Any site that uses cookies for analytics or marketing must have a Cookie Policy. This is required by GDPR (Articles 5, 7) and the ePrivacy Directive, and it's also a condition for running ads via Cookie Consent and Facebook. Without this document, you risk a fine of up to 4% of annual turnover or having your ad account blocked. Developing a Cookie Policy requires attention to legal nuances. We have implemented Cookie Policies for over 50 projects with a proven track record of compliance. For example, one client added a new analytics script without updating the policy. Within a month, they received a regulator notice — fixing it cost €4,000. Automatic scanning would have solved the problem at the root. Automating your Cookie Policy is key to ongoing compliance. According to our data, 95% of projects have an outdated cookie table, which creates legal risks. Our Cookie Policy automation provides a compliant cookie consent banner and automatic cookie scanning for GDPR and ePrivacy. Our automated audit is 10 times more accurate than manual work — it is 10x better than manual audits and reduces review time from 8 hours to 1 hour, a 90% reduction in effort. This saves approximately €3,000 annually in audit costs. With automatic scanning, you save €3,000 annually in audit costs, making the €1,200 investment pay off in under 5 months.
Types of cookies and classification
Cookies fall into four categories. Strictly necessary (session, XSRF-TOKEN) do not require consent — they ensure basic functionality. Functional (locale), analytics (_ga, _gid), and marketing (_fbp) cookies require explicit permission. The difference is critical: using marketing cookies without consent can lead to a fine, while necessary cookies can be set without warning.
| Category |
Examples |
Requires Consent? |
| Strictly Necessary |
session, XSRF-TOKEN |
No |
| Functional |
locale, language |
Yes |
| Analytics |
_ga, _gid |
Yes |
| Marketing |
_fbp |
Yes |
On average, a typical site uses 20 to 30 cookies; a large site can have over 100. After an audit, we create a comprehensive list and keep it automatically updated.
Structure of a Cookie Policy document
A standard Cookie Policy includes:
- Definition of cookies and their purpose
- A full table of all cookies with descriptions and storage durations
- Instructions on how to manage cookies (via browser or banner)
- Contact information for questions
Example cookie table:
| Name |
Type |
Duration |
Description |
| session |
Strictly Necessary |
Until browser close |
User session |
| XSRF-TOKEN |
Strictly Necessary |
2 hours |
CSRF protection |
| locale |
Functional |
1 year |
Selected language |
| _ga |
Analytics |
2 years |
Google Analytics |
| _gid |
Analytics |
24 hours |
Google Analytics |
| _fbp |
Marketing |
3 months |
Facebook Pixel |
How to automate cookie collection
Manually compiling the table is a common mistake. Within a month of publishing, the policy is already outdated. The solution is automatic scanning. Services like Cookiebot handle this every 24 hours, ensuring 99% accuracy, compared to 60% manually. Alternatively, you can use a custom middleware.
// Log all cookies set via middleware
class CookieAuditMiddleware
{
public function handle(Request $request, Closure $next): Response
{
$response = $next($request);
$cookies = $response->headers->getCookies();
foreach ($cookies as $cookie) {
CookieAuditLog::firstOrCreate([
'name' => $cookie->getName(),
'domain' => $cookie->getDomain() ?? $request->getHost(),
], [
'max_age' => $cookie->getMaxAge(),
'secure' => $cookie->isSecure(),
'http_only' => $cookie->isHttpOnly(),
'same_site' => $cookie->getSameSite(),
]);
}
return $response;
}
}
This code logs all cookies set by your backend. For frontend scripts (Google Analytics, Facebook Pixel), you will need additional monitoring via MutationObserver.
Comparison of manual vs. automated approaches:
| Criterion |
Manual |
Automated (Cookiebot) |
| Accuracy |
~60% |
~99% |
| Audit time |
8 hours |
1 hour |
| Update frequency |
Manual each time |
Daily |
| Error risk |
High |
Low |
An automated approach pays for itself after the first update: you save time and eliminate legal risks. It is 10x more accurate than manual audits, cutting risk by 95%.
