Cookie Policy

Effective: January 1, 2025 Last updated: January 30, 2026 Questions? privacy@auditrail.eu

1. Introduction

This Cookie Policy explains how Auditrail ("we," "our," or "us") uses cookies and similar tracking technologies when you use our compliance tool service ("Service").

2. What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.

3. Types of Cookies We Use

### 3.1 Essential Cookies These cookies are necessary for the Service to function and cannot be switched off. **Purpose:** - Maintain your authentication session - Remember your preferences (theme, sidebar state) - Ensure security and prevent fraud **Examples:** - Session cookies for authentication - CSRF protection tokens - Preference storage (appearance, sidebar state) **Retention:** Session-based or up to 1 year for preferences ### 3.2 Analytics Cookies (Optional) These cookies help us understand how visitors use the Service. They are only enabled with your consent. **Purpose:** - Analyze usage patterns - Improve Service functionality - Understand user behavior **Retention:** Up to 2 years **Note:** Analytics cookies are feature-flagged and only active if analytics is enabled in our configuration and you have provided consent.

4. Third-Party Cookies

### 4.1 Authentication (WorkOS) - WorkOS uses cookies for authentication and session management - These are essential for Service functionality - See WorkOS privacy policy for details ### 4.2 Payment Processing (Paddle) - Paddle may use cookies for payment processing - These are essential for billing functionality - See Paddle privacy policy for details

6. Managing Cookies

### 6.1 Browser Settings You can control cookies through your browser settings: - **Chrome:** Settings > Privacy and security > Cookies and other site data - **Firefox:** Options > Privacy & Security > Cookies and Site Data - **Safari:** Preferences > Privacy > Cookies and website data - **Edge:** Settings > Privacy, search, and services > Cookies ### 6.2 Impact of Disabling Cookies - Disabling essential cookies will prevent the Service from functioning properly - You may not be able to log in or access your account - Some features may not work as expected

7. Local Storage and Similar Technologies

### 7.1 Local Storage We use browser local storage to: - Store theme preferences - Remember sidebar state - Store cookie consent preferences (if applicable) ### 7.2 Session Storage We use session storage for: - Temporary data during your session - Form state and user interface preferences

8. Analytics and Tracking

### 8.1 Analytics Status - Analytics tracking is feature-flagged and disabled by default - Analytics only activates if: - Enabled in our configuration (`MARKETING_ANALYTICS_ENABLED=true`) - You provide explicit consent through our consent banner ### 8.2 What We Track (If Enabled) - Page views and navigation patterns - Feature usage and interactions - Error rates and performance metrics - Aggregated, anonymized usage statistics ### 8.3 What We Don't Track - Personal identifying information in analytics - Individual file contents or evidence data - Cross-organization data or comparisons - Sensitive compliance information

9. Third-Party Services

### 9.1 Embedded Content Some pages may contain embedded content from third parties (e.g., documentation, help resources). These third parties may set their own cookies. ### 9.2 Links to External Sites Our Service may contain links to external websites. We are not responsible for the cookie practices of external sites.

11. Contact Us

For questions about our use of cookies, contact us at: - Email: privacy@auditrail.eu - Support: support@auditrail.eu

12. Additional Resources

- [Privacy Policy](/privacy-policy) - How we handle your personal information - [Terms of Service](/terms-of-service) - Terms governing your use of the Service