Cookie Policy

ePrivacy Directive & AVG compliant · Effective 27 Sep 2026

Cookiebeleid conform de Telecommunicatiewet (Tw) Art. 11.7a en AVG/GDPR.

Cookie & Tracking Technologies Policy

Last updated: 27 September 2026
Version: 2.0
Effective: 27 September 2026
Jurisdiction: Netherlands & EU/EEA
Compliant: GDPR + Telecommunicatiewet


By continuing to use admun.eu, nlit.io, nlebike.com, and all associated platforms, you acknowledge that you have read this Cookie Policy and, where cookies require your consent, that you have provided it via our Cookie Preference Centre.

  • Strictly necessary cookies are placed without consent — they are required for the platform to function.
  • All other categories require your opt-in consent — you may withdraw it at any time without detriment.
  • This policy applies equally to products in pre-registration mode and beta testing mode.

Related Policies: This Cookie Policy forms part of and should be read together with our Privacy & GDPR Policy, Terms of Service, and Terms & Conditions. In the event of any conflict, the Privacy & GDPR Policy prevails on matters of personal data.


Table of Contents

  1. What Are Cookies & Tracking Technologies
  2. Legal Basis & Regulatory Framework
  3. Categories of Cookies We Use
  4. Analytics & Performance Tracking
  5. Marketing & Advertising Cookies
  6. Third-Party Cookies & Tools
  7. Beta & Pre-Registration Tracking
  8. Browsing Behaviour, Profiling & Personalisation
  9. Cookie Retention Periods
  10. Managing & Withdrawing Consent
  11. Do Not Track & Browser Signals
  12. Policy Changes & Right to Amend
  13. Governing Law & Contact

1. What Are Cookies & Tracking Technologies

Cookies are small text files placed on your device (computer, tablet, or smartphone) when you visit a website or use a web application. They are widely used to make websites work efficiently, provide a personalised experience, and give website operators analytical information.

In addition to traditional HTTP cookies, AdMun uses a range of related tracking technologies:

Technology Description Use Case
HTTP Cookies Small text files stored in your browser, either session-based (deleted on close) or persistent (retained for a set period) Authentication, preferences, analytics, marketing
Pixel Tags / Web Beacons Tiny invisible images embedded in pages or emails to track opens, visits, and conversions Email marketing, conversion tracking, ad attribution
Local Storage / Session Storage Browser-based key-value storage (larger capacity than cookies) Platform state, preferences, session persistence, cart contents
Session Tokens Temporary cryptographic tokens (JWT, opaque tokens) Secure authentication, API authorisation
Fingerprinting Device and browser characteristic signals (canvas, fonts, headers) Fraud detection & abuse prevention only — never marketing
API Tracking Tokens Tokens passed in API headers to log usage frequency, endpoint access Rate limiting, usage analytics, integration monitoring

Our use of cookies and tracking technologies is governed by:

Instrument Relevance
Telecommunicatiewet Art. 11.7a Dutch implementation of ePrivacy Directive. Requires prior informed consent for all non-essential cookies. Strictly necessary cookies exempt.
GDPR Art. 6(1)(a) Consent as legal basis for analytics and marketing cookies. Must be freely given, specific, informed, unambiguous. Withdrawable anytime.
GDPR Art. 6(1)(f) Legitimate interests for fraud detection, security monitoring, abuse prevention tracking.
ePrivacy Directive 2002/58/EC EU framework governing electronic communications privacy.
EDPB Guidelines 05/2020 on Consent European Data Protection Board guidelines on valid consent mechanisms.
  • Cookie Preference Centre accessible via footer and displayed on first visit
  • No pre-ticked boxes — pre-ticked boxes do not constitute valid consent
  • Granular toggles per category (Analytics, Marketing, Functional)
  • Consent log recording date, time, scope, and version — per GDPR Art. 7 accountability
  • Easy withdrawal — same interface, immediate effect

3. Categories of Cookies We Use

We use four categories of cookies. The table below summarises each category, its purpose, legal basis, and whether consent is required.

