Cookie Policy
An inventory of what lagancyber.co.uk writes to a reader’s device, what it asks the browser to fetch from elsewhere, and what governs both — entered as controls, in the same form as the privacy and terms registers.
How to read an entry
Same four fields as everywhere else in this legal register: the Control, its Implementation, the Evidence kept that would settle an argument about it, and the Owner who answers for it. The inventory at CKY-01 is the part worth reading if you only read one.
Two things are covered separately, because they behave differently. These public pages are static files. The subscriber platform sits behind a sign-in and needs a session, which is a different question with a different answer at CKY-05.
CKY-01 Storage inventory for these pages Controller
An inventory is only worth anything if it is complete. This one covers every category a cookie policy is normally asked about, with the position on each.
| Category | In use here | What it would be for | Consent needed |
|---|---|---|---|
| Strictly necessary | None on these pages | Keeping a signed-in session upright | Exempt when used |
| Preference | None | Remembering a display choice between visits | Yes, if introduced |
| Measurement | None | Counting readers and pages | Yes, if introduced |
| Advertising or cross-site | None | Following a reader between sites | Yes, and it would need one |
| Local and session storage | None written | Holding state in the browser | Treated as storage either way |
CKY-01
Controller
Control
Every category of device storage is inventoried with its position stated, so a reader can see the whole picture rather than the flattering part of it.
Implementation
The pages here are static files with no server-side session behind them, so a visit writes nothing to the device that returns on the next request. Anything added later gets a row above, a purpose and a consent position before it appears, not afterwards.
Evidence kept
The response headers this site publishes, and the page source, which can be read in a browser’s own storage inspector in under a minute. This entry is checkable rather than merely asserted.
Owner
Data Protection Lead.
CKY-02 Consent position, and the absent banner Controller
The reason no consent dialogue appears is worth one entry, since its absence is otherwise open to a less charitable reading.
CKY-02
Controller
Control
Consent is sought whenever the law requires it, and a banner is shown only when there is something real to consent to.
Implementation
Regulation 6 of PECR requires consent before storing information on a device or reading information from it, apart from what is strictly necessary to deliver a service the reader asked for. The inventory at CKY-01 has nothing in the categories that would trigger that duty, so there is no consent to collect and a banner would ask a question with no content behind it. Should a measurement or preference technology arrive, consent would be requested first, refusing it would be as easy as accepting, and this entry would change on the same day.
Evidence kept
The dated version of this register; the storage inventory it carries.
Owner
Data Protection Lead.
CKY-03 The one script these pages run Controller
A single script file is loaded across the site. Here is the whole of what it does.
CKY-03
Controller
Control
Client-side code is limited to presentation, holds no state on the device, and sends nothing anywhere.
Implementation
The script marks a coverage table as hoverable on devices with a precise pointer, flags a wide table when it has more content to scroll to, and keeps the navigation rail’s edge shading in step with its scroll position. It reads no identifier, writes no cookie, opens no network connection, and leaves nothing behind when the tab closes. With scripting switched off, every page here stays readable and every link still works.
Evidence kept
The script is served unminified at matrix.js and can be read end to end; the content security policy in the published headers confines script loading to this origin.
Owner
Engineering.
CKY-04 Typefaces fetched from a third party Controller
One outbound request leaves the browser for a host this company does not run, and it is for the lettering.
| Host | What is fetched | Storage set | What the host observes |
|---|---|---|---|
| fonts.googleapis.com | A stylesheet naming the font files | None | IP address, browser and the page requesting it |
| fonts.gstatic.com | The font files themselves | None | IP address and browser |
CKY-04
Controller
Control
A third-party request made on a reader’s behalf is disclosed with what the recipient can observe from it, rather than left for a network inspector to reveal.
Implementation
Lettering is requested from the hosts above when a page opens. Neither request carries a cookie for that provider, and neither is a route by which this company learns anything: the exchange happens between the reader’s browser and the host, with Google acting on its own account rather than on ours. What it can see is the ordinary content of any web request, listed in the table.
Evidence kept
The stylesheet reference in the page source; the font-src and style-src directives in the published content security policy, which allow those two hosts and nothing else.
Owner
Engineering.
CKY-05 Session cookies inside the platform Controller & processor
Signing in is a different problem from reading a page, and it needs a cookie to work at all.
CKY-05
Controller & processor
Control
The subscriber platform uses the minimum storage a signed-in session requires, all of it strictly necessary and none of it measuring anybody.
Implementation
A session cookie keeps a signed-in user signed in between requests and lets the platform recognise a submission as genuine rather than forged. It is marked secure and inaccessible to scripts, is scoped to the platform’s own hostname, and ends when the session does or when a user signs out. Nothing in it identifies a person beyond the session it represents, and nothing about it follows anyone to another website. Strictly necessary storage of this kind is exempt from the consent duty at CKY-02, which is why signing in does not produce a dialogue either.
Evidence kept
The cookie attributes visible to any signed-in user in their own browser; the session records described at PRV-09.
Owner
Engineering.
CKY-06 Control from the browser side Controller
Whatever a site says, the device is the reader’s. This entry sets out what that means here.
CKY-06
Controller
Control
Nothing on this site degrades because a reader blocks or clears storage, and no attempt is made to detect or work around a blocker.
Implementation
Every browser offers storage controls under its own privacy settings, and its own documentation is the accurate guide to them — menu paths move between releases, and a walkthrough written today would mislead somebody next year. Blocking storage here costs nothing, because the inventory at CKY-01 is empty. Blocking the font hosts at CKY-04 leaves the pages in a system typeface and fully readable. The only thing that genuinely needs storage is the signed-in session at CKY-05, and blocking that means being unable to stay signed in.
Evidence kept
The published headers and page source, which contain no storage-detection or paywall-style script.
Owner
Engineering.
CKY-07 Tracking signals Controller
Browsers can broadcast a preference about being followed. The honest answer here is about why it makes no difference.
CKY-07
Controller
Control
No profile is built of anyone reading this site, so a preference signal has nothing to switch off.
Implementation
A browser preference asking not to be followed — and the newer opt-out signals that carry legal weight in some jurisdictions — are respected by default, because the behaviour they exist to prevent does not happen. Readers are not profiled, segmented, scored or matched to an advertising identifier, and nothing about a visit is sold or shared for anyone else’s marketing. Server request logs described at PRV-07 keep the service running and expire after 30 days; they are not a readership analysis and are not used as one.
Evidence kept
The permissions policy in the published headers, which switches off interest-based cohort inference at the browser; the absence of any measurement tag in the page source.
Owner
Data Protection Lead.
CKY-08 Change control for this register Controller
A cookie policy dates faster than the rest, so the version and the route to a previous one are printed here.
CKY-08
Controller
Control
The inventory is amended before a change reaches production, never afterwards, and consent is obtained ahead of anything that needs it.
Implementation
This is version 2.0, in force 15 August 2026, replacing version 1.0 of 5 August 2026. Introducing measurement, a preference store or any third-party component would mean a new row at CKY-01, a consent mechanism under CKY-02 and a fresh version of this document published on the day it starts, not in the week that follows.
Evidence kept
Superseded versions, issued on request from hello@lagancyber.co.uk.
Owner
Data Protection Lead.
Questions about anything in this register, including a request to see an earlier version, go to hello@lagancyber.co.uk. The privacy register at PRV covers personal data more broadly, and PRV-21 carries the route to the regulator.