Privacy and cookies

How Veyra uses access cookies

This notice explains the first-party cookie used to provide authenticated account access. It is an operational cookie notice, not a substitute for jurisdiction-specific legal advice.

Controller

Name
Veyra
Address
"Soon to be added"
Privacy contact
ramirezian037+veyra@gmail.com

Access cookie

Name
veyra_browser_session
Type
First-party, HttpOnly, SameSite=Lax authentication cookie.
Purpose
Identifies the server-side browser session so Veyra can keep a signed-in user’s requested account access, account switching, logout, and session security controls working.
Retention
Up to 30 days while the browser session remains valid; it is expired when the session is ended.
Consent
This cookie is used only where it is strictly necessary to provide the authenticated service requested by the user. It is not used for analytics, advertising, or cross-site tracking, so this notice does not ask for consent to set it.
Legal basis
The related account-access processing is intended to rely on Article 6(1)(b) GDPR where necessary to provide the requested service. Security processing may rely on Article 6(1)(f) where the controller’s documented balancing test supports it.
Recipients
Access data is processed by the configured Veyra application infrastructure and its authorized hosting or service providers. The controller must document any international transfers and applicable safeguards in the complete privacy notice.

Data protection

The cookie value is an opaque token. Veyra stores a hash of the browser token and keeps application session secrets server-side. Access-cookie processing is limited to account authentication, session security, and the requested application service. It is not reused for unrelated profiling or marketing.

Blocking or deleting this cookie can prevent authenticated features from working. Public pages remain available without accepting non-essential cookies because this deployment does not set analytics or marketing cookies.

Your rights and choices

For access, correction, deletion, restriction, objection, portability, or other privacy requests, contact the configured privacy contact. You can also delete the access cookie in your browser; doing so signs you out or prevents the authenticated service from being used.