Legal
Cookie Notice
Short, because there is not much to say. The public site sets no cookies at all, and this is how we checked.
The whole answer, up front
The public KRAGOS site sets no cookies. Not one. It uses no local storage, no session storage and no IndexedDB. It loads no third party font, no analytics, no tag manager and no advertising pixel, and it makes no request to any host other than its own.
There is therefore no cookie banner, because there is nothing to consent to.
This is not an aspiration. It was measured in a real browser against the built site, and clause 3 gives the method and the result.
1. Scope
This notice covers cookies and similar technologies on the KRAGOS surfaces: the public site at kragos.ai and the authenticated products at kragos.app.
It is published by Ecopackaging (Pty) Ltd, trading as KRAGOS, and forms part of the Privacy Notice.
Cookie means a small file a website asks your browser to store. Similar technologies means anything that stores or reads state on your device for the same purpose, including local storage, session storage, IndexedDB, service workers and tracking pixels. This notice covers all of them.
2. The public site
The public site at kragos.ai sets no cookies.
It writes nothing to local storage, session storage or IndexedDB, and it registers no service worker.
It loads its typeface from our own server. It does not use Google Fonts or any other third party font host.
It runs no analytics, no tag manager, no heat mapping and no session recording.
It carries no advertising pixel, no conversion tracker and no remarketing tag.
It makes no request to any host other than its own. Nothing on the page causes your browser to contact a third party.
The site remembers nothing about you between visits, because it stores nothing.
Server access logs are kept, as clause 5 of the Privacy Notice describes and clause 21 of that notice times. A log is not a cookie: it records the request, it does not put anything on your device.
3. How we know
This is a statement of fact about the built site, so it was verified rather than assumed.
Every page of the built site was loaded in a Chromium browser, driven automatically. On each page the navigation drawer was opened, every expandable panel was expanded, and the free calendar bubble was activated, so that any state written by an interaction would be captured. After that, the following were read: document.cookie, the browser's own cookie jar for the whole session, localStorage, sessionStorage, the list of IndexedDB databases, and the service worker controller. Every network request the browser made was recorded.
The result, across every page: no cookie, no local storage entry, no session storage entry, no IndexedDB database, no service worker, and no request to any host other than the site's own.
The measurement is recorded in the build proof and will be repeated on each release.
4. The authenticated products
kragos.app requires you to sign in, and signing in requires state to be kept. The following are set.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| Session | Strictly necessary | To keep you signed in as you move between pages, and to bind your requests to your seat. Without it you would have to sign in on every page. | The browser session, or until you sign out. It does not survive closing the browser unless you chose to stay signed in. |
| Preference | Strictly necessary for the function you asked for | To remember a choice you made in the interface, for example a saved filter or a collapsed panel. It holds a preference, not an identifier, and it is not used to profile you. | Until you clear it or change it. |
Both are first party. Neither is shared with a third party, and neither is used for advertising or for cross-site tracking.
These two are the only categories we set. If we need to set anything else, this notice is updated and its version number raised before the change goes live.
Because both are strictly necessary to deliver the service you have asked for, they do not require consent. Section 11(1)(b) of the Protection of Personal Information Act 4 of 2013 supports them, and, where the GDPR and the ePrivacy Directive apply, Article 5(3) of Directive 2002/58/EC exempts strictly necessary storage from consent.
5. Third party cookies
We set no third party cookies on either surface.
We embed no third party widget, no social media button, no video player from a third party host, and no chat widget from a third party vendor on the public site.
Where you leave our site by following a link, the site you arrive at sets its own cookies under its own notice. We have no control over that and this notice does not cover it.
Where a meeting is booked through Microsoft Bookings, or held in Microsoft Teams, that service runs on Microsoft's own domain under Microsoft's own cookie notice. Clause 19 of the Privacy Notice lists Microsoft as a sub-processor.
6. Advertising cookies
There are none today. We run no advertising pixel, no conversion tracker, no remarketing tag and no cross-site identifier.
What changes if we add one. We are setting this out now so that the position is on the record before rather than after:
- We will not set an advertising or analytics cookie, or fire a pixel, until you have given prior, informed, specific, freely given consent. That is the standard in section 1 and section 11(1)(a) of the Protection of Personal Information Act 4 of 2013 read with section 69, and in Article 5(3) of Directive 2002/58/EC where it applies.
- Consent will be collected through a banner that asks before anything non-essential loads. Nothing non-essential will fire while the banner is open.
- Reject will be as easy as accept, and will be on the first layer of the banner, not hidden behind a settings screen.
- There will be no pre-ticked boxes, no legitimate interests toggle for advertising, and no cookie wall.
- You will be able to withdraw consent at any time, as easily as you gave it.
- This notice will be updated with the name, provider, purpose and lifetime of every cookie added, its version number will be raised, and clause 19 of the Privacy Notice, the sub-processor schedule, will be updated at the same time.
- The change will be made before, not after, the tag goes live.
Until all of that is in place, the answer in clause 6.1 stands.
7. Managing what is stored
You can block or delete cookies and site data in your browser's settings, and you can browse in a private window.
On the public site there is nothing to block, so blocking changes nothing.
On kragos.app, blocking the session cookie will prevent you from signing in. That is not a choice we can work around: without it there is no way to know that the request is yours.
Do Not Track and Global Privacy Control. We do not track, so there is nothing for these signals to change. We will honour them if we ever add anything they would apply to.
8. Questions and changes
Questions about this notice go to ops@kragos.app.
This notice is updated whenever what we set changes, and its version number is raised. Clause 6.2 sets out the process for adding anything non-essential.
Cookie Notice, version 1.0, last updated 5 September 2026. Published by Ecopackaging (Pty) Ltd (registration number 2014/032538/07, VAT registration number 4530265216) trading as KRAGOS, 750 Nieuwhout Street, Garsfontein, Pretoria, 0081, South Africa. All enquiries and notices to ops@kragos.app. Information Officer: Francois Petrus Heunis. Governed by the law of the Republic of South Africa; the parties consent to the jurisdiction of the Gauteng Division of the High Court of South Africa, Pretoria.