This Cookie Policy explains how Era University ("the University", "we", "us") uses cookies and similar tracking technologies on its websites, patient portal, Learning Management System (LMS), student and staff portals, mobile applications, and other digital properties (collectively, the "Sites").
This Cookie Policy supplements and should be read together with the University's Privacy & Data Protection Policy, which governs how Personal Data collected through the Sites, including through cookies and similar technologies, is collected, used, stored, shared, protected and retained.
The University is committed to using cookies and similar technologies responsibly and in a manner consistent with applicable privacy, data protection, cybersecurity and information technology requirements.
Cookies are small text files placed on a user's device by a website when it is visited. They allow a website to recognise a user's device across page visits or return visits and to store limited information, such as preferences or session identifiers.
This Policy also covers functionally similar technologies, including local storage, session storage, pixels, web beacons and Software Development Kit (SDK) identifiers used within mobile applications. These technologies are collectively referred to as "cookies" for convenience.
Cookies may be classified as follows:
The University may use cookies and similar technologies for the following purposes:
As of the date of this Policy, and subject to confirmation through the cookie audit referred to in Section 4, the University does not use cookies for third-party behavioural advertising or cross-site retargeting. This position will be verified when that audit is completed and corrected here if it proves inaccurate.
If the University introduces advertising, behavioural tracking or cross-site retargeting technologies in the future, this Policy and the applicable consent mechanism shall be reviewed and updated before such technologies are deployed, where required by applicable law.
| Category | Purpose | Consent Required? | Typical Duration* |
|---|---|---|---|
| Strictly Necessary / Essential | Authentication and session management for the patient portal, student/staff portal and LMS; load balancing; security, fraud prevention and essential system functionality. | No, where the cookie is strictly necessary for the requested service or Site functionality. | Session or, where required for security tokens, up to 24 hours* |
| Functional / Preference | Remember language, display, accessibility and other user preferences and previously entered non-sensitive information. | Yes, where consent is required under applicable law. | Up to 12 months* |
| Performance / Analytics | Aggregate and statistical analysis of Site usage to improve navigation, content, reliability and performance. | Yes, where consent is required under applicable law. | Up to 24 months*, or such shorter period as specified in the University's cookie inventory or applicable provider configuration. |
| Third-Party Service Cookies | Cookies associated with embedded or third-party services directly engaged by the user, such as payment gateways, video-hosting services or other integrated services. | No where strictly necessary to provide a service expressly requested by the user; otherwise yes, where consent is required under applicable law. | Based on the applicable service configuration and documented in the University's cookie inventory. |
* The durations above are indicative defaults, not figures taken from a completed technical audit of the Sites. They are provisional until the cookie audit referred to below is carried out; where that audit finds a different value, the Cookie Inventory (not this table) is authoritative until this Policy is next updated.
The University shall maintain a Cookie Inventory identifying, as applicable, the cookie or technology name, provider, purpose, category, type, duration, data collected, applicable consent requirement and relevant third-party privacy policy.
The Cookie Inventory shall be reviewed periodically and whenever there is a material change to the University's Sites or the technologies used on them.
Where cookies or similar technologies are deployed by a third-party service provider engaged by the University, such as an analytics provider, payment gateway, video-hosting provider or other technology provider, the provider may process information generated through those technologies in accordance with the applicable contractual arrangements, its privacy policy and applicable law.
The University shall take reasonable measures to ensure that third-party providers engaged to process Personal Data on its behalf implement appropriate technical, organisational, security and confidentiality safeguards consistent with the University's Privacy & Data Protection Policy and applicable legal and regulatory requirements.
Where required, appropriate contractual arrangements, including data processing and confidentiality obligations, shall be established with relevant third-party providers.
The University shall maintain and periodically update a record of relevant third-party providers that deploy cookies or similar technologies on the Sites.
Strictly Necessary cookies may be used without obtaining consent where they are essential for providing a service expressly requested by the user or for the secure and proper operation of the Sites.
