Skip to content

COOKIE POLICY

Version of 11 May 2026 · Golova Europe SL
1. Introduction

This Cookie Policy (the “Policy”) describes how Golova Europe SL (Tax ID B70717004, EU VAT ESB70717004, registered office at Calle l’Hospital, 95, Planta 1, Puerta 2, 08001 Barcelona, Spain — the “Controller”, “Golova”, “we”) uses cookies and similar technologies on the website golova.ai and within the Golova platform (the “Services”).

This Policy complements our Privacy Policy and is published in compliance with Article 22.2 of Spanish Law 34/2002 (LSSI-CE), Article 5.3 of Directive 2002/58/EC (ePrivacy Directive), Regulation (EU) 2016/679 (GDPR) and the Guidance on the use of cookies issued by the Spanish Data Protection Agency (AEPD).

2. What are cookies

Cookies are small text files that a website or application installs on your device (computer, tablet or smartphone) when you visit it. Cookies enable the site to recognise your device on subsequent visits, store your preferences, ensure security and measure how the Services are used.

This Policy also covers similar technologies that fulfil comparable purposes — local storage, session storage, web beacons, pixels and software development kits (SDKs) integrated into our mobile applications. For convenience, all of these are referred to below as “cookies”.

3. Categories of cookies we use

Cookies are classified by:

  • Who installs them — first-party (installed by golova.ai) or third-party (installed by the service providers we use);
  • Their duration — session cookies (deleted when you close the browser) or persistent cookies (retained for a specified period);
  • Their purpose — strictly necessary, preferences, analytics or marketing.

We do not use cookies for behavioural advertising, cross-site profiling or retargeting.

3.1. Strictly necessary cookies. Essential for the operation of the Services. They enable basic functions such as authentication, session management, security (CSRF protection, bot detection) and storage of your cookie preferences. They cannot be disabled via our consent management tool because the Services would not function without them. Strictly necessary cookies are exempt from the prior consent requirement (Article 22.2 LSSI-CE).

3.2. Preference cookies. These cookies remember the choices you have made about the appearance and behaviour of the Services, such as the language or theme selected. They are not strictly necessary but improve your experience. The legal basis is your consent — although where the preference is set by a direct user action (such as language selection), we treat it as strictly necessary under the AEPD exception for a “service expressly requested by the user”.

3.3. Analytics cookies. These cookies help us understand how the Services are used in aggregate form — which features are most popular, how long sessions last, where errors occur. The data is used to improve the Services. The legal basis is your prior consent. You can use the Services normally if you reject these cookies.

3.4. Marketing cookies. We do not currently use marketing or advertising cookies. If this changes, we will update this Policy and request your consent before installing any such cookies.

4. Specific cookies in use

The table below lists the cookies currently used in the Services. Where a third-party provider is named, that provider acts as our data processor under a written contract compliant with Article 28 GDPR. For details, see our subprocessor list at https://golova.ai/en/subprocessors.

Cookie Provider Type Purpose Duration
PHPSESSID / session_id golova.ai Strictly necessary Maintain the user’s session and authentication state. Session
XSRF-TOKEN, csrf_token golova.ai Strictly necessary Prevent cross-site request forgery (CSRF) attacks on forms. Session
cookie_consent golova.ai Strictly necessary Store the user’s cookie preferences and consent record. 12 months
language golova.ai Preferences Remember the user’s chosen interface language. 12 months
theme golova.ai Preferences Remember the user’s chosen interface theme (light / dark / auto). 12 months
__cf_bm, cf_clearance Cloudflare Strictly necessary Bot detection, DDoS protection, security challenges. 30 min / 30 days
_ga, _ga_*, _gid [analytics provider] Analytics Distinguish users and measure aggregate use. Only after consent. Up to 24 months
sentry-trace, sentry-baggage Functional Software Inc. (Sentry) Analytics Application error and performance monitoring. Only after consent. Session / 12 months

This list is reviewed and updated periodically. The current version is always available at https://golova.ai/en/cookie-policy. When we add or modify a non-strictly-necessary cookie, the consent banner requests your consent again.

5. Your consent and how to manage cookies

5.1. When you first visit golova.ai, a cookie consent banner is displayed. The banner allows you to: (a) accept all categories of cookies; (b) reject all categories of cookies, except those strictly necessary for the operation of the Services; or (c) configure your preferences granularly by category. Until you make your choice, no non-strictly-necessary cookies are installed.

5.2. The options to accept and to reject cookies are designed to require the same number of clicks and are presented with equivalent visibility, in line with the AEPD Cookie Guidance of 2023.

5.3. Your consent is recorded together with the date, the version of the banner displayed and the options chosen. You can withdraw or change your consent at any time by clicking the “Cookie preferences” link in the footer of any page of golova.ai.

5.4. You can also manage cookies directly from your browser:

5.5. Disabling strictly necessary cookies via the browser may cause parts of the Services to malfunction (for example, you may not be able to stay logged in).

6. Cookies in the mobile application

Our mobile applications (Android via Google Play, iOS via App Store) use comparable technologies for the same purposes — authentication, security, error monitoring and analytics. The mobile applications follow the same consent logic as the website: non-essential analytics and diagnostic functions are activated only after your consent given at first launch, and can be changed at any time in the application settings.

In addition, the mobile applications use Apple Push Notification Service (APNS) and Google Firebase Cloud Messaging (FCM) for notifications. These services may transfer technical identifiers to servers in the United States. For such transfers, we rely on Standard Contractual Clauses and, where applicable, on the EU-US Data Privacy Framework — see our Privacy Policy.

7. International transfers via cookies

Some of the cookies and third-party SDKs we use are operated by providers established outside the European Economic Area, in particular in the United States (Cloudflare, Apple, Google). The use of these cookies may involve an international transfer of your data.

For each such transfer, we rely on the safeguards described in section 7 of our Privacy Policy — adequacy decisions where available (in particular the EU-US Data Privacy Framework and the December 2025 adequacy decision for the United Kingdom), or Standard Contractual Clauses adopted by the European Commission together with supplementary measures and a Transfer Impact Assessment.

8. Updates to this Policy

We update this Policy whenever the cookies in use change. The date of the last update is indicated at the beginning of the document. When we add a new analytics or marketing cookie, we request your consent again via the banner — your previous consent does not automatically extend to new cookies.

9. Language of this Policy

This Policy is published in English as the master version. Translations into Spanish, Catalan, German, French and Brazilian Portuguese are provided for the convenience of users of those languages. For business Customers, in the event of any discrepancy between language versions, the English version prevails. For Consumers, the language version in which the Customer concluded the contract is binding.

10. Contact and complaints

Questions about this Policy may be addressed to privacy@golova.ai.

You also have the right to lodge a complaint with a supervisory authority. Since Golova is established in Spain, the lead supervisory authority is the Spanish Data Protection Agency (AEPD, www.aepd.es). Under the one-stop-shop mechanism (Article 56 GDPR), you may also lodge a complaint with the supervisory authority of your habitual residence in the EU/EEA.

— End of Cookie Policy —