Legal and policy

Cookie Policy

A short policy, because there is very little to describe. This website sets no cookies, loads nothing from anyone else's servers, and does not measure your visit. Here is what that means, and how to check it.

Last updated
Next review
Version
0.9 (draft for review)
A small side table by a window holding a closed laptop and a cup of tea, with rain on the glass outside.

Plain English

The short version

This is the rare policy that gets shorter the more honest it becomes. Here is the whole of it in six lines.

  • This site sets no cookies

    Not for analytics, not for advertising, not for remembering you. At the last review, a visit to this website left nothing stored on your device.

  • Nothing is loaded from anywhere else

    No CDN, no Google Fonts, no embedded maps or videos, no social buttons, no chat widget. Every file comes from this domain.

  • There is no consent banner

    Because there is nothing to consent to. A banner that asks permission for cookies that do not exist is theatre, and we would rather not perform it.

  • Your visit is not measured

    We have no visitor counts, no heat maps, no session recordings and no idea which page you read. That is a deliberate trade, and we accept the cost of it.

  • Server logs still exist

    Our hosting provider records the technical requests your browser makes, as every web server does. Those are not cookies and they are not used to profile you.

  • If that ever changes, we will say so first

    Analytics would require your prior consent under PECR. We would publish the change here, and ask properly, before anything was set.

If you find anything on this site that contradicts this page, that is a fault in the site and we want to hear about it.

Current status

What is actually stored on your device

Cookie policies usually list what a site does. This one is mostly a list of what it does not, so here is the same information as a table you can check against your own browser.

Cookies set by this site

None

No analytics, no preferences, no advertising, no session cookies.

Requests to other companies

None

Fonts, images, styles and scripts are all served from this domain.

Consent banners needed

None

There is nothing here that the law requires us to ask you about.

Cookie categories, whether each is used on this website, and whether consent would be required
CategoryIn use on this siteConsent requiredWhat it would do if we used it
Strictly necessaryNone at presentNo — exempt under PECRKeep a form submission working, or protect a form from automated abuse.
PreferencesNoneYesRemember a setting you had chosen, such as a text size or a dismissed notice.
Analytics and statisticsNoneYesCount visits, measure which pages are read, and record how far people scroll.
Marketing and advertisingNoneYesRecognise you across other websites in order to target advertising.
Third-party embedsNoneYesLoad a map, video or social post from another company's servers, which lets that company see your visit.

The three stat blocks above are the state of the site at the last review. The detail, and how to verify it yourself, is in the policy below.

The full cookie policy for Family Restore Ltd. Twelve short clauses, most of which explain what is not happening.

About this policy

This policy explains what Family Restore Ltd stores on your device when you visit this website, what it does not store, and what would have to happen before that changed. It sits alongside our privacy notice, which covers everything else the practice holds about you.

It describes the site as built and as last reviewed. If you find anything on this website that contradicts it, please tell us — that would be a fault, not a footnote.

What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to keep and hand back on the next visit. Cookies are not programs and cannot read the rest of your computer. What makes them significant is memory: a cookie is how a site recognises the same browser twice.

The law does not only cover cookies. It covers anything that stores information on your device or reads information already there, which includes:

  • local storage and session storage — larger stores built into your browser;
  • tracking pixels and web beacons — a tiny image whose only purpose is to report that it was loaded;
  • device fingerprinting — identifying a browser from the combination of its settings, fonts and screen size, without storing anything at all;
  • software development kits and tags embedded in a page by a third party.

This site uses none of them. Where this policy says “cookies”, it means all of the above.

What this website sets today

Nothing. At the time of the last review, loading any page on this site set no cookies and wrote nothing to local or session storage.

That is not an accident of configuration; it is how the site was built:

  • the pages are static HTML, generated ahead of time, with no user session to keep;
  • both typefaces are self-hosted and served from this domain, so nothing is requested from an external font service;
  • there is no analytics package, no tag manager, no advertising pixel and no chat widget;
  • the site’s content security policy blocks connections to other origins outright, so a third-party script could not load even if one were added by mistake.

You can check this yourself. Open your browser’s developer tools, look under Application or Storage, and you should find this site listed with nothing under it.

