Last updated and scope
Last updated: 7 September 2026. This overview supplements https://desklix.com/en/privacy/ and distinguishes the public website from the signed-in product. The periods below concern browser entries, not retention of related server data.
Marketing website: language preference
The marketing website’s own code does not set cookies or use advertising pixels or analytics services. Only an active language choice stores “de” or “en” under “desklix-locale” in local storage. The entry remains until changed or deleted, contains no user identifier and serves the requested language version. Without a choice, the browser language is used. Fonts and images are served as website files.
Platform: authentication and session protection
desklix_workos_session: encrypted authentication session, HttpOnly, cookie lifetime up to 7 days.
desklix_session_started: session start used to limit its duration, HttpOnly, up to 7 days.
desklix_csrf: protection against unwanted requests from other websites, up to 24 hours; readable in the browser for the required comparison.
desklix_pending_auth: temporary authentication state, such as email verification, organisation selection or MFA, HttpOnly, up to 10 minutes.
desklix_sso_state: association and protection of the SSO callback, HttpOnly, up to 10 minutes.
These are the maximum lifetimes set on the cookies. Sign-out, completed authentication steps and server-side security rules may end their use earlier; a renewed session can set cookies again.
Platform: persistent local preferences
Depending on use, local storage includes “theme” (appearance), “desklix.locale” (language), “desklix-current-user-slug” and “desklix-signed-out” (local display or sign-out state), and user- or organisation-specific check-in and visitor preferences. Local display information does not grant access rights. Entries without their own expiry remain until overwritten, removed by the application or deleted by you. Marketing and platform language storage is separate because the origins differ.
Platform: storage during authentication
Depending on the flow, session storage contains “workos:code-verifier” for PKCE, “desklix:auth-return-path” for the return destination, “desklix:workos-login-intent-email” to associate the business login email, and “desklix_pending_mfa” for a temporary MFA step. It also holds temporary view and host preferences. The application removes authentication entries after use; otherwise this storage ends with the tab’s browsing session. Reloading alone does not clear it; browser session restoration can restore a session.
Purposes, legal bases and optional services
Access to storage strictly necessary for expressly requested authentication, security and preferences relies on section 25(2), point 2 TDDDG. Subsequent personal data processing follows the bases in the privacy notice or, for Customer Data, the organisation’s instructions. An operating system permission or feature selection does not replace required data protection consent. Technologies requiring consent may only be enabled after that consent. Google Maps loads only after active selection; external Stripe/Link checkout has its own storage and privacy information.
Your controls
You can delete or block cookies and site data separately for desklix.com and app.desklix.com in your browser. This may remove authentication, saved language or other requested functionality. Device permissions are also managed in operating system settings. Clearing local site data does not delete server-side account or organisational data. The privacy notice explains the procedures and contacts for those requests.