What we mean by “cookie”

In everyday language, “cookie” often covers HTTP cookies, HTML5 local storage, session storage, and similar client-side files. A small first-party key may remember a language, while an analytics key may help us see, in the aggregate, how a page is used. The law in many jurisdictions treats that collection as a form of access to the device, which is why we separate necessary functions from the ones you can refuse.

What we are careful not to claim

We do not use cookies to re-identify you across unrelated companies without disclosure. We do not use them to copy health, union, or similar sensitive inferences. If a future product needs that kind of processing, we will publish a separate impact summary and, where the law says so, perform a data protection impact assessment in advance. For now, the site is designed as a light brochure, workshop narrative, and contact channel.

The categories in this build

localStorage and the consent object

When you press Accept, Reject, or Save, we write a small JSON value into localStorage. It may contain booleans for analytics and marketing, a fixed true for necessary, and a flag that you have made a final selection this session. The object is not encrypted because it is not meant to store secrets, only preferences; clearing site data in your browser removes it and will cause the banner to reappear, which is intentional. If you share a device, consider using a private window when testing choices.

Third parties and subprocessors in outline

Hosting companies, content networks, and optional analytics or advertising vendors are separate controllers or processors, depending on the contract. Their files may appear as first-party (our domain) or third-party (their domain) cookies. We list the names we use in an internal record and can share a subprocessor list on request, subject to commercial confidentiality, where a legitimate interest in transparency exists. Nothing on this public page is meant to be an exhaustive inventory of every subprocessor worldwide; the commercial annex does that in context.

How long the signals last

Per-session values disappear when the browser tab ends, unless a script promotes them. Session cookies for security might last minutes. The consent file in localStorage remains until you delete it or change your mind. Analytics vendors sometimes propose default expiry; we set those as short as the tool allows, consistent with a privacy-minded profile.

Withdrawing, updating, and your browser tools

You can reopen the cookie interface through any future link we add in the footer, or through your browser, which can delete, block, or partition cookies. If you only block all storage without reading the form, a feature such as a contact form might fail. We therefore keep the “necessary” lane honest and small. Withdrawing marketing consent does not undo lawful processing that already happened, but it stops new marketing tags the next time you load a page, subject to cache behaviour.

Contact and policy updates

Questions or objections about the practical effect of a cookie, or a vendor change that matters to you, can go to the studio using the same coordinates as the privacy policy. When we add a new optional category, we will refresh this page and, where appropriate, ask for a fresh consent. The dynamic hero date is not a substitute for a formal “last reviewed” line in a regulatory submission; it is a user aid only.