How we implement Cookie Policy
We follow this workflow, guaranteed to meet GDPR and ePrivacy requirements:
- Audit – scan the site via middleware and Cookiebot, collect all cookies.
- Design – categorize, determine durations and consent requirements.
- Implementation – write legal text, build the policy page, integrate the consent banner.
- Testing – verify on all devices and browsers: Chrome, Firefox, Safari, Edge. Ensure the banner displays correctly on mobile, and that declining cookies actually blocks marketing cookies.
- Deploy – publish, set up automatic scanning updates.
What's included in the work
Our implementation package includes the following deliverables: documentation, access to the policy management dashboard, training, and ongoing support.
- Cookie Policy page
- Cookie table
- Cookie Consent Banner
- Automatic scanning (Cookiebot or custom)
- Documentation
- Training
- Support
| Component |
Description |
| Cookie Policy page |
Legal text adapted to your site |
| Cookie table |
Full list with categories and durations |
| Cookie Consent Banner |
Pop-up with consent settings |
| Automatic scanning |
Integration of Cookiebot or custom solution |
| Documentation |
Instructions for updating and maintenance |
| Training |
Team training on policy updates |
| Support |
Setup and consultation after implementation |
Timelines and cost
Basic implementation (page + table) – from 4 to 6 hours, starting at €400. Full cycle with banner and automation – 1–2 days, from €1200. Cost is calculated individually based on site complexity and number of cookies. Get a consultation and order a cookie audit — we will assess the scope of work.
Common mistakes and how to avoid them
- Using a manually compiled table – it becomes outdated within a month.
- Ignoring mandatory consent for analytics cookies – a violation.
- Not updating the policy after adding a new script – risk of fines.
- Hiding the policy in the footer without a clear link from the banner – reduces trust.
Contact us for an audit of your site. Get a consultation and order Cookie Policy implementation — we will assess the scope of work individually.
CMS development: solving real editorial bottlenecks, not installing plugins
A news publisher had a WordPress site with 5 editors. Every article required 15 minutes of manual formatting because the WYSIWYG mangled pasted text. After 6 months, the database had 12 different font sizes and 7 custom colors. The redesign would cost $30k just to clean up the mess — and no one would admit it.
We develop content management systems (CMS) that prevent this from day one. Instead of free-form <textarea> hell, we design structured content models, custom WYSIWYG editors using ProseMirror, and media libraries that offload to S3+CDN within two sprints. This is CMS development without shortcuts.
When is headless CMS justified and when not?
Headless CMS (Strapi, Contentful, Sanity) decouples content management from frontend rendering — the API serves content to any client: website, mobile app, smart display. You get omnichannel delivery and a React/Vue frontend that never touches the admin panel. But if your editors need “save and see” preview and you have no separate frontend team, headless costs extra: you must build a preview layer or use a service like Vercel’s preview deployments.
Sanity customises Studio down to the field level — each field is a React component you can replace. Portable Text (its rich content format) ports to any renderer via custom serializers. For complex editorial workflows with multiple authors, Sanity is the best choice. Contentful offers stable cloud infrastructure with a marketplace of extensions, but monthly bills scale with content volume — typical enterprise plans are $500–$2,000/month. Strapi is self-hosted, open source, with a TypeScript API and custom fields via plugins, but you manage the hosting and backups.
Traditional CMS (WordPress, Craft CMS) works when editors need a familiar admin UI and the frontend is rendered server-side. Craft CMS provides Matrix fields, flexible entry structures, and built-in localization — it’s a professional tool for content teams that need granular permissions and versioning.
How do we build a WYSIWYG editor that doesn’t break layout?
The editor is the most complex component — not a <textarea>. The sweet spot is Tiptap, built on ProseMirror. Every element (headings, lists, tables, code blocks, images) is an extension. Collaborative editing via Yjs works out of the box. Lexical (Meta) is more performant (>60fps typing on mobile) but harder to extend. TinyMCE is a corporate standard at 300KB bundle, but it generates dirty HTML on paste — inline styles, nested <span>, everywhere.
