Corresso All legal documents

Cookie declaration

Effective [not yet set]

These are all the cookies Corresso sets. Corresso sets each of them itself, and each is strictly necessary: without them you could not sign in, or submit a form safely. Cookies that are strictly necessary for a service you have asked for need no consent under Danish law (Cookiebekendtgørelsen, BEK nr. 1148 af 9. december 2011, § 4, stk. 1, nr. 2), so there is no cookie banner. We publish this declaration anyway, so you can see exactly what your browser keeps.

Name Set by Purpose Duration Category
session_id Corresso (first party) Keeps you signed in. It holds only a signed number that points to your sign-in on our server, which ends when the cookie does. 30 days from when you sign in, or until you sign out Strictly necessary
_corresso_session Corresso (first party) Protects forms against cross-site request forgery, carries one-off messages such as “Password has been reset”, remembers the page to return to after signing in, and holds a random value our content security policy uses to tell our own scripts from injected ones. It is encrypted, so it cannot be read or changed in the browser. Until you close your browser Strictly necessary

How they are protected

Each is sent only over HTTPS, cannot be read by scripts on a page (HttpOnly), and is not sent with requests that other websites make in the background (SameSite=Lax).

What we do not use

Removing them

Signing out deletes session_id, and closing your browser deletes _corresso_session. You can delete both at any time in your browser’s settings; you will then simply be signed out.

The personal data involved

session_id holds only a signed number pointing to your sign-in on our server, which records the IP address and browser you signed in from. Our privacy notice explains how we handle that.