Cookie & Storage Notice
Caelex Scholar
Last updated: 1 July 2026Version: 1.2
This notice explains which cookies and comparable storage technologies Caelex Scholar uses on your device, for what purpose, on what legal basis, and for how long. It supplements the Caelex Scholar Privacy Policy.
Caelex Scholar is a sign-in-protected (SSO-gated) legal-research database licensed through your university. It is free of charge for you.
Section 1
Controller and roles
The controller for the technically necessary storage operations involved in operating Caelex Scholar, within the meaning of Section 25 TDDDG and the GDPR, is:
- Caelex — sole proprietorship, owner: Julian Polleschner
- Am Maselakepark 37, 13587 Berlin, Germany
- Small business under Section 19 of the German VAT Act (UStG)
- Email: cs@caelex.eu · Data protection: privacy@caelex.eu
Caelex Scholar is provided under a provider-to-university-to-students (B2B2C) model. Where Caelex processes data on behalf of the licensing university, the university is the controller and Caelex is the processor; for the technically necessary storage operations described here — operating and securing the service — Caelex acts as its own controller. The Privacy Policy sets out the role allocation in detail.
Section 2
What are cookies and comparable technologies?
Cookies are small text files that a website stores in your browser and reads back on later requests. Comparable technologies include browser storage (LocalStorage, SessionStorage), IndexedDB, and similar techniques that store information on, or retrieve information from, your device.
In legal terms, Section 25 TDDDG (the German Telecommunications Digital Services Data Protection Act, formerly Section 25 TTDSG) covers any access to information already stored on your device, and any storage of information on your device — regardless of whether that information is personal data.
Section 3
Principle: necessary cookies always, optional only with consent
Caelex Scholar always uses technically necessary cookies; their legal basis is Section 25(2) no. 2 TDDDG (technically necessary for a digital service you have expressly requested), in conjunction with Article 6(1)(b) and (f) GDPR. In addition, optional analytics, performance and error-diagnostics features are available. These are disabled by default and are loaded only after your explicit consent (Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR).
Caelex Scholar uses no marketing, advertising or cross-site tracking cookies, no third-party advertising networks, and no device fingerprinting. For the optional, consent-requiring features a consent banner is shown until you make a choice; without your consent they are not loaded.
Our usage statistics operate in two tiers. Tier 1 is an anonymous, cookieless baseline statistic that runs for all visitors without consent: it neither sets nor reads any identifier on your device, does not store your IP address, and produces only aggregate totals (e.g. how often a path in the Scholar area was opened). As no access to information on your device takes place, Section 25 TDDDG does not apply; for the aggregate evaluation we rely on our legitimate interest in a reach measurement (Article 6(1)(f) GDPR). Tier 2 is the richer, consent-based product analytics described in Section 5: it loads only after your opt-in, then sets a device/session identifier and, for signed-in users, links your account identifier. The two tiers are separate; Tier 1's anonymous aggregate counts cannot be joined to Tier 2 events.
The Scholar interface keeps a few strictly necessary entries in your browser's local storage: “caelex-theme” (your light/dark preference) and “caelex-cookie-consent” plus “caelex-cookie-consent-session” (your cookie decision and its proof under Article 7(1) GDPR). These are strictly necessary and require no consent (Section 25(2) no. 2 TDDDG). Your content preferences (e.g. the UI language) as well as bookmarks and reading lists are stored server-side in your account or in our database (described in the Privacy Policy).
Section 4
List of cookies in use
The table below lists the cookies Caelex Scholar actually sets. All are strictly necessary, set only on the domain caelex.eu (first party), marked HttpOnly (not readable by scripts in the browser), and — in production — transmitted with the Secure attribute (HTTPS only) and SameSite=Lax. In production, cookie names additionally carry the __Secure- or __Host- prefix.
authjs.session-token (production: __Secure-authjs.session-token)
- Purpose: login session — keeps you signed in after SSO/login authentication (NextAuth session token, JWT).
