Version 1.0 · In force from 4 August 2026

COOKIE & ONLINE TRACKING TECHNOLOGIES POLICY

Version 1.0 · Effective Date: 4 August 2026

1. INTRODUCTION

This Cookie & Online Tracking Technologies Policy (this "Policy") describes the manner in which DOSTART VENTURES LIMITED, registration number HE 487770, registered under the laws of Cyprus ("Dostart Ventures", the "Company", "we", "our" or "us"), utilizes Cookies and other online tracking technologies in connection with the operation of the Company's websites, customer portals and other online interfaces through which the Company's enterprise artificial intelligence-assisted communication platform marketed under the commercial name ONLYAI (the "Platform") is made available (collectively, the "Website").

The Company is committed to ensuring transparency regarding the technologies used to facilitate the operation, security, functionality and continuous improvement of the Website and to protecting the privacy rights of individuals interacting with our online services.

This Policy forms an integral component of the Company's broader Privacy Governance Framework and should be read together with the Company's Privacy Policy, which explains the manner in which the Company Processes Personal Data more generally.

Unless otherwise defined herein, capitalized terms shall have the meanings assigned to them in the Company's Privacy Policy or, where applicable, the Terms of Service (Master SaaS Terms).

2. PURPOSE OF THIS POLICY

The purpose of this Policy is to provide clear and comprehensive information regarding the Company's use of Cookies and comparable tracking technologies.

In particular, this Policy explains:

  • the technologies utilized by the Company;
  • the purposes for which such technologies are deployed;
  • the legal bases relied upon for their use;
  • the categories of information collected;
  • the circumstances under which third parties may place Cookies through the Website;
  • the options available to Users for managing their Cookie preferences;
  • the safeguards implemented by the Company to protect information collected through such technologies.

A complete inventory of the Cookies and comparable identifiers actually set on the Website and in the ONLYAI Platform is set out in Appendix C (Cookie Inventory).

This Policy applies exclusively to the Company's Website and does not govern the Processing of Customer Data performed by the Company on behalf of its enterprise Customers in its capacity as a Processor under the General Data Protection Regulation ("GDPR"). Such Processing activities are governed separately by the applicable Terms of Service (Master SaaS Terms) and Data Processing Agreement.

3. REGULATORY FRAMEWORK

The Company's use of Cookies and comparable technologies is governed by applicable legislation relating to privacy, electronic communications and the protection of Personal Data, including, where applicable:

  • Regulation (EU) 2016/679 (General Data Protection Regulation);
  • Directive 2002/58/EC concerning privacy and electronic communications (the "ePrivacy Directive"), as implemented under applicable national legislation;
  • applicable national data protection legislation;
  • applicable guidance issued by competent supervisory authorities.

The Company periodically reviews its Cookie practices to ensure continued compliance with evolving legal, regulatory and technological developments.

4. COOKIES AND SIMILAR TRACKING TECHNOLOGIES

The Website utilizes Cookies together with certain comparable technologies that enable information to be stored on, or retrieved from, a User's browser or device.

These technologies facilitate, among other things:

  • authentication;
  • security;
  • fraud prevention;
  • user preferences;
  • performance optimization;
  • website analytics;
  • operational monitoring;
  • service reliability.

For purposes of this Policy, the term "Cookie" shall be interpreted broadly and includes, where the context permits:

  • HTTP Cookies;
  • session Cookies;
  • persistent Cookies;
  • browser storage;
  • local storage;
  • session storage;
  • software development kits ("SDKs");
  • tracking pixels;
  • web beacons;
  • device identifiers;
  • API-based identifiers;
  • similar technologies performing substantially equivalent technical functions.

The Company does not distinguish between such technologies where they perform equivalent operational purposes and, accordingly, references to "Cookies" throughout this Policy shall include all comparable tracking technologies unless expressly stated otherwise.

5. PRINCIPLES GOVERNING THE USE OF COOKIES

The Company's deployment of Cookies is governed by the following fundamental principles.

5.1 Lawfulness

Cookies shall be deployed only where a valid legal basis exists under Applicable Data Protection Laws.

