Cookie Policy.
What we store on your device, why we store it, and how to switch off anything that is not essential.
In plain words.
We use the cookies the site needs to work and precious few others. Nothing here follows you around the internet. The full document below is the binding version.
The full text.
Cookies are small files, and similar pieces of stored data, that a website puts on your device or reads back from it. This policy explains what Calyraen stores, why we store it, how long it stays, and how to switch off anything that is not essential.
The short version: only strictly necessary cookies run before you make a choice. Everything else waits until you say yes, and you can change your mind at any time.
Last updated: 25 July 2026
Who is responsible for these cookies
Calyraen is a computing company established in the Netherlands. We design and build our own hardware, we write our own operating system (CalyOS, in the editions CalyOS Desktop, CalyOS Server and CalyOS Edge), we run CalyCloud for managing those machines from a browser, and we operate consumer platforms. This website, calyraen.com, is ours and we run it.
Where cookies involve personal data, Calyraen is the controller under the General Data Protection Regulation (Regulation (EU) 2016/679, known in Dutch as the AVG).
- Registered name: [registered company name]
- Registered address: [registered address]
- Chamber of Commerce (KvK) number: [KvK number]
- VAT number: [BTW-nummer]
- Privacy and cookie contact: [privacy contact address]
- Data protection officer: [data protection officer contact, if one has been appointed]
You can also reach us through our contact page.
What this policy covers
This policy covers calyraen.com. Where you sign in to CalyCloud, use one of our consumer platforms, or use an app we publish, the same principles apply, but the specific cookies and identifiers differ. Those services carry their own notice where that is the case, and this page tells you what happens on the website.
CalyOS itself is an operating system, not a website. What it stores on your machine is governed by the privacy settings on the device, not by this page.
The rules we follow
Two separate sets of rules apply to cookies, and both matter.
Placing and reading cookies
The rule that governs whether we may store anything on your device, or read something already stored there, is article 11.7a of the Dutch Telecommunicatiewet. That article implements the ePrivacy Directive (Directive 2002/58/EC, as amended by Directive 2009/136/EC) into Dutch law.
It says we may only do this if we have given you clear and complete information about what we are storing and why, and you have given permission first. There are two narrow exceptions where permission is not needed:
- cookies used purely to carry out or make possible the transmission of a communication, and
- cookies that are strictly necessary to deliver a service you have actually asked for.
Dutch law contains one further exemption, for measurement cookies that have no or only minor consequences for your privacy. We have chosen not to rely on it. We ask for consent for all analytics cookies, without exception.
This rule applies whether or not the stored information counts as personal data. Consent has to come first, not afterwards.
What happens to the data afterwards
Once a cookie collects information that can be linked to you, the GDPR applies as well. Our legal bases are:
- Consent (article 6(1)(a) GDPR) for preferences, analytics and marketing cookies, and for everything we do with the data they produce.
- Performance of a contract (article 6(1)(b) GDPR) for cookies that keep you signed in and let you complete an order, once ordering is open.
- Legitimate interests (article 6(1)(f) GDPR) for the cookies that keep the site secure and working, such as protecting forms against abuse and spreading traffic across servers. Our interest is running a site that functions and is not trivially attacked, and we have judged that this does not override your rights. You can ask us for a summary of that assessment at [privacy contact address].
Two regulators can act on this. The Autoriteit Consument en Markt (ACM) enforces the cookie rule in the Telecommunicatiewet. The Autoriteit Persoonsgegevens (AP) enforces the GDPR where personal data is involved.
What we mean by "cookies"
A cookie is a small text file placed in your browser. We use the word here to cover other techniques that work in a similar way, because the law treats them the same:
- Local storage and session storage, which hold small amounts of data in your browser.
- Pixels and tags, sometimes called web beacons, which are tiny elements in a page or an email that signal when content has loaded.
- Software development kits and device identifiers used inside our apps and on our own devices.
The Dutch rule is written in a technology-neutral way. It applies to storing or reading information on your equipment, whatever the method is called. So does this policy.
Nothing optional runs until you say yes
When you arrive, our banner asks what you are comfortable with. Until you answer:
- Only the strictly necessary category loads. It is the only category that runs without your consent, and the only one the law lets us run that way.
- Preferences, analytics and marketing cookies stay switched off.
How the banner behaves:
- Nothing is pre-ticked. Off is the starting position for every optional category.
- Refusing is on the first screen, in the same size and style as accepting. You do not have to open a settings panel to say no.
- Scrolling, clicking through to another page, or closing the banner is not consent. If you dismiss the banner without choosing, only strictly necessary cookies run.
- Consent is given per category. You can accept analytics and refuse marketing, or accept nothing at all.
