Cookie policy
This cookie policy explains which cookies and similar techniques pagewren.com and the PageWren client portal (portal.pagewren.com) use, what we use them for, and how you can manage them. It supplements our privacy statement and is based on art. 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet) and the General Data Protection Regulation (GDPR).
1. Who is responsible?
Picazzo Research & Development (trade name PicazzoLabs; PageWren is a PicazzoLabs service), Zinkstraat 24, Box C4687, 4823 AD Breda, the Netherlands — KvK 42060545, VAT NL005464235B85 — is the controller for the personal data processed through cookies and similar techniques on this website and the client portal. Contact: [email protected].
2. What are cookies and similar techniques?
A cookie is a small text file that a website places on your device and reads back later. Besides cookies there are comparable techniques that serve the same purpose: storing or reading data on your device, or recognising your device remotely — such as local storage in your browser, third-party scripts and pixels, and device fingerprinting. This policy treats all these techniques the same way, regardless of their technical name. Whether a technique requires prior consent depends on its purpose and its effect on your privacy — not on what it is called.
3. Our default: no tracking or advertising cookies
This website is privacy-friendly by design. We place no tracking or advertising cookies and use no external analytics. We do not follow you across other websites and we do not build advertising profiles of you. The public landing page at pagewren.com sets no cookies at all.
4. Functional/necessary techniques
Some techniques are strictly necessary for this website to work properly. No prior consent is required for these (art. 11.7a(3) Telecommunicatiewet), because they have no — or only a negligible — effect on your privacy. Exemption from the consent requirement does not exempt us from the duty to inform you, so here they are:
- Portal login session — when you sign in to the client portal with your email address and one-time code, we set a session cookie (
pw_session) so you stay signed in during and between visits. It is an HttpOnly cookie, used solely for authentication; it is not used to track you. - Cloudflare security cookies — our infrastructure provider Cloudflare may set cookies (names starting with
cf_or__cf, such as__cf_bm) to distinguish real visitors from malicious automated traffic and to protect the site against attacks. These are strictly functional security cookies.
| Name | Provider | Purpose | Retention | Type |
|---|---|---|---|---|
pw_session |
PageWren (portal.pagewren.com, first-party) | Keeps you signed in to the client portal after email + one-time-code login | 30 days | Functional/necessary — exempt from the consent requirement (art. 11.7a(3) Telecommunicatiewet) |
__cf_bm and other cf_* cookies |
Cloudflare | Security: bot detection and protection against malicious traffic | Typically up to 30 minutes; varies per cookie (see Cloudflare's cookie documentation) | Functional/necessary — exempt from the consent requirement (art. 11.7a(3) Telecommunicatiewet) |
Payments: billing and payment happen on pages hosted by Stripe (the Stripe customer billing portal). Any cookies used during checkout on Stripe's own pages are set by Stripe on its own domain and are covered by Stripe's own cookie policy.
5. Fonts loaded from Google (not a cookie, but a data transfer)
This website loads its fonts (Bricolage Grotesque and Instrument Sans) from Google Fonts, a service of Google. This sets no cookie, but it does mean that when a page loads, your browser requests the font files from Google's servers and thereby sends your IP address (together with standard technical request data) to Google, which acts as an independent controller for that request. This can involve a transfer to servers in the United States, which takes place under appropriate safeguards: the EU–US Data Privacy Framework and, as a fallback, the standard contractual clauses adopted by the European Commission (art. 46 GDPR). We are honest about this: hosting the font files ourselves would avoid this transfer entirely, and we are evaluating that change.
6. Why there is no cookie banner
Dutch and EU rules require prior consent (a cookie banner) only for cookies and similar techniques that are not strictly necessary — such as tracking, advertising or third-party analytics cookies. This website uses only the strictly functional techniques listed above, which are exempt. That is why you do not see a cookie banner. If we ever add a technique that requires consent, we will update this policy first and ask for your consent before that technique loads.
7. Managing or deleting cookies in your browser
You can always manage, block or delete cookies and local storage yourself through your browser settings. Note that blocking or deleting certain techniques may stop parts of this website from working properly — for example, deleting pw_session signs you out of the client portal.
8. Your rights
For the personal data processed through cookies and similar techniques, you have the same rights as described in our privacy statement: among others access, rectification, erasure, restriction, objection and data portability. If you have a complaint about how we handle this data, please contact us first at [email protected]. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (art. 77 GDPR, autoriteitpersoonsgegevens.nl).
9. Changes
We may update this cookie policy when we add or remove a technique, or when laws or regulations require it. The date at the top shows the latest revision.