Where consent is required, Cookies shall not be placed prior to obtaining the User's valid, informed and freely given consent through the Company's Consent Management Platform.

5.2 Transparency

Users shall be provided with clear, intelligible and easily accessible information regarding:

  • the categories of Cookies utilized;
  • the purposes for which Cookies are deployed;
  • the duration of Cookie storage;
  • the involvement of third-party technology providers;
  • available mechanisms for managing Cookie preferences.

5.3 Data Minimization

The Company seeks to deploy only those Cookies reasonably necessary for the legitimate operation, security, functionality or improvement of the Website.

Cookies shall not collect information beyond what is reasonably necessary to achieve their specified purpose.

5.4 Purpose Limitation

Information collected through Cookies shall be Processed solely for the purposes described within this Policy and shall not subsequently be Processed for incompatible purposes.

5.5 Privacy by Design

The Company's use of Cookies forms part of its broader Privacy by Design and Privacy by Default programme.

The deployment of new Cookies or tracking technologies is subject to appropriate privacy and compliance review prior to implementation.

5.6 Security

Information collected through Cookies is protected through administrative, organizational and technical safeguards proportionate to the nature of the information concerned.

The Company periodically reviews such safeguards to ensure their continued effectiveness.

6. LEGAL BASES FOR THE USE OF COOKIES

Depending upon the category of Cookie concerned, the Company may rely upon one or more of the following legal bases:

  • the User's consent;
  • the Company's legitimate interests;
  • compliance with legal obligations;
  • the necessity of providing a service expressly requested by the User.

Where consent constitutes the applicable legal basis, Users may withdraw such consent at any time without affecting the lawfulness of Processing undertaken prior to such withdrawal.

7. CONSENT MANAGEMENT

To the extent required under Applicable Law, the Company utilizes a Consent Management Platform ("CMP") designed to enable Users to make informed choices regarding the deployment of non-essential Cookies.

The CMP enables Users to:

  • accept all Cookies;
  • reject non-essential Cookies;
  • customize Cookie preferences by category;
  • withdraw previously granted consent;
  • modify Cookie preferences at any time.

The Company maintains records of User consent where required by Applicable Law.

8. CATEGORIES OF COOKIES UTILIZED BY THE COMPANY

The Company utilizes Cookies solely for legitimate operational, security, analytical and functional purposes consistent with the operation of the Website and the delivery of its services.

Cookies deployed through the Website are classified into the categories described below.

8.1 Strictly Necessary Cookies

Strictly Necessary Cookies are indispensable for the operation, security and administration of the Website.

These Cookies enable fundamental functionality without which the Website cannot operate properly.

Accordingly, such Cookies cannot ordinarily be disabled through the Company's Consent Management Platform.

Strictly Necessary Cookies may be used for purposes including:

  • establishing and maintaining authenticated user sessions;
  • preserving session integrity;
  • facilitating secure navigation between pages;
  • balancing application traffic;
  • protecting against unauthorized access;
  • preventing fraudulent or malicious activity;
  • ensuring website stability and operational resilience;
  • enabling essential security mechanisms.

The legal basis for Processing information through Strictly Necessary Cookies is the Company's legitimate interest in providing a secure and functional Website and, where applicable, the necessity of providing an information society service expressly requested by the User.

8.2 Functional Cookies

Functional Cookies enhance the usability of the Website by enabling the Website to remember information previously provided by the User.

Such Cookies may be used to preserve:

  • language preferences;
  • regional settings;
  • accessibility preferences;
  • dashboard configuration;
  • user interface customization;
  • other functional settings selected by the User.

These Cookies improve the overall user experience but are not strictly necessary for the basic operation of the Website.

Where required by Applicable Law, Functional Cookies shall be deployed only after obtaining the User's prior consent.

8.3 Analytics Cookies

The Company may utilize Analytics Cookies to obtain aggregated statistical information concerning the manner in which Users interact with the Website.

Analytics Cookies assist the Company in understanding:

  • Website usage patterns;
  • visitor navigation behaviour;
  • page popularity;
  • feature utilization;
  • system performance;
  • user engagement;
  • service reliability.