Purpose Essential for platform function. Without them, services such as login, account access, security, payment processing, and cart cannot be provided.
Legal Basis GDPR Art. 6(1)(b) contractual necessity + Art. 6(1)(f) legitimate interests (security)
Data Collected Session authentication tokens, CSRF protection tokens, load balancer routing IDs, cookie consent preference record, language/region selection, shopping cart & form input state
Cookie Name Domain Purpose Retention
session_id / __session admun.eu, nlit.io, nlebike.com User session authentication Session
csrf_token / _csrf All Cross-Site Request Forgery protection Session
cookie_consent / cc_consent All Records your cookie category choices 12 months
locale / language All Language/region preference 12 months
cart_id / cart_token nlebike.com Shopping cart persistence 30 days
XSRF-TOKEN nlit.io Laravel CSRF protection Session
laravel_session nlit.io Laravel session management Session
shopify_pay_redirect nlebike.com Shopify Payments secure redirect Session

Purpose Understand how visitors use our platforms, which pages are most visited, where users drop off, and how our services perform across devices and browsers. Directly informs product improvements.
Legal Basis GDPR Art. 6(1)(a) Consent
Data Collected Pages visited, time on page, scroll depth, click paths, navigation flows, exit pages, browser/OS/device, referring URL, geo (country/city from anonymised IP), feature usage, error/crash events, page load performance, search queries, session duration, return visit frequency
IP Handling Anonymised before storage (last octet zeroed) — not used to identify individuals. Aggregated data does not constitute personal data in processed form.
Cookie Name Provider Purpose Retention
_ga / _ga_* Google Analytics (GA4) Distinguish users, session tracking 26 months
_gid Google Analytics Distinguish users (legacy) 24 hours
_gat / _gat_* Google Analytics Throttle request rate 1 minute
_hjSession_* Hotjar Session identification for heatmaps/recordings 30 minutes
_hjSessionUser_* Hotjar User identification across sessions 12 months
sentry_* Sentry Error tracking, performance monitoring Session / 30 days
mixpanel_* Mixpanel (beta only) Product analytics, funnel analysis 12 months

Purpose Deliver relevant marketing communications, retargeted advertising, and personalised promotional content both on and off our platforms — consistent with marketing rights in Privacy Policy §5.
Legal Basis GDPR Art. 6(1)(a) Consent + Telecommunicatiewet Art. 11.7a
Data Collected & Used Browsing behaviour (pages, features, pricing viewed), product/service interest signals, email engagement (opens, clicks via pixels), cross-device identification signals, ad campaign attribution, audience segments (e.g., "viewed HR pricing", "registered for beta"), conversion events (demo bookings, registrations, purchases)
Cookie Name Provider Purpose Retention
_gcl_au Google Ads / GTM Conversion tracking, ad attribution 90 days
_fbp Meta Pixel Facebook/Instagram retargeting, conversion 90 days
_li_* LinkedIn Insight Tag B2B retargeting, professional audience segmentation 90 days
_tt_* TikTok Pixel Conversion tracking, audience building 90 days
IDE / ANID Google Ads (DoubleClick) Cross-site retargeting, ad personalisation 13 months
NID Google Preferences, ad personalisation (signed-in users) 6 months

Company Marketing Right: AdMun expressly reserves the right to use cookie-derived data — including browsing behaviour, platform interaction, and email engagement signals — for direct and programmatic marketing purposes (Privacy Policy §5). You must opt in to marketing cookies for this to apply; you may withdraw consent at any time.


Purpose Remember your preferences and personalise your experience. These cookies do not track you across third-party websites.
Legal Basis GDPR Art. 6(1)(a) Consent
Data Collected Language/locale preferences, UI theme (light/dark), display settings, saved filters/dashboard configs, acknowledged notices/modals, auto-fill hints (non-sensitive only)
Cookie Name Domain Purpose Retention
theme / color_mode All Light/dark mode preference 12 months
dismissed_* All Acknowledged banners, modals, announcements 12 months
saved_filters nlit.io Recruiter dashboard saved filters 12 months
recently_viewed nlebike.com Recently viewed products carousel 30 days
wishlist_id nlebike.com Wishlist persistence (guest) 90 days

4. Analytics & Performance Tracking in Detail

User Journey Mapping

We track the sequence of pages a user visits within a single session and across multiple sessions to understand feature usage, friction points, and paths to successful outcomes (demo bookings, registrations, purchases).

