What cookies are
Cookies are small files that a website can store on a user's device to remember information about their visit. The law regulates them — Article 22.2 of the LSSI-CE and Directive 2002/58/EC — because they involve storing or reading information on the user's device, not because they're inherently a risk.
The two cookies on this website
gopenux.com uses two cookies, and neither is an analytics, advertising or profiling cookie. One is written by the site itself, and only if you pick a language in the selector. The other is set automatically by the network that serves the site, to tell human traffic apart from automated traffic. No provider outside our hosting installs anything: the analytics run without cookies and the fonts are served from our own domain, so they are not requested from Google Fonts or any other external provider either.
| Name | Purpose | Duration | Type |
|---|
| gpx_lang | Remember the language you select, so that version is served on later visits without asking again | 1 year | Technical, first-party |
|---|
| __cf_bm | Tell human traffic apart from automated traffic, to protect the site against bots and denial-of-service attacks | 30 minutes | Technical security cookie, set by our network provider |
|---|
It is a technical personalisation cookie: it is created only in response to an action of yours — clicking the language selector — and stores nothing but the language code. Article 22.2 of the LSSI-CE exempts from consent those cookies needed to provide a service the user has expressly requested, which is the case here, and that is why the site shows no banner. You can delete it at any time from your browser settings; the only consequence is that the site will again suggest a language based on your browser's.
The __cf_bm cookie is set by Cloudflare, the delivery and protection network through which DigitalOcean serves gopenux.com. It is written on every page, without you having to do anything, and its only function is to work out whether a request comes from a person or from an automated program, in order to stop bots and attacks. It lasts 30 minutes, it is HttpOnly — no script on the page can read it—, it is generated separately for each website, so it cannot be used to follow you from one site to another, and it does not correspond to any user identifier. It is strictly necessary for the security of the service you requested, so it is exempt from consent under Article 22.2 of the LSSI-CE, just like the previous one; we declare it here because being exempt from consent is not being exempt from disclosure. Gopenux Lab cannot switch it off: it is configured by our hosting provider, not by the website.
How website usage is measured
Website analytics run on Umami, an open source tool that Gopenux Lab hosts on its own infrastructure. Umami measures aggregate usage — page views, traffic source, device type — without installing cookies or any other persistent identifier on the user's device: for that reason, under Article 22.2 of the LSSI-CE, this analytics setup doesn't require your consent, regardless of whether the data it processes is personal data or not.
Whether it also falls outside the scope of the GDPR depends on the IP address being processed irreversibly: through a hash function with a salt that rotates often enough to prevent its reconstruction, without being combined with any other data, without generating any identifier that is stable across visits or sites, and without the server logs retaining the full IP address beyond what's necessary for security. Gopenux Lab configures the Umami instance to meet these conditions. Until they're verified, this analytics setup is treated as if it involved personal data, on the basis of Gopenux Lab's legitimate interest in knowing how the website is used (Article 6.1.f of the GDPR), balanced against the rights of visitors: the impact is minimal because there's no persistent identifier, no profiling and no disclosure to third parties.
Where the data resides
Aggregate analytics data is processed and stored on a Umami instance managed by Gopenux Lab, without being sent to any external analytics provider: no third party receives your browsing activity. That instance is hosted on the same infrastructure as the website, described in section 5.
How to check this yourself
The absence of third parties can be verified by opening the browser's developer tools — the network tab — while browsing the website: gopenux.com doesn't make any request to a third-party domain. That check demonstrates that no third party receives your browsing activity; the location of Gopenux Lab's servers is described in section 5.