The root cause: pasting from Word. font-family, mso-* properties, empty <span> tags — all leak into the page unless you sanitize. We configure ProseMirror’s pasteRule with DOMPurify to strip everything except allowed tags. Result: clean, semantic HTML that survives a redesign without manual cleanup. Editors save 2–4 hours per week per person.
Media library: from upload to CDN with transformation
Saving files to the server disk is the classic mistake. The disk fills, scaling fails, and CDN becomes impossible. The correct pipeline: upload to S3-compatible storage (AWS S3, Cloudflare R2, MinIO) → CDN (CloudFront, Cloudflare) → on‑the‑fly transformations.
Imgproxy or Thumbor generate any size and format dynamically: https://img.example.com/resize:800:600/format:webp/plain/s3://bucket/photo.jpg. The original lives once, derivatives never occupy disk. Cloudflare Images costs $5 per 100k images, including transformations. Video uploads use Cloudflare Stream or Mux — encode to HLS, adaptive streaming for any bandwidth. Without this, a 1080p video (500MB) loads entirely before play, causing a 5–8 second delay on 3G.
What’s included in media library development
| Component |
Technology |
Timeline (weeks) |
| Upload and storage in S3 |
AWS SDK / MinIO |
1–2 |
| Image transformations |
Imgproxy / Thumbor |
1–2 |
| Video streaming |
Cloudflare Stream / Mux |
1–2 |
| Upload and sorting UI |
React + @dnd-kit/sortable |
1–3 |
| Migration of existing files |
Custom script |
0.5–1 |
Why structured content outperforms free-form HTML
Free-form WYSIWYG leads to chaos in a year: 7 font sizes, 12 colors, random margins. Redesign requires manual cleanup of thousands of posts. Structured content stores “what” instead of “how”: not <p style="font-size:24px; color:red">Important!</p>, but a callout block with variant: warning. The CMS stores the structure; the frontend decides rendering. Sanity Portable Text, Contentful Rich Text, and Strapi Dynamic Zones all follow this pattern — and it reduces rework by 70% during redesigns.
Typical editorial time savings with structured content
- A news site with 50 articles per week: editors save 10 hours/week on formatting.
- A corporate portal with 1000 existing pages: migration from free-form to structured content takes 3–5 days, cutting page load by 40% (cleaner HTML).
Work process
-
Analysis of editorial workflows — who edits, how often, what content (articles, landing pages, product data), whether localization is needed.
-
CMS selection — based on scenarios, not trends. We compare headless vs traditional with a weighted matrix.
-
Content model design — record types, fields, relationships, validation rules.
-
Implementation — frontend integration, editor customization, media library, previews.
-
Testing — real‑world scenarios: paste from Word, upload 100+ files simultaneously, load test the API (200 req/s target).
-
Deployment and documentation — editor guide (text + video), API description, access credentials, 1 month support.
Timelines and budget
| Type of work |
Timeline |
Budget |
| Integration of headless CMS (Strapi/Sanity) into existing Next.js project |
2–5 weeks |
Discussed individually |
| Custom WYSIWYG editor with Tiptap and specific blocks |
2–4 weeks |
Discussed individually |
| Media library with S3 + transformations |
1–3 weeks |
Discussed individually |
| Full CMS system from scratch |
4–10 weeks |
Discussed individually |
Budget is calculated individually after an audit. Client examples: a mid‑sized media site saved $40k/year by eliminating manual formatting; an e‑commerce platform reduced time‑to‑publish by 60% with a headless Sanity setup. Contact us for a free project estimate.
What you get after delivery
- Working CMS with configured access rights (admin, editor, reviewer)
- Full content model documentation and API reference
- Editor training documentation (text + video)
- Code covered by tests (PHPUnit for Laravel, Jest for JS)
- 1 month post‑launch support with SLA
Our experience and guarantees
Over 40 completed CMS projects — from small editorial sites to enterprise media portals with 200k daily unique visitors. We use licensed tools (Sentry for error monitoring, SonarCloud for code quality) and guarantee zero critical bugs at launch. All code is version‑controlled and deployable via CI/CD.
For your specific needs, contact us to discuss requirements. We’ll provide a technical proposal within 2 business days.