Cookie Notice
This Cookie Notice explains how BerrySoft.cz ("we", "us") uses cookies and similar technologies on this website. As of 3 Sep 2025 we deploy: (a) strictly necessary (essential) first‑party cookies / local storage and (b) Google Analytics cookies used to understand aggregate usage and performance. Analytics cookies are not strictly necessary and rely on your prior consent under Art. 6(1)(a) GDPR. No advertising / marketing or social media tracking cookies are set.
1. What Are Cookies?
Cookies are small text files placed on your device that allow a website to recognize your browser. They perform functions like maintaining a logged‑in session, remembering preferences, and enhancing security. Some cookies only last for the session; others may remain longer unless you clear them.
2. Summary of Cookies / Storage
Name / Key | Purpose | Type | Retention | Essential | Legal Basis |
---|---|---|---|---|---|
PHPSESSID | Maintains your authenticated session and security context. | HTTP cookie (first‑party) | Session (deleted when browser closes) | Yes | Art. 6(1)(b) & (f) GDPR (service delivery & security) |
bs_lang | Stores your chosen interface language. | HTTP cookie (first‑party) | 12 months (or until you clear cookies) | Yes (preference) | Art. 6(1)(f) GDPR (user experience preference) |
localStorage: bs_cookie_consent_v1 / v2 | Records your consent choice (accepted / declined) and version for audit and to avoid repeatedly showing the banner. | Local Storage (first‑party) | Until deleted by you or version changes | Yes (functional compliance) | Art. 6(1)(c) & (f) GDPR (legal compliance & legitimate interest) |
_ga | Google Analytics – distinguishes users (random identifier). | HTTP cookie (third‑party: Google) | 24 months | No | Art. 6(1)(a) GDPR (consent) |
_ga_* (e.g. _ga_123ABC) | Google Analytics – session state / attribution for property. | HTTP cookie (third‑party: Google) | 24 months | No | Art. 6(1)(a) GDPR |
_gid | Google Analytics – distinguishes users per day. | HTTP cookie (third‑party: Google) | 24 hours | No | Art. 6(1)(a) GDPR |
_gat / _ga_<container>_temp | Google Analytics – throttles request rate. | HTTP cookie (third‑party: Google) | 1 minute | No | Art. 6(1)(a) GDPR |
We do not set advertising, social media, or profiling cookies. Analytics identifiers are pseudonymous and used only in aggregate form.
3. Categories (Current & Future)
- Essential: Required for core functionality (authentication, security, language, consent log). Cannot be declined individually.
- Analytics (Active – Google Analytics): Help us understand aggregate usage (page views, device categories, referrers) to improve reliability and capacity planning. Activated only after consent; you can withdraw anytime.
- Marketing: Not in use.
- Performance / UX extras: Not in use.
If future non‑essential categories are introduced they will require separate consent. Banner granularity may be expanded accordingly.
4. Legal Bases
Essential cookies are necessary to provide the service you request (Art. 6(1)(b)) and to protect platform security (Art. 6(1)(f)). The consent record supports legal compliance (Art. 6(1)(c)/(f)). Google Analytics runs only with your prior consent (Art. 6(1)(a)); you may withdraw consent at any time via the Cookie Settings link without affecting prior lawful processing.
5. Managing & Withdrawing Consent
You can revisit your choice via the Cookie Settings link in the footer to reopen the banner and revoke analytics consent (which will disable further GA loading). Already collected anonymized / aggregated analytics data may persist until standard retention expiry. You can also delete cookies or clear site data directly in your browser. Instructions:
- Chrome / Edge: Settings > Privacy & Security > Cookies and other site data.
- Firefox: Settings > Privacy & Security > Cookies and Site Data.
- Safari: Settings/Preferences > Privacy > Manage Website Data.
- Mobile browsers: See the Help / Privacy sections in the app’s settings.
Declining optional cookies (when introduced) will not degrade core functionality, though some enhanced features may be unavailable.
6. Your Data Protection Rights
Subject to conditions and applicable law, you have rights to access, rectification, erasure, restriction, objection, and data portability, plus the right to lodge a complaint with the Czech Data Protection Authority (ÚOOÚ). For any request, contact us at info@berrysoft.cz. We may need to verify your identity before fulfilling a request.
7. Security & Data Minimization Measures
We apply security headers (CSP, HSTS, X-Frame-Options), rate limiting and pseudonymous analytics identifiers. IP addresses are truncated/anonymized before storage by Google (per GA configuration). No marketing trackers are loaded.
8. International Transfers (Analytics)
Google Analytics services are provided by Google Ireland Limited (EU) with infrastructure that may involve transfer to Google LLC in the United States. Standard Contractual Clauses (SCCs) and supplementary measures are relied upon. Residual risk of third‑country access is considered low and proportionate to the limited analytical data (no direct identifiers). You may decline analytics if concerned.
9. Updates to This Notice
Material changes (e.g., new categories) will appear here with a new date and, if required, a renewed consent prompt.