Skip to content
BeRelevant

Cookie Policy

Last updated: July 26, 2026

Version 1.1

This Cookie Policy is effective from July 26, 2026 and complies with Slovak Act No. 452/2021 Coll. on Electronic Communications (Section 109(8)) and with Regulation (EU) 2016/679 (GDPR). For visitors from the Czech Republic, Section 89(3) of Czech Act No. 127/2005 Coll. on Electronic Communications applies.

1. Introduction and Legal Basis

This page explains in detail how the BeRelevant platform, operated at berelevant.now by Mladí programátori s. r. o. (hereinafter "we" or "our platform"), uses cookies and similar terminal-equipment storage technologies, in accordance with:

  • Act No. 452/2021 Coll. on Electronic Communications, Section 109(8) (storing data on the user's terminal equipment)
  • Czech Act No. 127/2005 Coll. on Electronic Communications, Section 89(3) (for visitors from the Czech Republic)
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
  • Act No. 18/2018 Coll. on Personal Data Protection

Cookies are small text files stored on your device (computer, tablet, or smartphone) when you visit our website. We apply the same rules to data we store in your browser's local storage (localStorage) - legally, that is also storage on your terminal equipment under Section 109(8).

2. What Are Cookies and What They Do

Cookies are text files containing a small amount of information that are downloaded to your device when you visit a website. On every subsequent visit, cookies are sent back to the originating website or to another website that recognizes them. localStorage serves a similar purpose but, unlike cookies, it is not automatically sent to the server.

Cookies serve many purposes:

  • Technical functionality - enable core functions such as navigation, sign-in, and access to secure areas
  • Personalization - remember your preferences (language, theme, interface layout)
  • Analytics - help us understand how visitors use our site
  • Marketing - allow us to measure advertising campaign results and run remarketing

Cookies can be classified by various criteria:

By duration:

  • Session cookies - remain only during the browser session (deleted upon closing)
  • Persistent cookies - remain on the device for a specified period (days, months, or years)

By origin:

  • First-party cookies - set directly by our domain berelevant.now
  • Third-party cookies - set by external services (Google Analytics and Google Tag Manager, Meta Pixel)

3. Cookie Categories We Use

We group the cookies and browser storage we use into 5 categories. For each entry we state whether it requires your consent, its purpose, how long it is stored, and whether it is first-party (ours) or third-party (external). The list below reflects what is actually deployed on berelevant.now:

3.1 Strictly Necessary Cookies and Storage

NO CONSENT REQUIRED - Always Active

These cookies and browser entries are necessary to deliver the service you explicitly requested (sign-in, security, remembering your cookie choice). Without them the site would not work securely and reliably. Legal basis: the exemption under Section 109(8) of Act No. 452/2021 Coll. and legitimate interest under Art. 6(1)(f) GDPR.

No consent is required - this storage is strictly necessary to provide the service you requested.

Specific cookies and storage in this category:

access_token, refresh_tokenaccess_token 15 minutes, refresh_token until sign-out

Authentication and keeping you signed in (HttpOnly, Secure, SameSite)

BeRelevant (first-party, berelevant.now)

geo_cookie_consent (localStorage)12 months, after which the consent automatically expires and we ask you again

The primary record of your cookie decision - stored in your browser's localStorage (not as a cookie), containing your choice for each category separately, the date it was given, and the policy version

BeRelevant (first-party, localStorage in your browser)

geo_cookie_consent_status12 months

A flag indicating that you have already made a cookie decision, so the server does not show the banner repeatedly

BeRelevant (first-party, berelevant.now)

geo_landing30 minutes. If you reject both analytics and marketing cookies we delete it immediately.

A short-lived record of the campaign you arrived from - it holds only the utm parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the landing page address without its query string, and a timestamp. Advertising click identifiers (gclid, fbclid and the like) are never stored in it. Our server writes it at the moment of a redirect (for example / to /sk), because the redirect strips those parameters from the address and they could not be recovered otherwise. It exists solely so we can tell which channel brought your current visit.

