Legal

Cookie Policy

The public pages of this site set no cookies. The only ones we set keep you signed in to a gated area — which is why you are never asked to accept anything.

Version 2.0 · last updated 18 August 2026.

The short version: the public pages of this site set no cookies at all. The only cookies we set are three strictly necessary authentication cookies, and only after you sign in to a gated area. We run no analytics, no advertising and no third-party tracking tags, which is why this site does not ask you to accept anything.

1. What this policy covers

This policy covers internet.best and its sub-sites and preview environments. Websites published by customers using web.Best are controlled by those customers, who are responsible for their own cookie notices and consent — see Section 6.

A cookie is a small file stored on your device by your browser at a site's request. Similar technologies include local storage, session storage and pixels. What matters legally is not the technology but whether it reads from or writes to your device, and whether it is strictly necessary to deliver a service you asked for.

2. The categories we use — and the ones we do not

We use exactly one category: strictly necessary cookies, for authentication on gated areas. We do not use measurement or analytics cookies, advertising or retargeting cookies, social-network cookies, A/B testing cookies, or any third-party tag that observes your visit.

Because the only cookies we set are strictly necessary to deliver a service you expressly requested — signing in — they are exempt from consent under Article 82 of the Loi Informatique et Libertés and the equivalent provisions of the ePrivacy Directive. That is why you see no cookie banner. This is a description of how the site is built today, not a permanent promise: if we ever add measurement or advertising, those cookies will be set only after consent collected through a banner where refusing is as easy as accepting, and this policy will be updated before they ship.

3. The cookies we actually set

NamePurposeSet whenLifetimeFlags
inv_authKeeps you signed in to the investor areaAfter a successful sign-in at /investors7 daysHttpOnly, Secure, SameSite=Strict
dr_authKeeps you signed in to the data roomAfter a successful sign-in to the data room7 daysHttpOnly, Secure, SameSite=Strict
admin_authKeeps an administrator signed in to the internal dashboardAfter a successful sign-in at /dashboard7 daysHttpOnly, Secure, SameSite=Strict

All three are first-party, signed, and readable only by the server — the HttpOnly flag means no JavaScript on the page can read them, and SameSite=Strict means they are not sent on requests originating from other sites. They contain a signed session token and an expiry, not personal data.

The investor and data room areas also store a flag in your browser's local storage recording that you signed in, so the interface does not flash a login screen on every page change. It holds no personal data and is cleared when you sign out.

4. What we log regardless of cookies

Our servers and content-delivery provider record technical data about requests — IP address, timestamp, URL requested, user-agent, HTTP status and referrer — for security, abuse detection, capacity planning and debugging. This is not done through cookies, does not identify you by name, and is not subject to consent under Article 82. It is processed on the basis of our legitimate interests, as described in the Privacy Policy, and retained for 12 months.

Within the investor area only, we record which documents are viewed or downloaded, so we can tell an interested party from a passing visitor. This is first-party, server-side, and does not use cookies for measurement. It does not operate on the public pages.

5. Managing cookies in your browser

Every major browser lets you view, block and delete cookies through its settings. Because the only cookies we set are the authentication ones, blocking them has a single consequence: you will not be able to stay signed in to the investor area, the data room or the dashboard. Nothing on the public site depends on cookies, so browsing it with cookies disabled works normally.

6. Embedded content and customer sites

Where we embed third-party content such as video, it is loaded from our own content-delivery provider rather than from a third-party player that would observe your visit. If that ever changes, the embed will be loaded only after consent or behind a click-to-load placeholder, and this policy will say so.

Websites published by customers using web.Best may set their own cookies, over which we have no control. The customer is the controller for their site and is responsible for its cookie notice and consent mechanism.

7. Changes and contact

We update this policy when the technologies we use change. The date at the top indicates the current version. Because the site currently sets no non-essential cookies, the most likely future change is the introduction of measurement — which will arrive together with a consent banner, not before it.

Questions about this policy can be sent to privacy [at] internet.best, or to our Data Protection Officer, dpo [at] internet.best.