The full cookie policy for Family Restore Ltd. Twelve short clauses, most of which explain what is not happening.
About this policy
This policy explains what Family Restore Ltd stores on your device when you visit this website, what it does not store, and what would have to happen before that changed. It sits alongside our privacy notice, which covers everything else the practice holds about you.
It describes the site as built and as last reviewed. If you find anything on this website that contradicts it, please tell us — that would be a fault, not a footnote.
What cookies and similar technologies are
A cookie is a small text file that a website asks your browser to keep and hand back on the next visit. Cookies are not programs and cannot read the rest of your computer. What makes them significant is memory: a cookie is how a site recognises the same browser twice.
The law does not only cover cookies. It covers anything that stores information on your device or reads information already there, which includes:
- local storage and session storage — larger stores built into your browser;
- tracking pixels and web beacons — a tiny image whose only purpose is to report that it was loaded;
- device fingerprinting — identifying a browser from the combination of its settings, fonts and screen size, without storing anything at all;
- software development kits and tags embedded in a page by a third party.
This site uses none of them. Where this policy says “cookies”, it means all of the above.
What this website sets today
Nothing. At the time of the last review, loading any page on this site set no cookies and wrote nothing to local or session storage.
That is not an accident of configuration; it is how the site was built:
- the pages are static HTML, generated ahead of time, with no user session to keep;
- both typefaces are self-hosted and served from this domain, so nothing is requested from an external font service;
- there is no analytics package, no tag manager, no advertising pixel and no chat widget;
- the site’s content security policy blocks connections to other origins outright, so a third-party script could not load even if one were added by mistake.
You can check this yourself. Open your browser’s developer tools, look under Application or Storage, and you should find this site listed with nothing under it.
Strictly necessary cookies, and why they need no consent
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 — usually called PECR — says that storing information on someone’s device requires their consent, with two narrow exceptions: where the storage is solely to carry out a transmission, or where it is strictly necessary to provide a service the user has actually asked for.
“Strictly necessary” is a high bar. It covers the cookie that keeps items in a shopping basket, or the one that stops a contact form being submitted a thousand times by a robot. It does not cover analytics, however useful the practice might find them, and it does not cover anything to do with advertising.
If a strictly necessary cookie is ever added to this site — most likely in connection with the enquiry or booking form — it will be listed here by name, with its purpose and its lifetime, before it goes live. It still would not need your consent, but you would still be entitled to know about it, and we would rather over-explain.
What the law requires
Two pieces of law apply, and they work together.
PECR governs the act of storing or reading anything on your device. It applies whether or not the information is personal data. Consent must come first: the cookie may not be set while you are deciding.
The UK GDPR supplies the standard that consent has to meet. Consent must be freely given, specific, informed and unambiguous, and given by a clear affirmative action. In practice that means:
- no pre-ticked boxes, and no consent implied from scrolling;
- refusing must be as easy as accepting — a prominent “accept all” button with a “reject” option hidden two screens deep does not meet the standard;
- separate categories must be separately refusable, rather than bundled together;
- withdrawing consent must be as easy as giving it, and the site must keep working afterwards;
- a record of what was consented to, and when, must be kept.
The Information Commissioner's Office enforces both. Its guidance for organisations, and its plain-English guidance for the public, are at ico.org.uk.
Third-party content, fonts and embeds
Most cookie problems on small websites are not caused by the site owner. They are caused by convenience: an embedded map, a video, a font service, a social feed. Each one is a request to another company’s server, and each one tells that company that you visited this page.
On a therapy website that matters more than usual. So:
- typefaces are downloaded at build time and served from this domain;
- there is no embedded map. Directions are written out on the contact page instead;
- there are no embedded videos and no social media feeds;
- every image is served from this domain — there are no images hotlinked from elsewhere;
- there is no live-chat widget, no review-collection script and no booking iframe.
If a third-party service is ever genuinely needed — an online payment page is the most likely candidate — we will name it here, explain what it can see, and only load it at the point you choose to use it.
Server logs are not cookies
Every web server keeps a log of the requests it answers. When your browser asks our host for a page, that request is recorded with your IP address, the time, the page requested, and the browser you used.
These logs are not cookies. Nothing is stored on your device and no consent is required for them, because they are a by-product of transmitting the page you asked for. We rely on legitimate interests under Article 6(1)(f) of the UK GDPR to keep them, for one reason: to keep the site available and to investigate attacks on it.
They are not used to measure traffic, build a profile, or work out who you are. They are retained for [confirm log retention with hosting provider] and then discarded.
What would change if we added analytics
We may one day want to know which pages are actually read — it would make the site more useful. If that happens, here is what we commit to, in order.
- Consider a measurement method that needs no consent first. Aggregated, cookie-free, server-side measurement that does not identify individuals is preferable to a tracking script, and it is what we would try before anything else.
- Ask before, not after. Any analytics that stores or reads anything on your device would be blocked until you had actively agreed. Nothing would run while a banner was on screen.
- Make refusing as easy as agreeing. Equal prominence, one click either way, and no dark patterns.
- Publish the detail here. The provider, what it sets, how long each cookie lasts, where the data is held, and how to change your mind — updated on the same day the change goes live, not afterwards.
- Keep the site working either way. Refusing would never remove content, degrade the site, or trigger a second request later in the visit.
Until all of that is true, there is no banner on this site because there is nothing to ask you about.
Controlling cookies in your browser
Whatever a website does, your browser is the final say. Every modern browser lets you see what has been stored, delete it, and block categories of cookie in future. Menu names move between versions, so the routes below are described by what to look for rather than by exact wording.
- Chrome: Settings, then Privacy and security. Look for third-party cookie controls and “Delete browsing data”.
- Safari on Mac: Safari menu, then Settings, then the Privacy tab. “Manage Website Data” lists what is stored.
- Safari on iPhone or iPad: the Settings app, then Apps, then Safari, where you will find tracking prevention and “Clear History and Website Data”.
- Firefox: Settings, then Privacy & Security. Enhanced Tracking Protection and Cookies and Site Data are both there.
- Edge: Settings, then Cookies and site permissions, and separately Privacy, search and services.
Blocking cookies entirely will break a great many websites — anything you log in to, in particular. It will not break this one, because this one does not use any.
Private or incognito windows are also worth knowing about: they discard cookies and history when the window closes, which is genuinely useful if you are reading about therapy on a shared computer. They do not hide your visit from your internet provider or from an employer’s network.
Do Not Track and Global Privacy Control
Some browsers send a “Do Not Track” header, and some send a Global Privacy Control signal, asking sites not to track or sell your information. There is no settled UK law obliging a website to obey either, and many sites ignore them.
We have nothing to switch off, so the question does not arise here. If analytics were ever added, a Global Privacy Control signal would be treated as an objection and honoured without asking again.
Changes to this policy
This policy is reviewed at least once a year, and immediately whenever anything is added to the site that could store or read information on a visitor’s device. The date at the top of the page is the date of the current version.
A change that introduced any non-essential storage would be published here before it took effect, not after.
Questions and complaints
Ask us anything about this policy using the details at the foot of the page. If you think this site is doing something it should not, we would genuinely like to know: tell us, and we will check it the same week.
You can also complain directly to the Information Commissioner's Office, which regulates both PECR and the UK GDPR. Call 0303 123 1113 or visit ico.org.uk. You do not need to come to us first, and it costs nothing.



