01Cookies and browser storage
Cookies are small values stored by your browser and sent with matching requests. Local and session storage are accessed by website code. Information held in these forms can be personal information, depending on its use.
Some entries below are used only during sign-in or in the business portal. A storage item's duration describes that item, not the retention of related server records.
02Current purposes
Authentication and security storage supports requested sign-in and account access. Display preferences remember choices made in the portal. The consent record remembers the choices entered in the preference controls.
No analytics or advertising cookies are currently in use on this website. The Analytics and Marketing preference controls govern optional technologies that are not active today, so declining them changes nothing now. Technical diagnostics are separate from advertising and can involve information even without cookies.
03Storage inventory
authjs.session-token, named __Secure-authjs.session-token over HTTPS: business-account authentication. Configured session lifetime: 8 hours. The value may be split across numbered cookie chunks. Session renewal and sign-out affect the active session.
authjs.csrf-token and authjs.callback-url: sign-in protection and return destination. HTTPS names include __Host-authjs.csrf-token and __Secure-authjs.callback-url. These are browser-session cookies; their lifetime is not limited to the instant of sign-in. Browser session restoration can affect persistence.
authjs.pkce.code_verifier and authjs.state, with the __Secure- prefix over HTTPS when used: bind the configured authentication exchange. Maximum age: 15 minutes, with cleanup during the relevant checks.
nexion-session and nexion-session-blue, when issued by the load balancer: session affinity. Configured lifetime: 1 hour.
sidebar_state: remembers a signed-in user's sidebar open/closed choice. Lifetime: 7 days.
nexion-cookie-consent in local storage: preference choices, timestamp and version. The application treats a record as expired after 365 days and removes an expired record when read. Browser storage can remain until read or cleared; there is no browser timer guaranteeing deletion at that instant.
portal:sidebar-collapsed, admin:sidebar-collapsed and nxn-theme in local storage: requested portal display preferences. They remain until changed, removed by the application or cleared in the browser.
auth_returnTo and nl_auth_config_retry in session storage: resume requested sign-in and avoid a repeated retry loop. Cleared by the relevant sign-in handling or tab/session lifecycle.
av-document-request:... in session storage: a request identifier used to retry document generation. portal:portfolio-report:...: recent portfolio report data for the signed-in organization. These entries follow the tab/session lifecycle or earlier application cleanup; browser restoration behaviour may vary.
04Related services
Sign-in uses NexionLabs' authentication service built with Keycloak. Payment services opened from the business portal may use their own storage under their notices. Sentry diagnostic reporting can process technical information without advertising cookies.
When the contact form displays its security check, it uses Cloudflare Turnstile to help detect bots. Cloudflare processes network and browser signals, including IP address, TLS fingerprint, user agent and site origin. We use a one-use verification token and do not enable pre-clearance cookies. This is separate from analytics or advertising. See the Cloudflare Turnstile Privacy Addendum at https://www.cloudflare.com/turnstile-privacy-policy/.
05Account security
Authentication cookies support access protection but are not a guarantee against misuse. Sign out of shared devices and do not disclose session values. Blocking necessary sign-in storage can prevent account access.
06Your controls
Use the cookie preference controls to view or change the choice recorded for this browser and website origin. A saved choice is not a setting for all your devices. Browser settings can remove or restrict cookies and other storage.
Private browsing may limit persistence after a session closes, but does not prevent all cookies or storage operations during that session.
07Storage and retention
The inventory describes browser-storage lifetimes. Server-side enquiry, correspondence and diagnostic retention follows the purposes explained in the privacy notice. Clearing browser storage does not itself erase server records.
08Storage permissions
The rules governing storage or access on a device are separate from the legal basis for processing associated personal information. Storage needed for a requested service may be exempt from consent. Optional non-exempt processing requires the relevant consent before it begins. A legitimate interest does not replace device-storage consent where that consent is required.
09Personal information
The privacy notice explains recipients, international processing and privacy rights. The use of necessary storage does not itself establish compliance with every privacy obligation.
10Changes
We update this notice when storage practices change. Introducing a new optional technology requires information about its purposes and any required choice before activation; an earlier saved preference is not blanket permission for an unexplained new use.
Use the contact form for business enquiries. For privacy requests, email privacy@nexionlabs.com.
Read our privacy notice, website terms and cookie notice. Manage your cookie preferences.
Manage preferences ↗