Skip to content

Cookie Policy

Last updated: June 5, 2026 · Effective: June 5, 2026

1. What This Policy Covers

This policy explains which cookies and similar technologies GDPR Fix ("we", "us", "our") places on your device when you use gdprfix.eu, why we set them, and how you can control them. For how we handle personal data more broadly, see our Privacy Policy.

Cookies are small text files a website stores on your device. They can be first-party (set by the site you visit) or third-party (set by another domain), and they expire after a session or a fixed duration.

2. Our Approach: Necessary Cookies Only

We practice what we preach. GDPR Fix uses only strictly necessary and user-requested preference cookies, which are exempt from consent under Article 5(3) of the ePrivacy Directive.

We use zero analytics cookies, zero tracking pixels, zero marketing cookies, and zero third-party cookies. External images on our pages (such as directory badges) are served through our own first-party proxy, so the third parties behind them never receive a request from your browser and cannot set cookies on it.

3. Cookies We Set

The complete list — every cookie named, with provider, purpose, and duration, as GDPR Article 13 requires:

Cookie NameProviderPurposeCategoryDuration
authjs.session-tokenGDPR Fix (1st party)Maintains your authenticated session after sign-inStrictly necessary30 days
authjs.csrf-tokenGDPR Fix (1st party)Protects against cross-site request forgeryStrictly necessarySession
authjs.callback-urlGDPR Fix (1st party)Stores the redirect URL during OAuth sign-inStrictly necessarySession
themeGDPR Fix (1st party)Remembers your light/dark mode choice. Set only when you use the theme toggle.Preference (user-requested)1 year

The authjs.* cookies are set only when you sign in. If you never create an account, the only cookie you may receive is theme — and only if you use the light/dark mode toggle.

4. Similar Technologies (localStorage)

We use your browser's localStorage for one item:

KeyPurposeDuration
gdprfix-consentRemembers the choices you made in our cookie preferences dialog, so we don't ask again on every visitUntil you clear it or change your preferences

This value never leaves your browser — it is not transmitted to us or to anyone else.

5. Legal Basis

Strictly necessary cookies are exempt from the consent requirement under Article 5(3) of Directive 2002/58/EC (ePrivacy Directive), as they are essential to provide the service you explicitly request (authentication, security). The theme preference cookie is set only in direct response to your action and stores a choice you asked us to remember.

If we ever introduce cookies that require consent (e.g., analytics), they will be loaded only after you opt in through our consent dialog — never before.

6. Managing Cookies

You can review or change your preferences at any time via Cookie Settings in the footer. Beyond that:

  • Every browser lets you view, block, and delete cookies (usually under Settings → Privacy). Blocking our strictly necessary cookies will prevent sign-in from working.
  • Deleting the theme cookie simply resets the site to its default appearance.
  • Clearing site data removes the gdprfix-consent entry, and the consent dialog will appear again.

7. Changes to This Policy

If we add, remove, or change cookies, we will update the tables above and the "Last updated" date. Material changes (such as introducing any consent-requiring cookie) will be announced via the consent dialog before they take effect.

8. Contact

Questions about this policy or our use of cookies: