Cookie Policy

Last updated: 18 June 2026

This Cookie Policy (hereinafter: the “Policy”) governs the terms and conditions for the placement, use and management of cookies on the Platform operated by Nimatron d.o.o., Sprečka ulica 19, Zagreb, Croatia, Personal Identification Number (OIB): 27887722834 (hereinafter: “Nimatron”, “we”, “us” or “our”). For the purposes of this Policy, the term Platform means the website available at www.talentq.io, including all of its subdomains, interfaces and associated functionality.

Cookies

A cookie is a small text file that a web server stores, through a web browser, on a user’s terminal equipment (a computer, mobile device, tablet or other device used to access the Platform) when the user visits the Platform. On each subsequent visit to the Platform, the browser returns the stored cookie to the server, enabling the user or their device to be recognised and certain information about their preferences, activities and behaviour on the Platform to be stored and read.

Cookies may contain various types of information, including unique identifiers, display preferences, login data, device and browser information, and data concerning use of the Platform.

Types of Cookies

Depending on the entity that places the cookie, cookies are classified as follows:

First-party Cookies

These cookies are placed and managed directly by the Platform or the domain visited by the user. They are generally used to provide the Platform’s basic functionality, remember user preferences, maintain the user session and perform similar functions.

Third-party Cookies

These cookies are placed and managed by domains other than the domain directly visited by the user that are integrated into the Platform (for example, analytics service providers, advertising networks, social networks and other external service providers). They are generally used for analytics, advertising, content personalisation and tracking users across different websites.

Depending on how long they are stored, cookies are classified as follows:

Temporary (Session) Cookies

These cookies are stored temporarily and automatically deleted when the web browser is closed. The Platform does not currently use session cookies; instead, all cookies have a defined retention period.

Persistent Cookies

These cookies remain stored on the user’s device until a predetermined period expires or until the user deletes them through their web browser settings.

Depending on their purpose, cookies are classified as strictly necessary, analytics, marketing and security cookies.

Strictly Necessary Cookies

Strictly necessary cookies are essential for the operation of the Platform and for users to log in to the Platform. They are also used to ensure secure and convenient navigation on the Platform and to perform other actions necessary for its operation. The Platform may also use cookies to store the user’s basic technical settings within the browser. The user’s consent is not required for strictly necessary cookies because they are essential for the operation of the Platform itself.

By way of exception, the remember_web_[hash] cookie is placed only if the user actively selects the “Remember me” option when logging in. In doing so, the user expressly requests the persistent login functionality between visits to the Platform, and the cookie is therefore treated as technically necessary for the provision of a service expressly activated by the user. The user may deactivate this functionality at any time by logging out of the Platform or deleting the cookie through their web browser settings.

Analytics and Marketing Cookies

Analytics and marketing cookies are not necessary for the operation of the Platform.

Analytics cookies are used to collect information about how users use the Platform, such as the number of visits, traffic sources, most frequently visited pages and user behaviour on the Platform, for the purpose of understanding and improving the Platform’s functionality and content.

Marketing cookies are used to track users for the purposes of targeted advertising, measuring the effectiveness of advertising campaigns and personalising advertising content, including displaying advertisements tailored to the user’s interests based on their previous activities on the Platform.

The use of analytics and marketing cookies requires the user’s prior consent. Consent is collected through the cookie banner shown to the user on their first visit to the Platform. The user may consent to all cookie categories, only certain categories, or refuse consent. Analytics and marketing cookies are not placed on the user’s terminal equipment unless and until the user provides consent.

Security Cookies

Security cookies are used to protect the Platform and its users against malicious activities, including automated attacks (bots), spam and other forms of misuse. Although they serve a security purpose, certain security cookies from providers based in third countries (such as Google reCAPTCHA) also involve transferring browser and user behaviour data to the service provider for purposes extending beyond the security of the Platform itself. Their placement therefore requires the user’s prior consent.

The reCAPTCHA script is loaded only after the user consents to security cookies. Consent is collected in the same manner as for analytics and marketing cookies, through the cookie banner. If the user does not consent to security cookies, certain Platform functions protected by these mechanisms (such as the public contact form) remain operational through the use of other protective mechanisms (a hidden honeypot field and limits on the number of requests per IP address), although minor restrictions on use may apply.

The user may withdraw consent at any time, as easily as it was given, through the “Cookie Settings” link in the Platform footer.

List of Cookies

The following table provides details of the cookies used on the Platform, divided into categories according to their purpose.

Cookie name Source Purpose Technical characteristics Duration
1. Strictly Necessary Cookies
talentq-session Nimatron Maintains the user’s authenticated session and language preferences. First-party; HttpOnly; Secure; SameSite=Lax. Session data is stored on the server, while the cookie contains only the session identifier and no session content. 120 minutes
XSRF-TOKEN Nimatron Protection against Cross-Site Request Forgery (CSRF) attacks. First-party; Secure; SameSite=Lax 120 minutes
remember_web_[hash] Nimatron Remembers the authenticated user between visits; placed only if the user selects the “Remember me” option when logging in. First-party; HttpOnly; Secure; SameSite=Lax Five years (or until the user logs out)
2. Analytics Cookies — Google Analytics 4, Google LLC
_ga Google LLC Distinguishes individual visitors to the Platform. First-party (.talentq.io) Two years
ga[MEASUREMENT_ID] Google LLC Stores session state for Google Analytics 4. First-party (.talentq.io) Two years
_gid Google LLC Distinguishes users within a 24-hour period. First-party (.talentq.io) 24 hours
_gat / gat_gtag[MEASUREMENT_ID] Google LLC Limits the number of requests sent to Google Analytics (throttling). First-party (.talentq.io) One minute
3. Marketing Cookies — Meta Pixel, Meta Platforms Ireland Ltd.
_fbp Meta Platforms Ireland Ltd. Tracks advertising conversions, optimises campaigns and measures advertising effectiveness. First-party (.talentq.io) 90 days
_fbc Meta Platforms Ireland Ltd. Stores the Facebook advertisement click ID for conversion attribution; placed only if the user arrives through a Facebook advertisement. First-party (.talentq.io) 90 days
4. Security Cookies
_GRECAPTCHA Google LLC (Google reCAPTCHA v3) Protects the public contact form against automated attacks (bots) and spam; placed exclusively on the /contact page. Third-party; security cookie; involves the transfer of data to Google in the United States; requires the user’s consent Six months

Cookie Management by Users

The user may manage cookies at any time in the following ways:

Through the Cookie Banner

The cookie banner is displayed on the user’s first visit to the Platform and can be accessed again at any time through the “Cookie Settings” link in the Platform footer. Through the cookie banner, the user may give, refuse or change consent for individual categories of cookies.

Through Web Browser Settings

The user may also block, delete or restrict cookies directly through their web browser settings (including Google Chrome, Mozilla Firefox, Safari, Microsoft Edge and other browsers). Instructions for individual browsers are available on their official support pages.

Nimatron advises users that disabling strictly necessary cookies may prevent or seriously impair the use of certain parts or functions of the Platform, particularly user account login and communication security.

Nimatron may update this Cookie Policy from time to time to reflect changes to the Platform’s technical configuration, legal obligations or new functionality.

The user will be notified of material changes (in particular, the introduction of new categories of cookies or new data recipients) by the cookie banner being displayed again so that fresh consent may be obtained.