BeRelevant (first-party, berelevant.now)

NEXT_LOCALE12 months

Remembering the language version of the site (sk / cz / en)

BeRelevant (first-party, Next.js)

theme, theme-resolved12 months

Storing your interface theme setting (light / dark / follow system). Written only when you switch the theme yourself, and mirrored in localStorage under the key theme. It contains no identifier and is never used for tracking.

BeRelevant (first-party, berelevant.now + localStorage)

geo_user_session (sessionStorage)Until you close the browser tab (and cleared on sign-out)

Short-lived memory of your signed-in session inside the browser tab, so the interface does not briefly render as signed out while the session is being verified. It holds your user id, email address, role and subscription tier. It is written only after you sign in, never for a signed-out visitor.

BeRelevant (first-party, sessionStorage in your browser)

geo_authing_at (sessionStorage)Until you close the browser tab

Timestamp of an in-progress sign-in redirect, used solely to detect and stop an infinite redirect loop. It contains no personal data.

BeRelevant (first-party, sessionStorage in your browser)

imp_metaUntil impersonation ends or you sign out

Security flag marking that the current session is an administrator session temporarily acting on behalf of a user (impersonation). It keeps the warning banner visible in the interface. It is set only during that administrative action, never on a normal visit.

BeRelevant (first-party, berelevant.now)

Cloudflare Turnstile (cf_*, __cf_*)Session

Bot and spam protection on forms (CAPTCHA alternative)

Cloudflare, Inc. (third-party, USA - DPF certified)

Sentry (error monitoring)Nothing is stored on your device

Detecting and diagnosing application errors to keep the service reliable. Sentry stores NOTHING on your device - no cookie, no storage entry. An error report is sent directly to its European ingest endpoint (ingest.de.sentry.io) and contains technical error data, the page address, browser type and your IP address. It is sent before any cookie consent is given, because it is necessary to keep the service running - the legal basis is legitimate interest under Art. 6(1)(f) GDPR, not consent, and you may object to it (contact details in section 10).

Functional Software, Inc. (Sentry, third-party, EU data ingest - Germany, SCC safeguards)

3.2 Functional Cookies (Interface Preferences)

NO CONSENT REQUIRED, EXCEPT THE TWO ENTRIES MARKED BELOW - stored only at your request

These first-party cookies remember your own interface choices. They are written only at the moment you make the choice yourself, contain no tracking identifiers, and are never shared with third parties. Third-party services that you start yourself (such as the voice assistant) do not belong in this category - they are listed separately in section 3.3.

⚠️ Because they store a setting you explicitly requested, the exemption under Section 109(8) of Act No. 452/2021 Coll. applies. You can delete these choices at any time in your browser settings. Two exceptions are marked below: both geo_voice_widget_* entries are kept only while you have given functional consent - the conversation transcript is never written without it, and as soon as you withdraw that consent or it expires we delete both entries.

Specific cookies in this category:

sidebar:user:collapsed12 months

Remembering whether you keep the in-app sidebar collapsed or expanded

geo_onboarding_skipped12 months

Remembering that you skipped the onboarding guide so it is not shown again

email_verify_banner_dismissedSession

Remembering that you dismissed the email verification notice

geo_selected_brand_id (localStorage)Until you clear it in your browser settings

Remembering which of your brands you last had selected, so the same one opens when you come back. It is written only when you pick a brand yourself, and only inside the signed-in part of the app.

geo_audit_context_<brand-id> (sessionStorage)Until you close the browser tab

Temporary copy of the values you typed into the run-audit form (industry, location, notes) so they are pre-filled the next time you run an audit in the same session. It is written only after you submit the form.

geo_last_audit (sessionStorage)Until you close the browser tab (24 hours at most)

A note about the last quick audit you ran - the audited domain and its score, nothing else. It lets us offer to continue where you left off after a reload or after closing the result, instead of showing an empty form. The analysis itself is not stored, nor is anything you told us about yourself, and an audit is never re-run from it automatically.

