Last updated: 26 September 2026
This policy explains what coworkings.nl puts on your device when you browse the catalogue, and what it does not. The short answer is that we set no cookies of our own — but that is not the whole story: the site carries one analytics counter, which sets cookies of its own once it loads, and our hosting provider sets security cookies. The rest of this page sets out exactly what is stored, by whom, for how long, and how you can clear it or switch it off.
It sits alongside our Privacy Policy, which covers the details you send us through an enquiry form, and our Terms and Conditions.
The short version
- We set no cookies of our own — no advertising cookies, no session cookies.
- There is no account, no login and no server session on this site, so there is nothing for a session cookie to hold.
- One analytics counter runs on the site: Yandex.Metrica, with session replay (Webvisor) and click map. It sets its own cookies. It loads unless you switch analytics off in Cookie Settings in the footer; when it is off, its script is not requested at all.
- Cloudflare, which hosts and protects the site, sets its own technical cookies for security. These are strictly necessary and outside our control.
- We do use your browser's own storage to remember three small things that last — your shortlist of buildings, your cookie choice and a dismissed language hint. Everything else we write, including every pop-up record, lives only in the current tab and is gone when you close it. None of it is ever sent to us.
- Some page elements are loaded from other companies, which means those companies can see your IP address, and the map can store data of its own once it loads. They are listed below.
- Sending an enquiry keeps you on this domain: the form posts to coworkings.nl itself, and no third-party forwarding service is involved in delivering it.
Who this policy is from
coworkings.nl is a catalogue of flexible workspace in the Netherlands, operated by Fiato Trade Ltd., a company registered in Saint Vincent and the Grenadines under company number 25565 BC 2019, registered office First Floor, St.Vincent Bank Ltd, James Street, Kingstown, Saint Vincent and the Grenadines. Our contact address in the Netherlands is Rokin 92-96, 1012 KX Amsterdam.
For anything in this policy, write to info@coworkings.nl.
Cookies and browser storage: what is the difference
A cookie is a small file that a website asks your browser to keep and then sends back to a server with every later request to that site. Because it travels with each request, a cookie can be used to recognise a returning browser — which is why cookies are the usual tool for logins, analytics and advertising.
localStorage and sessionStorage are different. They are key-and-value stores that live inside your browser. Nothing in them is attached to network requests automatically. A value only leaves your device if the page's own code deliberately sends it — and on this site, none of it is sent anywhere. localStorage stays until you clear it. sessionStorage is wiped as soon as you close the tab.
The Dutch rules — article 11.7a of the Telecommunicatiewet, read together with the GDPR — apply to storing or reading information on your device whatever the technology is called. So we describe our browser storage here on the same footing as cookies, rather than leaving it out because it is technically not a cookie. Supervision of the cookie rules lies with the Autoriteit Consument & Markt (ACM) and, where personal data is involved, with the Autoriteit Persoonsgegevens.
We set no cookies of our own
This site is built in advance as a set of static pages and served from Cloudflare Workers. There is no application server of ours behind it, no user account, no shopping basket and no server-side session. As a result there is no first-party cookie of ours to describe — no table of them exists because none of them exist.
We also run no advertising tags, no social media pixels and no cross-site tracking of any kind. The one measurement tool on the site is the analytics counter described below.
Cookies set by Cloudflare
The site is hosted and protected by Cloudflare, Inc. Cloudflare's network sits in front of every page and may set its own technical cookies to keep the site available and to tell real visitors from automated traffic. These are set by the infrastructure, not by us, and we cannot read them or switch them off for you.
| Cookie | Set by | Purpose | Category |
|---|---|---|---|
| __cf_bm | Cloudflare | Distinguishes human visitors from bots so that abusive automated traffic can be filtered out. | Strictly necessary |
| cf_clearance | Cloudflare | Records that a browser has passed a security check, so the check is not repeated on every page. | Strictly necessary |
Both are security and delivery cookies rather than analytics or marketing cookies, and under article 11.7a of the Telecommunicatiewet strictly necessary cookies do not require consent. Their exact lifetimes are set by Cloudflare and are described in Cloudflare's own documentation. Depending on how you reach the site and how our security settings respond to your traffic, you may see one, both or neither.
Analytics: Yandex.Metrica
The site carries a Yandex.Metrica counter. It measures page views, where visitors come from, the device and browser used, and — because session replay (Webvisor) and the click map are switched on — how visitors move around a page: scrolling, clicks and mouse movement. The measurements are sent to Yandex, which processes them on its own infrastructure, including outside the European Economic Area.