Strictly necessary cookies, and why they need no consent

Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 — usually called PECR — says that storing information on someone’s device requires their consent, with two narrow exceptions: where the storage is solely to carry out a transmission, or where it is strictly necessary to provide a service the user has actually asked for.

“Strictly necessary” is a high bar. It covers the cookie that keeps items in a shopping basket, or the one that stops a contact form being submitted a thousand times by a robot. It does not cover analytics, however useful the practice might find them, and it does not cover anything to do with advertising.

If a strictly necessary cookie is ever added to this site — most likely in connection with the enquiry or booking form — it will be listed here by name, with its purpose and its lifetime, before it goes live. It still would not need your consent, but you would still be entitled to know about it, and we would rather over-explain.

What the law requires

Two pieces of law apply, and they work together.

PECR governs the act of storing or reading anything on your device. It applies whether or not the information is personal data. Consent must come first: the cookie may not be set while you are deciding.

The UK GDPR supplies the standard that consent has to meet. Consent must be freely given, specific, informed and unambiguous, and given by a clear affirmative action. In practice that means:

  • no pre-ticked boxes, and no consent implied from scrolling;
  • refusing must be as easy as accepting — a prominent “accept all” button with a “reject” option hidden two screens deep does not meet the standard;
  • separate categories must be separately refusable, rather than bundled together;
  • withdrawing consent must be as easy as giving it, and the site must keep working afterwards;
  • a record of what was consented to, and when, must be kept.

The Information Commissioner's Office enforces both. Its guidance for organisations, and its plain-English guidance for the public, are at ico.org.uk.

Third-party content, fonts and embeds

Most cookie problems on small websites are not caused by the site owner. They are caused by convenience: an embedded map, a video, a font service, a social feed. Each one is a request to another company’s server, and each one tells that company that you visited this page.

On a therapy website that matters more than usual. So:

  • typefaces are downloaded at build time and served from this domain;
  • there is no embedded map. Directions are written out on the contact page instead;
  • there are no embedded videos and no social media feeds;
  • every image is served from this domain — there are no images hotlinked from elsewhere;
  • there is no live-chat widget, no review-collection script and no booking iframe.

If a third-party service is ever genuinely needed — an online payment page is the most likely candidate — we will name it here, explain what it can see, and only load it at the point you choose to use it.

Server logs are not cookies

Every web server keeps a log of the requests it answers. When your browser asks our host for a page, that request is recorded with your IP address, the time, the page requested, and the browser you used.

These logs are not cookies. Nothing is stored on your device and no consent is required for them, because they are a by-product of transmitting the page you asked for. We rely on legitimate interests under Article 6(1)(f) of the UK GDPR to keep them, for one reason: to keep the site available and to investigate attacks on it.

They are not used to measure traffic, build a profile, or work out who you are. They are retained for [confirm log retention with hosting provider] and then discarded.

What would change if we added analytics

We may one day want to know which pages are actually read — it would make the site more useful. If that happens, here is what we commit to, in order.

  1. Consider a measurement method that needs no consent first. Aggregated, cookie-free, server-side measurement that does not identify individuals is preferable to a tracking script, and it is what we would try before anything else.
  2. Ask before, not after. Any analytics that stores or reads anything on your device would be blocked until you had actively agreed. Nothing would run while a banner was on screen.
  3. Make refusing as easy as agreeing. Equal prominence, one click either way, and no dark patterns.
  4. Publish the detail here. The provider, what it sets, how long each cookie lasts, where the data is held, and how to change your mind — updated on the same day the change goes live, not afterwards.
  5. Keep the site working either way. Refusing would never remove content, degrade the site, or trigger a second request later in the visit.

Until all of that is true, there is no banner on this site because there is nothing to ask you about.

Controlling cookies in your browser

Whatever a website does, your browser is the final say. Every modern browser lets you see what has been stored, delete it, and block categories of cookie in future. Menu names move between versions, so the routes below are described by what to look for rather than by exact wording.

  • Chrome: Settings, then Privacy and security. Look for third-party cookie controls and “Delete browsing data”.
  • Safari on Mac: Safari menu, then Settings, then the Privacy tab. “Manage Website Data” lists what is stored.
  • Safari on iPhone or iPad: the Settings app, then Apps, then Safari, where you will find tracking prevention and “Clear History and Website Data”.
  • Firefox: Settings, then Privacy & Security. Enhanced Tracking Protection and Cookies and Site Data are both there.
  • Edge: Settings, then Cookies and site permissions, and separately Privacy, search and services.

