Legal placeholder
Cookie Policy
Which cookies and browser-stored entries we use on the website, in the application and on the customer portal, for what purpose, for how long, and how you can change your decision.
- Last updated
- 2026-08-29
- Version
- 1.1.0
- Reading time
- 11 min read
1. What this notice covers
This notice describes which cookies and which other browser-stored entries we use on the public website (www.ravsolutions.eu), in the application (app.ravsolutions.eu) and on the customer portal (portal.ravsolutions.eu). Each one is named individually, together with its purpose, its lifetime and who places it.
The notice is limited to cookies and similar technologies. The full, article-by-article account of legal bases, retention periods, processors and data subject rights is in the GDPR notice, and the summary organised around everyday situations is in the privacy notice. Should this notice and the GDPR notice diverge, the GDPR notice prevails.
The controller is Varga Richárd E.V. (registered seat: 2030 ÉRD, VISEGRÁDI UTCA 4030/A/1; company registration number: 62764999). Questions and requests about cookies are welcome at privacy@ravsolutions.eu.
2. What a cookie is, and what counts as a similar technology
A cookie is a small text entry that the site you visit places in your browser and that your browser automatically sends back to the same domain on every further request. That is how the server can tell that two requests came from the same browser — without it, a signed-in state would not survive from one page load to the next.
Other browser stores achieve the same effect. localStorage keeps an entry after the browser is closed; sessionStorage discards it when the tab is closed. Your browser does not send either of them to the server on its own, but in law they are treated the same as cookies, which is why section 5 lists them item by item as well.
We use no tracking pixels, no device fingerprinting and no cross-site advertising identifiers on our sites. Server logging — which is not a cookie but an inherent part of every request on the internet — is outside the scope of this notice and is described in section 3 of the GDPR notice.
3. On what basis we place cookies
We do not ask for consent to strictly necessary cookies, because Article 5(3) of Directive 2002/58/EC and Section 155(4) of Hungarian Act C of 2003 on Electronic Communications exempt them: without these cookies the service you expressly requested cannot be provided. The personal data attached to them is processed to perform our contract with you (Art. 6(1)(b) GDPR) and, as regards keeping the service secure, on our legitimate interest (Art. 6(1)(f) GDPR).
Every other cookie and browser-stored entry may reach your device only with your prior, category-by-category, affirmative consent (Art. 6(1)(a), Art. 4(11) and Art. 7 GDPR). We use no pre-ticked switches, and continuing to browse is not by itself consent.
Refusing is available on the same screen and with the same number of clicks as accepting, and withdrawing consent is as easy as giving it (Art. 7(3) GDPR). Refusing the optional categories does not restrict your use of the website or of the service in any way.
4. Strictly necessary cookies
There are two of them. Both are placed by our own server (api.ravsolutions.eu), both are marked HttpOnly — so scripts running on the page cannot read them — and in production your browser sends both back over an encrypted (HTTPS) connection only.
“refreshToken”: created when you sign in, it holds a single-use token that renews your session. It is what spares you from entering your password again every quarter of an hour. Its lifetime is 30 days, with SameSite=Strict — meaning your browser does not send it on requests started from another site — and we delete it when you sign out. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
“rav_consent_id”: created in the application (app.ravsolutions.eu) only, at the moment you first answer the cookie banner. It holds nothing but a randomly generated identifier that links your browser to the consent record stored on our servers; it does not carry the decision itself and contains neither your name nor your e-mail address. Its lifetime is 13 months (395 days), with SameSite=Lax. Legal basis: our legal obligation to be able to demonstrate consent (Art. 7(1) and Art. 6(1)(c) GDPR).
Apart from these two, the only cookies written in the ravsolutions.eu domain are the Google Analytics ones described in sections 6 and 7, and those only if you consent to the analytics category. None of our sites places a third-party cookie in its own domain: the Analytics cookies are first-party, written by a script running on our own page rather than by a server of Google's.
5. Other entries stored in your browser
The entries below are not cookies; they live in the browser's own storage. Your browser does not send any of them to the server on its own, and none of them can be used to follow you across other websites.
“rav_lang” (localStorage; on the website, in the application and on the customer portal alike): stores the interface language you picked, so that you see the same language on your next visit. It stays until the browser storage is cleared. It is needed to deliver the service and therefore belongs to the strictly necessary set.
