Cookie Policy
Last updated: May 2026
In compliance with Article 22.2 of Spanish Law 34/2002, of 11 July, on information society services and electronic commerce (LSSI-CE) and Regulation (EU) 2016/679 (GDPR), this policy explains what cookies and similar storage technologies are, what types we use and how you can manage them.
1. What Are Cookies?
Cookies are small text files stored on your device (computer, tablet, smartphone) when you visit a website. They are used to ensure the site works properly, guarantee its security and remember your preferences. This policy also covers similar technologies such as browser local storage (localStorage).
2. Cookies We Use
Below is a description of the cookies and similar storage technologies currently used by REMOA Labs, together with any third-party technical service loaded on specific public forms when configured:
Necessary cookies
Essential cookies for site functionality, including authentication and CSRF protection. These cookies cannot be disabled through the website because they are necessary for the service. However, you may block or delete them through your browser settings, although doing so may prevent the website from functioning properly.
| Cookie | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
| remoa_labs_session | REMOA Labs (own) | Technical | User session management and authentication | 2 hours |
| XSRF-TOKEN | REMOA Labs (own) | Technical | CSRF attack protection | 2 hours |
| remember_web_{hash} | REMOA Labs (own) | Technical | Persistent session ("Remember me") for authenticated users | 400 days (13 months) |
3. Browser Local Storage
In addition to cookies, we use browser local storage (localStorage) for necessary technical data, including cookie notice records and technical interface preferences in authenticated administration areas. These preferences may include display theme or navigation sidebar state and are used only to provide the requested interface functionality. They are not used for analytics, advertising, tracking or profiling.
| Key / Category | Type | Purpose |
|---|---|---|
| remoaCookiesDismissed | Technical | Record that the cookie notice has been dismissed |
| remoaCookiesVersion | Technical | Version of the cookie policy notice displayed to the user |
| Administration interface preferences | Technical | Display theme and navigation state used only in authenticated administration areas |
4. Legal Basis
The first-party cookies and browser storage used by REMOA Labs are technical measures used for session management, security, policy notice versioning and authenticated features requested by the user. In accordance with Article 22.2 of the LSSI-CE, technical cookies are exempt from the consent requirement where they are necessary for the provision of the requested service.
Where the use of these technologies involves the processing of personal data, the applicable legal bases under the GDPR are the performance of the service relationship with the user (Art. 6.1.b GDPR) and REMOA's legitimate interest in ensuring the security and proper functioning of the website (Art. 6.1.f GDPR).
Certain public forms may load a third-party anti-abuse service, such as hCaptcha, where configured. The legal basis for the associated processing is REMOA's legitimate interest (Art. 6.1.f GDPR) in protecting the website, its users and public forms against spam, bots and automated abuse.
If any cookie or similar technology is used for analytics, marketing, advertising, profiling or other non-exempt purposes, REMOA will request consent before using it.
5. Cookie Security
Our first-party cookies are configured with the following security-related characteristics, where applicable:
- HttpOnly: Session and remember-me cookies are configured as HttpOnly where applicable, preventing access from JavaScript. Exception: XSRF-TOKEN, which must remain readable by client-side code for CSRF protection.
- Secure: First-party cookies are configured to use the Secure flag when the website is served over HTTPS.
- SameSite=Lax: First-party cookies use SameSite=Lax under the current application configuration to mitigate CSRF (Cross-Site Request Forgery) risks.
- Encryption: Laravel encrypts first-party cookies where framework encryption applies. The XSRF-TOKEN cookie is intentionally readable by client-side code for CSRF protection, and any third-party captcha provider manages its own cookies or similar technologies under its own policies.
6. How to Manage Cookies
You can manage or delete cookies through your browser settings. Below are instructions for the most common browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data.
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data.
- Safari: Preferences → Privacy → Manage Website Data.
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data.
Important notice: If you disable or delete necessary cookies, you will not be able to access site features that require authentication, CSRF protection will not be guaranteed and the user experience will be seriously affected.
7. Third-Party Cookies
REMOA does not currently use third-party cookies for analytics, marketing, advertising or profiling. However, selected public forms may load a third-party anti-abuse service when configured in order to protect the service against spam, bots and automated abuse. When enabled, that provider may use its own cookies or similar technologies under its own domain and policies.
hCaptcha is only loaded on selected public forms where anti-abuse protection is enabled.
Third-party technical service used on selected public forms
| Service | Provider | Type | Purpose | When used | Duration |
|---|---|---|---|---|---|
| hCaptcha | Intuition Machines, Inc. / hCaptcha | Security / anti-abuse | Protection of selected public forms against spam, bots and automated abuse | Only when forms protected by hCaptcha are loaded or submitted | Managed by hCaptcha under its own policies |
Where hCaptcha is enabled, data may be processed by Intuition Machines, Inc. / hCaptcha as a service provider. This may involve processing outside the European Economic Area. Where applicable, REMOA relies on appropriate safeguards such as the provider's data processing terms, Standard Contractual Clauses, adequacy mechanisms or other safeguards recognised under the GDPR.
Users can consult hCaptcha's own privacy and data processing information on hCaptcha's website.
8. Policy Updates
We may update this policy periodically to reflect changes in the cookies used or in the applicable legislation. We will notify you of significant changes through an appropriate notice on the website. We recommend reviewing this policy periodically.
9. Contact
For any queries regarding the use of cookies on this website, you may contact our Data Protection Officer at: dpo@labs.remoa.net