COOKIES POLICY

Definitions

Cookies: these are small text files that are stored in the browser and/or on the device that accesses or visits the pages of certain websites, so that the User’s preferences can be known when they reconnect. Cookies stored in the User’s browser and/or device cannot read the Data contained therein, access personal information, or read Cookies created by other providers.

This website uses Cookies and/or similar technologies that store and retrieve information when you browse. In general, these technologies can serve a variety of purposes, such as recognizing you as a User, obtaining information about your browsing habits, or customizing the way content is displayed. The specific uses we make of these technologies are described below.

Data: this is the information obtained by means of the User’s Terminal Equipment through the Data storage and retrieval device (Cookies or others).

Terminal equipment: the device from which the User accesses the service, such as a personal computer, mobile phone, tablet, etc., and from which the information is obtained.

Information society service: any service provided at the individual request of a User, whether for payment or not, remotely and electronically, provided that, for the purposes of this guide, it constitutes an economic activity for the Publisher whose provision gives rise to the use of Cookies. For example: the provision of a service for accessing information via a website or mobile application created by a magazine or newspaper, a financial service, an entertainment service, an e-commerce service from an online store, etc.

Publisher: any entity providing Information society services that owns a website that can be accessed by a User and for the provision of which Cookies are used.

User: the recipient, a natural person, who accesses the service provided by a Publisher, with a distinction being made between registered and unregistered Users.

What types of Cookies are there?

  • Depending on the owner of the Cookies, they can be classified as:
  • First-party Cookies: these are Cookies for which the Publisher itself is responsible and which are generally sent to the User’s Terminal equipment from a computer or domain managed by the Publisher itself and from which the service requested by the User is provided.
  • Third-party Cookies: these are Cookies for which an entity other than the Publisher is responsible and which are generally sent to the User’s Terminal equipment from a computer or domain that is not managed by the Publisher, but by another entity that processes the Data obtained through the Cookies.
  • Depending on the purpose of the Cookie, they can be classified as:
  • Strictly necessary Cookies (technical): these are Cookies that allow the User to browse a website, platform, or application and use the various options or services available on it, including those that the Publisher uses to enable the management and operation of the website and enable its functions and services, such as, for example, controlling traffic and Data communication, identifying the session, accessing restricted areas, remembering the items included in an order, completing the purchase process for an order, managing payment, controlling fraud linked to the security of the service, requesting registration or participation in an event, counting visits for the purposes of billing for licenses for the software with which the service operates (website, platform, or application), using security elements during browsing, storing content for the dissemination of videos or sound, enabling dynamic content (e.g., animation of text or image loading), or sharing content through social networks.
  • Preference or personalization Cookies: these allow information to be remembered so that the User can access the service with certain characteristics that may differentiate their experience from that of other Users, such as the language, the number of results to be displayed when the User performs a search, the appearance or content of the service depending on the type of browser through which the User accesses the service or the region from which they access the service, etc.
  • Analysis or measurement Cookies: these allow the person responsible for them to monitor and analyze the behavior of Users of the websites to which they are linked, including quantifying the impact of advertisements. The information collected through this type of Cookie is used to measure the activity of the websites, application, or platform, in order to introduce improvements based on the analysis of the usage Data made by the Users of the service.
  • Behavioral advertising Cookies: these store information on User behavior obtained through continuous observation of their browsing habits, allowing a specific profile to be developed in order to display advertising based on that profile.
  • Depending on how long Cookies remain active:
  • Session Cookies: these are designed to collect and store Data while the User accesses a website. They are usually used to store information that is only relevant for the provision of the service requested by the User on a single occasion (for example, a list of products purchased) and disappear at the end of the session.
  • Persistent Cookies: these are Cookies in which the Data remains stored on the terminal and can be accessed and processed for a period defined by the Cookie manager, which can range from a few minutes to several years.

What type of Cookies do we use on this website?

External job portals powered by Workday

Technical or mandatory Cookies:

Subgroup

Cookies

Description

Type

Duration

Session experience

PLAY_LANG, PLAY_SESSION, timezoneOffset, wd-browser-id, wday_vps_cookie, CXS_SESSION

Cookies that store information about the User, the device, and the session, as well as timestamps necessary to manage the automatic expiration of sessions due to inactivity. They expire at the end of the session.