  • Anonymised click, scroll, and hover behaviour to understand visual attention patterns
  • Session recordings to identify usability issues
  • No capture of sensitive fields (passwords, payment inputs, BSN, IBAN)

A/B Testing & Feature Experiments

  • Cookies assign you consistently to a test variant
  • Test data is aggregated; individual participation not used for profiling
  • Used for: pricing page variants, onboarding flows, feature rollouts

Error & Performance Monitoring (Sentry — Legitimate Interest)

  • JavaScript errors, failed API calls, page load times, browser crashes
  • Data: browser type, page URL, error stack traces — no user identity or personal data
  • Enables rapid identification and resolution of technical issues

AI Model Improvement Analytics

  • Platform interaction data (feature usage, search queries, AI result feedback) collected in anonymised and aggregated form
  • Improves: VBAR Engine, Screener Agent, RAG Compliance Engine, AI-Vector matching, product recommendations
  • Consistent with Privacy Policy §10

5. Marketing & Advertising Cookies in Detail

Specific Activities Enabled

Activity Description Platforms
Retargeting & Remarketing Show AdMun ads on partner sites/networks based on prior visit Google Display Network, LinkedIn, Meta
Conversion Tracking Record demo bookings, beta registrations, purchases for ROAS measurement Google Ads, LinkedIn, Meta, TikTok
Email Marketing Pixels Track email opens, link clicks for campaign performance & personalisation SendGrid, Mailchimp
Audience Segmentation Build segments (e.g., "viewed HR compliance", "abandoned cart") for targeted ads All ad platforms
Lookalike Audiences Find new customers with similar profiles to high-value segments Meta, LinkedIn, Google
Cross-Device Attribution Link activity across desktop/mobile/tablet for accurate journey mapping Google, Meta (with consent)

6. Third-Party Cookies & Tools

We integrate third-party services that may set their own cookies. We do not control third-party cookies; their use is governed by the respective provider's privacy policy.

Provider / Tool Category Purpose Consent Required?
Google Analytics (GA4) Analytics Traffic analysis, user journey, conversion tracking Yes
Google Tag Manager Tag Mgmt Deploys analytics/marketing scripts Partial (container loads necessary tags without consent)
Google Ads / GDN Marketing Retargeting, conversion tracking, audiences Yes
LinkedIn Insight Tag Marketing B2B retargeting, professional segmentation Yes
Meta Pixel (Facebook/Instagram) Marketing Retargeting, lookalike audiences Yes
TikTok Pixel Marketing Conversion tracking, audience building Yes
Hotjar Analytics Heatmaps, session recordings, UX analysis Yes
Sentry Error Monitoring App error detection, performance, crash reporting Legitimate Interest
Mixpanel / Amplitude Analytics Beta product analytics, funnel analysis Yes (beta only)
SendGrid / Mailchimp Email Delivery, open/click tracking, subscriber mgmt Yes (marketing emails)
Shopify Analytics Analytics E-commerce metrics (nlebike.com) Yes
Klaviyo Email Marketing E-commerce email flows, segmentation (NLEBIKE) Yes
Veriff Identity KYC session cookies (Rational HRM) Contractual necessity
Finqle / Mollie / Stripe Payments Secure payment flow, fraud prevention Contractual necessity

Data Transfers: Third-party providers process data subject to their own privacy policies and, where applicable, DPAs with AdMun. Transfers outside EU/EEA subject to appropriate safeguards under GDPR Art. 46 (SCCs or adequacy decisions).


7. Beta & Pre-Registration Application Tracking

Extended Tracking for Beta & Pre-Registration Products: Applications in pre-registration mode or beta testing mode are subject to enhanced cookie and tracking activity beyond what is applied to live production services. By registering for or accessing such applications, you explicitly consent to this extended tracking.

For beta and pre-registration applications, AdMun may additionally collect and process:

  • Full interaction logs — every click, input, navigation event, feature activation (bug identification, UX issues)
  • Form input patterns — keystroke timing, field completion sequences, abandonment points (excluding password/sensitive field content)
  • Onboarding completion funnel data — registration/setup steps completed, skipped, abandoned
  • Feature adoption metrics — modules, configurations, AI tools activated and frequency
  • Feedback & survey responses — in-app feedback, bug reports, satisfaction surveys linked to session/account for context
  • Third-party testing tool data — shared with Mixpanel, Amplitude, or equivalent. Sensitive data (BSN, IBAN, passwords) excluded from all such sharing.

This extended data collection ceases when a beta product transitions to full production status, at which point standard cookie rules apply.