In the application only: “rav_auth” (sessionStorage) holds the short-lived access token of your signed-in session and basic account details, and the browser discards it when the tab is closed; “files.viewMode” (localStorage) remembers whether you want files shown as a list or as a grid. On the customer portal only: the entry prefixed “portal-verify:” (sessionStorage) records that you supplied the verification detail needed to open the portal, and is discarded when the tab is closed.
“ravsolutions.cookieConsent.v1” (localStorage; on the public website and on the customer portal): on these surfaces your cookie decision is kept in your own browser only — we create no identifier and send the decision to no server. In the application, by contrast, the decision is recorded on our servers by means of the “rav_consent_id” cookie (see sections 4 and 9). Both arrangements serve a single purpose: not to ask you again about something you have already decided. Both therefore qualify as strictly necessary.
6. The optional categories and their current state
Besides the strictly necessary set, the cookie banner offers four optional categories: functional, analytics, marketing and preferences. They can be switched independently of one another, and the decision can be changed at any time.
Of the four optional categories, only analytics is in use. If you consent to it, we load Google Analytics 4 on the public website and in the application — not on the customer portal — and it writes two first-party cookies in the ravsolutions.eu domain: “_ga”, holding a randomly generated identifier for your browser, and “_ga_<stream identifier>”, holding the state of the current visit. Both last 2 years. In the functional, marketing and preferences categories we place nothing at all on your device: we load no advertising and no social media measurement tool, and those three switches stay without effect until such a tool is actually introduced.
This is how the analytics category came into use, and it is how any future one will: we named the tool in this notice together with its purpose and lifetime, raised the consent version number, and the cookie banner asked everyone again — consent given against the earlier version was not carried over. A purpose you were not told about at the time is never covered by a consent you have already given.
The links to our social media profiles are plain links: they carry no embedded button, player or tracking pixel, so no data reaches the social media providers unless you click.
7. Third-party services
The providers below are needed for the service to work. None of them places a cookie in the ravsolutions.eu domain; where a cookie does arise, it arises on the provider's own site at a different address and is governed by that provider's own notice. The application servers and the database are operated by RackForest Zrt. in Hungary (EU); that provider creates no entry in your browser.
Google Fonts (Google Ireland Limited, and Google LLC): the typeface used on our pages is loaded from fonts.googleapis.com and fonts.gstatic.com. This load happens when the page opens, before you answer the cookie banner. It creates no cookie and stores nothing on your device, but the request does disclose your IP address and your browser and operating system details to Google. If you wish to avoid this, you can do so through content blocking configured in your browser.
Google Sign-In (Google Identity Services): loaded from accounts.google.com on the sign-in and registration pages only, and solely so that you can also sign in with a Google account. In doing so Google may place cookies in its own google.com domain; we have no access to them and they cannot be read from our domain. The script loads on those pages because the button is shown there, whether or not you use it — but on none of our other pages.
Stripe (Stripe Payments Europe, Limited, and Stripe, Inc.): payment takes place on Stripe's own page at checkout.stripe.com, to which we redirect you when payment starts. No Stripe script runs on our pages and no Stripe cookie arises there. The cookies serving fraud prevention and the payment session — such as “__stripe_mid” and “__stripe_sid” — are placed by Stripe in its own domain, under its own privacy notice, after you have left our site.
Számlázz.hu (KBOSS.hu Kft.) and Brevo (Sendinblue SAS): invoices are issued by our server through the Számlázz.hu system, and system and notification e-mails are sent by our server through Brevo. Both connections run exclusively between our servers and the provider: your browser does not contact them, so neither places a cookie or any other entry on your device. The e-mails sent through Brevo carry no open-tracking pixel and no click-tracking redirect links.
Cloudflare R2 (Cloudflare, Inc.): stores uploaded files, attachments and invoice PDFs, configured for European Union. When you download, your browser receives the file directly from the store through a time-limited signed link; that request too creates neither a cookie nor any other entry on your device.
Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC): loaded from www.googletagmanager.com on the public website and in the application — never on the customer portal — and only once you have consented to the analytics category. Until then nothing is requested from Google and nothing is written to your device. It records which pages you open, in what order, and basic technical details of your browser and device, so that we can see which parts of the site and of the product are actually used. The two “_ga” cookies it needs are first-party, set in our own domain. Your IP address is truncated before it is stored, advertising features, Google Signals and ad personalisation are switched off in our configuration, so no cross-site advertising identifier arises and the data is not used for advertising. Google acts as our processor under Art. 28 GDPR, and the retention configured for the property limits user-level data to at most 14 months. Withdrawing consent stops the collection immediately and deletes the “_ga” cookies from your browser.
