Cookie Policy
Last updated: 11 June 2026
1. What are cookies
Cookies are small text files placed on your device by a website. They help the site recognise your browser, remember preferences, and keep you signed in.
This policy covers cookies set by app.dividata.nl. We do not control cookies set by third-party identity providers (Microsoft, Google, GitHub) when you authenticate through their sign-in pages.
2. Cookies we use
| Name | Type | Purpose | Duration |
|---|---|---|---|
| authjs.session-token | Strictly necessary | Keeps you signed in to PBI Docs. | 30 days |
| authjs.csrf-token | Strictly necessary | Prevents cross-site request forgery on auth actions. | Session |
| authjs.callback-url | Strictly necessary | Remembers where to redirect after sign-in. | Session |
| sso_state | Strictly necessary | Signed state token used during enterprise SSO OIDC flow. Automatically deleted after sign-in completes. | 5 minutes |
We currently use no analytics, advertising, or tracking cookies. If we introduce optional analytics in the future, we will update this policy and request your consent before setting any such cookies.
3. Strictly necessary cookies
The cookies listed above are strictly necessary to operate the service. They cannot be disabled without breaking sign-in and authentication. Under GDPR, strictly necessary cookies do not require consent.
All our cookies are:
- HttpOnly — not accessible to JavaScript, reducing XSS risk.
- Secure — only transmitted over HTTPS.
- SameSite=Lax or SameSite=Strict — limiting cross-site exposure.
4. How to manage cookies
5. Changes to this policy
We will update this policy if we introduce new cookies. Material changes will be communicated to workspace owners by email at least 14 days before taking effect.
6. Contact
Questions about our cookie practices: privacy@dividata.nl
For broader privacy questions see our Privacy Policy.