This is a comprehensive UK and EU-oriented website template, not a substitute for advice from a solicitor or data-protection professional. Replace every highlighted field with the company’s real legal name, company number, registered office, privacy email and service-specific information before launch.
Overview
This policy explains how SecureFlowGroup uses cookies and similar storage or access technologies, including local storage, pixels, SDKs and device identifiers. It should be read with the Privacy Policy.
In the United Kingdom, cookie use is governed principally by the Privacy and Electronic Communications Regulations as amended, together with the UK GDPR and Data Protection Act 2018. For EEA users, the EU GDPR and national laws implementing the ePrivacy rules may also apply.
Current site status
The current static website build does not intentionally set analytics or advertising cookies. Front-end demo forms do not create real accounts or store submissions. When authentication, analytics, payment, chat or marketing services are connected, this policy, the consent banner and the cookie register must be updated before those tools go live.
Strictly necessary technologies may later be used for account security, load balancing, consent records, fraud prevention, session continuity and user-requested features. These may not require consent where the legal exemption applies, but clear information must still be provided.
Cookie categories
Strictly necessary
Required to deliver a requested service, secure accounts, maintain sessions, prevent fraud or remember privacy choices. These cannot normally be switched off through the consent tool.
Preferences
Remember optional choices such as language, region, accessibility or display settings. Consent is requested where required.
Analytics
Help understand visits, performance and errors. Non-essential analytics will remain off until consent is given where consent is required.
Marketing
Measure campaigns or build advertising audiences. SecureFlowGroup will not set these without valid consent and a clear ability to refuse.
Consent and choices
Where consent is required, non-essential technologies must be off by default. The consent request must be clear, specific and separate from general terms. Accept and reject choices should be equally accessible, and consent can be withdrawn as easily as it was given.
Withdrawing consent does not affect processing that was lawful before withdrawal. A consent record may be retained to remember and demonstrate the choice. Low-risk exemptions introduced by amended UK law will only be used where the statutory conditions are met and users receive clear information and an appropriate way to object where required.
Cookie register
| Name or provider | Purpose | Category | Typical duration |
|---|---|---|---|
| SecureFlowGroup consent preference | Stores the user’s cookie choices when a production consent manager is enabled. | Strictly necessary | [CONFIRM DURATION] |
| Authentication provider | Maintains secure login, protects against request forgery and supports multi-factor authentication. | Strictly necessary | [ADD PROVIDER AND DURATION] |
| Payment provider | Processes checkout, fraud checks and payment-session continuity. | Strictly necessary | [ADD PROVIDER AND DURATION] |
| Analytics provider | Optional measurement of site use and performance. | Analytics | [ADD ONLY IF ENABLED] |
| Marketing provider | Optional campaign measurement or audience activity. | Marketing | [ADD ONLY IF ENABLED] |
The live cookie scanner and consent manager should be used to verify this register before release and after every new integration.
Third-party services
Embedded videos, identity providers, support chat, payment services, fonts, maps or social features may store or access information on a device. SecureFlowGroup must configure those services so non-essential technology does not load before the required consent.
Third parties may act as independent controllers for some processing. Their privacy information should be linked from the live consent panel where relevant.
Retention
Session cookies normally expire when the browser closes. Persistent cookies expire after the period shown in the live cookie register. Durations must be proportionate to the purpose and reviewed regularly. Consent should be refreshed where required by law or where purposes materially change.
Browser and device controls
Users can delete or block cookies through browser settings, although blocking strictly necessary technology may prevent login or other requested features. Privacy controls such as Global Privacy Control or “Do Not Track” may be honoured where legally required or technically supported, but they do not replace a valid consent mechanism where one is required.
Updates
This policy will be updated when technologies, providers or laws change. The consent panel should always provide the most current list of active technologies and purposes.
Contact
Questions about cookies or consent can be sent to [PRIVACY EMAIL] or through the contact page.