Browser preferences

Cookie policy

How browser storage, optional measurement and third-party content are handled on this website.

Last reviewed: August 2026

Purpose of this policy

This page explains cookies and similar storage technologies in relation to the current private website. It must be checked against the deployed site because hosting, security and embedded services can change the technologies used.

The policy does not cover cookies set on external websites reached through a link. Those services provide their own information and controls.

What cookies and similar technologies do

A cookie is a small piece of information that a website can ask a browser to store and return. Sites may also use local storage, session storage, pixels or other identifiers to provide a function, remember a preference, protect a session, measure use or personalise content.

Some technologies are necessary for a service requested by the visitor. Others support measurement, advertising or personalisation and may require prior choice depending on the applicable law and configuration.

Current website inventory

The static website does not intentionally enable analytics, advertising, behavioural profiling, user accounts, payment, chat, embedded maps or video. It therefore does not present a marketing or measurement consent panel.

A small browser-storage value may be used only where needed to remember a cookie-information choice. The final deployed environment must be inspected to confirm whether infrastructure or security services add essential identifiers.

Hosting and security technologies

A hosting or security provider may use short-lived identifiers to route traffic, defend against abuse, balance load or maintain service integrity. Whether such a technology is present, its duration and the information it handles depend on the final provider and configuration.

Necessary technologies should be limited to what the requested service requires and documented in a current inventory. They should not be reused for unrelated advertising or profiling without an appropriate legal basis and visitor choice.

How technologies are classified

An accurate inventory should group each technology by its real purpose rather than by the supplier's preferred label. Common groups include strictly necessary delivery and security, saved preferences, audience measurement, personalisation and advertising. A single tool may perform more than one function and must be assessed accordingly.

Calling a technology necessary does not make it so. The owner should document which visitor-requested function would fail without it, whether a less intrusive method is available and whether the information is used for any secondary purpose.

First-party, third-party, session and persistent storage

First-party storage is associated with the domain a visitor is viewing, while third-party services may receive requests or set identifiers through an embedded feature. This distinction helps explain who can read an identifier, but it does not by itself determine whether the technology is necessary or requires consent.

Session technologies normally expire when the browser session ends; persistent technologies remain until their configured expiry or manual deletion. The final table should state the actual provider, name, purpose and duration instead of relying only on broad labels such as session or essential.

Consent, refusal and withdrawal

If non-essential technologies are introduced, the site should present a clear choice before they are stored or accessed where prior consent is required. Accepting all and rejecting non-essential technologies should be comparably understandable, and consent should not be inferred from silence, scrolling or continued browsing.

A visitor should be able to reopen preferences and withdraw a choice without searching for a hidden control. The site should retain only the limited evidence needed to honour and demonstrate the choice, apply it for a documented duration and ask again when purposes materially change.

Embedded content and outbound links

A plain link does not normally load the destination service until it is followed, but an embedded video, map, social post, font or support widget may contact another provider as soon as the page loads. The owner should test network requests as well as checking visible cookie names.

Where an embedded service is non-essential, a privacy-preserving placeholder can allow the visitor to choose whether to load it. After leaving this site, the destination's own cookie and privacy terms apply.

Browser signals and device-level settings

Browsers and devices may send privacy preference signals or limit cross-site tracking. The legal and technical effect of those signals varies by jurisdiction, browser and service, so the final owner should document which recognised signals the deployed site can honour.

A site-level preference should not claim to erase storage placed by an unrelated external domain. Visitors may also need to use browser or provider controls, and the policy should explain those limits without implying that device settings replace any choice the site itself is required to offer.

Services that would change this policy

Adding analytics, embedded media, maps, chat, personalisation, A/B testing, advertising, social widgets or a third-party form may introduce new cookies or network requests. The owner must review the supplier, purpose, data, duration and transfer arrangements before activation.

Where consent is required, non-essential technologies must remain disabled until the visitor makes a choice. Refusing them should not block access to ordinary page content.

How visitors can control storage

Browsers provide settings to inspect, block and delete cookies and site data. Private-browsing modes may reduce persistence but do not make a visitor anonymous to networks or external services.

Blocking a strictly necessary technology can prevent a future feature from working correctly. The site should explain that consequence at the point of choice rather than using a broad warning for every cookie.

Review and updates

The owner should run a fresh cookie and storage inventory before launch, after provider changes and whenever a new embedded or measurement service is introduced. The visible controls and this policy must match the real behaviour of the site.

The last-reviewed date should be updated when the inventory changes. A verified privacy contact will be added before commercial operation for questions about cookies or personal data.