đŸ‡ĒđŸ‡ē Law 506/2004 ¡ GDPR v2.0 ¡ March 2026
Legal Documents

Cookie Policy

This Cookie Policy explains what cookies are, which cookies nocta.chat uses, and how you can control them — in compliance with GDPR (Reg. 2016/679) and Romanian Law 506/2004 implementing the EU ePrivacy Directive.

Effective date
1 March 2026
Legal basis
Consent (Art. 6(1)(a))
Governing law
GDPR ¡ RO Law 506/2004
Consent stored
localStorage — 13 months
§1 What Are Cookies §2 Categories §3 Cookie List §4 Third-Party §5 Consent §6 Manage Cookies §7 Your Rights §8 Changes §9 Contact
✅
Quick Summary

We use only strictly necessary cookies by default. Analytics and marketing cookies are only activated after you give explicit consent via our cookie banner. You can change or withdraw consent at any time. We do not use cookies to track you across other websites.

§ 1

What Are Cookies?

1.1 — Definition

Cookies are small text files placed on your device (computer, tablet, smartphone) when you visit a website. They allow websites to remember information about your visit, such as your preferred language or consent choices. Similar technologies — including localStorage, sessionStorage, and web beacons — serve similar functions and are also covered by this policy.

First-Party Cookies

Set directly by nocta.chat. Used for essential platform functionality, session management, and (with consent) analytics.

Third-Party Cookies

Set by third-party services integrated into our platform (e.g., Stripe for payments, analytics providers). These third parties have their own privacy policies.

§ 2

Cookie Categories

🔒 Necessary Cookies Always Active

These cookies are essential for the website and platform to function correctly. They cannot be disabled. They do not store any personally identifiable information beyond what is strictly necessary for the service to operate.

  • Maintain your session while using the chatbot (session_id)
  • Remember your cookie consent choices
  • Enable secure authentication for the tenant portal and admin panel
  • Prevent cross-site request forgery (CSRF protection)
  • Rate limiting — prevent platform abuse

Legal basis: Art. 6(1)(b) GDPR (performance of contract) + Art. 6(1)(f) (legitimate interest in platform security). No consent required under Romanian Law 506/2004 Art. 4(5)(a) for strictly necessary technical cookies.

📊 Analytics Cookies Consent Required

Analytics cookies help us understand how visitors interact with our website — which pages are most visited, where visitors come from, and how the chatbot widget performs. All data is aggregated and anonymised. No individual profiles are built.

  • Page view counts and session duration
  • Traffic source analysis (referrer URLs)
  • Chatbot widget performance metrics
  • Error tracking and platform reliability monitoring

Legal basis: Art. 6(1)(a) GDPR (consent). Active only after you accept analytics cookies via our banner. You can withdraw consent at any time.

đŸŽ¯ Marketing Cookies Consent Required

Marketing cookies enable us to show relevant advertisements to visitors who have shown interest in nocta.chat. These are managed by third-party advertising platforms and are subject to their respective privacy policies.

  • Retargeting — show nocta.chat ads after you visit the site
  • Conversion tracking — measure effectiveness of advertising campaigns
  • Audience building for lookalike targeting (anonymised)

Legal basis: Art. 6(1)(a) GDPR (consent). Active only after you explicitly accept marketing cookies. You can withdraw consent at any time without affecting your use of the platform.

§ 3

Complete Cookie List

🔒 Necessary

NameTypePurposeDurationSet by
nocta_session_id Necessary Maintains the chatbot conversation session across page loads. UUID only — no personal data. Session (tab close) nocta.chat (sessionStorage)
nocta_consent Necessary Stores your cookie consent choices (necessary/analytics/marketing + version + timestamp). 13 months nocta.chat (localStorage)
nocta_tenant_key Necessary Stores the API key for tenant portal authentication. Only present if you log into /portal. Session (localStorage) nocta.chat (localStorage)

📊 Analytics (requires consent)

