Template notice — not legal advice. This Cookie Policy is a starting-point template generated to help ComplyWise, Inc. accelerate launch. It is not legal advice and may not reflect the requirements of every jurisdiction or deployment. It must be reviewed and adapted by qualified legal counsel, and reconciled with your actual cookie configuration, before it is published or relied upon. Bracketed items (e.g. [registered address]) are placeholders for you to complete.
Cookie Policy
Last updated: [effective date]
This Cookie Policy explains how ComplyWise, Inc. ("ComplyWise", "we", "us") uses cookies and similar technologies in the ComplyWise compliance-training platform (the "Service"). It should be read together with our Privacy Policy. This policy describes cookies set by the ComplyWise application itself; individual operators (customer tenants) who deploy or configure the Service may enable additional optional features described below.
1. What are cookies?
Cookies are small text files that a website stores in your browser when you visit. They let a site remember information between page loads and visits — for example, keeping you signed in or remembering a display preference. Similar technologies (such as your browser's local storage) can serve comparable purposes; where relevant, references to "cookies" in this policy include those technologies.
Cookies can be first-party (set by the site you are using — here, ComplyWise) or third-party (set by another domain). The ComplyWise application is built on Next.js and uses first-party cookies only. We do not use third-party advertising cookies, cross-site tracking pixels, or ad-network trackers. Cookies may be session cookies (deleted when you close your browser) or persistent cookies (retained until they expire or you delete them).
2. Cookies we use
The table below lists the categories of cookies used by the Service. Exact names, lifetimes, and behavior may vary with configuration and future releases.
| Category | Cookie / item | Purpose | Type & duration | Consent required? |
|---|---|---|---|---|
| Strictly necessary | cw_session (httpOnly) |
Maintains your authenticated session (a stateless JWT stored in an httpOnly cookie) so you stay signed in while using the Service. It is not readable by client-side JavaScript and is required for the application to function. | Session / short-lived (subject to idle timeout) | No — essential |
| MFA pending cookie | Temporarily holds the state of an in-progress multi-factor authentication (TOTP) sign-in between the password step and the verification step. It is short-lived and cleared once sign-in completes or is abandoned. | Session / transient | No — essential | |
| Theme & locale preference | Remembers your interface choices, such as light/dark theme and language/locale, so the Service displays consistently on your next visit. | Persistent (e.g. [up to ~12 months]) | No — essential to deliver a service you requested | |
| Analytics (optional) | ComplyWise first-party analytics cookie(s); Vercel Web Analytics (script only — sets no cookies) | Loaded only after you select “Accept all” in the cookie banner; selecting “Essential only”, or making no choice, loads nothing. Two mechanisms sit behind this single consent: (a) ComplyWise’s own first-party analytics, which records page views to our servers; and (b) Vercel Web Analytics, which measures aggregate page views — it sets no cookies and uses no persistent visitor identifier. Both are used to understand aggregate usage so the Service can be improved. Neither is used for advertising or cross-site tracking. See Vercel in our Sub-processors list. | Persistent (per provider configuration) — off by default | Yes — set only after you accept |
Strictly necessary cookies are required for the Service to work — for example, to sign you in, to complete multi-factor authentication, and to protect the security and integrity of your session. Because they are essential to deliver a service you have actively requested, they are always active and cannot be switched off through the cookie banner. Disabling them in your browser may prevent you from signing in or using core features.
3. How consent works
We distinguish between essential and optional cookies:
- Strictly necessary cookies do not require consent. They are used on the legal basis that they are essential to provide the Service you have asked for, and they are always on.
- Analytics cookies are off by default. If the operator has enabled analytics for your tenant, no analytics cookie is set until you actively accept it. When required, a cookie banner is shown so you can Accept or Decline optional cookies. If you take no action or decline, optional cookies remain disabled and only strictly necessary cookies are used.
We record your choice so we do not repeat the request unnecessarily. Where many deployments have no analytics provider configured, the banner may not appear at all because there are no optional cookies to consent to.
4. How to withdraw consent or manage cookies
You can change or withdraw your choice at any time:
- In the Service: reopen the cookie preferences from [link/location of the "Cookie settings" control, e.g. the site footer] to accept or decline optional cookies. Withdrawing consent stops further use of analytics cookies and, where applicable, clears them.
- In your browser: most browsers let you view, block, or delete cookies through their settings. Clearing cookies for this site will remove your preferences (and may sign you out). Note that blocking strictly necessary cookies will prevent core functionality such as sign-in.
Because ComplyWise uses first-party cookies and no advertising trackers, there are no third-party ad profiles to opt out of for this Service.
5. Changes to this policy
We may update this Cookie Policy to reflect changes in the technologies we use or for legal or operational reasons. Material changes will be indicated by updating the "Last updated" date above and, where appropriate, through a notice in the Service.
6. Contact
If you have questions about this Cookie Policy or our use of cookies, contact:
- ComplyWise, Inc. — [registered address]
- Privacy contact / Data Protection Officer: [DPO / privacy contact email]
- Governing law: [Governing law: e.g., State of Delaware, USA]
If ComplyWise is deployed by your employer or another operator as a tenant of the Service, that organization may also be a controller of certain data; please also refer to their own privacy and cookie notices where provided.