Cookie Policy
1. What cookies and local storage are
Cookies are small text files saved by your browser on your device. Alongside cookies, the ProCordis Platform uses browser local storage mechanisms (`localStorage`, `sessionStorage`), which remember information on your side — on your own device.
The controller of data collected through these mechanisms is ProCordis spółka z ograniczoną odpowiedzialnością, ul. Andrzeja Frydeckiego 4/23, 54-115 Wrocław, Poland, KRS 0001182450, NIP 8943264248, REGON 542181105, share capital PLN 10,000.00. Contact: contact@procordis.ai. Data Protection Officer: Andrii Maslianyk, iod@procordis.ai.
Details of how we process personal data are set out in our Privacy Policy at https://procordis.ai/privacy-policy. The rules for using the Platform are set out in the Terms of Service at https://procordis.ai/terms.
2. What cookies and local data we use
The table below lists the items stored by the ProCordis Platform:
| Name | Type | Purpose | Category | Retention | Provider |
|---|---|---|---|---|---|
| `better-auth.session_token` | cookie (HttpOnly, Secure, SameSite=Lax) | Maintaining your logged-in session (authentication) | Strictly necessary | About 7 days, renewed on activity | ProCordis |
| Supporting authentication cookies (CSRF protection, login state) | cookie | Security of the login process | Strictly necessary | Session / short-lived | ProCordis |
| `procordis:paymentReturn:*` | sessionStorage | Prevents a payment confirmation being recorded twice when you return from the payment provider | Strictly necessary | Until the browser tab is closed | ProCordis |
| `vite-ui-theme` | localStorage | Remembering your chosen interface theme (light/dark) | Functional | Until you delete it | ProCordis |
| `sidebar_state` | localStorage | Remembering the sidebar state (expanded/collapsed) | Functional | Until you delete it | ProCordis |
| `user-preferences` | localStorage | Remembering your preferences, including interface language | Functional | Until you delete it | ProCordis |
| `ph_*` (analytics) | localStorage + cookie | Product analytics: analytics identifier, Platform usage events, masked session recordings | Analytics — only after you have given consent | 12 months; sooner if you withdraw consent | PostHog (EU region) |
| Payment provider cookies during the payment process | cookie | Completing and securing the payment | Strictly necessary for the payment process | Per the provider’s policy | Stripe Payments Europe, Ltd. |
We do not use marketing cookies or third-party tracking for advertising purposes. We do not sell data collected through cookies or local storage.
3. Categories
3.1 Strictly necessary (no consent required). Items needed to deliver the service you have explicitly asked for — logging in and maintaining your session, security, and correct handling of payments. Under art. 399 of the Polish Act of 12 July 2024 on Electronic Communications Law, which replaced the Telecommunications Law on 10 November 2024, these do not require consent. Without them the Platform cannot function.
3.2 Functional. These remember choices you have made in the interface (theme, language, sidebar layout). They are written only as a result of your own action — switching the theme, for example — and stored locally on your device; they are not used for tracking. You can delete them at any time by clearing site data in your browser.
3.3 Analytics (consent only). For product analytics we use PostHog in the European Union region. Analytics runs only after you have given your voluntary consent — during registration or later in your account settings. Until then, no analytics cookies or localStorage entries are created at all. Consent is voluntary and does not condition your use of the Platform.
We apply the following safeguards:
- IP address capture is disabled;
- session recordings are fully masked — the content of all fields and text is obscured;
- session recording is disabled in the redaction editor and in any view where an unredacted ECG image can appear — no analytics, session-replay or error-reporting tool captures the editor canvas or the image loaded into it;
- analytics data does not include ECG images or analysis results;
- data is sent to a PostHog instance in the EU region.
4. How to withdraw your analytics consent
You can withdraw your analytics consent at any time, as easily as you gave it and without affecting your ability to use the Platform: log in, go to Account settings → the consent and privacy section, and switch analytics consent off.
Once withdrawn, the Platform automatically stops collecting further events and removes all analytics localStorage entries and PostHog cookies from your browser (the `ph_*` keys). Withdrawal is recorded in a versioned consent register and does not affect the lawfulness of processing carried out beforehand.
Independently of the above, you can delete all cookies and local data in your browser settings — this will, among other things, log you out.
5. Why we do not display a cookie banner
The ProCordis Platform does not display a cookie banner because:
- before you log in, only strictly necessary items are used (session, security), which do not require consent;
- functional items are written only as a result of your own deliberate action in the interface;
- analytics items activate only after express consent given by a logged-in user at registration or in settings — that consent is collected through a dedicated, versioned consent mechanism rather than through a banner.
If we later introduce anything other than strictly necessary items on our public pages, we will implement an appropriate consent mechanism and update this Policy.
6. Changes to this Policy
We may update this Policy as the Platform develops — for example, if we add features that use local storage. The current version is always available at https://procordis.ai/cookie-policy. We will tell you about material changes affecting categories that require consent and, where required, ask for fresh consent.
7. Related documents and contact
- Privacy Policy — full information on the processing of personal data (GDPR): https://procordis.ai/privacy-policy;
- Terms of Service: https://procordis.ai/terms;
- questions and requests: contact@procordis.ai; Data Protection Officer: Andrii Maslianyk, iod@procordis.ai;
- you have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.