Version 1.1 · in force from August 20, 2026
Cookie Notice
Version 1.1 · Effective from 20 August 2026
1. Who is responsible
The controller of your personal data is Afterworc OÜ, registry code 17554808, registered address Mäealuse tn 10/2, Mustamäe linnaosa, Tallinn, Harju maakond, 12618, Estonia.
For any question about cookies or about your data, write to info@afterworc.com.
This notice explains which cookies the AfterWorc Platform sets, why, for how long, on what legal basis, and how you decide about them. It complements the Privacy Policy, which describes everything else we do with your data.
2. What a cookie is
A cookie is a small file that a website asks your browser to store and to send back on later requests. It lets the site recognise the same browser between page loads — which is how you stay signed in after you enter your password.
The same rules apply to anything else that stores data in your browser, such as localStorage. Where we use those, we say so in section 4.
3. The categories, and which of them we actually use
| Category | Do we use it? |
|---|---|
| Strictly necessary | Yes. Listed in full in section 4. |
| Functional | We set no functional cookie. Your interface language is carried in the page address, and your light or dark theme preference is stored in your browser's localStorage — see section 4.2. |
| Analytics | Yes, since 20 August 2026, and only if you say yes. The tools and their cookies are named in section 4.3. Until you agree, not one of them is loaded. |
| Marketing | Yes, since 20 August 2026, and only if you say yes. The tools and their cookies are named in section 4.3. We do not sell your data. |
Every cookie in section 4.1 is set by us, on our own domains. The cookies in section 4.3 are set by the providers named there — but only after you have agreed, and until you agree not one of those providers receives a single byte from this page. Our fonts are still served from our own servers, for the same reason: nothing loads from a third party that you have not been asked about.
4. The cookies we set
4.1. Strictly necessary
These make the Platform work: they sign you in, keep you signed in, protect your account, and remember your own decision about cookies. Without them the service cannot be provided, so they are set without asking and cannot be switched off. Deleting them in your browser signs you out; it does not otherwise restrict you.
All of them are first-party. All of them are marked Secure, so they are never sent over an unencrypted connection.
| Name | Party | Purpose | Lifetime | Flags |
|---|---|---|---|---|
__Host-aw_session |
First party, afterworc.com |
Keeps you signed in. The value is a random reference to a session record on our servers, not your data. | Up to 30 days, and it lapses after 14 days without activity — whichever comes first. Signing out ends it immediately. | HttpOnly, Secure, SameSite=Lax, Path=/ |
__Host-aw_2fa |
First party, afterworc.com |
Holds the half-finished state of a sign-in between your password and your second factor. It grants no access on its own: the only thing it can do is present a second factor. | 15 minutes | HttpOnly, Secure, SameSite=Strict, Path=/ |
__Host-aw_device |
First party, afterworc.com |
A random label for this browser, so that we can tell a sign-in from a device you have used before from a sign-in from a new one, and email you about the latter. It identifies the browser, not you, and grants no access. | 2 years | HttpOnly, Secure, SameSite=Lax, Path=/ |
__Host-aw_signup |
First party, afterworc.com |
Carries the email address you have just registered with to the confirmation screen, so that the screen can name it and offer to send the letter again. It is in a cookie rather than in the address bar precisely so that your email address does not end up in proxy logs, browser history or referrer headers. | 1 hour | HttpOnly, Secure, SameSite=Lax, Path=/ |
aw_cookie_consent |
First party, afterworc.com |
Your own decision about the optional categories, together with the moment you made it and the version of this notice it relates to. Without it we would have to ask you again on every page. | 12 months | Secure (over HTTPS), SameSite=Lax, Path=/. Not HttpOnly — the page has to read your decision in the browser, before anything optional could load. |
__Host-awadm_session |
First party, admin.afterworc.com |
Signs in a member of our staff to the administration panel. It exists on a separate domain from yours and is never sent to afterworc.com; if you are not our staff, you will never receive it. |
Up to 8 hours, and it lapses after 30 minutes without activity | HttpOnly, Secure, SameSite=Strict, Path=/ |
The __Host- prefix on most of these is a browser-enforced restriction: a cookie carrying it cannot be scoped to a domain, cannot be set from a subdomain, and cannot be set over an unencrypted connection.
Files you upload or download are served from a separate domain, files.afterworc.com, which is configured to send and receive no Platform cookies at all.
