Cookie Policy

Last updated: 11 June 2026

1. What are cookies

Cookies are small text files placed on your device by a website. They help the site recognise your browser, remember preferences, and keep you signed in.

This policy covers cookies set by app.dividata.nl. We do not control cookies set by third-party identity providers (Microsoft, Google, GitHub) when you authenticate through their sign-in pages.

2. Cookies we use

NameTypePurposeDuration
authjs.session-tokenStrictly necessaryKeeps you signed in to PBI Docs.30 days
authjs.csrf-tokenStrictly necessaryPrevents cross-site request forgery on auth actions.Session
authjs.callback-urlStrictly necessaryRemembers where to redirect after sign-in.Session
sso_stateStrictly necessarySigned state token used during enterprise SSO OIDC flow. Automatically deleted after sign-in completes.5 minutes

We currently use no analytics, advertising, or tracking cookies. If we introduce optional analytics in the future, we will update this policy and request your consent before setting any such cookies.

3. Strictly necessary cookies

The cookies listed above are strictly necessary to operate the service. They cannot be disabled without breaking sign-in and authentication. Under GDPR, strictly necessary cookies do not require consent.

All our cookies are:

  • HttpOnly — not accessible to JavaScript, reducing XSS risk.
  • Secure — only transmitted over HTTPS.
  • SameSite=Lax or SameSite=Strict — limiting cross-site exposure.

4. How to manage cookies

You can control cookies through your browser settings. Note that blocking strictly necessary cookies will prevent you from signing in to PBI Docs.

5. Changes to this policy

We will update this policy if we introduce new cookies. Material changes will be communicated to workspace owners by email at least 14 days before taking effect.

6. Contact

Questions about our cookie practices: privacy@dividata.nl
For broader privacy questions see our Privacy Policy.