8. Transfers outside the European Economic Area
With the Google and Stripe services listed in section 7, your data may also reach a company established in the United States. These transfers rest on an adequacy decision under Art. 45 GDPR where the recipient is certified under the EU-U.S. Data Privacy Framework, and otherwise on the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 under Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures.
You may request a copy of the safeguards applied to a given transfer at privacy@ravsolutions.eu. The transfers are described in full in section 6 of the GDPR notice.
9. Giving, changing and withdrawing consent
On your first visit the cookie banner asks what you consent to. “Accept all” and “Reject optional” sit at the same level and are one click away each; “Customise” opens the per-category switches. Until you decide, we place nothing on your device beyond the strictly necessary set.
You can change your decision at any time: on this page, in the “Cookie settings” block below the notice, and, once signed in, in your profile as well. Withdrawal is a single action, needs no reason, and takes effect immediately for the future. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn.
In the application we record your decisions on our servers rather than in your browser alone — together with the time of the decision, the categories concerned, the consent version number, the source of the decision, your shortened IP address (its last segment zeroed) and a truncated browser identifier. This is what allows us to demonstrate consent as required by Art. 7(1) GDPR. You can view your own decision history on this page.
If the categories or the purposes behind them change, we raise the consent version number and the cookie banner asks you again; an earlier decision does not carry over. In the application the consent identifier expires after 13 months, so you are asked again at that point too. On the public website and on the customer portal your decision stands until you change it or clear your browser storage.
10. Browser settings and deleting stored entries
Independently of us, you can also restrict or delete cookies and browser-stored entries in your browser's settings. The exact steps differ by browser and are documented in the help pages of Chrome, Firefox, Safari and Edge. You may use this at any time and need not notify us.
If you block the strictly necessary cookies as well, signing in and keeping a signed-in session will not work, and your cookie choice will not be remembered, so the banner will reappear on every visit. Reading the public website works regardless.
Deleting stored entries from your browser does not undo processing that has already happened, and it does not delete the consent record held on our servers for the application. If you wish to withdraw your consent, please do so as described in section 9, because the withdrawal has to be recorded as well.
11. How long we store them
The “refreshToken” cookie expires after 30 days and “rav_consent_id” after 13 months (395 days), at which point they disappear from your browser automatically. The Google Analytics cookies (“_ga” and “_ga_<stream identifier>”) expire after 2 years, and we delete them the moment you withdraw your consent to the analytics category. Entries in browser storage have no expiry: sessionStorage is cleared when the tab is closed, and localStorage can be cleared by you from your browser's settings.
We keep consent decisions and their history for 13 months from the decision, because that is how long we must be able to show what you consented to and when. After that the record is deleted.
Server logs are kept for 90 days. The retention periods of the other categories of data are listed in section 7 of the GDPR notice.
12. Your rights and remedies
The data processed in connection with cookies carries the same rights as any of your other data: information, access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent at any time. What these rights mean and how to exercise them is set out in sections 8 and 9 of the GDPR notice; send your request to privacy@ravsolutions.eu and we will answer within one month at the latest.
If you consider our processing unlawful, you may lodge a complaint with the supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) / Hungarian National Authority for Data Protection and Freedom of Information, address: H-1055 Budapest, Falk Miksa utca 9-11., Hungary, postal address: H-1363 Budapest, Pf. 9., Hungary, phone: +36 1 391 1400, e-mail: ugyfelszolgalat@naih.hu, website: https://naih.hu. You are also entitled to seek a judicial remedy.
13. Changes to this notice
We update this notice when we introduce a new cookie or storage mechanism, when the purpose or lifetime of an existing one changes, or when we engage a new provider. The header of the page always shows the version in force and the date it was last changed.
Where a change concerns a new purpose or otherwise affects the scope of consent, amending the text is not enough on its own: we raise the consent version number and the cookie banner asks you again before anything is placed on your device.
Cookie preferences placeholder
Adjust placeholder consent categories. Necessary cookies remain enabled.