Information collected through Analytics Cookies is used exclusively for legitimate business purposes including:

  • improving Website functionality;
  • enhancing user experience;
  • optimizing system performance;
  • identifying technical issues;
  • supporting product development.

Where reasonably practicable, analytics information is aggregated, anonymized or pseudonymized before being analyzed.

The Company does not use Analytics Cookies to identify individual Users unless strictly necessary for legitimate security or fraud prevention purposes.

Where required by Applicable Law, Analytics Cookies shall be deployed only following the User's consent.

8.4 Performance Cookies

Performance Cookies assist the Company in monitoring the technical performance and operational reliability of the Website.

Such Cookies may collect information relating to:

  • page loading performance;
  • application responsiveness;
  • service availability;
  • error diagnostics;
  • infrastructure performance;
  • browser compatibility;
  • operating system characteristics.

Performance information enables the Company to continuously improve the efficiency, stability and resilience of the Website.

Performance Cookies shall be used only to the extent reasonably necessary for these purposes.

8.5 Security Cookies

The Company deploys Security Cookies to protect the integrity, availability and security of the Website.

Such Cookies support, among other things:

  • user authentication;
  • protection against unauthorized access;
  • session integrity;
  • fraud prevention;
  • detection of automated attacks;
  • abuse prevention;
  • bot detection;
  • rate limiting;
  • account protection.

Given their essential security function, certain Security Cookies may qualify as Strictly Necessary Cookies under Applicable Law.

9. COOKIES THE COMPANY DOES NOT USE

The Company is committed to responsible and proportionate use of tracking technologies.

Unless expressly disclosed otherwise, the Company does not utilize Cookies for the purpose of:

  • behavioural advertising;
  • advertising retargeting;
  • cross-site behavioural profiling;
  • sale or commercialization of Personal Data;
  • creation of consumer advertising profiles;
  • disclosure of Cookie-derived information to third-party advertising networks;
  • interest-based advertising unrelated to the Company's own products or services.

The Company does not derive revenue from the sale, licensing or commercialization of Cookie-generated information.

10. THIRD-PARTY COOKIES

The Website may incorporate services provided by carefully selected third-party technology providers.

Where such providers deploy Cookies through the Website, they do so solely for purposes consistent with the operation, security and improvement of the Website.

Depending upon the services implemented by the Company, such providers may include organizations providing:

  • cloud infrastructure;
  • content delivery services;
  • identity and authentication services;
  • cybersecurity services;
  • website analytics;
  • customer communications;
  • technical monitoring;
  • application diagnostics;
  • fraud prevention.

Examples of such providers may include:

  • Microsoft Azure;
  • Cloudflare;
  • PostHog;
  • Microsoft Entra ID;
  • Auth0;
  • Google reCAPTCHA Enterprise;
  • Intercom;
  • Sentry.

The Company periodically reviews third-party technologies utilized through the Website and seeks to ensure that such providers maintain appropriate privacy and information security standards.

The deployment of third-party Cookies shall remain subject to the User's consent where required by Applicable Law.

11. COOKIE RETENTION

Cookies remain stored for varying periods depending upon their technical purpose.

The Company seeks to ensure that retention periods remain proportionate to the legitimate purposes for which the relevant Cookie has been deployed.

11.1 Session Cookies

Session Cookies remain active only for the duration of the User's browser session and are automatically removed upon termination of the session.

11.2 Persistent Cookies

Persistent Cookies remain stored on the User's device until:

  • expiration of the applicable retention period;
  • manual deletion by the User;
  • withdrawal of consent;
  • earlier removal by the browser.

The Company periodically reviews retention periods applicable to Persistent Cookies to ensure that they remain proportionate and consistent with applicable legal requirements.

12. COOKIE REGISTER

The Company maintains an internal Cookie Register documenting, among other matters:

  • Cookie name;
  • provider;
  • category;
  • purpose;
  • legal basis;
  • duration;
  • first-party or third-party status.

The Cookie Register may be updated from time to time to reflect technological or operational changes without requiring amendment of this Policy.

13. CONSENT WITHDRAWAL

Users may withdraw or modify previously granted Cookie consent at any time by accessing the Cookie Preference Centre available through the Website.

Withdrawal of consent shall not affect the lawfulness of Processing undertaken prior to such withdrawal.

