Quantum Secure Labs SL.
  • Third-party cookies: managed by external providers, such as analytics or advertising platforms.

By duration

  • Session cookies: deleted automatically when the browser is closed.
  • Persistent cookies: stored on the device for a specified period.

By purpose

  • Technical or necessary cookies: essential for the site to function.
  • Preference cookies: allow the user's preferences to be remembered.
  • Analytics cookies: collect statistical data on user behaviour.
  • Behavioural advertising cookies: allow advertising to be shown based on the user's profile.

4. Specific cookies used

qsecure.es does not set a language cookie: the language is resolved from the URL (/en versus the root), never from a preference cookie.

4.1 First-party cookies

NameEntityTypePurposeDuration
authjs.session-token (with the __Secure- prefix when the connection is HTTPS, which is the case on this site)First-partyTechnicalKeeps the session of whoever administers the blog signed in at /admin. Set by the authentication library (Auth.js/NextAuth) on sign-in; it cannot be seen or changed by anyone visiting the rest of the site.8 hours from sign-in
authjs.csrf-token (with the __Host- prefix when the connection is HTTPS, even stricter than __Secure-)First-partyTechnicalProtection against cross-site request forgery (CSRF) on the same /admin sign-in form: checks that the sign-in request really comes from the form, not from another site. Set by Auth.js on the first request of the sign-in process.Browser session cookie: deleted when the browser closes, no expiry of its own
authjs.callback-url (with the __Secure- prefix when the connection is HTTPS)First-partyTechnicalRemembers which page to return to after signing in or out at /admin. Set by Auth.js in the same sign-in process, together with the two cookies above.Browser session cookie: deleted when the browser closes, no expiry of its own
KeyStorage typePurposeDuration
qsl-cookie-consentBrowser localStorage, not a cookieRemembers the choice you made on the cookie banner (accept or reject), so it is not shown again on every visitUntil you clear this site's data in your browser; it does not expire on its own

4.3 Third-party cookies

NameEntityTypePurposeDuration
_ga / _gidGoogle (third-party)AnalyticsGoogle Analytics statistics. They are only set if you accept analytics on the banner and, in addition, the site has a Google Tag Manager container configured (Consent Mode v2: by default, until you accept, they are denied). As of this update, no container is configured, so they are not currently set._ga: 2 years · _gid: 24 hours (Google Analytics defaults once active)
Cloudflare Turnstile anti-spam checkCloudflare (third-party)Technical / spam preventionA widget that loads only on the contact form (/contact) and only when the site has a Turnstile site key configured, to distinguish people from automated programs before the form is sent. Cloudflare documents that Turnstile may use its own storage mechanisms as part of that check; we do not publish a specific cookie name here because that internal detail is controlled by the provider.Depends on Cloudflare

5. International data transfers

Some third-party cookies may involve the transfer of data to countries outside the European Economic Area (EEA). In such cases, Quantum Secure Labs SL ensures that such transfers take place under the standard contractual clauses adopted by the European Commission or other appropriate safeguards pursuant to Chapter V of the GDPR.

When first accessing the website, users are shown an information banner that allows them to accept all cookies, configure their preferences or reject non-essential cookies. Users can modify their preferences at any time through the cookie settings panel available on the site.

7. How to disable or delete cookies

Users can allow, block or delete cookies installed on their device by configuring their browser. Links to help pages for the main browsers are provided below:

  • Google Chrome: support.google.com/chrome/answer/95647
  • Mozilla Firefox: support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
  • Safari: support.apple.com/guide/safari/sfri11471/mac
  • Microsoft Edge: support.microsoft.com/en-us/microsoft-edge

8. Consequences of disabling cookies

Disabling certain cookies may affect the proper functioning of the website. In particular, rejecting technical or necessary cookies may prevent access to certain features or result in a degraded browsing experience.

9. Updates

Quantum Secure Labs SL may update this Cookie Policy in response to new legal or regulatory requirements, or to bring it in line with changes to the technologies used on the site. Any changes will be published on this page with the corresponding update date.

10. Contact

For any queries about the use of cookies on qsecure.es:

  • Email: legal@qsecure.es
  • Postal address: Calle de Gustavo Pérez Puig, 61, Hortaleza, 28055 Madrid, Spain