| Cookie | Type | Purpose | Retention |
|---|---|---|---|
auth.fixdigital.co.il |
Strictly necessary | Maintains authenticated state after successful login. | Session inactivity timeout (480 minutes), or up to 30 days when "Remember me" is enabled. |
.FixAuth.Session |
Strictly necessary | Stores temporary server session data for authentication steps. | Up to 1 hour. |
Auth.ReturnUrl |
Strictly necessary | Stores the target return URL between auth steps. | Up to 1 hour. |
.AspNetCore.Culture |
Preference | Stores preferred UI language. | Up to 1 year. |
auth.warning.seen |
Strictly necessary | Stores acknowledgement of the technical warning modal. | Up to 30 days. |
TrustedDevice |
Strictly necessary | Stores a device token that can skip repeated 2FA verification on this device. | Up to 30 days. |
To revoke trusted devices, contact support/security and request trusted device reset for your account.
If you have privacy questions about authentication cookies, contact our support/security team.
Authentication-related telemetry is processed for security, fraud prevention and operational support. These records are not used for marketing analytics.
| Data class | Purpose | Lawful basis | Retention | Storage | Owner |
|---|---|---|---|---|---|
| Authentication audit logs | Security incident investigation and abuse detection | Legitimate interests | 365 days | Elasticsearch | SecurityOps |
| Login timestamps | Operational account support and account activity checks | Contract | 365 days | SQL | AuthService |
| Trusted device telemetry | 2FA risk reduction and trusted device management | Legitimate interests | 30 days | SQL | AuthService |
| 2FA setup/login events | Authentication security and fraud prevention | Legitimate interests | 180 days | Elasticsearch | SecurityOps |
| Password reset events | Account recovery security | Legitimate interests | 180 days | Elasticsearch | SecurityOps |