Cookie Policy
This site sets no analytics cookies, no advertising cookies and no cookies of its own. This page lists everything that can be set anyway, and explains why you are not being asked to dismiss a banner.
01 What this policy covers
This policy explains the use of cookies and similar technologies on the website at lagancyber.co.uk and its subdomains, by WESTPORT CYBER LIMITED, trading as Lagan Cyber. It sits alongside our privacy notice, which explains how we handle personal data more generally, and our terms.
The Lagan Cyber platform is pre-launch and not publicly available. When it launches it will use a strictly necessary session cookie for authentication and may keep interface preferences in local storage. This policy will be updated to list those before the platform is available to anyone.
02 Cookies and local storage explained
A cookie is a small text file that a website asks your browser to store and send back on later requests. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another domain whose content the page loads. A session cookie is deleted when you close your browser; a persistent cookie survives until it expires or you delete it.
Local storage and session storage are browser storage areas a site can write to. They are not cookies, but the law treats storing or accessing information on your device the same way regardless of the mechanism, and so does this policy. Related technologies include pixels, web beacons, device fingerprinting and software development kits inside mobile applications.
This site writes nothing to local storage or session storage. It uses no pixels, no beacons, no fingerprinting, no tag manager and no embedded third-party widgets.
03 The law and the consent standard
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) says that storing information on, or gaining access to information stored on, a user’s device requires clear and comprehensive information about the purpose and the user’s consent. There are two exemptions in regulation 6(4): where the storage is solely for the purpose of carrying out a transmission over an electronic communications network, or where it is strictly necessary to provide a service the user has explicitly requested.
“Strictly necessary” is narrow. It covers things like keeping you logged in, remembering the contents of a basket, load balancing and security measures that protect the service you asked for. It does not cover analytics, however anonymised, and it does not cover anything for marketing.
Where consent is required, it must meet the UK GDPR standard: freely given, specific, informed and unambiguous, given by a clear affirmative action. Pre-ticked boxes do not work. Continuing to scroll does not work. Refusing must be as easy as accepting, and consent must be withdrawable at any time.
Where a cookie also involves personal data, we need a lawful basis under Article 6 UK GDPR as well as PECR compliance. Section 5 of the privacy notice sets out the bases we rely on.
04 Every cookie we use
The table below is complete as at the effective date of this policy.
| Name | Set by | Type | Purpose | Duration | Consent |
|---|---|---|---|---|---|
| __cf_bm | Cloudflare, Inc. — our hosting and content-delivery provider | Strictly necessary — bot management | Distinguishes automated traffic from human visitors so that the site can be protected against bots and denial-of-service attacks. It does not identify you, is not used for analytics or advertising, and is not shared for any other purpose. | 30 minutes | Not required — regulation 6(4) PECR strictly necessary exemption |
| cf_clearance | Cloudflare, Inc. | Strictly necessary — security challenge | Set only if you are shown and pass a security challenge, so that you are not challenged repeatedly during the same visit. Most visitors will never see this cookie. | Up to 1 year | Not required — regulation 6(4) PECR strictly necessary exemption |
That is the whole list. We set no first-party cookies. There are no analytics cookies, no advertising or retargeting cookies, no social media cookies, no A/B testing cookies, no session-recording or heat-mapping cookies, and no cookies from any advertising network, data broker or customer data platform.
Cloudflare cookie names and durations are set by Cloudflare and can change. If you see a cookie from our domain that is not listed here, we would genuinely like to know: hello@lagancyber.co.uk.
05 Why there is no banner
A consent banner is required when a site sets cookies that need consent. This site does not set any, so asking for consent would be theatre — a dialogue that collects a click without changing anything, trains people to dismiss consent requests without reading them, and makes the site worse to use.
The moment we introduce anything requiring consent, a compliant mechanism will appear and it will ask before setting, not after. Until then, the absence of a banner is the honest signal, not a shortcut.
06 Google Fonts
This site loads two typefaces, Inter and IBM Plex Mono, from Google’s font service. That is not a cookie — Google states that the font service does not set cookies — but your browser does make a request to fonts.googleapis.com and fonts.gstatic.com, and Google will see your IP address and user-agent as a result.
