How it works Who it is for Company Monitor Company Search Company Profile Pricing Guides API Reference Changelog Registry activity

Cookie Policy

Version 1.0 · Published: 7 August 2026 · Effective: 21 August 2026

1. General provisions

This Cookie Policy describes the rules for using cookies and similar technologies within the following services:

  • https://entiway.com – the public website,
  • https://app.entiway.com – the user Panel,
  • https://api.entiway.com – the API interface.

Depending on the domain, the scope of the technologies used differs and is described separately in points 4–6.

The rules for processing personal data are described in a separate Privacy Policy.

2. What cookies and similar technologies are

Cookies are small pieces of text information stored on the end device of the User in connection with the use of a website. They may be used to ensure the correct operation of the service, maintain sessions, provide security, remember preferences or carry out analytics.

Similar technologies means in particular the local storage of the browser (localStorage and sessionStorage), which stores data on the device of the User but – unlike cookies – is not automatically sent to the server with every request.

By lifetime, a distinction is made between:

  • session cookies – deleted automatically when the browser is closed,
  • persistent cookies – stored for a specified period or until deleted by the User.

3. The Entiway approach to cookies

Entiway uses exclusively cookies and mechanisms that are technically necessary to provide the service requested by the User. We do not use marketing, advertising, tracking or profiling cookies. We do not share cookie data with advertising networks or data brokers.

Analytics on the public website operates in cookieless mode, as described in point 4.

For this reason we do not use a cookie consent banner. Under the Act of 12 July 2024 – Electronic Communications Law, the consent of the User is not required for storing information on the end device where this is necessary to carry out a transmission or to provide a service expressly requested by the User. Only such cases occur in Entiway.

The category of necessary mechanisms also includes protection against automated traffic and network attacks, provided by the network layer provider Cloudflare, described in points 7 and 8.

4. entiway.com – the public website

The public website uses technically necessary session mechanisms required for:

  • handling the contact form available on the website,
  • protecting forms against abuse and request forgery attacks,
  • remembering the language version selected by the User.

The public website runs our own, self-hosted instance of Matomo Analytics, installed on a private server of the Controller. Analytics operates in cookieless mode (disableCookies) and with IP address anonymisation enabled – no Matomo cookies are stored on the device of the User for analytics purposes. The statistical data is aggregated only and is not linked to identified natural persons.

Traffic directed to the public website passes through the Cloudflare network protection layer, which may store on the device of the User the security cookies described in points 7 and 8.

The public website does not use marketing cookies or third-party tracking technologies.

5. app.entiway.com – the Panel

The Panel uses technically necessary cookies and session mechanisms required for:

  • logging in and maintaining the session of the User,
  • protecting forms and requests against abuse,
  • the correct operation of the Panel and of processes relating to authentication and security,
  • remembering basic interface preferences, including language version and time zone.

In addition to cookies, the Panel uses browser local storage in two cases:

  • remembering the selected interface theme – light or dark – in localStorage; this value is solely an appearance preference and is not sent to the server,
  • transferring data between the successive steps of the Account access recovery procedure – in sessionStorage; this data is deleted immediately after the procedure ends, and at the latest when the browser tab is closed.

Traffic directed to the Panel passes through the Cloudflare network protection layer, which may store on the device of the User the security cookies described in points 7 and 8.

These cookies are necessary in nature and are required for the correct provision of the electronic service in the Panel. Disabling these mechanisms in the browser makes it impossible to log in and use the Panel.

6. api.entiway.com – the API

The API does not use cookies to authorize use of the service. Access to the API takes place exclusively using API Tokens sent in the request header. API responses do not contain headers setting cookies.

Traffic directed to the API passes through the Cloudflare network protection layer. Where an anti-bot verification is triggered for a request originating from a browser, Cloudflare may store the security cookies described in points 7 and 8. They do not serve authorization purposes and are not used by Entiway.

If browser-based helper tools are made available in this domain in the future, they may use exclusively the technically necessary mechanisms required for their operation, and this document will be updated accordingly.

7. List of cookies and similar technologies used

The list below covers the technical names and storage periods of all technologies used in the individual services.

