Legal
Cookie policy.
Information about cookies and similar technologies used by this website, and the choices available to visitors.
Draft template. A production cookie audit and legal review are required.
Before publication
No production cookie or storage inventory has been supplied. This template must not be treated as confirmation that the deployed website is cookie-free. Domantha must audit the live service, including its hosting platform and third-party code, complete the inventory below, implement any required choices, and obtain appropriate business and legal review.
1. Status and scope
This draft covers storage and access technologies used on domantha.com. It is designed to be completed against the production build. Product websites operated under separate brands should provide their own accurate information and controls.
2. What cookies and similar technologies are
A cookie is a small file stored on a browser or device. Similar technologies can include local or session storage, pixels, scripts, tags, link decoration and device fingerprinting. They may remember a selection, support requested functionality, protect a service or provide information about how it is used.
UK rules can apply whenever a service stores information on, or accesses information from, a visitor's device. They are not limited to traditional cookies or to information that identifies a person.
3. Current inventory
No named production technologies have been confirmed in the website configuration. Before launch, the table must identify every first- and third-party technology found during a live audit.
| Name and provider | Purpose | Information involved | Duration | Consent or exception |
|---|---|---|---|---|
| To be completed after the production cookie and storage audit. Do not replace this entry with a general category: list each technology and provider accurately. | ||||
4. When consent may not be required
The Privacy and Electronic Communications Regulations provide limited, purpose-specific exceptions. Domantha must document why any exception applies to the actual technology and purpose. Current examples include:
- Communication: use whose sole purpose is carrying a communication over an electronic communications network.
- Strictly necessary:use essential to provide an online service the visitor requests, assessed from the visitor's perspective rather than Domantha's convenience.
- Statistical purposes: narrowly limited use to produce aggregate statistics about how the service is used so it can be improved. It must not identify, track or profile visitors, and clear information plus a simple, free way to object must be provided.
- Appearance or functionality:use solely to adapt the service to a visitor's preference or improve how it appears or functions. Clear information plus a simple, free way to object must be provided.
- Emergency assistance:use solely to identify a device's location to provide emergency assistance. No such feature is specified for this corporate website.
An exception applies to a defined purpose, not to a label such as “essential” or “analytics”. If a technology also serves a non-exempt purpose, prior consent may still be required for that purpose.
5. Consent and visitor choices
Where no exception applies, Domantha must obtain valid consent before the technology is enabled. The production mechanism should:
- make refusing non-exempt technologies as easy as accepting them;
- require a positive action, with non-exempt options off by default;
- offer understandable, granular choices for each purpose and identify relevant third parties;
- avoid treating silence, continued browsing or browser defaults as consent; and
- allow a visitor to revisit and withdraw consent as easily as they gave it.
Browser controls can also delete or block cookies, but they do not replace an on-site consent or objection mechanism where the law requires one. If Domantha relies on the statistical-purpose or appearance exception, the production website must provide the simple and free objection route required for it.
6. Third parties and external links
Any provider that sets or accesses information through the website must be named, with a clear explanation of what it does, why, and how long the technology operates. Domantha must also confirm its arrangements and data-protection responsibilities with that provider.
Following an ordinary link to another website may take a visitor to a service with its own technologies and policy. A link alone should not silently activate tracking on this website. Embedded media, social plugins and externally hosted resources must be assessed during the production audit.
7. Review, privacy information and contact
The inventory and choices should be retested whenever the website, deployment platform or third-party services change, and at appropriate regular intervals. Durations must be proportionate and limited to the purpose. Any processing of personal information must also be described in the privacy policy.
Questions or objections can be routed through the contact page using Privacy enquiry. A monitored direct contact and the policy's effective date must be confirmed before production.