1. Current public website storage
Public informational pages are designed to work without advertising cookies and without optional analytics by default.
The website may use only storage actually enabled in deployment. This policy must not list analytics, advertising or profiling technology unless installed and approved.
2. Essential session storage
Where a linked or integrated application session requires browser storage, essential session data may maintain authenticated state, protect requests and keep the service functioning.
Essential storage should be limited, use appropriate cookie protections where cookies are used and expire according to the session design.
3. Authentication and device storage
Authentication or device-identifier storage may be used only when the deployed browser application actually supports account access or device-control functions.
Sensitive authentication secrets must not be placed in readable client-side storage; secure, HTTP-only and same-site protections should be used where applicable.
4. Security storage
Security-related storage may support request integrity, abuse prevention, rate limiting, session protection or fraud detection.
Security storage must not be repurposed for advertising or unrelated analytics.
5. Preference and consent storage
Preference storage may remember an implemented accessibility, language or interface choice. Consent storage may record a choice if optional technologies require consent.
The current public pages do not need a consent banner merely to display static information when no optional tracking technology is active.
6. Analytics and advertising
Analytics storage is not part of the default implementation. Advertising storage is not part of the default implementation.
Before either is introduced, the provider must be approved, this policy updated, required consent controls implemented and transfer and retention terms reviewed.
7. Managing storage
Users can control cookies through browser settings. Blocking essential storage may prevent authenticated or security-sensitive functions from operating.
The final production policy should name actual cookies or keys, purposes, providers and durations after deployment verification.
8. Updates and contact
This policy should be reviewed whenever browser storage, analytics, authentication or consent behaviour changes.
Questions should use the configured support or privacy contact method.











