SMS Bridge, a product of Ino Tek Plus Holding
This is a template prepared for review by qualified counsel. It is not legal advice.
Last reviewed: August 31, 2026
This covers the inotekplus.com/SMS-Bridge marketing site and any web app login/dashboard surface, plus the AI transparency questions raised by the classifier and any AI auto responder feature.
Cookie Policy for SMS Bridge (inotekplus.com/SMS-Bridge)
We use cookies and similar technologies for the following purposes:
- Strictly necessary cookies: required for the site and app to function, for example maintaining your login session or remembering your cookie preference. These do not require consent under any regime reviewed below, but we still disclose them.
- Analytics cookies: help us understand how visitors use the site, for example page views and time on page. Not strictly necessary; require consent in the EU/UK and Quebec, and an opt-out mechanism in California.
- Marketing/advertising cookies: used for retargeting or measuring ad campaigns, if we run them. Not strictly necessary; same consent treatment as analytics cookies.
You can manage your preferences using the cookie banner shown on your first visit, or by contacting info@inotekplus.com.
Verified against the live site on 31 August 2026: the SMS Bridge product page, the demo, and these legal pages set no cookies at all, use no analytics, and load no third party scripts. Typefaces are served from our own server, so no visitor request reaches a third party and no visitor IP address is disclosed to one. The demo keeps a role selection in the browser's own session storage, which is cleared when the tab closes and is never sent anywhere. If analytics or advertising are added later, this page and the banner must be updated before the first such cookie is set.
| Region | Model | What this means for the banner | Source |
|---|---|---|---|
| EU / UK | Opt-in. Under the ePrivacy Directive and UK PECR, non-essential cookies (analytics, marketing) may not be set until the visitor affirmatively consents. The ICO is currently reviewing this guidance following the UK's Data (Use and Access) Act, so the exact UK position may shift; I don't know whether that Act changes the strict opt-in requirement in a way that would let low-risk analytics cookies move to opt-out, needs counsel to check the current state of that review before this table is relied on (ico.org.uk, "Electronic mail marketing," accessed Aug 31 2026, notes the guidance is under review, though that specific page covers email/SMS marketing consent rather than cookies directly; the general EU/UK cookie opt-in principle under ePrivacy/PECR is well established separately from that specific review). | Banner must block non-essential cookies until the visitor clicks an affirmative "Accept" or equivalent; a pre-ticked box or continued browsing does not count as consent. | ePrivacy Directive; ICO PECR guidance, accessed Aug 31 2026 |
| Quebec (Law 25) | Opt-in for profiling/identification technology; the law's privacy-by-default rule for technological products explicitly does not extend to browser cookies as such (mccarthy.ca, "Quebec's Law 25 and Cookies," accessed Aug 31 2026, citing Law 25 s.9.1's carve-out for browser cookies). However, s.8.1 requires that if a technology's function is to identify, locate, or profile a person, the business must inform the person of that use and the means available to deactivate it, before the tracking begins for that purpose, which functionally still means Quebec sites should give clear notice and a genuine opt-out for cookies used for profiling or analytics, even though the strict "privacy-by-default" rule does not itself apply to cookies. | Banner should clearly disclose any cookie used for identification/profiling and provide an accessible way to decline before it is used for that purpose. | mccarthy.ca, dated, accessed Aug 31 2026 |
| Rest of Canada (CASL/PIPEDA) | No cookie-specific opt-in statute; general PIPEDA consent principles apply to any personal information collected via cookies (for example an identifier tied to a person). | A clear notice plus a reasonable ability to decline non-essential tracking is a defensible baseline. | General PIPEDA principles |
| California (CCPA/CPRA) | Opt-out, not opt-in, for the "sale" or "sharing" of personal information (which can include certain advertising cookie/pixel data shared with ad tech vendors). Requires a "Do Not Sell or Share My Personal Information" link or equivalent, and honouring the Global Privacy Control browser signal as an opt-out. | Banner or footer link providing an opt-out is sufficient for non-essential cookies that constitute a sale/share, no need for opt-in first. | General CPRA principle, well established; specific current GPC enforcement posture not independently re-verified for this draft. |
| Australia, Brazil, others in the regulatory map | I don't know the current specific cookie consent standard (opt-in vs opt-out) for Australia's Privacy Act or Brazil's LGPD with enough confidence to state a firm rule here; needs counsel before assuming either an EU-style opt-in or a CCPA-style opt-out approach is safe in those markets. |
May set before consent, in every region reviewed: - Session cookies strictly necessary for the site to function (for example, a cookie remembering the visitor already dismissed the cookie banner). - Security-related cookies (for example, CSRF protection tokens). - Load balancing cookies necessary for the site to serve the visitor correctly.
Must not set before consent, in the EU/UK and, per the profiling disclosure duty, functionally also recommended for Quebec: - Analytics cookies (for example, page view tracking). - Advertising/retargeting cookies or pixels. - Any cookie or script that builds a cross-site profile of the visitor.
May set in California and most of Canada outside Quebec's profiling rule, but must offer a clear opt-out: - Analytics and advertising cookies, provided a "Do Not Sell/Share" or equivalent opt-out is available and honoured, including honouring the Global Privacy Control signal in California.
Practical recommendation: build the banner to the strictest applicable standard (EU/UK opt-in) and serve it globally, or geo-detect and serve the appropriate banner per region. Geo- detection avoids annoying non-EU visitors with an opt-in wall they do not legally need, but adds engineering complexity and a small risk of misdetection; which approach to take is a product/ marketing decision, not a legal one, though counsel should confirm the geo-detection approach if chosen still meets each region's standard.
Reminder: this document mixes verified, dated sourcing with explicit "I don't know, needs counsel" flags on several open points, particularly the exact form of Article 50 disclosure wording, the current UK PECR cookie position pending the Data (Use and Access) Act review, and Australia/Brazil cookie consent standards. Do not publish or rely on this as final without counsel closing those gaps.