Name Type Storage period When it is created Purpose
entiway.com
entiway-session Cookie (HttpOnly, Secure, SameSite=Lax) 2 hours from the last request On entering the website Maintaining the technical session, handling the contact form and remembering the selected language version.
XSRF-TOKEN Cookie (Secure, SameSite=Lax) 2 hours from the last request On entering the website Protecting forms against request forgery attacks (CSRF). Read by the website script, which is why it is not marked as HttpOnly.
Matomo First-party analytics (self-hosted), cookieless mode (disableCookies), with IP address anonymisation Not applicable – no cookies are stored Aggregated traffic statistics for the public website; the data is not linked to identified natural persons.
app.entiway.com
entiway-session Cookie (HttpOnly, Secure, SameSite=Lax) 2 hours from the last request On entering the Panel Logging in, maintaining the session of the User and interface preferences, including language version and time zone.
XSRF-TOKEN Cookie (Secure, SameSite=Lax) 2 hours from the last request On entering the Panel Protecting Panel forms and requests against CSRF attacks. Read by the Panel script, which is why it is not marked as HttpOnly.
theme Local Storage Indefinitely (until cleared by the User) After a manual change of the interface theme Remembering the selected interface theme (light / dark).
recovery_master_token, recovery_token_ref, recovery_email Session Storage Until the procedure ends, no longer than until the browser tab is closed During the Account access recovery procedure Transferring data between the successive steps of access recovery. Deleted immediately after the procedure ends.
Paddle Third-party cookie – Paddle.com Market Limited (United Kingdom) In accordance with the Paddle policy On starting the payment process Carrying out and securing the payment transaction.
api.entiway.com
No first-party cookies; authorization by API Token API responses do not set cookies.
all services
__cf_bm, cf_clearance Cookie (HttpOnly, Secure) – set by Cloudflare, Inc. __cf_bm: 30 minutes; cf_clearance: in accordance with the Cloudflare service configuration On the anti-bot verification performed by Cloudflare Distinguishing human-generated traffic from automated traffic and remembering a positive verification result so that it does not have to be repeated for every request.

The __cf_bm and cf_clearance cookies are not set by Entiway code, but by Cloudflare, Inc. as the provider of protection against automated traffic and network attacks (see point 8). They constitute a mechanism necessary to ensure the security of the services, and therefore their use does not require the consent of the User. They are received only by a visitor for whom the anti-bot verification is triggered.

The list above is complete. That scope does not and will not include marketing or tracking cookies.

8. Third-party technologies

Cloudflare. All Entiway services – the public website, the Panel and the API – operate behind the layer of Cloudflare, Inc. (USA / global), acting as a content delivery network, DNS server, DDoS protection and reverse proxy. All HTTP and HTTPS traffic passes through the Cloudflare infrastructure, which processes visitors' IP addresses for security purposes and to optimise content delivery. Cloudflare may store on the device of the User the security cookies indicated in point 7.

Cloudflare CDN. In the Panel, in the service usage view, and in the API documentation, presentation libraries are loaded from the public cdnjs.cloudflare.com network. As a result, the browser of the User establishes a connection with that network, which may receive technical connection data, including IP address and browser information. These libraries serve solely to present data and do not perform tracking functions.

Google Fonts. The typefaces used in the presentation layer are loaded from the fonts.googleapis.com and fonts.gstatic.com domains, belonging to Google LLC, both on the public website and in the Panel. As a result, the browser of the User establishes a connection with Google servers, which may receive technical data such as IP address, browser information and connection data. Google processes this data in accordance with its own privacy rules.

Paddle. In the Panel, in processes relating to payments and subscriptions, the Paddle.js script provided by the Payment Operator is used. Paddle acts as Merchant of Record and may apply its own mechanisms necessary to carry out and secure transactions, in accordance with its own privacy policy and cookie policy.

Entiway does not embed advertising scripts, social network tracking pixels or remarketing tools in its services.

9. Managing browser settings

The User may independently manage cookie and local storage settings from within their web browser – in particular review stored data, delete it and block its storage for selected websites or globally. The method of configuration differs between browsers and is described in their documentation.

Because Entiway uses exclusively technically necessary mechanisms, restricting or blocking them will make it impossible to log in to app.entiway.com and use the Panel, and on the public website it may disrupt the operation of forms and the remembering of the language version.

10. Changes to the Cookie Policy

The Controller may update this Cookie Policy in the event of technological, legal or organisational changes, in particular where the scope of the technologies covered by the list referred to in point 7 changes.

The current version of the document, together with its version number and effective date, is published on the relevant Entiway service.