HygiControl
Cookie management policy
Cookies and trackers used on hygicontrol.fr and in the HygiControl applications
Updated: 6 August 2026·CK-HC-2026-001 · V1.0
This policy describes the cookies and similar technologies used by EASYTECH SOLUTIONS in connection with the HygiControl service. It complements the Privacy Policy and is prepared in accordance with Article 82 of French Act No. 78-17 of 6 January 1978 as amended and CNIL recommendations. If language versions diverge, the French version prevails.
1. The essentials in three sentences
This situation is verified as of the date shown at the top of this document. If a non-essential tracker were added in the future, a consent banner would be put in place first — allowing refusal as easily as acceptance — and this policy would be updated.
2. What is a cookie or tracker?
A cookie is a small file placed on your device (computer, phone or tablet) when you visit a website. Other technologies have an equivalent effect: browser local storage (localStorage, sessionStorage, IndexedDB), notification identifiers and diagnostic tools built into mobile apps. This policy covers all of these technologies, referred to as “trackers”.
The rules distinguish two categories. Trackers that are strictly necessary to provide a service expressly requested by the user are exempt from consent: they support authentication, security, load balancing or remembering a display preference. All others — audience measurement, advertising, personalisation, social networks — require prior, free and revocable consent.
3. Cookies set by the website
Inventory of trackers set on the website and customer portal. All are set by HygiControl itself (first-party cookies) and are strictly necessary.
- Name
- ckhygiene-locale
- Type
- Cookie
- Purpose
- Remembers the chosen language so the site is shown in the user’s language on later visits.
- Duration
- 1 year
- Consent
- Exempt — display preference
- Name
- ckhygiene-locale
- Type
- Local storage
- Purpose
- Backup copy of the language preference, used if the cookie is unavailable.
- Duration
- Until cleared
- Consent
- Exempt — display preference
- Name
- ow_at
- Type
- Secure cookie
- Purpose
- Access token that keeps a signed-in portal session active. Not accessible to scripts (httpOnly).
- Duration
- 15 minutes
- Consent
- Exempt — authentication
- Name
- ow_rt
- Type
- Secure cookie
- Purpose
- Refresh token that avoids asking the user to sign in again each time a session expires. Not accessible to scripts (httpOnly).
- Duration
- 7 days
- Consent
- Exempt — authentication
- Name
- ow_auth
- Type
- Cookie
- Purpose
- Tells the interface that a session is open so the account menu is shown instead of the sign-in button.
- Duration
- 7 days
- Consent
- Exempt — authentication
On public pages, when you are not signed in, only the language preference is stored. Session cookies appear only after portal authentication.
4. Cookies related to payment and hosting
- Origin
- Stripe (payment provider)
- When they appear
- Only when the user starts a payment or subscription and is redirected to Stripe’s secure page. No Stripe cookie is set during ordinary browsing of the site.
- Purpose and status
- Securing the transaction, fraud prevention and completing the payment. These trackers are necessary to perform a service requested by the user. They are governed by Stripe’s privacy policy at stripe.com.
- Origin
- Host and infrastructure
- When they appear
- Where applicable, from the first visit.
- Purpose and status
- Technical security cookies set by the hosting infrastructure (bot and attack protection, load balancing). They enable no advertising tracking and are exempt from consent on security grounds.
5. Mobile application trackers
The mobile apps do not use browser cookies, but rely on comparable technical components.
- Component
- Push notifications (Firebase Cloud Messaging)
- Role
- Deliver functional alerts to the phone: missing temperature reading, overdue task, reported non-conformity.
- Data concerned and status
- A technical identifier is assigned to the app install to address notifications. It does not identify a person outside the service. Necessary for alerts; notifications can be disabled at any time in phone settings.
- Component
- Crash reports (Firebase Crashlytics)
- Role
- Automatically report app crashes to the publisher so they can be fixed.
- Data concerned and status
- Transmitted: nature of the error, device model, OS version and app version. No data entered in the app is voluntarily transmitted. Used only for technical diagnosis and fixing defects, not for audience measurement or advertising.
- Component
- Local storage on the device
- Role
- Enable offline use and avoid signing in on every launch.
- Data concerned and status
- Auth tokens are kept in the OS secure store (Keychain on iOS, Keystore on Android). Cached data and photos pending upload are stored in the app’s private space. Everything is cleared on sign-out.
The apps include no audience-measurement tools (Firebase Analytics is not integrated), no advertising components, and do not access the device advertising identifier (IDFA on iOS, Android Advertising ID). No advertising tracking prompt is therefore shown.
6. What the service does not use
As of the publication date, neither the website nor the apps use:
- audience-measurement tools (Google Analytics, Matomo, Plausible, Hotjar, Clarity or equivalent);
- advertising cookies or tracking pixels (Meta, LinkedIn, Google Ads or equivalent);
- share buttons or embedded content from a social network;
- third-party instant messaging or support widgets;
- online web-font services: fonts are bundled with the site and apps, with no call to an external server;
- libraries loaded from a third-party server, embedded interactive maps, embedded video, or captcha-style anti-bot devices.
7. How to control trackers
Because the trackers used are strictly necessary, refusing them prevents normal use of the service: deleting session cookies signs you out immediately. You nonetheless retain full control of your device.
- Web browser
- Settings let you view, delete and block cookies: Chrome — Settings, Privacy and security, Cookies; Firefox — Settings, Privacy & Security; Safari — Settings, Privacy; Edge — Settings, Cookies and site permissions. Private browsing clears cookies when the window is closed.
- Mobile apps
- Disable notifications in the phone settings for the app. Signing out clears locally stored data. Uninstalling removes all data stored on the device.
- User account
- Signing out from the app or portal deletes session cookies and cached data.
8. Retention and updates
Each tracker’s lifetime is listed in the tables above; none exceeds thirteen months. This policy is reviewed whenever the service’s technical stack changes, and at least once a year. The applicable version is the one published on hygicontrol.fr, identified by its version number and update date.
If language versions diverge, the French version prevails.
Contact
Questions about cookies may be sent to contact@easytechsolutions.fr (subject: “Cookies”). General personal-data processing and rights are described in the Privacy Policy (https://ckhygiene.cloud/privacy). A complaint may be lodged with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07.