Cookie Policy
Effective date: 28 July 2026. Last updated: 28 July 2026. This Policy explains how Olleu AB uses cookies, local storage, session storage, and similar browser technologies in Fonoria.
1. Scope of this Policy
This Policy applies to the public Fonoria website, login flows, application dashboards, support tools, and related B2B SaaS services operated by Olleu AB. It should be read together with the Privacy Policy and Terms and Conditions.
Cookies and browser storage can contain identifiers or usage information that qualify as personal data under the EU General Data Protection Regulation (GDPR). Where that happens, Olleu AB handles the information according to the Privacy Policy, the applicable data processing agreement, and any consent choices required by law.
2. What browser technologies we use
A cookie is a small text file stored by a browser. Local storage and session storage are browser storage mechanisms that can keep information on a user's device. Pixels, tags, scripts, and software development kits may collect technical events from a page or application session.
Fonoria uses these technologies to authenticate users, protect sessions, remember settings, route users to the correct workspace, keep dashboards working, prevent fraud, diagnose errors, and maintain limited first-party workflow state.
3. Strictly necessary technologies
Strictly necessary storage is required for secure login, session continuity, account protection, role-based access, fraud prevention, support forms, and core application functionality. This includes the Supabase authentication session stored in the browser and short-lived session records used to prevent duplicate workflow events.
Authentication records normally remain until they expire, the user signs out, or the browser data is cleared. Session-storage records normally end with the browser session. Exact key names and lifetimes may change when security or authentication providers are updated, but their purpose remains limited to delivering and protecting the requested service.
4. Preference and functionality storage
Preference storage helps remember choices such as theme, language, interface preferences, dashboard filters, saved view settings, dismissed notices, onboarding progress, and other configuration that makes Fonoria usable for returning business users.
Preference and permitted local workflow records generally remain until the user changes them, signs out where the record is account-bound, the application replaces them, or the browser data is cleared. Some settings are stored in the user's account or workspace instead; clearing browser storage does not delete those server-side records.
5. Analytics and performance technologies
Fonoria can emit limited first-party events when a business signup is completed or a payment method is added. If an analytics endpoint is configured, those events contain the event name, route, time, role or account type, and source; the event sanitizer excludes contact details, credentials, tokens, card details, and customer identifiers. Session storage may remember that an event was already sent.
Configured error monitoring may receive a sanitized error message, route, time, and whether the user was authenticated. It is used to secure and maintain the service, and default personal-information collection is disabled. Optional measurement that requires access to a user's device will not be enabled without the consent required by applicable EU and Swedish rules.
6. Marketing and third-party technologies
Fonoria does not currently deploy advertising cookies, remarketing pixels, or cross-site behavioral trackers. They are not required to use the public website or secure application workspace.
If Olleu AB later introduces optional marketing, attribution, or third-party analytics technologies, we will identify the relevant providers and purposes, update this Policy, and obtain any consent required before activating them.
7. Legal bases and consent
Where browser technology also processes personal data, Olleu AB relies on performance of a contract for requested account functionality, legitimate interests in maintaining and securing the B2B service, legal obligations for required records, or consent for optional analytics and marketing, as applicable.
Storing or accessing information on a user's device generally requires consent unless the technology is strictly necessary to provide a service requested by the user. Fonoria currently limits device storage to necessary and functional uses. Before adding an optional category that requires consent, Olleu AB will provide a control that allows users to accept or reject it.
8. Managing choices
Users can inspect, block, or delete cookies and browser storage through browser settings. Blocking or deleting strictly necessary storage may prevent login, workspace access, saved preferences, support submission, or other core features from working correctly.
Because no optional marketing or cross-site tracking category is active, Fonoria does not currently show a marketing-cookie banner. If a consent-required category is introduced, a consent control will be made available. Requests about browser storage or privacy settings can be sent to support@fonoria.com.
9. Retention, logs, and Swedish bookkeeping records
Storage lifetimes vary by purpose. Session records normally end with the browser session. Authentication records follow the session expiry and refresh settings. Preferences and permitted local workflow records can remain until they are changed, replaced, or cleared. Server-side security and monitoring records follow the retention periods in the Privacy Policy.
Some digital records associated with cookies, consent, billing, support, security, and platform usage may need to be retained because they form part of accounting information, support documentation, audit logs, or legally relevant business records. Olleu AB and Customers that are subject to the Swedish Bookkeeping Act (bokforingslagen) must consider statutory retention duties before deleting records that support invoices, transactions, account administration, or audit trails.
10. EU Data Act considerations
The EU Data Act may affect access, portability, switching, and fair contractual handling of certain data held by data processing services. Browser storage and logs can be connected to customer-entered data, generated workflow data, consent records, security metadata, and usage events.
Where an eligible Customer requests access to or portability of data that includes cookie-derived or browser-storage-derived information, Olleu AB will assess the request under the EU Data Act, GDPR, confidentiality duties, security requirements, trade secret protections, and the rights of other suppliers, resellers, users, and service providers.
11. Updates and contact
We may update this Cookie Policy when we change providers, introduce new categories, update consent tools, add analytics, modify retention periods, or respond to legal developments. Material updates will be communicated through reasonable channels, such as the website, application, email, account notice, or an updated effective date.
Questions about cookies, consent, browser storage, or related privacy rights should be sent to support@fonoria.com.