HEM · Cookie
HEM Cookie
KVKK and GDPR compliant cookie scanning, consent and archive
Putting a banner up is not enough; you have to be able to show which user consented to what, and when. HEM Cookie keeps that record for you.
- KVKK
- GDPR
- ePrivacy
The banner is there, the compliance is not
Nobody knows what cookies the site sets
Tags, pixels and third-party scripts have accumulated over the years. What each one collects has never been documented.
Consent is collected but cannot be proven
People click the banner, but no record is kept of who consented to what under which version. When a complaint arrives there is no document to show.
Refusing is harder than accepting
Setups where the reject option is hidden, or where cookies keep running after a refusal, increase the risk instead of delivering compliance.
Scanning, consent and archive in one flow
Seven modules complete the chain from cookie inventory to audit record.
Automatic cookie scanning
Scans your site periodically and finds newly added cookies and trackers, so the inventory stays current on its own.
Smart categorisation
Sorts the cookies it finds into strictly necessary, functional, analytics and marketing; you can correct the classification by hand.
Customisable consent banner
Banner text, colour and position follow your brand. Accept and reject are presented with equal weight.
Audit-ready consent archive
Every consent is stored with a timestamp, the banner version and the categories chosen. Exportable as a single record.
Multi-language support
Banner texts are managed per language; the visitor sees the text for their own language.
White label
The banner appears entirely under your brand; a HEM Bilişim mark is not required.
Tag manager integration
Consent state is passed to your tag manager; tags in a non-consented category do not fire.
How the consent signal reaches your tag manager
The link between the consent banner and your analytics/marketing tags is made through four signals. Without that link, tags keep firing even when the user declines.
The four consent signals
ad_storageAdvertising cookiesanalytics_storageAnalytics cookiesad_user_dataUser data for advertisingad_personalizationPersonalised advertisingThe flow
Default: denied
All four signals are set to denied as the page loads; no tag can write data before consent arrives.
The banner appears
Choices are offered per category. Refusing is as easy as accepting.
Signals update
As soon as a choice is made, a consent update command is sent and tags behave accordingly.
The record is kept
Which categories were consented to, under which text version and when, is stored with a timestamp.
This site's own cookie banner runs on the same four signals. We apply the setup we describe to ourselves first.
Steps to go live
Scan
The site is scanned and the cookie inventory produced.
Classify
Cookies are categorised and described.
Publish
The banner is added with a single script.
Archive
Consents are recorded and periodic scanning begins.
Connects to your existing systems
- Installation on any web stack with a single line of script
- Consent signal for Google Tag Manager and similar tag managers
- Cookie policy page generated automatically from the inventory
- Consent records forwarded to the HEM KVK evidence store
Frequently asked questions
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
