This Cookie Policy explains how Kadac ("Kadac", "we", "our", or "us") uses cookies and similar browser-based technologies across its digital ecosystem.
1. Scope of This Policy
This Cookie Policy applies across the entire Kadac digital ecosystem, including, as applicable:
The Kadac corporate and public websites;
Kadac web applications;
Kadac Vendor Portal;
Kadac Admin Portal;
Customer-facing and partner-facing portals;
Web-based modules and services;
Current and future Kadac ecosystem products; and
Other Kadac-operated websites, applications or digital services that use cookie-based functionality.
Unless a specific Kadac product or service provides a separate Cookie Policy or notice, the principles described in this policy apply consistently across the Kadac ecosystem.
Public or static sections of the Kadac website may not require authentication cookies where login functionality is not involved. Authenticated Kadac applications and portals use strictly necessary cookies for authentication, session management and application security as described below.
At present, Kadac does not use cookies for behavioural advertising, targeted advertising or marketing profiling unless specifically disclosed for a particular product or service.
2. What Are Cookies?
Cookies are small text files stored on a user's device or browser when accessing a website or web application.
Cookies may be used to maintain authenticated sessions, protect application security, remember essential application state and enable the secure operation of web-based functionality.
Kadac currently uses only cookies necessary for the secure and reliable operation of the applicable website, application, portal or product.
3. Cookies We Use
Authenticated Kadac applications and portals use the following necessary cookies:
Cookie TypePurposeDurationHttpOnlySecureSameSiteSession CookieMaintains the authenticated user session and keeps the user signed in while using the application.1 hour of inactivityYesYes, in productionLaxCSRF CookieProtects the application against Cross-Site Request Forgery (CSRF) attacks and allows the frontend to provide the required CSRF token with requests.Up to 1 yearNoYes, in productionLax
4. Session Cookie
The session cookie is used to maintain a user's authenticated session following successful login.
The session cookie:
Expires after 1 hour of inactivity;
Is extended while the user remains active;
Is configured as HttpOnly, preventing frontend JavaScript from directly accessing the session cookie;
Is transmitted securely using HTTPS in production;
Uses SameSite=Lax to provide additional protection against cross-site requests; and
Is cleared or invalidated when the user logs out.
5. CSRF Protection Cookie
Kadac applications use a CSRF cookie to protect users and applications against Cross-Site Request Forgery (CSRF) attacks.
Where applicable, the frontend application reads the CSRF token and includes it within the X-CSRFToken request header when communicating with Kadac backend services.
Because the frontend application requires access to this token, the CSRF cookie is intentionally not configured as HttpOnly.
The CSRF cookie:
May remain valid for up to 1 year;
Is transmitted securely over HTTPS in production;
Uses SameSite=Lax;
Is cleared or invalidated as applicable during logout or session lifecycle management; and
Is regenerated with a new CSRF token upon every login.
6. Strictly Necessary Cookies
The cookies described above are considered strictly necessary for secure application functionality.
They may be required for purposes including:
Authenticating users;
Maintaining secure user sessions;
Protecting login and authenticated functionality;
Preventing unauthorised or forged requests;
Protecting application and user data;
Managing login and logout activity;
Maintaining application security; and
Providing essential functionality within Kadac products and services.
Because these cookies are essential to the operation and security of authenticated Kadac services, disabling them may prevent users from logging in or accessing secured functionality.
7. Public and Static Kadac Websites
Certain parts of the Kadac ecosystem may consist of public or static website pages that do not require user authentication.
Where a public or static page does not require cookies for its operation, Kadac may not place application authentication or session cookies on the user's device.
If the user proceeds from a public Kadac website to an authenticated Kadac application, portal or product, the necessary cookies described in this policy may then be used.
8. Analytics, Advertising and Tracking Cookies
Kadac does not currently use the cookies described in this policy for:
Behavioural advertising;
Targeted advertising;
Cross-site advertising tracking;
Marketing profiling; or
Unnecessary tracking of users.
Where a specific Kadac website, product or service introduces analytics, third-party integrations or other cookie categories in the future, the relevant policy or notice will be updated accordingly.
Where legally required, appropriate consent or cookie-management mechanisms will also be implemented.
9. Cookie Security
Kadac applies appropriate technical controls to cookies used throughout its ecosystem.
In the production environment:
Cookies are transmitted over secure HTTPS connections;
Session cookies are configured as HttpOnly;
Session and CSRF cookies use SameSite=Lax;
Authenticated sessions expire following the configured inactivity period;
User activity may extend an active authenticated session;
CSRF tokens are refreshed on login; and
Session information is cleared or invalidated when the user logs out.
These measures help reduce risks including session misuse, unauthorised cross-site requests and improper access to authentication information.
10. Third-Party Services
Certain Kadac products may integrate with external technology providers or third-party services.
If a third-party service independently places cookies or similar technologies through a Kadac website or application, such cookies may be governed by that third party's privacy or cookie practices.
Kadac will disclose material third-party cookie usage where applicable and required.
11. Managing Cookies
Users may control or delete cookies through their browser settings.
However, because authentication and security cookies are necessary for secured Kadac applications, disabling or deleting these cookies may:
Sign the user out;
Prevent successful authentication;
Affect application functionality; or
Prevent access to secured sections of a Kadac product.
12. Changes to This Cookie Policy
Kadac may update this Cookie Policy from time to time to reflect:
Changes to Kadac products or services;
New application functionality;
Changes in technology;
Security enhancements;
Introduction of new cookie categories; or
Changes in applicable legal or regulatory requirements.
The latest version will be made available through the relevant Kadac website, application, portal or product.
13. Contact Us
If you have any questions regarding this Cookie Policy or the use of cookies across the Kadac website, web applications, portals or wider Kadac ecosystem, please contact Kadac using the contact information provided on the relevant website, application or service.

