Last updated: 21 September 2026
This English version is a translation provided for convenience only. In the event of any discrepancy between the two versions, the French version prevails.
This page describes what the OpusRH websites and services, published by OREXIS, place in your browser: cookies and local storage. Everything relating to your personal data — purposes, retention periods, recipients, how to exercise your rights — is set out in the Personal data protection policy.
The website sets no cookies and loads no third-party resource. It stores the following in your browser's local storage:
| Name | Purpose | Duration |
|---|---|---|
| orh_vid | Visitor identifier used for audience measurement | Valid for 13 months, then replaced |
| orh_sid | Visit identifier: groups the pages viewed during one visit | Valid for 30 minutes after the last page viewed, then replaced |
| orh_lang | Remembers the language you chose, when you click FR or EN | Until the site's data is cleared |
In addition, a test entry, deleted immediately, checks that local storage is available.
Audience measurement. For each page viewed, OREXIS records the page viewed, the referring site (domain name only), the browser language, the screen dimensions, the device type and the two identifiers above. The IP address is not recorded with this data, which is kept for 25 months and is used only to produce traffic statistics. The measurement is carried out by OREXIS itself, with no third party involved.
The following applies to every page of the console, including the sign-in pages and legal pages such as this one.
| Cookie | Purpose | Duration |
|---|---|---|
| console_auth | Keeps you signed in. Set after a successful sign-in, deleted when you sign out | Up to 10 years; your browser may impose a shorter duration |
| console_af | Security token: protects forms against forged requests | Session: deleted when the browser is closed |
| ui_lang | Remembers the language chosen on the sign-in and sign-up pages, when you click the language selector | 365 days |
| dash_group | Remembers the last team displayed in the dashboard | 180 days |
| cur_tenant | For resellers and the publisher: remembers the customer workspace currently being viewed | 30 days |
The console also stores the following in your browser's storage:
| Key | Purpose | Duration |
|---|---|---|
| pv-theme | Light or dark theme chosen | Until the site's data is cleared |
| pdvTlMode | Display mode chosen for the timeline of a day | Until the site's data is cleared |
| daSeen-… | Date of the last alert you viewed, so that only new ones are flagged; the key name contains the technical identifiers of your account and of the customer workspace viewed | Until the site's data is cleared |
| htmx-current-path-for-history | Address of the current page, for the browser's "Back" button | Lifetime of the tab |
None of these keys is sent to OREXIS. Preferences (language, team, customer workspace, theme) remain after you sign out. The console can be installed as an application: for that purpose, even before you sign in (from the sign-in page or a legal page such as this one), it registers in your browser a technical component (a service worker) which stores no data. One additional technical cookie (ek_fresh, two minutes) is set only on the publisher's own workstation, when administering the platform.
Each sign-in is also recorded on the server (IP address, browser) for security purposes: see section 3.e of the Personal data protection policy.
On the Licenses page and the subscription screens of the console, which are restricted to administrators, the payment module is loaded from Stripe (js.stripe.com), our payment provider. Stripe sets its own fraud-prevention cookies there — according to its documentation, __stripe_mid (one year) and __stripe_sid (thirty minutes). OREXIS neither reads nor uses them. See Stripe's privacy policy. No other page loads it: not the website, not the sign-in pages, not the employee space. Once loaded, it may remain present in the tab on other console pages until the page is next fully reloaded. If your bank requires authentication (3-D Secure), its own page is displayed during the payment.
When the employer has enabled the task management module, employees open their space through a personal access link. This space uses:
| Name | Purpose | Duration |
|---|---|---|
| emp_auth (cookie) | Keeps the employee signed in. Set when the access link is opened, deleted on sign-out | Up to 10 years; the browser may impose a shorter duration |
| console_af (cookie) | Security token for forms | Session: deleted when the browser is closed |
| td-theme (local storage) | Light or dark theme chosen | Until the site's data is cleared |
| htmx-current-path-for-history (session storage) | Address of the current page | Lifetime of the tab |
The employee space involves no audience measurement, no third-party service and no advertising.
You can delete cookies and local storage at any time from your browser's settings ("site data"). Deleting the sign-in cookie signs you out.
For any question, write to rgpd@jhm-it.fr. Your rights and how to exercise them are described in the Personal data protection policy.