# Cookie Policy

Last updated: April 30, 2026.

## 1. Purpose

This policy explains which cookies and trackers are used on Harmate, why they are used, and which choices you have.

## 2. Consent Principle

Harmate applies explicit opt-in for analytics cookies:

- strictly necessary cookies: enabled by default;
- analytics cookies: enabled only after explicit consent.

Rejecting is as easy as accepting.

## 3. Cookie Categories

### 3.1 Strictly necessary cookies

These cookies are required for core service operation, including:

- authentication and session continuity;
- application security;
- essential technical preferences.

Without these cookies, core services cannot operate correctly.

### 3.2 Analytics cookies (optional)

These cookies are used to measure product usage and improve experience.

They are set and used only after explicit consent.

Tools currently used:

- Google Analytics;
- PostHog.

## 4. Consent Management

User choice is stored in a dedicated cookie:

- name: `eu-consent`
- content: choice (`accepted` or `rejected`) + timestamp
- duration: 180 days

You can change your choice at any time via `Cookie Settings`.

## 5. Analytics Data Collected

After consent, Harmate collects audience and navigation metrics with minimization:

- raw URL query strings are removed from tracked URLs;
- useful attribution signals are retained (for example `utm_*`, `gclid`, `fbclid`);
- aggregate metadata is kept for URL query usage (presence/count).

## 6. Transfers And Processors

Depending on analytics providers, some processing may involve transfers outside the EU.  
Such processing is framed under applicable legal transfer mechanisms for each provider.

## 7. Retention And Deletion

- The consent cookie automatically expires after 180 days.
- Other retention periods depend on provider policies and applicable service configurations.

## 8. Your Rights

You can:

- accept or reject analytics cookies;
- change your choice at any time;
- exercise GDPR rights via `contact@harmate.com`.

You may also lodge a complaint with the CNIL: <https://www.cnil.fr/>.
