Cookie policy
Which cookies and similar technologies we use and how to change your choice.
Content: Cookie policy
Draft – requires legal review before publication. Items marked “to be completed” will be filled in once confirmed by the Seller.
This English version is provided for customers using the English version of the website. [to be completed: whether contracts are concluded in English and which language version prevails – any clause giving priority to the Polish version requires legal review with regard to consumers.]
This policy describes which cookies and similar technologies (localStorage, sessionStorage) the AutomaizeIT website uses, why, and how you can change your choice. The rules follow Article 5(3) of Directive 2002/58/EC (ePrivacy Directive) and the Polish Electronic Communications Law of 12 July 2024.
In brief
- We only use essential storage – to protect the forms (order, registration, sign-in), to keep you signed in to your customer account, for the admin panel session and to remember your choice.
- Diagnostic data about how the website works is collected only with your consent and sent only to our own server.
- Bot protection for forms is provided by Cloudflare Turnstile – it is not a tracking or advertising tool; the storage it needs to run the check is essential for the form to work and requires no consent.
- We do not use advertising cookies or third-party tracking tools. Fonts are hosted locally.
List
| Name | Type | Purpose | Category | Duration | Provider |
|---|---|---|---|---|---|
csrf_zam |
cookie (HttpOnly) | protects the public forms (order, account registration, sign-in, password reset) against CSRF attacks | essential | 2 hours | AutomaizeIT (first party) |
konto_sesja |
cookie (HttpOnly, SameSite=Lax) | keeps you signed in to your customer account; the cookie holds only a random token, and we store only its hash on the server | essential | until sign-out, a password change or session expiry – 30 days at most | AutomaizeIT (first party) |
sesja_admin |
cookie (HttpOnly, /admin path only) | session of the logged-in admin panel user – does not apply to visitors | essential | until logout or the browser is closed | AutomaizeIT (first party) |
csrf_logowania |
cookie (HttpOnly, /admin path only) | protects the admin login form – does not apply to visitors | essential | 30 minutes | AutomaizeIT (first party) |
zgoda |
localStorage | remembers your consent choice (policy version, categories, time) so we don't ask again and you can change it | essential | until you change your choice or clear browser data | AutomaizeIT (first party) |
dz_s |
sessionStorage | random tab session ID for the diagnostic log | analytics / diagnostics (with consent) | until the tab is closed | AutomaizeIT (first party) |
dz_k |
sessionStorage | temporary record of a click time – to measure how long it takes to open the next page | analytics / diagnostics (with consent) | removed after the measurement, at the latest when the tab is closed | AutomaizeIT (first party) |
Bot protection for forms (Cloudflare Turnstile)
On pages with a form (contact, registration, password reset, sign-in after a series of failed attempts, order) – while the protection is switched on – we load the Cloudflare Turnstile script. It checks whether the form is being filled in by a person or by an automated script. Turnstile sets no advertising or tracking cookies and is not used for profiling; whatever it stores in the browser is needed only to run and recognise the check for that one form submission. We therefore classify it as essential – just like CSRF protection – and do not ask for consent (Art. 5(3) of Directive 2002/58/EC: storage strictly necessary to provide a service explicitly requested by the user).
Cloudflare, as the provider, receives the IP address and browser data of the person filling in the form. The scope and legal bases of that processing, including transfers outside the EEA, are described in the Privacy policy.
Without JavaScript the widget will not appear and the form cannot be sent – in that case please contact us by e-mail (the address is in the footer and on the contact page).
Customer account session
The konto_sesja cookie is essential for using the customer account – without it you cannot stay signed in. It is set only after you sign in and requires no consent, because it serves solely to provide the service you have asked for. You can end a session with the “Sign out” button, and changing your password invalidates all sessions; the list of active sessions (browser, time of creation and of last activity) is shown in your account. The session data is described in the Privacy policy.
Diagnostic log
If you consent to the “Analytics and diagnostics” category, the website's script records interface events: clicks (label of the clicked element), page load times and JavaScript errors, together with a random tab session ID. The data is sent only to the AutomaizeIT server and stored in a technical log with a hashed IP address. We do not combine it with form data or share it with third parties. Processing details: Privacy policy.
Without consent – or if JavaScript is disabled – the diagnostic log does not run.
Server logs
Regardless of consent, the server keeps technical logs of HTTP requests with a hashed IP address for security and diagnostics (legitimate interest). Server logs do not require storing anything on your device.
Application licence verification
The applications sold on the Website connect to our licence server to activate and periodically verify the licence. This does not store anything in your browser and uses no cookies, so it requires no cookie consent. The data sent (licence identifier, hashed device identifier, application and operating system version, shortened IP address) is described in the Privacy policy, and how the protection measures work is set out in § 9 of the Terms of sale.
Visitor statistics
Visitor statistics do not use cookies or any other storage on your device – they are counted on the server in aggregated form (see the privacy policy), so they do not require consent.
How to change or withdraw consent
- Click “Cookie settings” in the footer of any page – a window opens where you can accept, reject or change your choice. Withdrawing consent is as easy as giving it.
- Each decision is recorded in the consent log (decision ID, policy version, categories, time, hashed IP) so that we can demonstrate that consent was given or withdrawn.
- When this policy's version changes, we will ask you to choose again.
Browser settings
You can also delete stored data or block cookies in your browser settings (usually under “Privacy” or “Cookies and site data”). Blocking essential cookies will prevent you from placing an order and from signing in to your customer account; deleting localStorage data will make the consent window appear again.
Payments
Once you move to the Przelewy24 payment page, the payment operator's (PayPro S.A.) rules apply – the operator's website may use its own cookies in line with its policy.
Version 1.2 of 21 September 2026. Version 1.2 adds a description of bot protection for forms (Cloudflare Turnstile) and classifies it as essential. Earlier versions: 1.1 added the customer account session cookie (konto_sesja), extended the description of the csrf_zam cookie to cover account forms, and explained that application licence verification uses no cookies; 1.0 – the original version.
