| __session | BRG s.a.s. | necessary (required) | maintains the server-authenticated session and protects restricted application routes | session / up to 5 days for the server-side authenticated session cookie | technical necessity; ePrivacy exemption for strictly necessary user-requested functionality |
| Firebase Authentication browser persistence Used only to keep the requested sign-in state between navigations or across browser sessions depending on the user's login choice. | Firebase Authentication | necessary (required) | browser-side sign-in continuity and support for the authenticated session exchange | browser session or persistent browser storage depending on the 'remember me' choice | technical necessity; ePrivacy exemption for the user-requested authentication flow |
| avb_booking_access Signed HttpOnly cookie, Secure in production, and SameSite=Lax; it contains no IP address, Turnstile token, or fingerprint. | BRG s.a.s. | necessary (required) | temporarily proves successful anti-spam verification and allows the calendar to be disclosed | 30 minutes | technical necessity; ePrivacy exemption for the user-requested booking feature |
| Cloudflare Turnstile challenge storage The widget loads only on the booking page. BRG s.a.s. validates the token server-side without retaining it and does not intentionally send the IP address to Siteverify. | Cloudflare Turnstile | necessary (required) | performs the anti-bot check before the calendar becomes available | technical duration defined by Cloudflare for the requested verification | technical necessity; abuse prevention for a user-requested feature |
| Cal.com hosted booking storage The Cal.com iframe loads only after user interaction and anti-spam verification; it is not used for site analytics or marketing. | Cal.com | necessary (required) | handles availability, email verification, booking, cancellation, and rescheduling | session and technical periods defined by Cal.com for the booking flow | technical necessity; user-requested calendar functionality |
| we-gentic:privacy-consent | BRG s.a.s. | necessary (required) | stores the privacy-banner decision and avoids re-prompting outside the allowed cases | up to 180 days or until replaced by a newer decision | technical necessity and documentation of the user's privacy choice |
| we-gentic:privacy-consent-queue | BRG s.a.s. | necessary (required) | queues consent receipts locally when the browser is offline or the audit endpoint is temporarily unavailable | until successful backend delivery or until browser data is cleared | technical necessity and compliance-interest in preserving consent receipts during temporary network failures |
| sidebar_state Optional technology: saved only after preference consent to remember whether the authenticated-app sidebar is expanded or collapsed. | BRG s.a.s. | preferences | stores the display preference for the authenticated application sidebar | up to 7 days | consent |
| we-gentic:privacy-locale Optional technology: saved only after preference consent to remember the preferred language of the legal pages. | BRG s.a.s. | preferences | stores the selected language for the Privacy Notice and Cookie Notice | up to 180 days or until browser data is cleared | consent |
| we-gentic:client-create-draft Optional technology used only in the admin /clients/new area to restore an unfinished draft. | BRG s.a.s. | preferences | stores a local draft of the client-create form for operational convenience | until the form is submitted, manually cleared, or browser data is removed | consent |