Skip to Content

Cookie Policy

Introduction

Effective Date: June 2026| Last Updated: September 2026

This policy explains which cookies and similar technologies Y-Institute, trading as Y-Institute ("we", "us"), uses on y-institute.com (the "Website") and in the Y Intelligence platform ("Y", the "Platform"), and how you can control them. It is written to meet Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet), which implements Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive), and Article 13 of Regulation (EU) 2016/679 (GDPR). It forms part of our Privacy Policy

1 What cookies are


Cookies are small text files a website stores on your device. Local storage and session storage are similar browser mechanisms that store data without sending it with every request. Under Article 11.7a of the Telecommunications Act we need your consent before placing cookies or reading information on your device, except for cookies that are strictly necessary to provide a service you have asked for or to transmit a communication. Every cookie in this policy falls within that exception, so we do not ask for consent and do not show a cookie banner. If we ever add analytics, marketing or other non-essential cookies, we will ask for your consent first and update this policy. 



2 The cookies and storage we use


2.1 The Platform (app.y-institute.com and related Y domains)

NameTypePurposeLifetimeCategory
yi.authCookie (HttpOnly, Secure)Keeps you signed in for the current session30 minutes from sign-in, then you are asked to sign in againStrictly necessary
yi.rtCookie (HttpOnly, Secure)Refresh token that lets Y renew your session without asking for your passwordUntil sign-out or expiry of the refresh tokenStrictly necessary
yi.wsCookie (Secure)Remembers which Workspace you are working in across Y's appsUntil sign-out or Workspace changeStrictly necessary
yi.themeCookieRemembers your light or dark display preference12 monthsStrictly necessary (preference you asked for)
Anti-forgery tokenCookie (HttpOnly, Secure)Protects forms and API calls against cross-site request forgerySessionStrictly necessary
cms_access_tokenLocal storageHolds the access token the app uses to call Y's APIUntil sign-out or token expiryStrictly necessary
cms.lastLocation.*Local storageReturns you to the page you were on after signing in againUntil clearedStrictly necessary

2.2 The Website (y-institute.com)

NameSet byPurposeLifetimeCategory
session_idOdoo (our website platform)Identifies your browsing session so that forms and pages workSession, up to 7 daysStrictly necessary
frontend_lang, tzOdooRemember your language and time zone12 monthsStrictly necessary (preference)
__cf_bm, cf_clearance, __cfruidCloudflareDistinguish humans from bots and protect the site against attacks30 minutes to 12 monthsStrictly necessary (security)

2.3 Third-party services

When you sign in with Microsoft or Google, those providers set their own cookies on their own domains under their own policies. When you pay, our payment processor [PAYMENT PROCESSOR] sets cookies on its checkout pages to process the payment and prevent fraud; its cookie policy applies there. Videos embedded from our content delivery network do not set tracking cookies. We do not use Google Analytics, Meta Pixel, LinkedIn Insight or any other analytics or advertising tracker on the Website or the Platform.


3 Your choices


You can delete or block cookies in your browser settings at any time. Because every cookie we use is necessary for sign-in, security or a preference you chose, blocking them will stop you signing in to Y or cause the Website to behave incorrectly. Deleting yi.theme, frontend_lang or tz only resets your display preferences. Instructions for common browsers: Chrome, Edge, Firefox, Safari.


4 Changes


If we add a cookie that requires consent, we will introduce a consent mechanism that meets Article 11.7a of the Telecommunications Act and the guidance of the Autoriteit Persoonsgegevens, and update this page and its date before the cookie is placed.


5 Contact


Y-Institute

Chamber of Commerce (KvK): 

Registered office: 

Data protection contact: [email protected]

Telephone:

You may also complain to the Autoriteit Persoonsgegevens or the Autoriteit Consument & Markt, which supervise cookie compliance in the Netherlands.