LAGAN CYBER
Control register — CKY series

Cookie Policy

An inventory of what lagancyber.co.uk writes to a reader’s device, what it asks the browser to fetch from elsewhere, and what governs both — entered as controls, in the same form as the privacy and terms registers.

Register CKY · Version 2.0 · In force 15 August 2026 · Entity: WESTPORT CYBER LIMITED · Company No. NI741244 · Register owner: Data Protection Lead · hello@lagancyber.co.uk

How to read an entry

Same four fields as everywhere else in this legal register: the Control, its Implementation, the Evidence kept that would settle an argument about it, and the Owner who answers for it. The inventory at CKY-01 is the part worth reading if you only read one.

Two things are covered separately, because they behave differently. These public pages are static files. The subscriber platform sits behind a sign-in and needs a session, which is a different question with a different answer at CKY-05.

CKY-01 Storage inventory for these pages Controller

An inventory is only worth anything if it is complete. This one covers every category a cookie policy is normally asked about, with the position on each.

Storage inventory — CKY-01, lagancyber.co.uk public pages
Category In use here What it would be for Consent needed
Strictly necessary None on these pages Keeping a signed-in session upright Exempt when used
Preference None Remembering a display choice between visits Yes, if introduced
Measurement None Counting readers and pages Yes, if introduced
Advertising or cross-site None Following a reader between sites Yes, and it would need one
Local and session storage None written Holding state in the browser Treated as storage either way

CKY-01
Controller

Control

Every category of device storage is inventoried with its position stated, so a reader can see the whole picture rather than the flattering part of it.

Implementation

The pages here are static files with no server-side session behind them, so a visit writes nothing to the device that returns on the next request. Anything added later gets a row above, a purpose and a consent position before it appears, not afterwards.

Evidence kept

The response headers this site publishes, and the page source, which can be read in a browser’s own storage inspector in under a minute. This entry is checkable rather than merely asserted.

Owner

Data Protection Lead.

CKY-02 Consent position, and the absent banner Controller

The reason no consent dialogue appears is worth one entry, since its absence is otherwise open to a less charitable reading.

CKY-02
Controller

Control

Consent is sought whenever the law requires it, and a banner is shown only when there is something real to consent to.

Implementation

Regulation 6 of PECR requires consent before storing information on a device or reading information from it, apart from what is strictly necessary to deliver a service the reader asked for. The inventory at CKY-01 has nothing in the categories that would trigger that duty, so there is no consent to collect and a banner would ask a question with no content behind it. Should a measurement or preference technology arrive, consent would be requested first, refusing it would be as easy as accepting, and this entry would change on the same day.

Evidence kept

The dated version of this register; the storage inventory it carries.

Owner

Data Protection Lead.

CKY-03 The one script these pages run Controller

A single script file is loaded across the site. Here is the whole of what it does.

CKY-03
Controller

Control

Client-side code is limited to presentation, holds no state on the device, and sends nothing anywhere.

Implementation

The script marks a coverage table as hoverable on devices with a precise pointer, flags a wide table when it has more content to scroll to, and keeps the navigation rail’s edge shading in step with its scroll position. It reads no identifier, writes no cookie, opens no network connection, and leaves nothing behind when the tab closes. With scripting switched off, every page here stays readable and every link still works.

Evidence kept

The script is served unminified at matrix.js and can be read end to end; the content security policy in the published headers confines script loading to this origin.

Owner

Engineering.

CKY-04 Typefaces fetched from a third party Controller

One outbound request leaves the browser for a host this company does not run, and it is for the lettering.

Outbound requests made by the browser — CKY-04
Host What is fetched Storage set What the host observes
fonts.googleapis.com A stylesheet naming the font files None IP address, browser and the page requesting it
fonts.gstatic.com The font files themselves None IP address and browser

CKY-04
Controller

Control

A third-party request made on a reader’s behalf is disclosed with what the recipient can observe from it, rather than left for a network inspector to reveal.

Implementation

Lettering is requested from the hosts above when a page opens. Neither request carries a cookie for that provider, and neither is a route by which this company learns anything: the exchange happens between the reader’s browser and the host, with Google acting on its own account rather than on ours. What it can see is the ordinary content of any web request, listed in the table.

Evidence kept

The stylesheet reference in the page source; the font-src and style-src directives in the published content security policy, which allow those two hosts and nothing else.

Owner

Engineering.

CKY-05 Session cookies inside the platform Controller & processor

Signing in is a different problem from reading a page, and it needs a cookie to work at all.

CKY-05
Controller & processor

Control

The subscriber platform uses the minimum storage a signed-in session requires, all of it strictly necessary and none of it measuring anybody.

Implementation

A session cookie keeps a signed-in user signed in between requests and lets the platform recognise a submission as genuine rather than forged. It is marked secure and inaccessible to scripts, is scoped to the platform’s own hostname, and ends when the session does or when a user signs out. Nothing in it identifies a person beyond the session it represents, and nothing about it follows anyone to another website. Strictly necessary storage of this kind is exempt from the consent duty at CKY-02, which is why signing in does not produce a dialogue either.

Evidence kept

The cookie attributes visible to any signed-in user in their own browser; the session records described at PRV-09.

Owner

Engineering.

CKY-06 Control from the browser side Controller

Whatever a site says, the device is the reader’s. This entry sets out what that means here.

CKY-06
Controller

Control

Nothing on this site degrades because a reader blocks or clears storage, and no attempt is made to detect or work around a blocker.

Implementation

Every browser offers storage controls under its own privacy settings, and its own documentation is the accurate guide to them — menu paths move between releases, and a walkthrough written today would mislead somebody next year. Blocking storage here costs nothing, because the inventory at CKY-01 is empty. Blocking the font hosts at CKY-04 leaves the pages in a system typeface and fully readable. The only thing that genuinely needs storage is the signed-in session at CKY-05, and blocking that means being unable to stay signed in.

Evidence kept

The published headers and page source, which contain no storage-detection or paywall-style script.

Owner

Engineering.

CKY-07 Tracking signals Controller

Browsers can broadcast a preference about being followed. The honest answer here is about why it makes no difference.

CKY-07
Controller

Control

No profile is built of anyone reading this site, so a preference signal has nothing to switch off.

Implementation

A browser preference asking not to be followed — and the newer opt-out signals that carry legal weight in some jurisdictions — are respected by default, because the behaviour they exist to prevent does not happen. Readers are not profiled, segmented, scored or matched to an advertising identifier, and nothing about a visit is sold or shared for anyone else’s marketing. Server request logs described at PRV-07 keep the service running and expire after 30 days; they are not a readership analysis and are not used as one.

Evidence kept

The permissions policy in the published headers, which switches off interest-based cohort inference at the browser; the absence of any measurement tag in the page source.

Owner

Data Protection Lead.

CKY-08 Change control for this register Controller

A cookie policy dates faster than the rest, so the version and the route to a previous one are printed here.

CKY-08
Controller

Control

The inventory is amended before a change reaches production, never afterwards, and consent is obtained ahead of anything that needs it.

Implementation

This is version 2.0, in force 15 August 2026, replacing version 1.0 of 5 August 2026. Introducing measurement, a preference store or any third-party component would mean a new row at CKY-01, a consent mechanism under CKY-02 and a fresh version of this document published on the day it starts, not in the week that follows.

Evidence kept

Superseded versions, issued on request from hello@lagancyber.co.uk.

Owner

Data Protection Lead.

Questions about anything in this register, including a request to see an earlier version, go to hello@lagancyber.co.uk. The privacy register at PRV covers personal data more broadly, and PRV-21 carries the route to the regulator.

← Back to Lagan Cyber