Interface specification
Cookie notice
1. The boundary this document specifies
One boundary is at issue here: the line between these pages and the storage belonging to the device you are reading them on. Everything crossing that line in either direction is registered at section 3, and the register is short enough to read in full rather than summarise.
The company writes interface contracts for a living, and the same discipline applies to its own site. A boundary worth specifying is a boundary worth specifying honestly, which means naming the one item that may be written, naming who writes it, and giving you a way to check the claim without taking anyone's word for it.
2. What the law calls a write to your device
A cookie is a short piece of text handed to your browser for safekeeping and handed back on a later request. Other mechanisms reach a comparable result by different means, among them local storage, session storage and the pixel tag, and the law groups all of them together rather than treating each on its own.
The controlling instrument in this country is PECR, the Privacy and Electronic Communications (EC Directive) Regulations 2003, which runs alongside the UK GDPR rather than inside it. Regulation 6 carries the rule: putting information onto equipment belonging to a user, or retrieving information already sitting there, demands clear information plus that user's agreement.
One narrow carve-out exists. Where the operation is strictly necessary to deliver something the user expressly asked for, agreement is not required. The regulator reads that carve-out tightly. It does not reach measurement, it does not reach advertising, and it does not reach anything an operator simply finds handy.
3. The write register
These pages are static files. No sign-in, no basket, no server-side session and no submitted form exists here, which removes every ordinary reason a first-party cookie would be defined in the first place.
| Item | Written by | Function | Standing under regulation 6 |
|---|---|---|---|
__cf_bm, or a comparably named Cloudflare item |
Cloudflare, Inc., which hosts and delivers this site | Bot management. Tells an automated client apart from a person, which is what keeps the pages reachable. Written at the moment the protection layer engages and not on an ordinary visit | Strictly necessary: without it the service you asked for cannot be kept secure or kept up. Agreement is therefore not required |
| Nothing further | Not applicable | These pages define no cookie of their own, write nothing to local storage and write nothing to session storage | Not applicable |
Documentation for the Cloudflare item is published by Cloudflare, not by this company. Both the precise identifier and how long it persists are decided at that end, which is why the register above characterises it by what it does instead of quoting a lifespan nobody here has authority over.
4. Why no consent gate stands here
A consent gate exists to collect agreement for writes that fall outside the strictly necessary exception. The register at section 3 contains no such write, so a gate here would be asking your permission for nothing at all.
Putting one up anyway is not a neutral act. A dialogue that demands agreement to nothing trains a reader to click past the identical control on a site where clicking past it costs them something, and it suggests machinery is running here that is not. Leaving the gate out is a decision, and this paragraph is the record of the reasoning behind it.
Were measurement, or anything else falling outside the carve-out, ever introduced, three things would happen in sequence: agreement collected before the code executes, refusal made precisely as easy as acceptance, and this document reissued under a new date ahead of both.
5. Verifying the register yourself
Checking the register takes under a minute, and a check you run yourself is the only kind worth having. Open your browser's developer tools, switch to whichever panel lists site data, then request any page from this domain.
Expect one of two results: an empty cookie list, or a list holding a single Cloudflare entry. Expect local storage to hold nothing whatever. Anything further means the register above is inaccurate, and section 11 says how to report that.
6. The one outbound edge on page load
Drawing a page here sends your browser after two typefaces held by Google's font service. Two hosts are involved: fonts.googleapis.com, which answers with the stylesheet, then fonts.gstatic.com, which answers with the font files themselves.
Nothing is written to your device by either exchange, so regulation 6 never engages. What does happen is that your address and your ordinary request headers become visible to Google LLC, which makes the exchange a movement of personal data past the United Kingdom border and lands it in the privacy notice instead of this document. Google publishes a position that requests of this kind feed no advertising profile. Nothing at this end can audit that statement, so the exchange is disclosed and the weighing of it left with you.
Every response from this domain carries a content security policy naming those two hosts and refusing all others, which puts a hard bound on what any page here is even able to reach for. That policy sits in the response headers, inspectable in the same developer tools as the site data panel.
Serving the typefaces from this domain instead would shut the edge for good, and that remains the better arrangement. What is described above is the position as it genuinely stands today rather than a description of how it ought to look, and any change to it moves the issue date at the head of this page under section 10.
7. Request logs sit outside this boundary
Answering a request creates an entry in the hosting provider's log. An entry of that sort is a record held at the far end, not storage deposited on equipment of yours, which places it entirely beyond PECR.
It remains personal data, and it is specified as interface IF-01 in the privacy notice: the address, timestamp, path, response code, user agent and referrer of a request, retained on the provider's own short cycle, used to keep the site reachable and to investigate abuse, joined to nothing and profiling nobody.
8. Controlling the boundary from your side
Control of your own device storage does not require anyone's cooperation. Every current browser exposes the ability to inspect, block and clear what sites have written.
- Chrome: Settings, then Privacy and security, then Third-party cookies; Site settings holds the per-site controls.
- Safari: Settings, then Privacy, then Manage Website Data, with Prevent cross-site tracking alongside it.
- Firefox: Settings, then Privacy and Security, then Cookies and Site Data, with Enhanced Tracking Protection alongside it.
- Edge: Settings, then Cookies and site permissions.
Refusing the Cloudflare item produces exactly one observable consequence. The protection layer can no longer see that your browser already cleared a check, so it may put a challenge in front of you more often than it otherwise would. Beyond that, nothing published here leans on device storage at all, which means refusing everything leaves these pages behaving precisely as they behave now.
Any extension that intercepts requests to other domains will shut the font edge at section 6. Pages then draw in whichever typefaces your own system offers, and the layout was built to survive that substitution rather than to depend on the substitution never happening.
9. Browser signals
Some browsers emit a Do Not Track header and some emit a Global Privacy Control signal. No settled standard obliges a website to respond to either in a particular way.
Here the question has no practical content. Nothing on these pages tracks anybody, so honouring a signal and disregarding it produce an identical outcome. The point is recorded so that a reader looking for a position finds one instead of silence.
10. Change control
This document describes the site as it stands on the issue date at the head of the page. Anything introduced that writes beyond the strictly necessary triggers three steps in order: this notice is revised, the issue date moves, and a consent mechanism is in place before the new code loads for the first time.
The sequence matters more than the promise. A revision published after the event is a record of what already happened, not a choice offered to the reader.
11. Questions and escalation
Write to [email protected] with "Cookies" at the front of the subject line. If you believe the register at section 3 misdescribes what actually happens, say what you observed and how you observed it; the claim will be checked and the page corrected where you are right.
Supervision of PECR and of data protection in this country rests with one regulator, and a complaint may go to it at any point. Reach the Information Commissioner's Office by post at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, by telephone on 0303 123 1113, or through the complaint form published at ico.org.uk. Going there before writing here costs you nothing at all, though this company would sooner be handed the opportunity to correct an error itself.