Skip to main content

Cookie Policy

Last updated: 2026-09-04

MspCoreX SRL, a company registered in Romania, operates the MspCoreX platform — this website (mspcorex.com), the web application at app.mspcorex.com, the associated mobile applications, and the endpoint monitoring agents. This page covers the website. It expands on section 4 of our Privacy Policy and does not replace it.

There is one cookie on this website. It is a session cookie, it holds a language code, and it is not always set. That is the whole inventory.

1. What a cookie is

A cookie is a small piece of text a website asks your browser to store and send back on later requests. The same law that governs cookies — Article 5(3) of the ePrivacy Directive, implemented in Romania by Law 506/2004 and by its equivalent in the country you are reading from — governs every equivalent technique: localStorage, sessionStorage, IndexedDB, device fingerprinting, and tracking pixels. Everything below is written against that wider definition, not just against cookies.

2. The cookie this website sets

  • Name: NEXT_LOCALE
  • Set by: us, first-party, on the host you are reading, with no Domain attribute — no other website can read it.
  • Contains: one of exactly four values — en, ro, de, fr. No identifier, no number, nothing tied to you.
  • Purpose: remembering which language version of the site you are reading, so a later visit to a bare address lands on the same one.
  • Duration: none. The cookie carries no Expires and no Max-Age attribute, so it is a session cookie — your browser drops it when you close it.
  • Attributes: Path=/, SameSite=Lax. It carries neither HttpOnly nor Secure — the library that writes it sets neither. It is written by our server on the response, and no script on this site reads or writes it.

It is also not set on every visit. The cookie is written only when your request does not already show that you want the language you are being served — that is, when you switch language, or when the address you followed points at a language your browser did not ask for. If your browser asks for English and you are reading the English pages, no cookie is set at all.

3. Why there is no cookie banner

Article 5(3) requires consent for storing or reading information on your device, with two exemptions: carrying out a transmission, and what is strictly necessary to provide the service you asked for. A cookie that holds nothing but the language of the page you requested falls in the second exemption: it is required to serve you the language version you asked for, it carries no identifier, and it does not outlive the browser session. There is nothing else to consent to — no advertising cookie, no analytics cookie, no third-party cookie, and no localStorage, sessionStorage or IndexedDB written by this site's own code.

4. Analytics without a cookie

Our traffic measurement sets no cookie and writes nothing to your device. We run it ourselves — Umami, on our own infrastructure in the EU — and what it records, and on what legal basis, is set out in section 5 of our Privacy Policy. If your browser sends Do Not Track, nothing is recorded at all. We do not act on Global Privacy Control.

The measurement writes nothing to your device, but it does perform a single read. Before recording anything, it checks for an opt-out flag named umami.disabled in your browser's local storage, and stays silent if it finds one. Nothing on this site ever creates that flag — it is there for you or your browser extension to set. Reading it is still access to your device under Art. 5(3), and it is exempt for the same reason the language cookie is: it exists only to honour what you asked for. Setting that flag, or sending Do Not Track, is also how you object to the measurement under Art. 21; your other rights are in our Privacy Policy, and you can complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority where you live.

5. The application and mobile apps

The application is a separate host with its own login, and nothing on this website sets a cookie for it. Signing in there sets strictly-necessary authentication and CSRF cookies, and the application keeps session state in your browser — none of it before you sign in, none of it used for measurement or advertising. Unlike this website, the application does contact third parties on some screens: a font host, a payment provider where card details are entered, a bot check on public sign-up. Client portals served on a domain your provider owns work the same way, under that domain. The detail belongs to the application rather than to this page; the processing is covered by our Privacy Policy.

The mobile applications are not web pages and set no cookies. They keep sign-in tokens in the operating system's secure storage — the iOS keychain or the Android keystore — and non-secret preferences such as language and theme in the app's own private storage.

6. What we do not use

  • No advertising, retargeting, or third-party tracking cookies.
  • No social network pixels, share buttons, or embedded feeds.
  • No session replay, heatmaps, or scroll recording.
  • No cross-site or cross-device identifiers, and no fingerprinting.
  • No A/B testing, personalisation, or consent-management platform.
  • No tag manager, and no third-party analytics or advertising script on any page.

7. Third parties your browser contacts

Nothing your browser loads on this website comes from another domain: no third-party script, font, image, frame, or pixel. Fonts are served from this domain, images are served from this domain, analytics is served from this domain. There are no iframes, no embedded video, no maps, no chat widget, no CAPTCHA. Links to outside sites are plain links: your browser contacts them only if you click, and our referrer policy sends them our address without the page you were on. There is one exception, and it is not a page resource.

This site is delivered through a content delivery network (Cloudflare), which sits between your browser and our servers and therefore sees your request. Its headers also instruct your browser to report failed network connections to a Cloudflare collector at a.nel.cloudflare.com — failures only, no page content, no cookie. We have observed no Cloudflare cookie on our pages. A CDN can set a strictly-necessary cookie to filter bot traffic; if ours ever does, it is set on our domain, it is our responsibility, it serves no advertising or profiling purpose, and we will name it here. Our infrastructure providers are listed at /legal/subprocessors, and our technical measures are described on the Security page.

8. Controlling cookies in your browser

Every browser lets you block or delete cookies and site data, in its privacy or site settings, per site or across the board. Nothing here needs an exception. If you block or clear the one cookie this site sets, the site keeps working exactly as before; you may land on the language your browser asks for rather than the one you last chose, and you can switch again in one click or by using an address that begins with your language. Blocking it costs you nothing else, because it does nothing else.

9. Changes to this policy

If we add anything that stores or reads information on your device, we will describe it here, and where consent is required we will ask for it first. The date at the top reflects the latest revision.

10. Contact

MspCoreX SRL
CUI 55420060 · Reg. Com. J2026049623008 · EUID ROONRC.J2026049623008
Aleea Sinaia nr. 6, Sector 2, Bucharest, Romania
Email: privacy@mspcorex.com
Web: www.mspcorex.com