geo_feature_gate_hits_<user-id> (sessionStorage)Until you close the browser tab

List of premium features whose limits you have already hit in this session, used solely so we do not repeat the same prompt (and the follow-up email). It is written only after you sign in and only on first contact with such a feature.

geo_voice_widget_state (localStorage)Until you clear the conversation, withdraw functional consent, or clear it in your browser settings (at most 50 messages, 200 kB)

Stores your conversation with the voice assistant - a transcript of the last 50 messages (both your questions and the assistant's replies), a summary of the last call (its length and message count) and the assistant language you picked, so you can pick up where you left off after a reload or a page change. It is written only after you start the assistant yourself, and only if you allowed functional storage. If you withdraw functional consent we delete the stored transcript immediately; you can also delete it yourself with "Clear conversation" inside the assistant panel.

geo_voice_widget_tooltip_dismissed (localStorage)Until you withdraw functional consent or clear it in your browser settings

A flag recording that the voice assistant's introductory bubble should no longer be shown. It holds the single value "true", contains no identifier, and is written when you close the bubble yourself OR when you open the assistant - in both cases only after your own click. It is an interface preference, not strictly necessary storage. It is not used for tracking. Like the transcript, it is kept only with functional consent - if you withdraw that consent we delete it together with the transcript.

3.3 Third-party services you start yourself

STARTS ONLY WHEN YOU ASK IT TO - transfer to the USA

This category contains no cookies. It covers external services that are not started by loading the page, but only at the moment you activate them yourself - and where your data (including the content of the call and your IP address) leaves our infrastructure and is disclosed to third parties, one of them outside the EU. We list them separately from section 3.2 deliberately: that section is strictly about our own first-party preferences, which are shared with nobody, whereas here disclosure to a third party genuinely happens.

🎙️ Until you start a call yourself, the microphone stays off and nothing is sent - loading the page neither begins a conversation nor contacts either service. Pressing the call button is your instruction to begin the processing, and you can end the call at any time. Nothing is stored on your device in the process, so the Section 109(8) exemption of Act No. 452/2021 Coll. does not apply here - this is assessed under the GDPR alone.

Legal basis: your consent, expressed by starting the call, under Article 6(1)(a) GDPR; and, to the extent you are asking about our services, pre-contractual steps under Article 6(1)(b) GDPR. We process your voice as ordinary personal data - the assistant is not used for biometric identification or voice-based authentication, so this is not a special category of data under Article 9 GDPR.

Specific services in this category:

Voice assistant - ElevenLabs and Prebi (no cookie)Nothing is stored on your device. The conversation transcript is kept in your browser only with functional consent (see geo_voice_widget_state in section 3.2).

Purpose: When you start a call yourself, the browser asks for microphone access and connects directly to wss://api.elevenlabs.io, streaming your microphone audio there in real time; the voice reply and its transcript come back over the same connection. ElevenLabs therefore processes your voice and the content of the conversation together with your IP address and browser details. The short-lived access URL for that connection is issued at our request by the Prebi platform (api.prebi.eu), to which we pass your IP address to protect the service from abuse. Neither ElevenLabs nor Prebi stores anything on your device. Until you start a call the microphone stays off and nothing is sent - simply loading the page does not begin a conversation.

Provider: ElevenLabs, Inc. (third-party, USA - Standard Contractual Clauses) and Prebi (voice platform operator, EU)

Shared Data: ElevenLabs: real-time microphone audio, the content of the conversation and its transcript, IP address, browser and device details. Prebi: your IP address (to cap how often a call can be started and to prevent abuse); nothing else about your visit is passed to Prebi, not even the address of the page you start the call from. If you fill in the contact form at the end of a call, we process the details you submit ourselves - see the Privacy Policy.

Data transfer outside the EU:

ElevenLabs, Inc. is a processor established in the USA. The transfer relies on Standard Contractual Clauses (SCCs) approved by the European Commission together with a transfer impact assessment. If you would rather your voice were not transferred to the USA, simply do not start a call - all other content on the site remains fully available without it, and you can ask us the same questions by email or through the contact form. The Prebi platform runs in the EU.

