Skip to content
ProCordis.AI

Cookie Policy

Effective from [1 September 2026] · The Polish version is the binding text

1. What cookies and local storage are

Cookies are small text files saved by your browser on your device. Alongside cookies, the ProCordis Platform uses browser local storage mechanisms (`localStorage`, `sessionStorage`), which remember information on your side — on your own device.

The controller of data collected through these mechanisms is ProCordis spółka z ograniczoną odpowiedzialnością, ul. Andrzeja Frydeckiego 4/23, 54-115 Wrocław, Poland, KRS 0001182450, NIP 8943264248, REGON 542181105, share capital PLN 10,000.00. Contact: contact@procordis.ai. Data Protection Officer: Andrii Maslianyk, iod@procordis.ai.

Details of how we process personal data are set out in our Privacy Policy at https://procordis.ai/privacy-policy. The rules for using the Platform are set out in the Terms of Service at https://procordis.ai/terms.

2. What cookies and local data we use

The table below lists the items stored by the ProCordis Platform:

Name Type Purpose Category Retention Provider
`better-auth.session_token` cookie (HttpOnly, Secure, SameSite=Lax) Maintaining your logged-in session (authentication) Strictly necessary About 7 days, renewed on activity ProCordis
Supporting authentication cookies (CSRF protection, login state) cookie Security of the login process Strictly necessary Session / short-lived ProCordis
`procordis:paymentReturn:*` sessionStorage Prevents a payment confirmation being recorded twice when you return from the payment provider Strictly necessary Until the browser tab is closed ProCordis
`vite-ui-theme` localStorage Remembering your chosen interface theme (light/dark) Functional Until you delete it ProCordis
`sidebar_state` localStorage Remembering the sidebar state (expanded/collapsed) Functional Until you delete it ProCordis
`user-preferences` localStorage Remembering your preferences, including interface language Functional Until you delete it ProCordis
`ph_*` (analytics) localStorage + cookie Product analytics: analytics identifier, Platform usage events, masked session recordings Analytics — only after you have given consent 12 months; sooner if you withdraw consent PostHog (EU region)
Payment provider cookies during the payment process cookie Completing and securing the payment Strictly necessary for the payment process Per the provider’s policy Stripe Payments Europe, Ltd.

We do not use marketing cookies or third-party tracking for advertising purposes. We do not sell data collected through cookies or local storage.

3. Categories

3.1 Strictly necessary (no consent required). Items needed to deliver the service you have explicitly asked for — logging in and maintaining your session, security, and correct handling of payments. Under art. 399 of the Polish Act of 12 July 2024 on Electronic Communications Law, which replaced the Telecommunications Law on 10 November 2024, these do not require consent. Without them the Platform cannot function.

3.2 Functional. These remember choices you have made in the interface (theme, language, sidebar layout). They are written only as a result of your own action — switching the theme, for example — and stored locally on your device; they are not used for tracking. You can delete them at any time by clearing site data in your browser.

3.3 Analytics (consent only). For product analytics we use PostHog in the European Union region. Analytics runs only after you have given your voluntary consent — during registration or later in your account settings. Until then, no analytics cookies or localStorage entries are created at all. Consent is voluntary and does not condition your use of the Platform.

We apply the following safeguards:

  • IP address capture is disabled;
  • session recordings are fully masked — the content of all fields and text is obscured;
  • session recording is disabled in the redaction editor and in any view where an unredacted ECG image can appear — no analytics, session-replay or error-reporting tool captures the editor canvas or the image loaded into it;
  • analytics data does not include ECG images or analysis results;
  • data is sent to a PostHog instance in the EU region.

4. How to withdraw your analytics consent

You can withdraw your analytics consent at any time, as easily as you gave it and without affecting your ability to use the Platform: log in, go to Account settings → the consent and privacy section, and switch analytics consent off.

Once withdrawn, the Platform automatically stops collecting further events and removes all analytics localStorage entries and PostHog cookies from your browser (the `ph_*` keys). Withdrawal is recorded in a versioned consent register and does not affect the lawfulness of processing carried out beforehand.

Independently of the above, you can delete all cookies and local data in your browser settings — this will, among other things, log you out.

5. Why we do not display a cookie banner

The ProCordis Platform does not display a cookie banner because:

  • before you log in, only strictly necessary items are used (session, security), which do not require consent;
  • functional items are written only as a result of your own deliberate action in the interface;
  • analytics items activate only after express consent given by a logged-in user at registration or in settings — that consent is collected through a dedicated, versioned consent mechanism rather than through a banner.

If we later introduce anything other than strictly necessary items on our public pages, we will implement an appropriate consent mechanism and update this Policy.

6. Changes to this Policy

We may update this Policy as the Platform develops — for example, if we add features that use local storage. The current version is always available at https://procordis.ai/cookie-policy. We will tell you about material changes affecting categories that require consent and, where required, ask for fresh consent.

7. Related documents and contact