Version 24 September 2026
1.1 In this Cookie Policy the following terms have the following meanings. Capitalised terms not defined here have the meanings given in the Privacy Policy.
1.2 Headings are for convenience only. "Including" does not limit the words that precede it.
2.1 This Cookie Policy describes every Item that the Site and the Service place in or read from a User's browser, and forms part of the Privacy Policy.
2.2 All Items are first-party Items placed by the Site or the Service itself. No third party places or reads any Item through the Site or the Service. The Site and the Service do not load scripts, fonts, images, frames or other resources from any third party, and do not use pixels, web beacons of third parties, device fingerprinting or cross-site tracking.
2.3 No Item is used for advertising, profiling or the sale or sharing of Personal Data.
3.1 Strictly Necessary Items are placed without consent because they are strictly necessary to provide a service expressly requested by the User, or to protect its security. They cannot be switched off through the Site; a User may block them in the browser, in which case the functions that depend on them are not available.
3.2 Functional Items are held only in the User's browser, are not transmitted to the Company, and last no longer than the visit. They are placed without consent because they record a choice made by the User, or serve a function invoked by the User, within that visit. Functional Items that persist beyond the visit are placed only with consent.
3.3 Usage Measurement Items are placed only after the User accepts Usage Measurement on the Consent Notice, and are deleted when the User refuses or withdraws acceptance.
3.4 The placing and reading of Items is governed, where applicable, by Article 5(3) of Directive 2002/58/EC as implemented in the Member States of the European Economic Area, by regulation 6 of and Schedule A1 to the Privacy and Electronic Communications (EC Directive) Regulations 2003 of the United Kingdom, and by other applicable law. Personal Data obtained through Items is processed as described in the Privacy Policy.
| Name | Category | Placed by | Content | Purpose | Duration |
|---|---|---|---|---|---|
ls_consent | Strictly Necessary | The page script, when a choice is made on the Consent Notice | The choice made (accepted or refused) and the version of the Consent Notice shown | To record the choice so that the Consent Notice is not displayed again and the choice is applied | 6 months |
ls_id | Usage Measurement | The page script, after acceptance | A random identifier generated in the browser | To distinguish a returning visit from a first visit | 12 months, or until acceptance is withdrawn |
ls_s | Usage Measurement | The page script, after acceptance | A random identifier for the visit | To relate the pages of one visit to each other | Until the browser is closed, or until acceptance is withdrawn |
ls_acct | Strictly Necessary | The Company's server, on sign-in | A random token standing for the sign-in session | To keep the Authorised User signed in to the Account | Until the browser is closed; where the User ticks "Keep me signed in for 30 days" at sign-in, 30 days from sign-in. In either case, until sign-out or the end of the session on the server, whichever is earlier |
ls_code | Strictly Necessary | The Company's server, when a sign-in code is requested | A random identifier standing for the request for a sign-in code | To ensure that a sign-in code can be used only in the browser that requested it | 1 hour, or until sign-in or sign-out |
ls_dev | Strictly Necessary | The Company's server, on sign-in | A random identifier standing for the browser | To recognise a browser from which the Account has been accessed, so that it is not locked out by code requests made by others, and to detect sign-ins from unfamiliar browsers | 180 days, or until "Sign out everywhere" or deletion of the Account in that browser; the server ceases to recognise it earlier where a password is set, changed or removed from another browser |
4.1.1 The "Keep me signed in for 30 days" box is not ticked by default.
4.1.2 Cookies placed by the Company's server are marked HttpOnly and SameSite=Strict, are stored by the server only in hashed form, and are marked Secure on the Public Service. ls_code and ls_dev are returned by the browser only to the sign-in addresses of the Service. Cookies placed by the page script are marked SameSite=Lax and, on the Public Service, Secure. Requests to the Public Service over an unencrypted connection are redirected to an encrypted connection before any Cookie is placed. Non-Public Environments may be accessed without encryption, in which case the Secure attribute is not set.
| Key | Storage | Category | Content | Purpose | Duration |
|---|---|---|---|---|---|
acct_draft | Session storage | Strictly Necessary | The email address and the state of the acceptance box entered in the sign-in form | To preserve the sign-in form when the User leaves it to read the Terms or the Privacy Policy and returns | Until sign-in, or until the tab is closed |
acct_wait | Session storage | Strictly Necessary | The email address to which a sign-in code was sent, and the state of the acceptance box | To keep the code entry field available after the page is reloaded | Until sign-in, or until the tab is closed |
acct_nudge | Session storage | Functional | An indicator that the invitation to open an Account was closed | Not to display the invitation again during the visit | Until the tab is closed |
geo_open | Session storage | Functional | An indicator of whether a panel was left open | To restore the panel on return to the page | Until the tab is closed |
back_from | Session storage | Functional | The address of the calculation page from which the User opened a document page | To return the User to that calculation | Until the tab is closed |
4.2.1 Entries in Browser Storage are not transmitted to the Company. No entry is placed in local storage.
4.3.1 Non-Public Environments are protected by access credentials. Where a User enters them, the browser retains them in accordance with its own settings. The Company does not place or read them other than for access control.
5.1 The Consent Notice offers acceptance and refusal of Usage Measurement as options of equal prominence. No Usage Measurement Item is placed and no Measurement Data is collected before acceptance.
5.2 A browser that transmits a Global Privacy Control or Do Not Track signal is treated as having refused Usage Measurement. The Consent Notice is not displayed to it as a request.
5.3 A User may change or withdraw the choice at any time through the link displayed at the foot of every page of the Site. Refusal or withdrawal deletes ls_id and ls_s immediately and causes the deletion of the Measurement Data recorded under the Visitor Identifier. Withdrawal does not affect the lawfulness of processing carried out before it.
5.4 The Company keeps a Consent Record of each choice for 1,100 days, as described in the Privacy Policy. On withdrawal the Visitor Identifier is removed from the Consent Record.
6.1 A User may delete Items and block their placement through the settings of the browser. Blocking Strictly Necessary Items prevents sign-in and the use of Accounts. Clearing the Site's data removes all Items, including the record of the choice on the Consent Notice.
6.2 A User may object to Functional Items by closing the tab, by clearing the Site's data or by writing to the Contact Email.
7.1 The Company may amend this Cookie Policy at any time. The version and effective date appear at the top of this Cookie Policy. Where the Company introduces an Item of a new category or for a new purpose that requires consent, consent is requested before that Item is placed.
8.1 Pallarium, hello@pallarium.com; before its incorporation, the founder of Pallarium. Contact Email: [CONTACT EMAIL = hello@pallarium.com].