4.2. Other storage in your browser
Theme preference. Whether you chose the light or the dark interface is stored in your browser's localStorage, under the key theme. It never leaves your browser, is never sent to our servers, and contains nothing about you.
Interface language. Your language is part of the page address (/en, /et, /ru). No cookie is involved.
Storage used by the tools in section 4.3. Once you agree, those tools also write a few entries into your browser's storage, which the law treats exactly as it treats cookies. We measured what they write, on 20 August 2026: Microsoft Clarity puts _cltk into sessionStorage; the Meta pixel puts lastExternalReferrer and lastExternalReferrerTime, and Google Ads puts _gcl_ls, into localStorage. All of them are deleted when you withdraw the category they belong to.
4.3. Analytics and marketing
Since 20 August 2026 we measure how the Platform is used, and we measure advertising. Nothing described here loads, and none of these cookies is set, before you have said yes to the category it belongs to. Saying no leaves the Platform working exactly as it works now.
The tools, and who runs them:
| Tool | Provider | Category | What it is for |
|---|---|---|---|
| Google Analytics 4 | Google Ireland Limited | Analytics | Counts visits and steps through the site: which pages are opened, which forms are abandoned, which searches come back empty. |
| Google Ads | Google Ireland Limited | Marketing | Connects a visit to an advertisement that was clicked, so that we can tell which advertising is worth paying for. |
| Microsoft Clarity | Microsoft Ireland Operations Limited | Analytics | Records how a page is used — scrolling, clicks, where people get stuck — and aggregates it into heatmaps. |
| Meta Pixel | Meta Platforms Ireland Limited | Marketing | Measures the effect of advertising on Facebook and Instagram. |
| LinkedIn Insight Tag | LinkedIn Ireland Unlimited Company | Marketing | Measures the effect of advertising on LinkedIn. |
All five are loaded through Google Tag Manager, itself operated by Google, which loads nothing at all until you have decided. Your answer reaches each tool as a machine-readable consent signal rather than as a promise: with analytics refused, Google Analytics and Clarity receive nothing; with marketing refused, the advertising tags do not run and do not set their cookies. We checked this by running the container in a browser before publishing this notice, on 20 August 2026.
These are the cookies they set on our own domain. Every name and every lifetime below is checked against the running code on each build, so this table cannot quietly fall behind what actually happens:
| Name | Provider | Category | Purpose | Lifetime | Flags |
|---|---|---|---|---|---|
_ga |
Analytics | Tells one browser from another, so that two visits by the same person are not counted as two people. | 400 days | SameSite=Lax, not HttpOnly |
|
_ga_LDGCNP0PCK |
Analytics | Holds the state of the current session for our Analytics data stream. | 400 days | SameSite=Lax, not HttpOnly |
|
_clck |
Microsoft | Analytics | A lasting label for this browser in Clarity. | 365 days | SameSite=Lax, not HttpOnly |
_clsk |
Microsoft | Analytics | Joins the page views of one sitting into a single session in Clarity. | 1 day | SameSite=Lax, not HttpOnly |
_fbp |
Meta | Marketing | A browser label used to measure the effect of Meta advertising. | 90 days | SameSite=Lax, not HttpOnly |
_gcl_au |
Marketing | Connects a click on a Google advertisement to what happened after it. | 90 days | SameSite=Lax, not HttpOnly |
None of them is HttpOnly: they are written by script and read by script. That is a fact about how they work, not a choice of ours.
4.4. Cookies these providers set on their own domains
Part of what those tools do happens on the provider's own domain — clarity.ms, facebook.com, linkedin.com, google.com. Cookies set there are third-party cookies. They belong to the provider, not to us; our code can neither read nor delete them; and most browsers now block them by default.
We name them because you are entitled to know they exist, not because we control them:
| Provider | Where | What they are for |
|---|---|---|
| Microsoft | clarity.ms, bing.com |
Recognising the same browser across the sites that use Clarity — among them MUID, CLID, ANONCHK, MR, SM, SRM_B. |
| Meta | facebook.com |
Connecting a visit to a Facebook or Instagram account, where one exists. |
linkedin.com |
Connecting a visit to a LinkedIn account, where one exists — among them bcookie, lidc, UserMatchHistory. On our own domain LinkedIn sets nothing at all; we measured that on 20 August 2026. |
|
google.com, doubleclick.net |
Advertising measurement across sites, among them NID. |
To remove these, use your browser's settings or the provider's own controls — ours cannot reach them. Refusing the category stops the tag that would cause them from running in the first place.