When it is allowed to run, the counter sets cookies of its own. These are set by Yandex, not by us; their names and lifetimes are set by Yandex and described in Yandex's own documentation. The ones you are most likely to see are:
| Cookie | Set by | Purpose | Category |
|---|---|---|---|
| _ym_uid | Yandex.Metrica | Identifies a browser across visits so that returning visitors can be counted. | Analytics |
| _ym_d | Yandex.Metrica | Records the date of the browser's first visit. | Analytics |
| _ym_isad | Yandex.Metrica | Records whether the browser has an ad blocker. | Analytics |
| _ym_visorc | Yandex.Metrica | Allows session replay (Webvisor) to work. | Analytics |
How it is switched on and off. The counter's script is requested about a second and a half after the page finishes loading, or at your first touch, scroll, key press or mouse movement — but only if the analytics switch in Cookie Settings in the footer is on. The switch stands in the "on" position until you change it. If you turn it off, the page reads that choice (the rot_cookie_analytics entry described below) before anything is loaded, and the script is not requested at all; nothing is sent to Yandex. Cookies the counter set on an earlier visit are not deleted by the switch — clear them in your browser, as described under "How to control what is stored".
Google Analytics is not loaded. The pages contain a prepared but disabled Google Analytics block; if it is ever switched on, it will follow the same switch in Cookie Settings, and this page will be updated first.
What we keep in your browser storage
This is the complete list of what coworkings.nl itself stores. Every entry below is written and read only by the page you are looking at. None of it is transmitted to us, to our hosting, or to anyone else. Clearing your browser's site data for coworkings.nl removes all of it, and the site keeps working normally afterwards.
Third-party components can store data of their own on your device, which is not covered by the list below: the Yandex.Metrica counter does so through its cookies, and the Mapbox map does so once it loads — and it loads only after you interact with a page that has a map (a scroll, a click or a movement of the mouse). If you would rather that did not happen, switch analytics off in Cookie Settings, block third-party storage for this site in your browser, or browse privately.
localStorage — stays until you clear it
| Key | What it holds |
|---|---|
| rot_favs | Your shortlist of saved buildings, so the ones you marked as favourites are still there when you come back. It is a list of building references, nothing more. |
| rot_cookie_analytics | The choice you made in the Cookie Settings panel about analytics. This is what the page reads before deciding whether to load the counter, and what allows us to honour a refusal rather than ask you again. |
| rot_bridge_off | Remembers that you dismissed the language hint, so it is not shown to you again. It is written only when you dismiss it. |
sessionStorage — wiped when you close the tab
| Key | What it holds |
|---|---|
| promoShownAt, bdPromoShownAt, cwPromoShownAt, mcPromoShownAt, brandPromoShownAt, rotAnyPopupAt | Timestamps recording when each type of enquiry pop-up was last displayed, so the same window is not thrown at you repeatedly during your visit. |
| rotPromoClosed, rotBdClosed, rotCwClosed, rotMcClosed | Flags recording that you closed a particular pop-up, so it stays closed for the rest of the visit. |
None of these entries identify you by name, build a profile, follow you to other websites, or feed any advertising system. Apart from your shortlist, your analytics choice and the dismissed language hint, everything above disappears together with the tab.
Most entries are written only after you do something — save a building, close a window, make a choice. The pop-up records are the exception: a timestamp is written when a window is first displayed, precisely so that it is shown less often. Those records are deliberately kept in tab-only storage, so nothing about which pop-ups you have seen is carried into a later visit. If you would rather nothing at all was written, use a private window, or block storage for this site in your browser.
Third-party services that can see your IP address
Whenever a browser fetches a file from another company's servers, that company necessarily receives your IP address, your browser's user-agent string and the address of the page requesting the file. That happens on almost every website; here is who it involves on ours.
- Cloudflare, Inc. — hosting, content delivery and protection against attacks. Every request passes through it, and it sets the technical cookies described above. Cloudflare is also more than our host: the code that receives an enquiry runs on its network, and the e-mail copy of an enquiry is sent by Cloudflare's own e-mail service, as described below. Building photographs are served from Cloudflare storage (R2) at photos.rentofficetoday.com.
- Amazon Web Services (S3) — some original building photographs are served directly from storage there, so those image requests reach AWS.
