Back

Cookies policy

Prosio limits the use of cookies to what is strictly necessary for the operation of the service. No advertising cookies, no third-party behavioural tracking cookies are placed.

Last updated · September 12, 2026

1. What is a cookie?

A cookie is a small text file placed by a website on the user's device (computer, smartphone, tablet) and read on subsequent visits. Cookies enable, among other things, the maintenance of an authentication session, the memorisation of preferences or audience measurement.

This policy covers the use of cookies and equivalent technologies (local storage, session storage, fingerprinting) by the prosio.be website and the Prosio application.

2. Legal framework

The placing and reading of cookies are governed:

— for strictly necessary cookies, by the exception provided for in Article 129 § 1, 2° of the Belgian Act of 13 June 2005 on electronic communications (no consent required) ; — for cookies that are not strictly necessary, by the requirement of prior informed consent stemming from the GDPR (Article 6.1.a) and the ePrivacy Directive (2002/58/EC).

3. Strictly necessary cookies

These cookies are essential for the operation of the service and for compliance with security. They do not require consent. Disabling them makes the application unusable.

4. List of cookies used

Supabase session cookies: sb-<project-reference>-auth-token, potentially split into multiple chunks. They maintain and renew the session. The installed SDK defaults to a 400-day cookie lifetime; actual session validity also depends on the authentication server. Not all cookies are HttpOnly.

NEXT_LOCALE: FR/NL/EN language preference managed by next-intl when saved. The current configuration sets no persistent lifetime: a session cookie.

outlook_oauth_state and outlook_oauth_return_to: Microsoft connection security and return path, up to 10 minutes, HttpOnly, SameSite=Lax, Secure in production.

prosio_google_oauth: encrypted Google connection state, up to 10 minutes, HttpOnly, SameSite=Lax, Secure over HTTPS.

This inventory describes current code; cookies actually present depend on the functions used and must be rechecked on the deployed domain.

5. Audience measurement

To date, no third-party audience measurement cookie (Google Analytics, Hotjar, Plausible cloud, etc.) is placed. Any internal usage statistics are exclusively aggregated and anonymised at the service level, without creating a persistent individual identifier or profiling.

6. Third-party cookies

No advertising cookies, retargeting pixels or social network cookies are placed by the prosio.be website or the application.

The Microsoft Azure AD SSO authentication may result in cookies being placed by Microsoft on the login.microsoftonline.com domain, under the editorial and legal responsibility of Microsoft Ireland Operations Ltd.

7. Retention period

Lifetimes differ by cookie; see the inventory above. A browser cookie lifetime does not guarantee that the server session remains valid for that entire period. Deleting sign-in cookies may end your session.

8. Consent

To date, no cookie that is not strictly necessary is placed. Should Prosio introduce such cookies in the future, an informed consent banner would be displayed, in accordance with the recommendations of the Belgian Data Protection Authority (recommendation no. 01/2015 and subsequent EDPB guidelines).

9. Management by the user

The user may at any time delete cookies from the settings of their browser (Chrome, Firefox, Edge, Safari, etc.) or refuse their placement by configuring their browser accordingly.

The deletion or blocking of strictly necessary cookies will result in the user being logged out of the service and the application becoming unusable until reconnection.

10. Contact

For any question relating to this cookie policy: contact@prosio.be.