5. Legal basis
Cookies are governed by the ePrivacy rules, which require your consent for anything not strictly necessary, and — where a cookie processes personal data — by the GDPR.
| Category | Basis |
|---|---|
| Strictly necessary | Storing them is permitted without consent, because they are strictly necessary to provide the service you asked for. Where the underlying processing involves personal data, it rests on GDPR Art. 6(1)(b) — performance of our contract with you — and, for the security-related ones, on Art. 6(1)(f), our legitimate interest in keeping accounts safe. |
| Functional | Not applicable: we set none. |
| Analytics | GDPR Art. 6(1)(a) — your consent. Nothing loads before you give it. |
| Marketing | GDPR Art. 6(1)(a) — your consent. Nothing loads before you give it. |
6. How you decide, and how you change your mind
Giving consent. On your first visit a banner offers exactly three actions of equal weight: accept all, decline everything non-essential, or open the settings and choose category by category. Nothing optional is pre-selected, declining is presented no less prominently than accepting, and the banner does not block the page or trap your keyboard. Refusing does not restrict your use of the Platform in any way.
Changing or withdrawing. Withdrawal is as easy as consent. Two routes, both permanent:
- the Cookie settings link in the footer of every page, which reopens the same choice;
- the page at /settings/cookies, which you can bookmark or receive as a link. It does not require an account.
What happens after you withdraw. The optional categories are switched off immediately: nothing further is loaded, the cookies and storage entries listed in sections 4.3 and 4.2 that sit on our own domain are deleted, and the page reloads so that whatever was already running stops running. What we cannot delete is what sits on the providers' own domains — section 4.4 says which, and why no script of ours may touch it. Withdrawal has no effect on what happened before it, which is why we record the moment of each decision. Your consent record is not deleted on withdrawal — the withdrawal is written as a new entry alongside it, because a deleted record could not show that you had withdrawn.
Expiry. A decision lasts 12 months. After that we ask again, because a consent the person no longer remembers giving is not a consent.
Your browser. You can also block or delete cookies in your browser settings. Blocking the strictly necessary ones will sign you out and prevent you from signing in again; that is a consequence of how sessions work, not a penalty.
7. Third parties and transfers outside the EU
We do not sell your data. Beyond what section 4.3 describes, we share nothing for advertising — and nothing in section 4.3 happens until you have said yes.
The data behind the cookies in section 4.1 — session records, device labels, consent records — is stored and processed in the European Union, on servers in the EU, by us. It is not transferred outside the EEA.
The data behind section 4.3 is a different matter, and we say so plainly rather than leaving it to be discovered. Google, Microsoft, Meta and LinkedIn are engaged through their Irish entities, but each belongs to a group with infrastructure in the United States, and what your browser sends them may be processed there. Those transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework and, where it does not cover a particular transfer, on Standard Contractual Clauses. If you refuse the analytics and marketing categories, none of this happens: not one request leaves your browser to any of them.
The processors we use for the Platform as a whole are listed on the Platform and in our Privacy Policy.
8. How long we keep the record of your decision
The cookie holding your decision lives for 12 months (section 4.1).
If you are signed in when you decide, the decision is also written to our consent register, so that it survives a change of browser and can be shown as evidence later. That record is kept for as long as we need it to demonstrate that our processing was lawful, and it is never deleted on withdrawal — see section 6.
If you are not signed in, no server-side record is created: there is no account to attach it to, and creating an identifier merely to store a refusal would be the opposite of data minimisation.
9. Your rights
You have the full set of GDPR rights over the data behind these cookies — access, rectification, erasure, restriction, objection, portability, and withdrawal of consent — and the right to complain to a supervisory authority.
How to exercise them, how quickly we answer, and where to complain are set out in section 8 of our Privacy Policy. We do not restate them here, because two texts about the same rights eventually say two different things.
10. Changes to this notice
We may update this notice. Every published version stays available, and each recorded consent names the version it was given against.
If we change what we actually set — a new cookie, a new purpose, a longer lifetime, or any tool from a third party — the change takes effect only after we have published the new version, and your existing consent to the optional categories does not carry over to it: the banner asks again. A change that only corrects wording takes effect on publication.
11. Contact
Afterworc OÜ, Mäealuse tn 10/2, Mustamäe linnaosa, Tallinn, Harju maakond, 12618, Estonia.