Cookie policy
Effective date: 19 August 2026.
1.1 This policy explains how RENDUS LTD, 37 Sandy Lane, WOKINGHAM, RG41 4SS United Kingdom, uses cookies and comparable local-storage or pixel technologies on https://rendus.help. It should be read with our privacy notice. Questions may be sent in plain text to about@rendus.help or raised by telephone on +44 7399 888999.
1.2 The site is aimed principally at organisations seeking database design, management and related IT services. This policy nevertheless applies to every visitor. We follow the Privacy and Electronic Communications Regulations 2003 and the UK GDPR: non-essential technologies are not placed or read before valid consent, while strictly necessary technologies are limited to functions the visitor requests or that are essential to secure delivery.
2. What cookies are
2.1 A cookie is a small text record stored by a browser and returned to the relevant service on later requests. Similar technologies can store identifiers in local storage, use pixels to report that a resource loaded, or retain a consent state. The legal treatment depends on the act of storing or accessing terminal-equipment information, not merely on the technology's marketing label.
2.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
2.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
3. Strictly necessary technologies
3.1 These technologies support requested page delivery, load balancing, security, fraud resistance and storage of privacy choices. They are not used to build advertising profiles. Consent is not required where the PECR exemption applies, but we still describe their purpose, limit their duration and avoid combining their output with unrelated datasets.
3.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
3.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
4. Preference technologies
4.1 Preference storage remembers optional interface choices such as display or region settings. It is activated only after consent unless the selected function cannot be delivered without remembering the choice. Rejecting it may require the visitor to select the preference again, but must not prevent access to ordinary public content.
4.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
4.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
5. Analytics technologies
5.1 Analytics help us understand page performance, navigation patterns, approximate visitor numbers and technical errors. Optional analytics are disabled until consent. Where enabled, we configure data minimisation, short retention and IP or identifier controls where the chosen service supports them, and we use reports to improve site reliability rather than identify named individuals.
5.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
5.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
6. Marketing and social technologies
6.1 The site does not assume that marketing trackers are necessary merely because they support outreach. Any technology used to measure campaigns, recognise a visitor across services, create an interest profile or enable social-network tracking belongs in a non-essential category and requires a clear affirmative choice before activation.
6.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
6.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
7. First and third parties
7.1 A first-party cookie is set in the context of our site; a third-party service may set or receive information through embedded functionality. Classification does not determine whether consent is needed. We assess the actual purpose, recipient and access. A supplier may act as our processor, joint controller or independent controller depending on its contractual freedom and use.
7.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
7.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
8. Consent mechanism
8.1 On a visitor's first relevant visit, the consent interface offers a genuine choice between accepting and rejecting non-essential categories. Optional switches default to off. The interface does not treat scrolling, continued browsing or silence as consent, does not bundle unrelated purposes and provides enough information for a specific, informed decision.
8.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
8.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
9. Changing or withdrawing consent
9.1 A visitor may revisit cookie settings through the site's privacy controls and withdraw a category as easily as it was accepted. Withdrawal stops future optional storage or access; it cannot retrospectively erase measurements already lawfully produced. We keep a limited consent record to demonstrate the choice and honour the current state.
9.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
9.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
10. Cookie duration
10.1 Session technologies expire when the browser session ends, subject to browser behaviour. Persistent technologies remain until their stated expiry or deletion. We choose the shortest duration consistent with purpose, review vendor defaults rather than accepting them automatically, and refresh consent where the purpose materially changes or the existing choice is no longer reliable.
10.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
10.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
11. Browser controls
11.1 Browsers commonly permit blocking, deletion and restriction of cookies, including third-party cookies. Those controls operate independently of our consent interface and may remove the saved choice, causing the banner to reappear. Blocking strictly necessary security or session functions can affect operation, but refusal of optional analytics or marketing must not deny equivalent access to public information.
11.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
11.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
12. Information produced by cookies
12.1 Cookie-related data can include a random identifier, consent status, timestamps, IP address, user agent, page path, referrer, event label, device characteristics and approximate location. We do not ask optional analytics to capture form text, passwords, database credentials or confidential client content. Technical identifiers may be personal data even where we do not know the visitor's name.
12.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
12.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
13. Lawful basis under UK GDPR
13.1 For optional terminal access, consent under PECR is also the UK GDPR basis for associated personal-data processing where required. For strictly necessary security and delivery records, our basis is usually legitimate interests in operating a secure service, subject to balancing. Contract necessity applies only where processing is objectively needed for a requested contractual function.
13.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
13.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
14. Transfers and suppliers
14.1 Before deploying a third-party tag, we assess its documentation, data uses, contractual protections, retention and transfer route. Restricted transfers may rely on UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum, supported by a transfer risk assessment and supplementary controls. Consent to cookies is not treated as a blanket international-transfer waiver.
14.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
14.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
15. Auditing the site
15.1 We periodically scan and manually test the site to identify storage, pixels and network requests. Changes in content management, hosting, embedded media or vendor scripts can introduce new technologies, so deployment review includes consent classification. Unknown or unjustified trackers are disabled pending investigation rather than silently assigned to a convenient category.
15.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
15.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
16. Updates and contact
16.1 We update this policy when technologies, providers, purposes or legal requirements change and show the effective date. Material changes may trigger renewed choice. For questions or concerns contact RENDUS LTD at 37 Sandy Lane, WOKINGHAM, RG41 4SS United Kingdom, email about@rendus.help, telephone +44 7399 888999. A privacy complaint may also be raised with the Information Commissioner's Office.
16.2 Our implementation follows a documented classification. The relevant entry identifies the provider, precise purpose, information involved, recipient, duration and category. If a technology serves several purposes, it is controlled according to the least optional exemption available and is not activated merely because one subsidiary function might be necessary.
16.3 We review the setting when code, provider behaviour or purpose changes. Evidence includes consent configuration, observed network requests, storage duration and supplier terms. A technology that cannot be accurately explained or reliably controlled is withheld until the issue is resolved.
17. Current cookie register
17.1 The current site is designed to operate with a minimal technology footprint. Strictly necessary consent storage may remember whether the visitor accepted or rejected optional categories and the policy version presented. Security and hosting infrastructure may use short-lived request-routing or abuse-prevention values where essential. Exact names can vary after a secure infrastructure update, so purpose and provider are the controlling descriptions.
- Consent state: first-party, strictly necessary, used to remember category choices and policy version; retained only for the period needed to avoid repeatedly asking and to demonstrate consent.
- Security or routing value: first-party or hosting-provider, strictly necessary, used to distribute requests, resist automated abuse or maintain a requested session; normally session-based or short-lived.
- Optional analytics identifier: only present if the visitor opts in and if analytics are deployed; used for aggregated visit and performance measurement; duration is displayed in the consent interface before activation.
- Optional campaign measurement: only present if separately disclosed and accepted; used to attribute a visit to an outreach campaign, not to access client systems or service-delivery data.
18. Embedded content
18.1 Maps, videos, code demonstrations, scheduling widgets and social media components may contact an external provider. We use click-to-load or equivalent controls where the provider would otherwise store or read non-essential data immediately. The visitor is told which provider will receive the request before choosing to activate the content.
18.2 Any deployment decision records necessity, proportionality and less intrusive alternatives. The technology is removed or reclassified when its purpose ends, a supplier changes its practices, or testing shows that the consent control cannot reliably govern it.