Skip to content
Trust / Cookie noticeVersion 1.4 · Effective 25 Sep 2026
Version 1.4, effective 25 Sep 2026

Cookie notice

What we store in your browser on veil.pritect.ai, why, and how to change your mind. The short version: what the service cannot run without, plus analytics on the public pages if you agree to them.

This notice covers veil.pritect.ai, both the public pages and the signed-in application. It sits alongside the Privacy notice, which covers personal data more broadly.

The domain is the boundary: this notice covers veil.pritect.ai only, and the parent domain pritect.ai is a different site that sets its own cookies, asks for its own consent and answers for them in its own cookie notice, so a decision made on one of the two is not a decision about the other.

1What we set, and what we do not

1.1

On the public pages, Veil sets strictly necessary cookies and, if you agree to them, the two analytics cookies in section 2.3. Nothing else. There is no advertising cookie, no social media cookie and no cross-site tracking on this domain.

Behind sign-in the answer is what it has always been: strictly necessary cookies only. The application loads no analytics tag on any page, so there is nothing there for a banner to ask about, and the consent banner itself loads on the public pages only.

The analytics cookies are set only after you accept the analytics category. Until then the tag that would set them is never requested, so declining is not a cleanup after the fact. The script does not run at all.

1.2What a cookie is

A cookie is a small piece of data a site asks your browser to store and send back on later requests. Related technologies do the same job by other means: local storage and session storage keep data in the browser without attaching it to requests.

This notice covers all of them, because the legal test is whether we store or access information on your device, not which mechanism we use.

2The cookies we set

2.1Strictly necessary

These cannot be switched off through the banner, because switching them off would break sign-in or lose your place in the application. They are exempt from consent under Article 5(3) of the ePrivacy Directive as strictly necessary for a service you have requested.

Signing out clears the session cookie, and the organisation cookie is cleared with it.

The consent banner is Pritect Beacon, the consent platform from our own product family. Besides the entries below that keep your decision in your browser, it sends a record of the decision and its timestamp to Beacon's consent log, which is how we evidence the choice. Your browser also asks the same place for the banner's settings and for which privacy regime applies to your location, so the right banner is shown. All of this runs in a Supabase project of Beacon's own, separate from the one this service uses, which Supabase hosts in Ireland, in the European Union.

NameSet byPurposeDuration
sb-<project>-auth-tokenSupabaseHolds your authenticated session so you stay signed in between requests. Split across numbered parts when the token is long1 year, refreshed on use
veil-active-orgPritect VeilRemembers which organisation you last worked in, so the application opens on the right tenant1 year
pb_consentPritect BeaconRecords your consent decision and its timestamp, so we do not ask again on every page and can evidence the choice12 months

2.2Browser storage

These are not cookies and are never sent to a server. They stay in your browser.

KeySet byPurposeDuration
themePritect VeilRemembers whether you chose the dark or the light interface, so the page does not flash the wrong one on loadUntil cleared
pb_consent_<domain>Pritect BeaconThe full record of your decision per category, which is what the preferences panel reads when you reopen itUntil cleared
pb_geoPritect BeaconCaches which privacy regime applies to your location, so the correct banner is shown without repeating the lookupUntil cleared

2.3Analytics

These are set by Google Analytics 4, on the public pages only and only after you accept the analytics category in the consent banner. They are not set on any page behind sign-in, and they are not set at all if you decline or simply never answer.

The lawful basis is your consent, under Article 5(3) of the ePrivacy Directive and Article 6(1)(a) GDPR. Withdraw it at any time through the cookie preferences link in the footer. Withdrawing stops the tag from sending anything further, deletes both cookies below and reloads the page without them, and no page you open afterwards loads the tag at all.

Pritect Beacon classifies both of these under the Analytics category, which is the switch in the preferences panel that controls them.

NameSet byPurposeDuration
_gaGoogleDistinguishes one visitor from another, so a repeat visit is not counted as a new one. It holds a randomly generated identifier and nothing else13 months
_ga_<property>GoogleHolds the state of the current visit for the single Google Analytics property this site uses, so the pages you read in one visit are counted as one visit. The suffix is our measurement id with its leading G and hyphen removed13 months

2.4The live register

The table below is generated by Pritect Beacon from an automated scan of this site rather than written by hand. It is the same register we would hand an auditor. If it disagrees with the tables above, the tables above are out of date and we want to hear about it.

3Your choices

3.1Changing your decision

Use the cookie preferences link in the footer of any page. On the public pages it reopens the consent panel where you are; inside the signed-in application, where the consent platform does not load, it opens this notice and the panel with it. Either way you can review the categories and change your answer at any time. Withdrawing consent is as easy as giving it.

3.2Through your browser

Every major browser lets you block or delete cookies for a specific site. Blocking the strictly necessary cookies above will prevent you from signing in, because the session has nowhere to live. The public pages will continue to work.

3.3Do Not Track and Global Privacy Control

We honour the Global Privacy Control signal where the applicable law gives it effect. Where it applies, it is treated as a refusal of the analytics category, and because the analytics tag is requested only on an explicit acceptance, a refusal means it is never fetched and neither analytics cookie is set. The strictly necessary cookies are unaffected, because they do not depend on consent.

4Changes and contact

4.1

If we introduce a cookie that is not strictly necessary, this notice is updated and the banner asks for consent before that cookie is set. That is what happened with the analytics cookies in section 2.3, and it is what will happen with anything after them.

Prior-consent blocking is enforced by the consent platform, which holds non-essential scripts before they execute rather than cleaning up afterwards. The analytics tag is gated a second time in the application code, which does not request it until a decision granting the analytics category has been recorded.

4.2

Questions about this notice go to privacy@pritect.ai.

Questions about this document

Write to legal@pritect.ai, or to privacy@pritect.ai for anything about personal data. White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, Norway.

White Label Consultancy AS, Fjordalleen 16, 0250 Oslo, NorwayVersion 1.4 · Effective 25 Sep 2026

Live cookie register

Generated by Pritect Beacon from its most recent scan of this site. It is empty until the first scan of a deployed build completes.