Cookie policy for the customer area
1. Controller
F.O.D IT onDemand UG (haftungbeschränkt)
Ruschestr.103
10365 Berlin
E-Mail: datenschutz@fod-it.de
2. Which cookies are used?
The customer area uses only technically necessary cookies. No analytics, advertising, profiling or social-media cookies are included.
- FOD49SESSID: manages the secure session after login. It is configured as HttpOnly and SameSite=Strict and is deleted when the browser is closed.
- fod49_cookie_notice: stores confirmation of the necessary-cookie notice for 180 days.
3. Purpose and legal basis
The cookies are required to provide the requested protected customer area, login, two-factor authentication, protection against session hijacking and logout. Technically necessary storage may be used under Section 25(2)(2) TDDDG without advertising consent under Section 25(1) TDDDG. Where personal data is processed, Article 6(1)(b) GDPR applies to the user relationship or contractual steps and Article 6(1)(f) GDPR applies to system security.
4. Refusal
If you do not confirm the necessary cookies or block them in your browser, the protected customer area cannot be used. The public website remains available.
5. Retention
The session cookie is normally deleted when the browser is closed. Confirmation of the cookie notice is stored for 180 days. A concrete deletion period for server logs and security events must be documented before production use: 180 days.
6. Third parties
The demo version does not load external analytics or advertising services. TOTP calculation takes place locally between the server and the authenticator application selected by the user.
7. Version
Version: July 2026
