OWNER-APPROVED ENGLISH VERSION — EFFECTIVE 26 AUGUST 2026. Version 1.0.0. Independent Czech legal review is recommended but has not been obtained. This English document applies only where English satisfies applicable language requirements. Publication does not enable paid signup, Stripe Live, a blocked territory or an unverified product capability.
1. What this Policy covers
Cookies are small values stored in a browser. Similar technologies include local storage, SDKs, pixels and device identifiers. This Policy explains technologies used or prepared on diriai.com and the DIRI AI application. The Privacy Policy explains the related personal-data processing.
2. Current necessary technologies
The following inventory reflects the current product design and must be re-scanned against the deployed website before non-essential technology is enabled and after each material release:
| Name or function | Provider | Purpose | Maximum/default lifetime | Status/consent |
|---|---|---|---|---|
__Host-ai_call_coach_session | DIRI AI | authenticate and protect the signed-in session | up to 8 hours | strictly necessary; HttpOnly, Secure and SameSite=Lax in production |
diriai_locale | DIRI AI | remember the language selected by the visitor | up to 1 year | functional setting requested by the visitor; verify classification per territory |
ai_call_coach_trial | DIRI AI | prevent repeated use of a separate public product demo | up to 30 days | conditional and necessary only if that demo is enabled; it is not the paid seven-day subscription trial |
| security/load-balancing values that may be set by Cloudflare or the hosting platform | infrastructure provider | deliver, protect and route the website | provider/session dependent | only values strictly necessary for the requested service may load without consent; exact deployed names must be inventoried |
No Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, PostHog, Mixpanel, Segment, Plausible or equivalent marketing/product analytics tracker is implemented in the verified repository as at the preparation date. Planned marketing does not make a tool active and the effective inventory must never list an unused vendor as if it received data.
3. Categories requiring a prior choice
The following categories must be off by default until the visitor makes a valid choice:
- analytics and product measurement not strictly necessary to provide the requested service;
- advertising, retargeting, conversion pixels and cross-site identifiers;
- personalisation not requested by the visitor;
- embedded third-party media or social features that read or write non-essential identifiers; and
- any future experimentation or session-replay technology.
Newsletter signup itself does not require an advertising cookie, but campaign measurement or profiling may. A consent for email marketing does not automatically permit advertising cookies, and a cookie choice does not automatically subscribe a visitor to email.
4. Consent design required before marketing activation
Where consent is required, the website must:
- block the technology before consent;
- offer Accept and Reject non-essential at the same level and with comparable prominence;
- explain purposes and vendors before the choice;
- avoid pre-ticked boxes, deceptive colours, bundled purposes and consent inferred from scrolling or closing the banner;
- record the version, time, categories and proof without exposing more data than necessary;
- provide a persistent Cookie settings control on every page where non-essential technology can be enabled, normally in the site footer; and
- make withdrawal as easy as acceptance and stop future collection after withdrawal.
The default interval is no more than 12 months for a positive choice and at least 6 months before asking again after refusal, unless a material processing change or deleted browser storage makes a new request appropriate. A valid Global Privacy Control or equivalent legally recognised signal must be honoured where applicable.
5. Browser controls
Visitors can delete or block cookies through browser settings. Blocking a necessary session cookie will prevent sign-in. Browser controls may not stop server-side account, security or billing records; those are described in the Privacy Policy. A browser's generic “Do Not Track” signal is handled only where law or an implemented standard gives it a defined effect.
6. Provider and transfer information
The Subprocessor List identifies infrastructure providers. If a consented analytics or advertising vendor is added, this Policy must first state its name, purposes, cookie identifiers, lifetime, recipients, international-transfer basis and a direct control. Vendor defaults must be reviewed; installing a tag is not legal configuration.
7. Updates and contact
The effective website must re-scan cookies on public, signup, authenticated, checkout and embedded- content routes after every material release. A material new category or vendor requires renewed choice before it runs.
Questions or rights requests: privacy@diriai.com. Effective version: 1.0.0. Effective date: 26 August 2026.