- We keep a record of what you chose and when, so we can show that consent was properly given, as article 7(1) GDPR requires. We keep that record while your choice is valid and for a short period afterwards, then delete it.
- We ask again after about six months, and sooner if we add a category or start using cookies for a new purpose.
The four categories
| Category | What it does | Runs without consent | Roughly how long it lasts |
|---|---|---|---|
| Strictly necessary | Signs you in, keeps your session, protects forms against abuse, balances traffic, remembers your cookie choice, and holds a basket and completes checkout once the shop is open | Yes. This is the only category that does | Most last only while your browser is open. The record of your cookie choice lasts about six months |
| Preferences | Remembers choices you make, such as language, region, currency, and light or dark appearance | No | From one browser session up to about twelve months |
| Analytics | Counts visits, shows which pages are used, and finds errors and slow pages so we can fix them | No | From about one day up to thirteen months |
| Marketing | Measures whether our campaigns worked and, if you allow it, shows Calyraen messages on other sites | No | Up to about thirteen months, though some partner cookies last up to twenty-four months |
The exact cookie names, the provider behind each one and its precise lifetime are set out here: [full list of cookies in use, with name, provider, purpose and lifetime]. The same detail is shown in the cookie settings panel on this site. We update both when the cookies we use change.
Strictly necessary
These make the site work. Without them you could not sign in, submit a form, or keep an order together. Because the site cannot deliver the service you asked for without them, they fall under the exception in article 11.7a of the Telecommunicatiewet and are always on. They cannot be switched off through our banner.
They include:
- our session cookie, which keeps you signed in and holds your session together as you move between pages,
- XSRF-TOKEN, which protects forms and requests against cross-site request forgery,
- a cookie that stores your cookie choice, so we do not ask you again on every page, and
- once the shop is open, cookies that hold the contents of your basket and carry you through checkout.
We do not use this category to learn anything about you beyond what is needed to run the site.
Preferences
These remember decisions you have made so you do not have to make them again. Language, region, currency and display settings are the usual examples.
If you refuse them, the site still works in full. Some conveniences reset each time you visit, and you may need to set your language or appearance again.
Analytics
These tell us how the site is actually used. Which pages people read, where they give up, which pages are slow, and where something is broken. We use it to fix problems and to write better pages.
We ask for your consent before any analytics cookie is set, even though Dutch law offers a narrow exemption for low-impact measurement. If you refuse, we simply have less information. Nothing about your visit changes.
Where we use an analytics provider, it is named here and in the cookie settings panel: [analytics provider].
Marketing
These measure whether a campaign reached anyone and, where you allow it, let us show Calyraen messages on other sites and platforms. They are usually set by advertising or social media companies rather than by us.
Nothing in this category runs unless you switch it on. If you never switch it on, no marketing cookie is ever placed.
Where we work with an advertising partner, it is named here and in the cookie settings panel: [advertising partner].
Email and tracking pixels
If you have asked us to send you email, we may include a pixel that tells us whether the message was opened and whether a link was followed. This is measurement, and it needs the same consent as an analytics or marketing cookie. If you have not consented, we do not include one. You can turn it off by withdrawing your consent, or by asking us at [privacy contact address], and you can stop the email itself with the unsubscribe link in every message.
How long cookies last
Cookies come in two kinds.
Session cookies exist only while your browser is open. They are deleted when you close it or when your session ends. Most of our strictly necessary cookies work this way.
Persistent cookies stay on your device for a set period, or until you delete them. The periods in the table above are the ones we work to. Where a cookie is set by another company, that company controls its lifetime, and we publish the figure they give us.
You can delete any cookie at any time through your browser, whatever its stated lifetime says.
Cookies set by other companies
Some cookies come from companies other than Calyraen, because we have included a tool, an embedded video, a map or a measurement service from them. Those companies may use cookies to build a picture of your activity across different sites over time.
Two things we hold ourselves to:
- Nothing in the preferences, analytics or marketing categories loads until you have consented. Third-party scripts are blocked before that, rather than loaded and asked to behave.
- We name each third party in the cookie settings panel, with a link to its own privacy and cookie notice, so you can see who you are agreeing to.
We do not control what those companies do with what they collect. Their own terms govern that.
We do not sell the personal data that cookies collect.
Transfers outside the European Economic Area
Some providers in these categories are established outside the European Economic Area, or use sub-processors that are. Where personal data goes to a country without an adequacy decision under article 45 GDPR, we rely on the European Commission's standard contractual clauses under article 46 GDPR, together with an assessment of whether extra measures are needed for that country.
The current list of providers, the countries involved and the safeguard used for each is here: [list of third party providers, destination countries and the transfer safeguard used for each]. You can ask us for a copy of the safeguards at [privacy contact address].
Changing or withdrawing your consent
You can withdraw your consent whenever you like, and it has to be as easy to withdraw as it was to give. It is.