3.4 Analytics Cookies

CONSENT REQUIRED

These cookies let us recognize and count visitors and see how they use our website. They help us improve the site by showing which pages are the most and least popular.

📊 We activate analytics cookies only after your explicit, affirmative consent. No box is pre-ticked, refusing is as easy as accepting, and you can withdraw your consent at any time. Until consent is given, none of the entries below is stored. FOR FULL TRANSPARENCY: the Google Tag Manager script is loaded as soon as the page opens, in Google Consent Mode v2 with consent DENIED by default. In that state Google stores nothing on your device (no cookie, no identifier), but loading the script and the single anonymous ping it sends do mean that Google already sees your IP address, the address and title of the page, its language, your screen resolution and basic browser and device data at that moment. This data is not tied to a persistent identifier and is not linked to a profile. If you do not consent, no further measurement happens and nothing is written to your device; if you do consent, the cookies listed below are activated.

Legal basis: consent under Section 109(8) of Act No. 452/2021 Coll. (Section 89(3) of Czech Act No. 127/2005 Coll. for Czech visitors), together with Art. 6(1)(a) GDPR

Specific cookies in this category:

_ga, _ga_*_ga and _ga_*: 2 years

Purpose: Google Analytics 4 - traffic measurement and on-site user behavior

Provider: Google Ireland Limited / Google LLC (third-party, USA - Data Privacy Framework certified)

Shared Data: Truncated IP address, device and browser data, visit time, pages visited, on-page events. The same events (e.g. a completed payment) may also be sent server-side via the Google Measurement Protocol, carrying the same event identifier so the two are deduplicated.

Google Tag Manager (no cookie)Nothing is stored on your device

Purpose: Measurement script management - Google Tag Manager loads analytics and marketing tags only after the relevant consent is granted (Google Consent Mode v2). Tag Manager itself stores no cookie on your device.

Provider: Google Ireland Limited / Google LLC (third-party, USA - Data Privacy Framework certified)

Shared Data: Loaded tags, device data, on-page events (only after consent). Note: the _gcl_au cookie belongs to the Google Ads conversion linker, which is NOT deployed on berelevant.now and is never set.

geo_attr_first, geo_attr_lastgeo_attr_first: 90 days, geo_attr_last: 30 days

Purpose: Our own visit attribution - stores the source of a visit (utm parameters, referrer, landing page) at the first and the most recent touch so we can tell which channels bring users. It contains no advertising identifiers.

Provider: BeRelevant (first-party, berelevant.now)

Shared Data: Not shared with third parties. After sign-up the contents are sent to our own backend to evaluate acquisition channels.

Data transfer outside the EU:

Google Analytics and Google Tag Manager: data may also be processed in the USA. Google LLC is certified under the EU-US Data Privacy Framework (DPF). More information: https://privacy.google.com/businesses/compliance/

Our own attribution cookies (geo_attr_*) stay on our EU infrastructure. Sub-processors outside the EU are either DPF certified or covered by Standard Contractual Clauses (SCC) approved by the European Commission.

3.5 Marketing Cookies

CONSENT REQUIRED

We use these cookies to measure advertising campaign results and to run remarketing. They let us attribute a conversion (for example a sign-up) to the specific ad you clicked.

We activate these cookies only after your explicit consent. Without it, the Meta Pixel measurement script is not loaded into the page at all. Refusing them is as easy as accepting, and you can withdraw your consent at any time.

Legal basis: consent under Section 109(8) of Act No. 452/2021 Coll. (Section 89(3) of Czech Act No. 127/2005 Coll. for Czech visitors), together with Art. 6(1)(a) GDPR

Specific cookies in this category:

_fbp, _fbc, fr_fbp and _fbc: 90 days, fr: 90 days

Purpose: Meta Pixel - conversion measurement and remarketing campaigns on Facebook and Instagram. The script is loaded from connect.facebook.net only after marketing consent is granted.