- Category: strictly necessary.
- Legal basis: Section 25(2) no. 2 TDDDG; Article 6(1)(b) GDPR.
- Retention: session cookie with a maximum lifetime of 24 hours; ends at the latest on sign-out.
- Attributes: HttpOnly, Secure (production), SameSite=Lax.
authjs.csrf-token (production: __Host-authjs.csrf-token)
- Purpose: protection against cross-site request forgery (CSRF) on state-changing requests.
- Category: strictly necessary (security).
- Legal basis: Section 25(2) no. 2 TDDDG; Article 6(1)(f) GDPR (security of the service).
- Retention: session (deleted when the browser session ends).
- Attributes: HttpOnly; in production __Host-bound (origin-bound, with no Domain attribute).
authjs.callback-url (production: __Secure-authjs.callback-url)
- Purpose: stores the return destination during sign-in (e.g. after the redirect through your university's SSO/OAuth flow).
- Category: strictly necessary.
- Legal basis: Section 25(2) no. 2 TDDDG; Article 6(1)(b) GDPR.
- Retention: session.
- Attributes: HttpOnly, Secure (production), SameSite=Lax.
Note on signing in through your university (single sign-on): during the redirect to and from your university's identity provider or the Google OAuth service, those providers may set their own authentication-necessary cookies under their own responsibility. These are governed by the respective provider's privacy and cookie notices; Caelex has no control over them.
Local storage (localStorage)
- caelex-theme — stores your light/dark preference. Category: strictly necessary (Section 25(2) no. 2 TDDDG). Retention: until you delete it.
- caelex-cookie-consent — stores your cookie decision (versioned). Category: strictly necessary. Retention: up to 12 months, then re-prompted.
- caelex-cookie-consent-session — anonymous identifier evidencing consent (Article 7(1) GDPR). Category: strictly necessary. Retention: until you delete it.
- Analytics identifier (only after consent) — a device/session identifier for the optional product analytics; set only if you enable the “Analytics” category (see Section 5). Without consent it is not set.
Section 5
Consent-based analytics, performance and error diagnostics
With your consent, we use first-party, self-hosted product analytics on our own EU infrastructure to understand how Caelex Scholar is used and to improve the service. It stores a device/session identifier in your browser and, for signed-in users, links the recorded usage events to your account identifier. The legal basis is your consent (Section 25(1) TDDDG in conjunction with Article 6(1)(a) GDPR). Without consent this analysis does not take place.
Also only with your consent, a performance measurement (load times) and client-side error diagnostics are available. Like analytics, these are disabled by default and can be enabled individually in the consent banner. You can withdraw your consent at any time with effect for the future (see Section 6).
Independently of your consent, we use server-side error monitoring (Sentry) for the stability and security of the service. It operates without storing anything on your device and with personal data removed before transmission. The service providers used are listed in the Sub-processors register.
Section 6
Managing and deleting cookies
No consent is required for the strictly necessary cookies and storage; they cannot be switched off without making the service unusable. You decide about the optional features (analytics, performance, error diagnostics) in the consent banner; your choice is stored and re-requested after 12 months at the latest. You can change or withdraw your consent at any time with effect for the future — by deleting the stored “caelex-cookie-consent” entry (which makes the banner reappear) or by managing cookies and local storage in your browser settings.
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Settings → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
If you block or delete the strictly necessary cookies you cannot sign in or will not stay signed in; the service will then be unavailable or only partially usable.
Section 7
Your rights and contact
Where personal data is processed through cookies, you have the data-subject rights described in the Privacy Policy (access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority).
Please direct questions about this notice to privacy@caelex.eu. For further detail on the processing of personal data, see the Caelex Scholar Privacy Policy; the service providers used are listed in the Sub-processors register.
Section 8
Changes to this notice
We update this notice when the cookies in use or the legal requirements change. The version published at caelex.eu/scholar/legal/cookies, bearing the date shown above, is authoritative.