Non-essential cookies, including Functional, Performance/Analytics and other non-essential Third-Party Service cookies, shall be deployed only in accordance with applicable law — presently the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and, as its provisions are progressively brought into force, the Digital Personal Data Protection Act, 2023 ("DPDPA") — and, where consent is required, only after obtaining valid consent from the user. See the "Regulatory Commencement Status" section of the University's Privacy & Data Protection Policy for the current position on which of these frameworks is presently binding.
Where consent is required, the University shall provide users with clear and understandable information about the relevant categories of cookies and their purposes before consent is obtained.
Where technically and legally applicable, users shall be provided with a cookie banner or preference centre allowing them to:
Consent shall be obtained through a clear affirmative action and shall not be based on pre-ticked boxes or other forms of implied consent where affirmative consent is legally required.
Withdrawal of consent shall be as easy as giving consent.
Where consent is the lawful basis for processing, withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.
The University shall maintain appropriate records of consent where required by applicable law.
Users may manage cookies and similar technologies through the following methods:
Disabling or deleting Strictly Necessary cookies may affect core functionality. For example, it may prevent a user from remaining signed in to the patient portal, student portal or LMS or may interfere with certain transactions.
Disabling Functional or Performance/Analytics cookies should not prevent access to core Site functionality, although certain preferences or analytics functionality may not operate.
The University shall take appropriate measures to minimise the risk of cookies and similar technologies collecting or disclosing health information or other information requiring enhanced protection.
Cookies used on patient portals and related clinical systems should, wherever reasonably practicable, be limited to purposes such as authentication, session management, security and essential functionality.
The University shall not intentionally use cookies or similar technologies to collect, infer or create profiles concerning a user's health status, diagnosis, treatment or other clinical information unless such processing is permitted by applicable law and is supported by an appropriate lawful basis and safeguards.
Where analytics or third-party tools are deployed on pages associated with patient or clinical services, they shall, wherever reasonably practicable, be configured to prevent the collection of identifiers, URL parameters or other information that could unnecessarily reveal health information.
The University shall not use cookies for advertising or behavioural profiling based on health information or other Personal Data requiring enhanced protection.
Where information relating to children is processed through cookies or similar technologies, the University shall apply appropriate safeguards and comply with applicable requirements governing children's Personal Data.
Cookie data shall be retained only for the period necessary to fulfil the purpose for which the cookie or similar technology was deployed, subject to applicable legal, regulatory, security, operational and institutional requirements.
The applicable retention period for each cookie shall be documented in the University's Cookie Inventory.
Underlying analytics or other Personal Data generated through cookies shall be retained in accordance with the University's Privacy & Data Protection Policy, applicable retention requirements and documented processing purposes.
Where the retention period expires, the relevant data shall be deleted, anonymised, de-identified or otherwise securely disposed of, as appropriate and in accordance with applicable requirements.
The University shall implement appropriate technical and organisational measures to protect information collected through cookies and similar technologies against unauthorised access, disclosure, alteration, loss, misuse or other security risks.
Security measures may include appropriate access controls, encryption where appropriate, secure configuration, monitoring, logging, vulnerability management and periodic security assessments.
Third-party providers engaged by the University shall be expected to maintain appropriate security and confidentiality measures in accordance with applicable contractual and legal requirements.
This Cookie Policy may be reviewed and updated from time to time to reflect:
Material changes, particularly the introduction of advertising, behavioural tracking or cross-site tracking technologies, shall be communicated through appropriate means, including the cookie banner or preference centre where applicable.
The updated version shall be made available through the University's relevant digital properties.
For questions regarding this Cookie Policy, cookies and similar technologies, or to exercise applicable privacy and data protection rights, please contact:
This Cookie Policy is intended to be approved by the Executive Council of Era University, Lucknow, alongside the University's Privacy & Data Protection Policy.
The Policy shall be reviewed at least annually and whenever there is a material change in applicable law, the University's Sites, cookies or similar tracking technologies, third-party service providers, or the University's processing activities.
The IT/Web Team shall be responsible for maintaining the Cookie Inventory and coordinating periodic cookie audits with the Data Protection Officer and relevant stakeholders.
Any material change in the University's use of cookies or similar tracking technologies shall be assessed for privacy, security and compliance implications before implementation.