1. What are cookies?
Cookies are small text files or similar identifiers that a website can store or read on a browser or device. They can support essential functions such as security and user-session continuity, remember choices, or — where lawfully enabled — help measure how a website is used.
Not every technical record is a cookie. Server and security logs may be generated independently of cookies and are handled under the Privacy Policy.
2. Current and planned use
The website is being prepared as a corporate B2B site. Strictly necessary technologies may be used where required for core functionality and security. Analytics, preference or marketing technologies must not be treated as essential merely because they are available in the theme or a future integration.
GA4 and other analytics integrations are listed in the project brief as a later launch-stage task. They should only be enabled after the production configuration, legal basis and consent behaviour have been reviewed.
| Category | Purpose | Default approach | Consent |
|---|---|---|---|
| Strictly necessary | Core site operation, security, load/session handling where required | May operate where genuinely necessary | Not requested where another lawful basis applies |
| Preferences / functionality | Remember non-essential choices or enhanced functions | Off unless configured and justified | Requested where required |
| Analytics / performance | Measure traffic and site performance | Not enabled in this development build | Opt-in where required |
| Marketing / targeting | Advertising, profiling or cross-site targeting | Not configured | Opt-in before activation where required |
3. Consent and cookie controls
Where applicable law requires consent for a non-essential cookie or similar technology, that technology should remain inactive until the user takes an affirmative action. A banner or preference centre should make it possible to accept, reject and manage optional categories without treating continued browsing as consent.
A user should be able to revisit the cookie settings and withdraw or change a choice for future use. Withdrawing consent does not affect processing that was lawful before withdrawal.
4. Cookie categories in more detail
- Strictly necessary: technologies required for functions explicitly requested by the user, security, fraud/abuse prevention or technical delivery of the site.
- Preference/functionality: technologies that remember choices or enable non-essential enhancements.
- Analytics/performance: technologies used to understand visits, traffic sources, page performance or aggregate usage patterns.
- Marketing/targeting: technologies used for advertising, profiling, retargeting or tracking across services. The current project scope does not require these technologies.
5. Third-party technologies
If the final website uses third-party tools such as analytics, embedded maps, video, social-media widgets or other external services, those providers may place or read their own technologies. Such integrations should be configured so that optional third-party technologies do not load before the required user choice has been made.
The production cookie inventory should identify each relevant cookie or comparable technology by provider, purpose, category and retention period once the final integrations are known.
6. How to manage cookies
Where a cookie preference panel is provided, the easiest way to control optional cookies will be through that panel. Browsers also provide controls to block or delete cookies; however, blocking strictly necessary cookies may prevent some functions from working correctly.
Browser settings do not always provide the same level of control over all local-storage, SDK or third-party technologies, so the site-level preference mechanism should remain the primary control for optional categories.
7. Duration and inventory
Cookie duration depends on the technology. A session cookie normally expires when the browser session ends, while a persistent cookie remains until its configured expiry date or until it is deleted. The production policy should list the actual durations used by the final website rather than relying on generic estimates.
Before public launch, the site should be scanned after all integrations are installed and the table on this page should be updated with the final cookie names, providers, purposes, durations and first/third-party status.
8. Personal data and your rights
Where a cookie or similar identifier relates to an identified or identifiable person, the resulting information may be personal data. The Privacy Policy explains the broader processing purposes, legal bases, recipients, retention approach and rights that may apply.
Read the Privacy Policy9. Updates and contact
This Cookie Policy will be updated when cookie categories, providers, consent tools or website functionality change. Questions about cookies can be sent through the Contact page until a dedicated privacy contact is confirmed.
Go to Contact