Where consent is withdrawn, the Company shall cease deploying non-essential Cookies requiring such consent as soon as reasonably practicable.

14. MANAGING COOKIE PREFERENCES

The Company recognizes the importance of providing Users with meaningful control over the deployment of non-essential Cookies and other online tracking technologies.

Accordingly, Users may manage their Cookie preferences at any time through one or more of the following mechanisms, depending upon the functionality available through the Website and the User's browser configuration:

  • the Company's Cookie Preference Centre;
  • browser privacy settings;
  • browser Cookie management functionality;
  • deletion of previously stored Cookies;
  • browser-specific controls relating to tracking technologies.

Where a User elects to disable or restrict the use of certain categories of Cookies, portions of the Website may not function as intended or certain features may become unavailable.

The Company shall not be responsible for any reduction in Website functionality resulting from the User's decision to disable Cookies that are necessary for the operation of particular Website features.

15. BROWSER CONTROLS

Most modern web browsers permit Users to exercise a degree of control over the placement and retention of Cookies.

Depending upon the browser utilized, Users may be able to:

  • review Cookies stored on their device;
  • delete previously stored Cookies;
  • block future Cookies;
  • restrict Cookies to first-party websites;
  • configure browser notifications before Cookies are placed;
  • disable certain categories of tracking technologies.

Information regarding browser-specific Cookie settings may generally be obtained from the relevant browser developer.

The Company does not control the operation of browser settings and recommends that Users consult the documentation provided by the relevant browser vendor where additional assistance is required.

16. "DO NOT TRACK" SIGNALS

Certain internet browsers support "Do Not Track" ("DNT") functionality intended to communicate a User's preference not to be tracked across websites.

At present, no universally accepted technological or legal standard exists governing the interpretation or implementation of DNT signals.

Accordingly, unless and until such standards become generally accepted, the Website may not respond consistently to DNT signals transmitted by Users' browsers.

Nothing contained in this section shall limit the rights afforded to Users under Applicable Data Protection Laws.

17. INTERNATIONAL TRANSFERS OF INFORMATION

Where information collected through Cookies constitutes Personal Data and is transferred outside the European Economic Area, the United Kingdom or another jurisdiction recognized as providing an adequate level of protection under Applicable Data Protection Laws, the Company shall implement appropriate safeguards designed to ensure that such transfers are conducted lawfully.

Depending upon the relevant circumstances, such safeguards may include:

  • adequacy decisions adopted by the European Commission;
  • the Standard Contractual Clauses approved by the European Commission;
  • the UK International Data Transfer Addendum or International Data Transfer Agreement;
  • binding corporate rules;
  • other legally recognized transfer mechanisms.

Additional technical, contractual or organizational safeguards may also be implemented where appropriate having regard to the nature of the Processing activities concerned.

18. PERSONAL DATA COLLECTED THROUGH COOKIES

Certain information collected through Cookies may constitute Personal Data under Applicable Data Protection Laws.

Where Cookie-derived information constitutes Personal Data, such information shall be Processed in accordance with:

  • this Policy;
  • the Company's Privacy Policy;
  • Applicable Data Protection Laws.

Depending upon the relevant Cookie, such information may include:

  • IP address;
  • browser type;
  • device identifiers;
  • operating system;
  • session identifiers;
  • authentication status;
  • language preferences;
  • approximate geographic region;
  • Website interaction data;
  • technical diagnostics;
  • security-related information.

The Company does not intentionally collect Special Categories of Personal Data through Cookies.

19. USER RIGHTS

Where Cookie-derived information constitutes Personal Data, Users may be entitled, subject to Applicable Law, to exercise certain rights, including:

  • the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of Processing;
  • the right to data portability;
  • the right to object to Processing;
  • the right to withdraw consent;
  • the right to lodge a complaint with a competent supervisory authority.

The exercise of such rights is subject to the conditions and limitations prescribed by Applicable Data Protection Laws.

Further information regarding the exercise of these rights is available in the Company's Privacy Policy.

