Legal
Cookie statement
This site sets no cookies of its own and runs no analytics, so there is no consent banner. Two things still reach beyond the page and both are set out here.
Effective 10 August 2026Version 1.0PECR 2003 and the UK GDPR
1The short answer
This website sets no cookies of its own. No analytics, no advertising, no tracking pixel, no session recording.
There is no consent banner, because there is nothing here that requires consent.
Two things still reach beyond the page: a strictly necessary security cookie our hosting provider may set, and a request to Google's font servers. Both are described below.
2The rule this answers to
The operative rule is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, read with the UK GDPR. Storing information on your device, or gaining access to information already stored there, requires clear information and consent.
Regulation 6 is technology neutral: local storage, session storage, IndexedDB, pixel tags and device fingerprinting are caught exactly as cookies are.
The one exemption
Consent is not required where the storage is strictly necessary for a service you explicitly requested. The ICO reads that narrowly: a security or load balancing mechanism qualifies, and analytics does not, however anonymous it claims to be.
3Why there is no banner
A banner exists to collect permission for storage that is not strictly necessary. There is none here, so a banner would be asking you to consent to nothing.
That is worse than leaving it out. It trains people to dismiss a control that matters elsewhere, and it implies the site is doing something it is not.
If anything outside the exemption is ever added, we will ask before it loads, make refusing exactly as easy as accepting, record the consent with a timestamp and the wording agreed, and update this page and its effective date first.
4Everything this site may store
Two cookies, neither set by us.
- __cf_bm, set by Cloudflare, our hosting provider. Distinguishes automated traffic from human traffic so abusive requests can be blocked. 30 minutes, refreshed on activity. Strictly necessary.
- cf_clearance, set by Cloudflare only if you are shown and pass a challenge, recording that you passed so you are not asked again. Up to 30 days. Strictly necessary.
That is the complete list, and neither is readable by us as an identifier of you.
5What this site does not do
- No Google Analytics, Plausible, Fathom, Matomo or any other analytics.
- No advertising and no advertising cookies.
- No Meta pixel, LinkedIn Insight tag or conversion tracking.
- No session recording, heatmapping or scroll tracking.
- No embedded video, map, chat widget or social widget.
- No local storage, session storage or IndexedDB written by our code.
- No fingerprinting and no attempt to recognise a returning visitor.
- No visitor identification service resolving your IP address to your employer for a sales pipeline.
Open the Application and Network panels in your browser's developer tools and compare them with this list. That is a better assurance than a paragraph of promises.
6The one outbound request
This site loads two typefaces from Google Fonts, at fonts.googleapis.com and fonts.gstatic.com. That request discloses your IP address, your user agent and the referring page to Google's servers. Google states the Fonts service sets no cookies and does not use the requests for advertising or profiling.
Self hosting the files would remove the request and it is on our list. Until then this is the honest description rather than an omission, and blocking those two hosts leaves the site fully readable in a system font.
7Server logs are not cookies
Every web server records the requests it receives. Our hosting provider logs IP address, timestamp, path, user agent and response code. Nothing is stored on your device, so regulation 6 is not engaged, but an IP address is personal data under the UK GDPR and it belongs in an honest account.
The lawful basis is legitimate interests under Article 6(1)(f). The logs sit with the provider on its own cycle, currently under 30 days, and are not combined with anything else.
8Controlling storage, and signals we honour
Every major browser lets you block cookies, delete them, and inspect what a site has set. Blocking the two above may mean Cloudflare challenges you more often, but the site will work.
- Chrome: Settings, then Privacy and security, then Third-party cookies and Site data.
- Safari: Settings, then Privacy, then Manage Website Data.
- Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
- Edge: Settings, then Cookies and site permissions.
Do Not Track and Global Privacy Control are both honoured, which is easy because there is nothing here to switch off. We say so anyway: a site that ignores these signals and stays quiet about it has made a choice it would rather you did not notice.
9Client systems
This page describes this website. It says nothing about a system we build for a client.
Where we build something that sets cookies, the client is the controller and decides. What we will do is tell them in writing, before launch, which cookies fall inside the strictly necessary exemption and which do not, and decline to describe a non-essential cookie as essential in their banner.
10Changes, questions and complaints
If anything that stores information on your device is added beyond what is listed here, this page and its effective date change before it goes live, and consent is collected where regulation 6 requires it.
Questions go to [email protected] and are answered within five working days; a data protection request within one month.
If our answer does not satisfy you, complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk.
TRYGG HEALTH LTD, company number 17061747.