8. Browsing Behaviour, Profiling & Personalisation

AdMun collects and analyses your browsing behaviour on our platforms to:

Purpose Description
Personalise platform content Surface relevant services, features, resources based on industry, role, past interactions
Build behavioural profiles for marketing Browsing history (services viewed, pricing checked, blogs read) determines relevant marketing messages (Privacy Policy §5)
Improve AI recommendation quality Anonymised interaction patterns inform training/calibration of AI systems
Provide relevant third-party advertising When you consent to marketing cookies, behavioural profile informs ads on external platforms

No Sensitive Profiling

Behavioural profiling by AdMun never includes:
- Special category data (health, religion, political opinion, etc.) per GDPR Art. 9
- BSN, IBAN, or any data classified as sensitive
- Data used for automated decisions with significant legal effect on individuals

Profiles are used for service personalisation and marketing only.


Cookies are retained for the shortest period necessary for their purpose.

Cookie Category Typical Retention Notes
Strictly Necessary (session) Session only Deleted when browser closed
Strictly Necessary (persistent) Up to 12 months Login state, consent record, language preference
Analytics Cookies Up to 26 months GA4 default; anonymised after 14 months
Marketing / Retargeting Up to 90 days Standard ad platform retargeting window
Email Pixel Tracking Up to 12 months Linked to email engagement records
Functional Preferences Up to 12 months Reset on preference change
Beta/Pre-reg Extended Logs Until GA launch + 6 months Auto-purge on GA transition

Specific cookie names, providers, and retention periods are detailed in the Cookie Preference Centre (footer). This list is updated when new cookies are added.


You have full control over non-essential cookies. Manage preferences at any time:

Methods

Method How
Cookie Preference Centre Footer of any page → toggle categories → save. Changes take effect immediately.
Browser Settings Most browsers: Privacy/Security → block/delete cookies. Note: blocking all cookies may impair functionality.
Google Analytics Opt-Out GA Opt-out Browser Add-on — prevents GA tracking across all sites.
Ad Network Opt-Out Your Online Choices (EU) or NAI Opt-Out
Email Marketing Opt-Out Unsubscribe link in any AdMun marketing email, or email info@admun.eu
LinkedIn & Meta Controls Manage ad preferences in your LinkedIn/Meta account settings → "Ad Preferences" / "Ad Settings"

Withdrawing consent does not affect the lawfulness of processing carried out prior to withdrawal. Strictly necessary cookies cannot be disabled.


11. Do Not Track & Browser Signals

Some browsers transmit a "Do Not Track" (DNT) signal. Currently there is no binding legal requirement or universally agreed standard for how websites must respond to DNT signals in the Netherlands or EU.

AdMun does not currently alter its cookie behaviour in response to DNT signals; your choices via the Cookie Preference Centre are the operative mechanism for controlling tracking.

We will review our position on DNT and the forthcoming ePrivacy Regulation as it progresses and update this policy accordingly.


12. Policy Changes & Our Right to Amend

Unilateral Right to Amend: AdMun expressly reserves the right to modify, update, or replace this Cookie Policy at any time, with or without prior notice. Changes take effect immediately upon publication. Your continued use of the platform after any amendment constitutes your acceptance of the revised policy. This right applies equally to changes in third-party tools, cookie categories, and marketing data collection practices.

In practice, AdMun aims to:

  • Update the Cookie Preference Centre whenever new cookies are added
  • Notify registered users by email of material changes to marketing/analytics data collection (where commercially practical)
  • Display a re-consent prompt where changes require fresh consent under GDPR
  • Maintain the "Effective Date" at the top of this page to reflect the most recent revision

13. Governing Law & Contact

This Cookie Policy is governed by the laws of The Netherlands and applicable EU law, including the Telecommunicatiewet and GDPR 2016/679. Disputes are submitted to the courts of 's-Gravenhage (The Hague), The Netherlands.

For questions about this Cookie Policy, to exercise your rights, or to withdraw consent for any category of cookie:

Channel Details
Email info@admun.eu • chishty@admun.eu
Address Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands
KVK 84121998 (Eenmanszaak)
Supervisory Authority Autoriteit Persoonsgegevens
EU ODR Platform ec.europa.eu/consumers/odr

Privacy & GDPR Policy | Terms & Conditions | Terms of Service | Disclaimer


© 2026 AdMun / NetherlandsIT — KVK 84121998 — Eenmanszaak registered in The Netherlands.
Cookie & Tracking Technologies Policy v2.0 — Effective 27 September 2026