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the typefaces used across the site.
- Yandex (mc.yandex.ru) — the analytics counter described above, requested only while analytics is switched on in Cookie Settings.
- Mapbox — the interactive map. It is deliberately not loaded when the page opens: the map code is only requested after you do something on the page, such as scrolling, clicking or moving the mouse. If you open a page and leave it alone, no request reaches Mapbox. Once it has loaded, Mapbox can store data of its own on your device, which we neither control nor read.
Sending an enquiry does not hand your browser over to anybody else. The form posts to an address on coworkings.nl itself, and our own code, running on Cloudflare's network, deals with it there. From there the message goes to two places: to Telegram (Telegram Messenger Inc.), which is established outside the European Economic Area, and to an e-mail sent by Cloudflare's own e-mail service from an address on this domain to our verified mailbox. There is no third-party forwarding or mailing service anywhere in that chain. Because those messages are sent by our code and not by your browser, neither Telegram nor the mail path receives a request from you, and your IP address is not passed to them as part of it. What happens to the details you type is set out in the Privacy Policy.
Your IP address is, however, used at that endpoint for one narrow purpose, and no cookie or stored value is involved in it: the code counts recent submissions from the same address and, above six in a minute, declines and asks you to try again shortly rather than pretending your message was sent. The form is protected in the same cookie-free way against automated abuse — by a hidden field that only automated software fills in, by a check that the request comes from a page on this site, by a ceiling on the size of what may be submitted, and by discarding administrative fields such as those that would try to redirect a copy of your message to another address.
These companies act under their own privacy terms for the technical data they receive. We do not send them any of the details you type into a form as part of loading a page.
How to control what is stored
Cookie Settings
Every page has a Cookie Settings link in the footer. It opens a panel where you can switch analytics on or off. Your answer is recorded in your browser (the rot_cookie_analytics entry above) and takes effect on the next page load: with analytics off, the Yandex.Metrica script is not requested. The panel has no separate control for the pop-up records, because none of them outlive the tab you are using.
Your browser
Browser settings give you the real control, and they cover things we cannot switch off for you — including Cloudflare's security cookies, cookies the analytics counter set on an earlier visit, and anything the map stores. In Chrome, Edge, Firefox and Safari you can, for this site specifically:
- view and delete cookies and site data;
- block cookies and storage from third parties, or from all sites;
- clear everything a site has stored, including localStorage and sessionStorage.
Clearing site data for coworkings.nl resets everything listed on this page. The practical effect is small: your saved shortlist disappears, your analytics choice returns to its starting position, and pop-ups you had dismissed may appear again. Nothing else breaks. There is no sign-in to lose, and no form on the site depends on a cookie in order to submit: the enquiry endpoint checks that the request comes from a page on this site, which needs nothing stored on your device.
Blocking Cloudflare's cookies is your right, but be aware that the security layer may then ask you to pass a check more often.
Private browsing
Opening the site in a private or incognito window is the simplest option if you want nothing to persist. Everything described above is discarded when you close that window.
How to withdraw your consent
You can withdraw your consent to analytics at any time in the Cookie Settings panel in the footer, and clear the stored record of it in your browser. Withdrawal is as easy as giving consent in the first place:
- open Cookie Settings in the footer and turn analytics off — from your next page view the counter is not loaded;
- delete the counter's cookies in your browser if you want the record of earlier visits gone from your device;
- clear the site's data in your browser if you want the record of the choice itself gone;
- close the tab, and every pop-up record described above goes with it — there is nothing left to withdraw.
Withdrawing consent does not affect anything that was lawfully collected before you withdrew it.
Your rights and how to complain
This policy is written to meet article 11.7a of the Telecommunicatiewet and the GDPR. Where information stored on your device counts as personal data, the rights set out in our Privacy Policy apply to it — including the right to ask what is held and to ask for it to be deleted.
If you think we have handled any of this badly, tell us at info@coworkings.nl. Your right to complain to the Autoriteit Persoonsgegevens, and how to use it, is set out in our Privacy Policy.
Changes to this policy
We will update this page if what we store changes — in particular if we change or add an analytics tool, a new third-party service, or any cookie of our own. The date at the top always shows the current version. There is no mailing list here, so the page itself is the notice; it is worth a glance if this matters to you.
Contact us
Questions about cookies, browser storage or anything else on this page: info@coworkings.nl. Related documents: Privacy Policy, Terms and Conditions, Usage Policy.