Blocking cookies entirely will break a great many websites — anything you log in to, in particular. It will not break this one, because this one does not use any.

Private or incognito windows are also worth knowing about: they discard cookies and history when the window closes, which is genuinely useful if you are reading about therapy on a shared computer. They do not hide your visit from your internet provider or from an employer’s network.

Do Not Track and Global Privacy Control

Some browsers send a “Do Not Track” header, and some send a Global Privacy Control signal, asking sites not to track or sell your information. There is no settled UK law obliging a website to obey either, and many sites ignore them.

We have nothing to switch off, so the question does not arise here. If analytics were ever added, a Global Privacy Control signal would be treated as an objection and honoured without asking again.

Changes to this policy

This policy is reviewed at least once a year, and immediately whenever anything is added to the site that could store or read information on a visitor’s device. The date at the top of the page is the date of the current version.

A change that introduced any non-essential storage would be published here before it took effect, not after.

Questions and complaints

Ask us anything about this policy using the details at the foot of the page. If you think this site is doing something it should not, we would genuinely like to know: tell us, and we will check it the same week.

You can also complain directly to the Information Commissioner's Office, which regulates both PECR and the UK GDPR. Call 0303 123 1113 or visit ico.org.uk. You do not need to come to us first, and it costs nothing.

A promise, not a hypothetical

If analytics are ever added

We may one day want to know which pages are read. These are the four commitments we would keep if we did, in this order.

  1. Try the consent-free option first

    Aggregated, cookie-free measurement that never identifies an individual would be preferred over any tracking script.

    Before anything is chosen

  2. Ask before anything is set

    Nothing would be stored on your device while you were still deciding. Refusing would be exactly as easy as agreeing.

    At the point of choice

  3. Publish the whole list

    Provider, cookie names, lifetimes, where the data is held, and the route to change your mind — on this page, on the day.

    Same day as the change

  4. Work perfectly if you say no

    No nagging, no second banner later in the visit, no content withheld from anyone who declines.

    Always

A person's hands resting on a laptop keyboard, the screen angled away from the camera.

In your hands

Checking and clearing cookies yourself

Your browser is the final say on what any website stores. These are the routes to the settings, described by what to look for rather than by exact menu wording, because the wording moves between versions.

  • Chrome

    Settings, then Privacy and security. Third-party cookie controls sit there, alongside “Delete browsing data” for clearing what is already stored.

  • Safari on Mac

    The Safari menu, then Settings, then the Privacy tab. “Manage Website Data” lists every site that has stored something and lets you remove it.

  • Safari on iPhone or iPad

    The Settings app, then Apps, then Safari. Tracking prevention and “Clear History and Website Data” are both on that screen.

  • Firefox

    Settings, then Privacy & Security. Enhanced Tracking Protection and Cookies and Site Data are the two sections that matter.

  • Edge

    Settings, then Cookies and site permissions for the controls, and Privacy, search and services for tracking prevention.

  • Any browser, quickly

    A private or incognito window discards cookies and history the moment you close it — the fastest option on a device you share with someone else.

Reading this on a shared device

A private or incognito window discards cookies and browsing history when you close it, which is worth knowing if you are looking at therapy websites on a computer someone else uses. It will not hide the visit from your internet provider or from a workplace network.

Blocking cookies will not break this site

Because there are none to block. Every page here is static HTML and works identically with cookies switched off entirely, with JavaScript disabled, and with an aggressive content blocker running.

A tidy desk corner with a notebook, a pencil and a small vase of dried grasses beside a window.

Get in touch

Something here look wrong?

If you spot anything on this site that stores something it should not, or contradicts this page, tell us. We would rather hear it from you than find it in a complaint.

Telephone
07395 854051
By post
Family Restore Ltd
3 Regina Road, Chelmsford, Essex [confirm full postcode]

We aim to reply within one working day. Messages are read during consulting hours only.

This is not a crisis service and no inbox here is monitored overnight. If you need help now, call 999 in an emergency, call 111 and choose the mental health option, or ring Samaritans on 116 123. More routes are listed on our urgent help page.