Cookie Policy for neonpublic.ai
Last updated: 2026-08-03
This is an English translation provided for convenience. In case of any discrepancy, the Polish-language version is authoritative.
1. What this document covers
1.1. This Cookie Policy describes the cookies and similar technologies used on the neonpublic.ai website and the rules for using the Google Analytics 4 analytics tool and the Meta Pixel marketing tool.
1.2. It supplements the Neon Flower Personal Data Protection Policy, which governs the processing of personal data in accordance with the GDPR (controller, purposes, legal bases, rights). For matters not regulated here, that policy applies.
1.3. Legal basis for cookies other than necessary ones: Article 399 of the Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221; consent requirement for storing information or accessing information stored in a terminal device), where that consent meets the GDPR consent standard (Article 400 of the Electronic Communications Law), and Article 6(1)(a) GDPR (consent) for processing data from those cookies.
2. Controller
The controller is NEON FLOWER sp. z o.o., ul. Eliasza Radzikowskiego 94A/106, 31-315 Kraków (KRS 1193580, NIP 9452316953). Contact: privacy@neonflower.ai. Full information about processing and your rights is available in the Personal Data Protection Policy.
3. Cookies used on the website
| Name | Category | Purpose | Lifetime | Consent? |
|---|---|---|---|---|
cc_cookie | Necessary | Remembering your consent decision | ~182 days | Not required |
_ga | Analytics | User identifier (GA4) | 2 years | Yes |
_ga_* | Analytics | Session state (GA4) | 2 years | Yes |
_gid | Analytics | User identifier (GA4) | 24 h | Yes |
_fbp | Marketing | Browser identifier assigned by the Meta Pixel | 90 days | Yes |
_fbc | Marketing | Record of a click on a Meta ad (ClickID parameter) | 90 days | Yes |
firebaseLocalStorageDb (IndexedDB) | Necessary | Recognizing a logged-in user and redirecting to the chat application | Until cleared | Not required |
theme (localStorage) | Necessary | Remembering light/dark mode | Until cleared | Not required |
3.1. The lifetime of the _fbp and _fbc cookies is set by Meta’s library, not by us. For _fbc, Meta states 90 days in its own technical documentation. For _fbp, Meta publishes no figure, so we state the lifetime observed directly in the browser — the actual expiry of the cookie as set by Meta’s script on our site. Meta may change either value without our involvement and without notice; we update this table when it does. Most recent _fbp measurement on this site: 3 August 2026 — 90 days.
4. Consent and its withdrawal
4.1. We activate cookies other than necessary ones only after consent is given in the cookie banner. Until consent is given, they are blocked by the Google Consent Mode v2 mechanism (default state “denied” for all signals).
4.2. You can change or withdraw your consent at any time using the “Cookie Settings” button in the footer of the website, or by deleting cookies in your browser. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. After consent is withdrawn, analytics and marketing cookies are automatically deleted and the Meta Pixel stops sending events.
4.3. Analytics consent and marketing consent are independent — you can give one without the other. Rejecting is exactly as easy as accepting: both buttons carry equal weight and are available on the first layer of the banner.
5. Google Analytics 4
5.1. We use Google Analytics 4 (loaded via the Firebase Analytics SDK) for traffic statistics and to improve the website. The tool collects, among other things, cookie identifiers, a truncated IP address, and information about the device and behaviour on the website.
5.2. Provider / processor: Google Ireland Ltd / Google LLC. Data retention period in GA4: 14 months. Legal basis: your consent.
5.3. Transfer outside the EEA: data may be transferred to the USA on the basis of the EU-U.S. Data Privacy Framework (Google LLC is certified). More: Google Privacy Policy, Google transfer frameworks.
6. Meta Pixel
6.1. After marketing consent is given, we load the Meta Pixel — a script by Meta that measures the performance of our ads on Facebook and Instagram. The Pixel stores the _fbp and _fbc cookies in your browser (see the table in §3) and sends Meta information about your visit to the site and about submitting the demo booking form (the PageView and Lead events).
6.2. We do not transmit any personal data from the form. Advanced Matching is disabled — no e-mail address, first name, last name, phone number or user identifier reaches Meta, not even in hashed form. We transmit only the fact that the event occurred, together with the cookie identifiers listed in §3.
6.3. Joint controllership. For the stage of collecting data in your browser and transmitting it to Meta, we are joint controllers with Meta Platforms Ireland Ltd. (Merrion Road, Dublin 4, D04 X2K5, Ireland) under Article 26 GDPR. Meta alone is responsible for any further processing of that data for its own purposes. The essence of the arrangement between the joint controllers: Meta Controller Addendum. Information on Meta’s processing: Meta Privacy Policy and Meta Cookies Policy.
6.4. Legal basis: your consent — Article 6(1)(a) GDPR and Article 399 of the Electronic Communications Law. Without marketing consent the Meta Pixel is not loaded and no connection to Meta’s servers takes place.
6.5. Transfer outside the EEA: data may be transferred to the USA. Meta Platforms Inc. is certified under the EU-U.S. Data Privacy Framework.
6.6. You can withdraw marketing consent at any time — see §4.2. After withdrawal the _fbp and _fbc cookies are deleted and the Pixel stops sending any events.
7. Necessary functions operating without consent
7.1. The following processing operations are strictly necessary and operate without consent, but we inform you about them:
Firebase Auth (Google) — reading the login state from IndexedDB in order to redirect a logged-in user to the chat.neonpublic.ai application.
Server logs / hosting — Firebase Hosting (Google), for the security and proper functioning of the website.
7.2. The Inter font is hosted locally (no calls to Google Fonts); icons are embedded at build time — no incidental connections to third-party CDNs.
8. Contact form (for information)
8.1. Data from the demo booking form (first and last name, name and type of institution, e-mail, description of needs) is processed under the rules described in the Personal Data Protection Policy — the form is covered by that policy as pre-contractual contact. The form is provided by Tally BV (Belgium, EU; data in the EU); a submission notification is sent to our address via the subprocessor SendGrid (USA).
9. Your rights
With respect to data processed through cookies/analytics, you have the rights described in the Neon Flower Personal Data Protection Policy, including the right to withdraw consent (see §4) and the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
10. Changes
We may update this policy; the current version is always available on the website together with its effective date.