20. CHANGES TO THIS POLICY

The Company reserves the right to amend, revise or otherwise update this Policy from time to time in order to reflect, among other matters:

  • developments in Applicable Laws;
  • regulatory guidance;
  • technological developments;
  • changes to the Website;
  • implementation of new technologies;
  • operational changes;
  • modifications to the Company's privacy governance framework.

Where material changes are made to this Policy, the revised version shall be published on the Website together with the updated effective date.

Where required by Applicable Law, Users shall be provided with appropriate notice prior to such changes becoming effective.

21. CONTACT INFORMATION

Questions, requests or concerns relating to this Policy or the Company's use of Cookies and similar tracking technologies may be directed to:

DOSTART VENTURES LIMITED

Email: info@onlyai.work

Registration Number: HE 487770

Where the Company has appointed a Data Protection Officer or designated privacy contact, additional contact details shall be published on the Company's Website and Privacy Policy.

APPENDIX A

COOKIE CATEGORIES OVERVIEW

CategoryPurposeLegal BasisConsent RequiredTypical Retention
Strictly Necessary CookiesAuthentication, security, session management and core Website functionalityLegitimate Interests and/or necessity of providing the requested serviceNo (subject to Applicable Law)Session or short-term
Functional CookiesUser preferences, interface customization and accessibilityConsent (where required)YesUp to 12 months
Analytics CookiesWebsite analytics, product improvement and statistical reportingConsent (where required)YesUp to 24 months
Performance CookiesMonitoring Website performance, diagnostics and service optimizationConsent or Legitimate Interests, depending on the specific technology and Applicable LawWhere requiredUp to 12 months
Security CookiesFraud prevention, bot detection, account protection and Website integrityLegitimate Interests and/or legal obligationsGenerally NoSession or operationally necessary duration

APPENDIX B

GOVERNING PRINCIPLES OF THE COMPANY'S COOKIE GOVERNANCE FRAMEWORK

The Company's Cookie Governance Framework is founded upon the following principles:

  • Lawfulness – Cookies shall be deployed only where supported by an appropriate legal basis under Applicable Data Protection Laws.
  • Transparency – Users shall receive clear, accurate and readily accessible information concerning the Company's use of Cookies.
  • Purpose Limitation – Cookies shall be utilized solely for specified, explicit and legitimate purposes.
  • Data Minimization – Only those Cookies reasonably necessary to achieve legitimate operational objectives shall be deployed.
  • Privacy by Design and by Default – Cookie technologies shall be evaluated as part of the Company's broader privacy governance programme prior to implementation.
  • Security – Information collected through Cookies shall be protected through appropriate technical and organizational safeguards.
  • Accountability – The Company shall maintain appropriate governance processes documenting and periodically reviewing the Cookies and tracking technologies utilized through the Website.

APPENDIX C

COOKIE INVENTORY

The following identifiers are set on the Website and in the ONLYAI Platform as at the Effective Date of this Policy. All of them are first-party identifiers set on the Company's own domain; the Company does not currently deploy analytics, advertising, profiling or third-party tracking Cookies.

NameProviderPurposeCategoryDuration1st/3rd partyLegal basis
__Secure-better-auth.session_tokenONLYAIAuthentication and session managementStrictly necessary7 days1stNecessity for the provision of the requested service
__Secure-better-auth.stateONLYAICross-site request forgery protection during Google sign-inStrictly necessary5 minutes1stNecessity for the provision of the requested service
__Secure-better-auth.dont_rememberONLYAIRecords that the User asked not to remain signed inStrictly necessarySession1stNecessity for the provision of the requested service
sidebar_stateONLYAIRemembers whether the dashboard sidebar is expanded or collapsedFunctional7 days1stConsent (where required)

Where the Website is served over an unencrypted connection in a local development environment, the __Secure- prefix is not applied and the corresponding identifiers are named better-auth.session_token, better-auth.state and better-auth.dont_remember.

Signing in with Google redirects the User to a domain operated by Google LLC, which sets its own identifiers on that domain under Google's own privacy policy. Those identifiers are not set by the Company and are not within the scope of this Policy.

The Company shall update this Appendix whenever a new identifier is introduced or an existing one is changed or withdrawn, and shall publish the revised version in accordance with Section 20 (Changes to this Policy).