On this site. Use the "Cookie settings" link in the footer of any page. It reopens the same panel you saw on your first visit, with your current choices shown. Turn any category off and save. The change takes effect straight away and we stop setting new cookies in that category.
In your browser. Every major browser lets you see stored cookies, delete them, block third-party cookies, or clear everything when you close the window. Look under "cookies", "privacy" or "site data" in the settings.
On our own devices. On CalyOS Desktop, CalyOS Server and CalyOS Edge, and in our apps, the equivalent permissions and identifiers are managed through the privacy settings on the device.
Withdrawing consent stops future processing. It does not make what happened before unlawful, because your consent was valid at the time. Cookies already stored on your device are not deleted by changing the panel, so clear them in your browser if you want them gone now.
Your choices are saved per browser and per device. If you use a different browser, a private window, or another computer, you will be asked again.
Saying no does not lock you out
Refusing preferences, analytics and marketing cookies does not block access to this website. There is no cookie wall here. You get the same pages, the same information, the same ability to contact us, and the same ability to buy from us once the catalogue opens, as someone who accepted everything.
Consent only counts if it is freely given. Making access conditional on it would mean it was not freely given, which is why the Autoriteit Persoonsgegevens does not accept cookie walls on sites like ours, and why we do not use one.
The only thing you give up by refusing preferences cookies is convenience: a few settings will reset between visits.
Children
This website is aimed at adults and at people buying for a business. We do not knowingly target children with it.
Under article 8 GDPR and the Dutch Uitvoeringswet AVG, a child under 16 cannot give valid consent for an online service on their own. A parent or guardian has to give or authorise it. If you believe a child under 16 has consented to optional cookies here, tell us at [privacy contact address] and we will withdraw the consent and delete the data.
Do Not Track and Global Privacy Control
Some browsers send a "Do Not Track" header. There is no agreed standard for what a website should do with it, so we do not read it as a consent choice. Your setting in our cookie panel is what we act on.
Where a browser or extension sends a Global Privacy Control signal, and the law requires us to treat it as a valid objection or withdrawal, we aim to honour it for the browser and device that sent it. These signals are tied to one browser on one device, so you may need to set them, or set your cookie preferences, everywhere you browse.
Your rights over the data cookies collect
Where cookies collect personal data, you have the rights the GDPR gives you:
- Access (article 15): a copy of the personal data we hold about you and an explanation of what we do with it.
- Rectification (article 16): correction of anything wrong or incomplete.
- Erasure (article 17): deletion, where the law allows it.
- Restriction (article 18): a pause on processing while something is checked or disputed.
- Portability (article 20): the data you gave us, in a machine readable form, where the processing rests on consent or a contract.
- Objection (article 21): the right to object to processing based on our legitimate interests, and an absolute right to object to direct marketing.
- Withdrawal of consent (article 7(3)): at any time, for any optional category, with no reason needed.
Our Privacy Policy sets these out in full, along with how we handle a request and how long we take.
To use any of them, write to [privacy contact address] or use our contact page. We may need to check who you are before we act, and we will answer within one month, as article 12(3) GDPR requires. If a request is complicated we may take up to two further months, and we will tell you within the first month if that happens. Using your rights is free.
If you think we have handled your data badly, please tell us first so we can put it right. You do not have to. You can complain directly to the Autoriteit Persoonsgegevens, the Dutch data protection authority, at autoriteitpersoonsgegevens.nl, under article 77 GDPR. If your complaint is about cookies being placed without consent rather than about your personal data, the regulator is the Autoriteit Consument en Markt, at acm.nl. If you live in another EU country, you may go to your own supervisory authority instead. You can also go to court.
Automated decisions
Our cookies do not feed any automated decision making that produces legal effects for you or similarly significantly affects you, in the sense of article 22 GDPR. Analytics tells us how pages perform. It does not decide anything about you.
Where you consent to marketing cookies, the advertising partner named above may use them to group audiences for showing adverts. That is not a decision about you with legal or similarly significant effects, and you can stop it at any time by withdrawing consent.
Changes to this policy
We update this page when the cookies we use change, when we add or drop a provider, or when the law changes. The "Last updated" date at the top always reflects the current version.
If a change means we want to store something new on your device, or use it for a new purpose, we ask for your consent again through the banner. We do not treat an old consent as covering a new purpose.
How this fits with our other policies
This page covers what we store on your device and why. Our Privacy Policy covers everything else we do with personal data: what we collect, who we share it with, how long we keep it, and your rights in full. Read them together.
Contact
Questions about this policy, about a specific cookie, or about a choice you made: write to [privacy contact address], or use our contact page. We will reply.
More to read.
Terms, privacy, warranty and more. And a human, if you need one.