We receive nothing from Google about you. We consider this a proportionate use of legitimate interests under Article 6(1)(f), but it is a disclosure of your IP address to a third party that you did not separately agree to, so we would rather state it than bury it. Self-hosting the fonts would remove the request and is on our list of changes.
If you would prefer not to make the request, a content blocker or a browser configured to block third-party requests will stop it. The site is built to remain fully legible in your system typefaces if the webfonts do not load.
07 If we ever introduce anything else
Should we introduce analytics, product telemetry or any non-essential storage, we commit that before it is deployed we will: update the table in section 4 with the name, provider, purpose, duration and category of every new item; implement a consent mechanism that asks first and sets nothing until you agree; make refusing exactly as easy as accepting, with no dark patterns, no pre-ticked boxes and no cookie wall; provide a way to change your mind later; and update the effective date on this page.
Any analytics we adopt would be chosen for being privacy-preserving — no cross-site tracking, no advertising identifiers, no data sold on. Adding advertising or retargeting cookies to this site is not something we intend to do.
08 Controlling cookies in your browser
You can block or delete cookies in your browser at any time. Blocking the strictly necessary cookies listed above may mean you are challenged more often by our provider’s security layer, but the site will still work. Blocking cookies broadly will affect other sites more than this one.
Google Chrome (desktop)
⋮ menu → Settings → Privacy and security → Third-party cookies, to control blocking; and Privacy and security → Delete browsing data, to clear cookies already stored. Site-specific controls are behind the icon at the left of the address bar.
Safari (macOS)
Safari menu → Settings → Privacy, where you can block all cookies and manage website data. Safari → Settings → Advanced → Privacy also controls advanced tracking and fingerprinting protection.
Mozilla Firefox
☰ menu → Settings → Privacy & Security. Enhanced Tracking Protection offers Standard, Strict and Custom modes; Cookies and Site Data lets you clear or manage stored data and block cookies entirely.
Microsoft Edge
⋯ menu → Settings → Cookies and site permissions → Manage and delete cookies and site data. Settings → Privacy, search, and services controls tracking prevention at Basic, Balanced or Strict.
iOS and iPadOS (Safari)
Settings app → Apps → Safari → Advanced → Block All Cookies. Settings → Apps → Safari → Clear History and Website Data clears what is already stored. Settings → Privacy & Security → Tracking controls whether apps may request permission to track.
Android (Chrome)
Chrome → ⋮ menu → Settings → Site settings → Third-party cookies. Chrome → ⋮ menu → Delete browsing data clears stored cookies. Android system-wide, Settings → Privacy → Ads lets you delete or opt out of the advertising ID.
Menu paths change between versions. If yours differs, search your browser’s help for “cookies”. Guidance for a general audience is also published at ico.org.uk.
09 Do Not Track and Global Privacy Control
Do Not Track (DNT) is a browser header asking sites not to track you. It never became an enforceable standard, most sites ignore it, and several browsers have removed the setting. We do not track you across sites in the first place, so there is nothing for a DNT header to switch off here. We do not treat DNT as a consent signal because there is nothing on this site that requires consent.
Global Privacy Control (GPC) is a more recent signal, expressed as a header or a JavaScript property, conveying a request to opt out of the sale or sharing of personal data and, in some jurisdictions, of targeted advertising. We do not sell or share personal data for advertising, and we set no advertising cookies, so there is no opt-out for GPC to exercise.
We honour both signals in substance by not doing the things they exist to prevent. If we ever introduce processing that a GPC signal would legitimately govern, we will treat a GPC signal as a valid objection and act on it automatically, without requiring you to find a settings page.
10 Changes and contact
This is version 1.0, effective 5 August 2026. We will update it whenever the cookies or storage used by this site or by the platform change, and always before a change takes effect rather than after. The effective date at the top shows when it was last revised.
Questions about this policy, or about anything you have found in your browser that is not listed here: hello@lagancyber.co.uk. We reply within two working days.
You can complain to the Information Commissioner’s Office at Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, on 0303 123 1113, or at ico.org.uk.