NameTypePurposeDurationSet by
_ga Analytics Google Analytics — distinguishes unique users. Anonymised IP. Only loaded after consent. 2 years Google Analytics
_ga_* Analytics Google Analytics 4 — stores and counts page views. Only loaded after consent. 2 years Google Analytics
plausible_* Analytics Plausible Analytics (privacy-first, cookieless) — if activated, uses no cookies. Listed for completeness. N/A (cookieless) Plausible.io

đŸŽ¯ Marketing (requires consent)

NameTypePurposeDurationSet by
_fbp Marketing Meta Pixel — identifies browsers for ad delivery and conversion tracking. Only loaded after consent. 90 days Meta (Facebook)
_gcl_au Marketing Google Ads — conversion tracking and remarketing. Only loaded after consent. 90 days Google Ads

đŸ’ŗ Payment Processor

NameTypePurposeDurationSet by
__stripe_* Necessary Stripe payment processing — fraud detection and secure checkout. Set only when you proceed to payment. PCI-DSS required. Session / 1 year Stripe
§ 4

Third-Party Technologies

â„šī¸
Third-Party Cookie Control

Third-party cookies (Google, Meta, Stripe) are controlled by their respective companies. We only activate these when you give consent (except Stripe, which is necessary for payment processing). Each third party has its own privacy policy governing their cookies. We do not control the data practices of these third parties beyond their contractual DPA obligations with us.

Google Fonts

We load fonts from Google Fonts (fonts.googleapis.com). This sends your IP address to Google's servers. Google may set performance cookies. Google Privacy Policy →

Stripe

When you access the checkout page, Stripe sets security cookies required for PCI-DSS compliant payment processing. These cannot be disabled on checkout pages. Stripe Privacy Policy →

Anthropic / OpenAI

Chat messages are processed by Anthropic/OpenAI APIs. These are server-side API calls — no cookies are set by these providers in your browser. Data is covered in our Privacy Policy.

§ 6

Managing Your Cookie Preferences

6.1 — Via Cookie Settings Panel

You can update your consent preferences at any time by clicking the button below. Changes take effect immediately — analytics and marketing scripts are unloaded if consent is withdrawn.

6.2 — Via Browser Settings

You can also control cookies via your browser. Note that blocking all cookies may affect platform functionality (especially the chat session). Browser instructions:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Options → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies
6.3 — Google Analytics Opt-Out

Install the Google Analytics Opt-out Browser Add-on to prevent data collection by Google Analytics across all sites, regardless of consent settings.

6.4 — Ad Preferences

Manage Google ad preferences at adssettings.google.com. Manage Meta ad preferences at facebook.com/settings?tab=ads.

§ 7

Your Rights Regarding Cookie Data

Cookie data may constitute personal data under GDPR. You have the following rights regarding data collected through cookies:

  • Right to access — request what cookie data we have about you
  • Right to erasure — request deletion of cookie-derived personal data
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — at any time, without consequence
  • Right to complain — to ANSPDCP (anspdcp.ro) or your national DPA

To exercise these rights: privacy@nocta.chat

§ 8

Changes to This Policy

We may update this Cookie Policy when we add or remove cookies, change purposes, or when legal requirements change. When we make material changes we will update the effective date and, where required, seek renewed consent via the banner. The consent version stored in your browser is automatically compared against the current policy version — a new banner will appear if they differ.

  • v2.0 — 1 March 2026 — Updated cookie list, added Stripe and analytics sections, consent versioning
  • v1.0 — 1 January 2026 — Initial publication
§ 9

Contact

Cookie Questions

Email: privacy@nocta.chat
Subject line: "Cookie Policy Query"
Response time: Within 30 calendar days
Operator: Rauta ER PFA, Bucharest, Romania, EU

Supervisory Authority

ANSPDCP — Romania
www.anspdcp.ro

You may also contact the supervisory authority in your EU country of residence. List available at: edpb.europa.eu

Document: Cookie Policy v2.0 ¡ Effective: 1 March 2026 ¡ Next review: 1 September 2026 ¡ Legal basis: GDPR Art. 6(1)(a) + Romanian Law 506/2004 ¡ Controller: Rauta ER PFA, Romania, EU