Cookies and Storage Notice

This page describes the storage technologies currently used on the Rolfes SDG Academy website and the consent categories applied to them.

Last updated: March 26, 2026. This is a technical baseline and should still be reviewed by the site owner and legal counsel before final go-live.

1. How consent works on this site

Necessary storage stays active so the website can remember your privacy choices and keep core features working. Preferences, analytics, and marketing tools stay off until you actively opt in. Rejecting non-essential categories is presented with the same prominence as accepting them, and you can reopen the Privacy settings link at any time.

2. First-party storage currently used

Key Type Purpose Category
rsa_consent Cookie Stores the current consent record so your decision can be applied across pages. Necessary
rsa_consent_record localStorage Stores the latest consent object in a readable format for the site and future developers. Necessary
rsa_consent_history localStorage Stores a short local history of consent changes for technical inspection and troubleshooting. Necessary
rsa_certificate_admin Session cookie Used only if the separate certificate admin area is deployed and an administrator signs in. Necessary

3. Consent categories used on the site

Necessary

Required for consent storage, security-related session handling, and core site operation. These are always active.

Preferences

Reserved for optional convenience features or non-essential interface settings. No active preference service is loaded by default in the current build.

Analytics

Reserved for anonymous usage measurement. The current codebase does not activate analytics by default; an analytics service only loads if the site owner configures one and the visitor opts in.

Marketing

Used for optional fundraising or third-party embeds such as the Donorbox donation form. These stay blocked until you opt in.

4. Third-party services relevant to storage or transfers

  • Donorbox: the embedded donation form on the Support page is blocked until marketing consent is granted. A direct hosted donation link is available without enabling the embed.
  • Same-origin form handlers: the contact, partnership, magazine, Solar Cohort, debate, and newsletter forms now submit to PHP endpoints hosted on the academy domain.
  • Certificate registry: the verification pages now use a same-origin PHP endpoint backed by the certificate database or a protected local registry file.
  • LinkedIn and Instagram: these are plain outbound links. No social media widget is embedded automatically in the current public pages.

Some of these vendors may process personal data outside Germany or the EEA. See the privacy policy and deployment notes for the current transfer review status.

5. Managing and withdrawing consent

You can change your decision at any time by opening the Privacy settings link shown on the site. Withdrawing consent stops future loading of non-essential embeds and scripts, but it does not undo data already sent to an external service before withdrawal.

6. Browser controls

You can also manage or delete cookies and local storage through your browser settings. Please note that removing necessary storage may cause the site to ask for your privacy preferences again or interrupt parts of the certificate admin workflow.

7. Contact and review status

Rolfes SDG Academy
Albert-Schweitzer-Str. 22
32602 Vlotho, Germany
Email: info@rolfessdgacademy.org

This notice reflects the current technical setup of the repository. It should be checked again whenever a new analytics service, embed, payment tool, or hosting provider is introduced.