Provider: Meta Platforms Ireland Limited, transferred to Meta Platforms, Inc. (third-party, USA - DPF certified)

Shared Data: IP address, device and browser data, pages visited, and conversion events. The same conversion event may also be sent server-side via the Meta Conversions API with a shared event ID (for deduplication); on a form submission it may include a hash of your email address. The server-side send is likewise conditional on your marketing consent.

geo_attr_marketing90 days

Purpose: Our own first-party record of ad-click identifiers (gclid, fbclid) from your most recent ad visit, so we can attribute a paid conversion to the right campaign

Provider: BeRelevant (first-party, berelevant.now)

Shared Data: On conversion, the ad-click identifiers may be passed to the relevant advertising platform (Google, Meta) to match the conversion.

How to opt out of marketing tracking:

Browser settings: you can block all third-party cookies or enable tracking protection.

Opt-out tools:

4. Your Rights and Consent Management

You have full control over which cookies we may use.

Your rights:

  • Accept all cookies - actively consent to all categories
  • Reject optional - only strictly necessary cookies stay active; refusing is as easy as accepting
  • Customize - choose specific categories (analytics yes, marketing no, etc.)
  • Withdraw consent - you can change your decision at any time in cookie settings

How to manage cookies on our site:

  • Cookie banner - on your first visit a cookie banner appears where you can select your preferences; no category is pre-enabled
  • Cookie settings - in the page footer you'll find a "Cookie settings" link where you can change your decision at any time
  • Footer link - click on "Cookies" at the bottom of the page
  • Consent validity - your consent is valid for 12 months, then we'll ask for confirmation again

Managing cookies through your browser:

5. Validity and Withdrawal of Consent

Consent validity period:

Withdrawal of consent:

6. Third Parties and Sub-processors

To provide our services we work with the sub-processors listed below, which may set cookies on our platform or process related data. We use no other advertising or analytics providers on berelevant.now:

EU-US Data Privacy Framework (DPF):

7. Security and Data Protection

Security measures:

  • HttpOnly flag: Cookies containing authentication data are marked HttpOnly (not accessible via JavaScript) - protection against XSS attacks
  • Secure flag: In production, cookies are transmitted only over HTTPS
  • SameSite attribute: Protection against CSRF attacks (cookies are not sent on cross-site requests)
  • Content Security Policy: Every page has its own CSP with a single-use nonce, which blocks any unapproved third-party script from loading

Retention period:

  • Session cookies: Deleted immediately when the browser is closed
  • Persistent cookies: Stored for the period listed with each entry (at most 24 months for Google Analytics)
  • Consent record (geo_cookie_consent in localStorage and geo_cookie_consent_status): 12 months, then renewed

8. Cookies and Personal Data (GDPR)

GDPR compliance:

  • Strictly necessary cookies: the exemption under Section 109(8) of Act No. 452/2021 Coll. and legitimate interest (Art. 6(1)(f) GDPR) - ensuring functionality
  • Optional cookies: consent (Art. 6(1)(a) GDPR) - must be freely given, specific, informed, and unambiguous, expressed by an affirmative action

Your rights under GDPR:

  • Right of access - you can request a copy of data stored in cookies
  • Right to rectification - you can request correction of inaccurate data
  • Right to erasure ('right to be forgotten') - you can request deletion of cookies
  • Right to restriction of processing - you can request suspension of processing
  • Right to data portability - you can request export of data in a machine-readable format
  • Right to object - you can object to processing based on legitimate interest
  • Right to lodge a complaint - you can file a complaint with the Slovak Data Protection Office: https://dataprotection.gov.sk

9. Changes to This Cookie Policy

10. Contact and GDPR Requests

Data controller:

GDPR requests:

Supervisory authority:

Questions about cookies?

If you have any questions about this Cookie Policy, consent management, or your rights, please don't hesitate to contact us.

Contact Support