COOKIE POLICY

Qyrotec Pty Ltd

Version: V1.0 Effective date: 27 August 2026 Last updated: 27 August 2026


Introduction

This Cookie Policy explains how Qyrotec Pty Ltd ACN 696 749 505 (Qyrotec, we, us or our) uses cookies and similar technologies on our website at www.qyrotec.com (the Website) and in connection with the Pantha software product and our related services (the Service).

This Cookie Policy is governed by the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles set out in the Privacy Act (the APPs). It should be read together with our Privacy Policy and our Pantha Terms of Use and EULA (the Terms). Terms defined in the Privacy Policy or the Terms have the same meaning in this Cookie Policy unless the context requires otherwise.

The Website and the Service use cookies and similar technologies differently, so this Cookie Policy addresses each separately: our Website in clause 3, and our Service (the Pantha desktop application) in clause 4. By using the Website or the Service, you acknowledge our use of cookies and similar technologies as described in this Cookie Policy. Where your consent is required under applicable law for any non-essential cookie or technology, we will obtain it in the manner described in clause 5.


1. What are Cookies?

    (a) Cookies are small text files that are placed on your device (computer, smartphone or tablet) when you visit a website or use an application. Cookies allow the website or application to recognise your device and store information about your preferences or past actions.

    (b) In this Cookie Policy, we use the term "cookies" broadly to also refer to similar technologies, including local storage, session storage, web beacons, pixels, scripts and software development kit (SDK) tools.

1.1 First-Party and Third-Party Cookies

Cookies are either:

    (a) first-party cookies, placed by us directly; or

    (b) third-party cookies, placed by a third party (such as an analytics provider, an authentication provider or a provider of embedded content) when you use the Website or the Service.

1.2 Session and Persistent Cookies

Cookies are either:

    (a) session cookies, temporary cookies that expire when you close your browser or session; or

    (b) persistent cookies, cookies that remain on your device for a set period or until you delete them.


2. Our Approach

We take a privacy-respecting approach and keep our use of cookies and similar technologies to a minimum. In particular:

    (a) we do not use advertising, targeting or cross-site tracking technologies anywhere on the Website or in the Service, and we do not build profiles of your interests or serve behavioural or targeted advertising (this is consistent with clause 1 of our Privacy Policy and clause 8.6 of the Terms), although embedded third-party content (such as YouTube videos) may set or access its own cookies, as described in clause 3(d);

    (b) we do not set any first-party cookies on the Website; and

    (c) the limited cookies and similar technologies we do use differ between the Website and the Service, and are described in clauses 3 and 4.


3. Cookies and Similar Technologies on Our Website

Our Website is an informational website. When you visit the Website:

    (a) No first-party cookies. We do not set any first-party cookies on the Website.

    (b) Performance and analytics (cookie-less). We use Vercel Speed Insights, a cookie-less performance and analytics script that measures Website performance (such as page-load metrics, route, and general browser, device and country information) without setting cookies or persistent identifiers and without cross-site tracking.

    (c) Theme preference. Our Website's theming framework may store a light or dark theme value in your browser's local storage. This is not a cookie and is not used for tracking.

    (d) Embedded third-party content. The Website may include embedded third-party content, such as YouTube videos. The third party (YouTube or Google) may receive technical information and may set or access its own cookies when the embedded content loads or when you interact with it. That third party's handling is governed by its own privacy and cookie policies, which we do not control. This does not limit any obligations that apply to Qyrotec under the Privacy Act.


4. Cookies and Similar Technologies in Our Service (the Pantha Desktop Application)

The Service is a desktop application rather than a website. It does not use cookies to track you, and it does not use advertising or cross-site tracking technologies. The cookies and similar technologies associated with the Service are as follows.

4.1 Sign-In (AWS Cognito)

We use Amazon Web Services (AWS) Cognito to sign you in. When you sign in, the AWS Cognito hosted sign-in screen is shown within the Service (it is the only third-party web page displayed inside the Service). That screen sets authentication and security cookies on the AWS Cognito domain (not on our own domain). These cookies are set and managed by AWS and are governed by AWS's privacy and cookie terms, which we do not control. This does not limit any obligations that apply to Qyrotec under the Privacy Act. They are used for the following purposes:

    (a) protecting sign-in requests against cross-site request forgery, and maintaining consistency across the sign-in redirects (for example, cookies named XSRF-TOKEN, csrf-state and csrf-state-legacy);

    (b) remembering a successful sign-in for a short period (a session cookie named cognito, which typically lasts around one hour);

    (c) remembering your language preference on the sign-in screen (a cookie named lang); and

    (d) holding temporary data while you navigate the sign-in pages (a cookie named page-data).

The exact cookies, their names and their durations are set and may be changed by AWS. These cookies are strictly necessary to sign you in securely.

4.2 Payments (Stripe)

Payments are handled by our payment services provider, Stripe. When you make a payment, the Service opens a secure Stripe payment page in your device's default external browser. Stripe is not embedded within the Service, so no Stripe cookies are set inside the Service. Any cookies Stripe sets in your external browser are governed by Stripe's own privacy and cookie policies, which we do not control.

4.3 Local Application Data

The Service stores certain data locally on your device in application files, rather than in cookies. This includes an encrypted sign-in token (used to keep you signed in), your settings and preferences (including your theme), and operational data used to create, run and clean up the local sandboxed environment that confines the execution of code on your device. This on-device data is not a cookie, is not shared for advertising, and is not used for advertising or cross-site tracking. How we handle your information generally is described in our Privacy Policy.