First party

Session

Security management

TS*

They prevent cyberattacks by verifying that the Data in the domain and subdomain Cookies has not been altered during communication between the server and the client.

Part One

Session

Security management

CALYPSO_CSRF_TOKEN

Contains a CSRF token to prevent cross-site request forgery (CSRF) attacks, preventing a User from performing unwanted operations on the portal.

First part

Session

Security Management

__cf_bm

Identifies and mitigates automated traffic to protect the platform from malicious bots.

Part One

30 minutes of downtime

Load balancing

WorkdayLB_UICLIENT, WorkdayLB_SAS (WorkdayLB_* nomenclature)

Allows all requests from the same User to be redirected to the same server, ensuring a consistent experience.

Part One

Session

Optional Cookies:

Subgroup

Cookies

Description

Type

Duration

Cookie Preference

enablePrivacyTracking

Maintains the User’s preference regarding the use of non-essential Cookies selected in the Cookie banner on the external portal.

First party

Session

Performance (Analytics)

_ga* (Google Analytics)

Cookies that allow web analytics Data to be collected through Google Analytics to measure traffic on the external portal.

First party

400–730 days

Functional (Apply with LinkedIn)

JSESSIONID, lang, bcookie, bscookie, li_gc, lissc, lidc, fcookie, fid

Cookies necessary to enable the “Apply with LinkedIn” feature. Details depend on LinkedIn’s own policy.

Third parties

Session (JSESSIONID, lang); 2 years (rest)

Persán website and Workday corporate application

Technical or mandatory Cookies:

Subgroup

Cookies

Description

Type

Duration

Session experience

PLAY_LANG, PLAY_SESSION, timezoneOffset, helpLastCheckin, JSESSIONID, LastUserActivity, learningLastCheckIn, SessionTimeoutMS, UserSignedIn, sessionLoggingInfo, uid, wd-alt-sessionid, wd-browser-id

Cookies linked to the User, device, and session management, including timestamps necessary to control expiration due to inactivity. They expire at the end of the session.

Part One

Session

Security management

TS*

They prevent cyberattacks by verifying that the Cookies exchanged between the client and server have not been tampered with.

Part One

Session

Security management

deviceID

Identifies the device for the “Trusted Devices” function.

Part One

1 year

Security Management

__cf_bm

Identifies and reduces automated traffic to protect the platform.

Part One

30 minutes of downtime

Security Management

_cfuvid

Cookie used only if the site uses this option in a Rate Limiting Rule. Allows the Cloudflare firewall to distinguish Users who share the same IP.

First part

Session

Load Balancing

WorkdayLB_BP, WorkdayLB_MICROSCOPE, WorkdayLB_PEX, WorkdayLB_SAS, WorkdayLB_TALK, WorkdayLB_TALK_rest, WorkdayLB_TALK_ws, WorkdayLB_UI, WorkdayLB_UIAUTHGWY, WorkdayLB_USB, WorkdayLB_VPS2, WorkdayLB_WDRIVE_client, WorkdayLB_WDRIVE_server_rest, WorkdayLB_WDRIVE_server_ws

Ensure that all requests from the same User are directed to the same server to maintain service consistency.

Part One

Session

Load balancing

__cflb

Cookie used by Cloudflare to ensure that the User returns to the same origin server for a specified period, guaranteeing a continuous experience.

First party

11 hours

How to disable Cookies?

The way in which the User can disable Cookies will depend on the browser or browsers they use. All browsers allow you to change your Cookie settings. Below are links to each browser:

Firefox

Chrome

Safari

Microsoft Edge

Android

iOS

If you do not want to be tracked by Cookies, Google has developed a plug-in for your browser that you can access at the following link.

What are the consequences of disabling Cookies?

If the User prevents the activation of Cookies or deactivates them after having previously authorized them, this may affect the functioning of some features of the website, such as, among others, not saving information about the acceptance of the initial Cookie notice, which will therefore be displayed again on the next visit.

Similarly, we will not be able to obtain information about Users’ browsing on our website, which will prevent or hinder the improvement of the information and content we publish, as well as its presentation.

