EPAV DESK · COOKIE POLICY
Version 1.0 · Effective from 9 October 2026
Operator: NeriusCognitaren OÜ, registry code 17503018, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Questions: privacy@epavdesk.com
1. What this policy covers
Cookies are small text files that a website stores in your browser. Browsers also offer "local storage", which websites use in a similar way. The same rules apply to both, so this policy covers both.
This policy describes what EPAV Desk stores in browsers:
- on our website epavdesk.com (Section 2a);
- in the cabinet at my.epavdesk.com (Section 3);
- in the panel and the help center of a Site (Section 4);
- in the chat that a company places on its own website or app (Section 5).
We do not use advertising cookies or third-party analytics. Everything listed below is set by EPAV Desk itself. One of the chat's cookies identifies a browser to time a company's proactive messages (Section 5).
2. Who is responsible
For the cabinet and our own websites, EPAV is responsible. A company that uses EPAV Desk is responsible for the cookies and storage of its Site and of the chat on its own website, because it decides to use them there; we act for it as its processor. This policy describes them so that the company can tell its visitors, and its own cookie policy should cover them.
2a. Our website (epavdesk.com)
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
aksioma.lang | Local storage | The language you chose | Until cleared |
aksioma.langBanner | Local storage | Remembers that you closed the language suggestion | Until cleared |
aksioma.cookieNotice | Local storage | Remembers that you closed the notice about cookies | Until cleared |
epav.support.level, epav.support.product | Local storage | Remembers what you chose in the price calculator | Until cleared |
These stay in your browser and are not sent to us. The website loads its fonts and scripts from itself. Our website also shows the EPAV Desk chat, which sets the cookies and storage listed in Section 5 on epavdesk.com; we are responsible for them there.
3. The cabinet (my.epavdesk.com)
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
cab | Cookie (HttpOnly, Secure, SameSite=Lax) | Keeps you signed in. Contains a random token; we store only its hash | 30 days, or until you sign out |
lang | Cookie (Secure, SameSite=Lax) | Remembers the language of the cabinet | 365 days |
The cabinet uses no local storage and loads no third-party scripts or fonts. Both cookies are strictly necessary for a service you asked for, so they need no consent.
4. The panel and the help center of a Site
Panel (for Agents)
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
libredesk_session | Cookie (HttpOnly, Secure, SameSite=Lax) | Keeps the Agent signed in | 9 hours by default |
csrf_token | Cookie (Secure) | Protects forms against cross-site request forgery | Until the browser is closed |
| Interface settings, such as panel sizes, open sidebars, the last inbox opened, availability status and log filters | Local storage | Remembers how the Agent arranged the panel | Until cleared |
| Drafts of messages | Local storage | Keeps an unsent reply or new conversation if the page is reloaded; drafts of new conversations are cleared at sign-out | Until sent or cleared |
Help center (public)
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
libredesk-hc-theme | Local storage | Light or dark theme | Until cleared |
hc-announcement-<id> | Local storage | Remembers that you closed an announcement | Until cleared |
hc-feedback:<page> | Local storage | Remembers your "was this helpful" vote | Until cleared |
The help center contains no analytics of ours. The company running a Site can add its own scripts to its help center; if it does, its own cookie policy applies to them. If the help center shows the chat, Section 5 applies too.
5. The chat on a company's website
The chat is added to a website with a small script. Its cookies are set on the website's own domain (first-party cookies). Unless the company sets a different cookie domain, they are set on the main domain of the website.
| Name | Type | Purpose | Lifetime | Set when |
|---|---|---|---|---|
support-session-<inbox> | Cookie (SameSite=Lax, Secure on HTTPS) | Session of the visitor or of the signed-in user, so the conversation continues across pages and visits | 1 year | When the chat creates a session for the visitor |
support-visitor-<inbox> | Cookie (same flags) | Token of an anonymous visitor, so the history can be kept when the visitor later signs in | 1 year | When the chat creates an anonymous visitor |
support-campaign-<inbox> | Cookie (same flags) | Random identifier of the browser, used to decide when to show the company's proactive messages and not to repeat them | 1 year | When the page with the chat loads |
support-campaign-session-<inbox> | Cookie (same flags) | Random identifier of the visit, for the same purpose | Until the browser is closed | When the page with the chat loads |
__support_test__ | Cookie | Finds the right domain for the cookies above; deleted at once | Immediately deleted | When the page with the chat loads |
support-previews-<inbox>-<id> | Local storage | Remembers which message previews and proactive messages the visitor closed | Until cleared | When the visitor closes one |
On the server, a visitor's session is kept for 180 days and extended with each use; for users who sign in through the company's own website or app, the company sets the duration. The chat also sends the address and title of the page the visitor is on, so that Agents can see the last 20 pages visited; this list is kept for 24 hours. Records of which proactive messages were shown to a browser are kept until the Site is removed.
In a mobile app that uses the EPAV Desk chat, the chat keeps the session in the app's own storage instead of cookies, and the app plugin stores the signed-in user and sign-out state on the device.
What the company should consider. The session and visitor cookies serve the chat that the visitor uses, which is why we consider them strictly necessary. The two campaign cookies are set when the page loads, even before the visitor opens the chat, and their use for proactive messages may need the visitor's consent under the rules that apply to the company's website. The company decides how to handle this in its cookie banner, and can tell its visitors using the table above.
6. How to control cookies
You can delete cookies and local storage in your browser settings, and block them for a given website. If you block the cookies of the cabinet or the panel, you cannot sign in. If you block the chat's cookies, the chat may not remember your conversation between pages and visits.
7. Changes
We update this policy when EPAV Desk starts or stops storing something in browsers, publish every version with its date, and tell account owners about material changes by email at least 15 days before they take effect.