4.4 Telemetry

As described in our Terms and our Privacy Policy, the Service may collect telemetry for purposes such as reliability monitoring, security, fraud and abuse prevention, error diagnosis, performance measurement and product improvement. Where telemetry uses a persistent identifier to associate related events, that identifier is used only for those purposes. Any telemetry we collect is based on your use of the Service and is not designed to collect the content of your prompts (although limited content associated with an error may be included in crash or diagnostic records), does not include advertising identifiers, session replay or screen capture, and is not used for advertising or cross-site tracking.


5. Consent and How to Manage Cookies

5.1 Consent

Because we do not set first-party cookies on the Website and do not use advertising, targeting or cross-site tracking technologies, we do not display a cookie consent banner. The AWS Cognito cookies described in clause 4.1 are strictly necessary to sign you in securely. If we introduce any non-essential cookie or technology that requires your consent under applicable law, we will provide an appropriate consent mechanism at that time and update this Cookie Policy.

5.2 Third-Party Embedded Content

Where the Website includes embedded third-party content, such as YouTube videos, the relevant third party may set or access its own cookies when the content loads or when you interact with it. Those cookies are governed by the third party's own policies, which we do not control. You can manage or block them using the browser controls described in clause 5.3.

5.3 Browser Controls

You can manage and delete cookies through your browser settings. Most browsers allow you to view the cookies stored on your device, delete cookies, block cookies (either all cookies or only those from third parties), and be notified when a cookie is set. Please refer to your browser's official documentation for managing cookies.

5.4 Managing Data Held by the Service

You can sign out of the Service to end your application session and can change your settings within the Service. Local application files may remain on your device after sign-out or uninstallation unless they are removed through the Service, the uninstall process or your operating system. How we retain and delete your information is described in our Privacy Policy.

5.5 Impact of Disabling Cookies

If you block or delete cookies and similar technologies, some features of the Website or Service may not work properly, and your experience may be degraded. Cookies that are strictly necessary (such as the AWS Cognito sign-in cookies) cannot be disabled without preventing you from signing in or otherwise affecting the functioning of the Service.


6. Third-Party Services

Some cookies and content are provided by third parties when you use the Website or the Service. Those third parties may collect information in accordance with their own privacy and cookie policies, which we do not control. This does not limit any obligations that apply to Qyrotec under the Privacy Act. The third-party services relevant to this Cookie Policy are:

    (a) Vercel Speed Insights (Website): a cookie-less performance and analytics script that measures Website performance without setting cookies or persistent identifiers and without cross-site tracking;

    (b) AWS Cognito (Service): authentication and security cookies set on the AWS Cognito domain when you sign in, as described in clause 4.1;

    (c) Stripe (Service): opened in your external browser to process payments, as described in clause 4.2, and subject to Stripe's own policies; and

    (d) YouTube (Google) (Website): embedded video content that may set or access third-party cookies when it loads or when you interact with it, as described in clause 3(d).

We recommend that you review the privacy and cookie policies of any third-party provider before interacting with its content or services.


7. Specific Cookies and Technologies We Use

The table below lists the specific cookies and similar technologies associated with the Website and the Service, their purpose and how long they persist. This table will be updated from time to time.

Name or technologyWebsite or ServiceSet byPurposeTypeDuration
Vercel Speed InsightsWebsiteVercel (third party)Measures Website performance without cookies, persistent identifiers or cross-site tracking.Cookie-less scriptNo cookie set
Theme preferenceWebsite and ServiceUsStores the current light or dark theme value. On the Website this occurs only if theme selection is enabled or changed. Not used for tracking.Local storage (Website) or local application file (Service); not a cookieUntil cleared or changed
Embedded YouTube contentWebsiteYouTube / Google (third party)Cookies YouTube may set or access when an embedded video loads or when you interact with it. Governed by the third party's policies.Third-party cookiesSet by the third party
XSRF-TOKEN, csrf-state, csrf-state-legacyService (sign-in)AWS Cognito (third party)Protect sign-in requests against cross-site request forgery and maintain consistency across sign-in redirects.Third-party cookies (AWS Cognito domain)Set and managed by AWS (short-lived)
cognitoService (sign-in)AWS Cognito (third party)Session cookie that remembers a successful sign-in for a short period.Third-party cookie (AWS Cognito domain)Approximately 1 hour
langService (sign-in)AWS Cognito (third party)Remembers your language preference on the sign-in screen.Third-party cookie (AWS Cognito domain)Set and managed by AWS
page-dataService (sign-in)AWS Cognito (third party)Holds temporary data while you navigate the sign-in pages.Third-party cookie (AWS Cognito domain)Session or temporary
Sign-in tokenServiceUs (via AWS Cognito)Keeps you signed in to the Service. Stored as an encrypted file on your device.Encrypted local application file; not a cookieUntil expiry or removal (a residual file may remain after sign-out or uninstallation)
Settings and preferencesServiceUsStores your settings and preferences (including theme). Stored as a file on your device.Local application file; not a cookieUntil changed or removed (a residual file may remain after uninstallation)
Sandbox operational dataServiceUsLocal data used to run and clean up the code-execution sandbox on your device. Contains no advertising or tracking data.Local application file; not a cookieUntil removed

8. Changes to this Cookie Policy

We may amend this Cookie Policy from time to time. We will give you reasonable notice of any material change, including by posting the updated Cookie Policy on the Website and updating the "Effective date" and "Last updated" details. The updated Cookie Policy applies from its effective date. Where a change introduces a use of cookies or similar technologies for which your consent is required, we will obtain that consent before that use begins.


9. Contact Us

If you have any questions about our use of cookies or similar technologies, please contact our Privacy Officer at:

Privacy Officer - Qyrotec Pty Ltd

Email: support@qyrotec.com