Changes or updates to our Cookies Policy

The structure and functionality of this website may be modified to add new sections, services, or content, which may result in changes to its use and, therefore, to our Cookies Policy. We therefore recommend that Users review the published Cookies Policy each time they access our website to see if there have been any changes since their last visit.

We recommend that you visit this website for more information about Cookies.

Data controller and contact details

For questions and/or comments about our Cookies Policy and this statement, please contact us using the following contact details, depending on the Persán Group company you wish to contact:

Spain

Poland

France

Persán, S.A.

A91380014

Calle Pino Albar, nº 2

Postal code 41016 Seville

Email: gdpr@persan.es

Tel.: (+34) 954 99 83 50

Persán Polska, S.A.

Tax ID: 527-272-39-10

ul. Innowacyjna 10, 55-330 Wróblowice, Poland

Email: gdpr@persan.es

Tel.: (+48) 71 37 00 599

Persan France, S.A.S.

RCS No.: 891 336 976

235 Rue Charles de Gaulle, Plaine de l’Ain Industrial Park.

01150, Saint Vulbas, France.

Email: gdpr@persan.es

Tel: (+33)4 74 34 22 00

Other questions about personal Data processing

Purpose of processing: we use Cookies for different purposes, as indicated for each type of Cookie in the section “What types of Cookies do we use on this website?“, so we invite you to consult this section to find out more about these purposes.

Legitimacy of processing: the legal basis that legitimizes the processing of personal Data carried out through the use of these Cookies depends on each one, since, for necessary Cookies, the legitimacy is precisely their necessity for the proper functioning of the website and, where applicable, its security. With regard to analytical Cookies, the legal basis that legitimizes such processing is the consent given by the User through the system enabled in the initial notice displayed when accessing the website.

Recipients of the Data: Personal Data will not be disclosed to third parties, without prejudice to the third-party Cookies to which we have referred and the international transfers of Data reported below.

International Data Transfers: on this website we use third-party Cookies that may be outside the European Economic Area, although the international Data transfers involved in their use have the appropriate safeguards provided for in Article 46.2 c) of the General Data Protection Regulation (standard contractual clauses approved by the European Commission), or are certified under the EU-US Data Privacy Framework.

This is particularly the case for Google Cookies  such as those mentioned above:

Cookie policy

Privacy Policy

For more information about Google Analytics Cookies, click this link.

Google, LLC is a certified entity under the EU-US Privacy Shield Framework, as you can see at this link.

In addition to the information on Google’s Cookie Policy and Privacy Policy that we have just provided, we recommend that you visit this link to learn how Google uses information from websites or applications that use its services and this other link to learn how Google uses Cookies in advertising.

In any case, you can find out about transfers to third countries that, where applicable, are carried out by the third parties identified in this Cookies Policy in their corresponding policies.

Retention period: the duration of each Cookie varies, so we invite you to read the information we have published on this subject, in relation to each type of Cookie and each one of them in the section “What type of Cookies do we use on this website?“, so we invite you to consult it.

Data protection rights: as the owner of the personal Data, you may exercise your rights of access, rectification, limitation of processing, deletion, opposition, and the right to the portability of your Data, either on your own behalf or through a legal or voluntary representative.

To exercise these rights, you must contact PERSÁN by email at gdpr@persan.es , indicating in the subject line “Data Protection Rights” and the company to which you are addressing your request, or, if you prefer, by post to the address indicated above, specifying which right you wish to exercise. We may ask you for a copy of your ID card if it is necessary to verify your identity.

We will respond to your request within a maximum of 30 days from the date of receipt, making every effort and using all means at our disposal to reduce this period as much as possible. If you are not satisfied, you may request the protection of your rights by contacting the competent supervisory authority in the country where the company to which you wish to address your complaint is located.

Complaint to the supervisory authority: you may lodge a complaint with the competent supervisory authority in the country where the company to which you wish to address the complaint is located.

You can consult the information on the processing of personal Data in our “Privacy Policy – Persán“.

Changes to the Cookies Policy

This Cookies Policy was approved on February 16th of 2026. We may update its content at any time by publishing an updated version here. The new modified Cookie Policy will apply from the date of revision. Therefore, we recommend that you review this Policy periodically to stay informed about how we protect your information.

Persán