Cookies

Contents
  1. 1. Definitions and Interpretation
  2. 2. Scope
  3. 3. Categories and Legal Basis
  4. 4. Items
    1. 4.1 Cookies
    2. 4.2 Browser Storage
    3. 4.3 Access Credentials for Non-Public Environments
  5. 5. Consent Notice
  6. 6. Control by the User
  7. 7. Changes
  8. 8. Contact

Version 24 September 2026

1. Definitions and Interpretation

1.1 In this Cookie Policy the following terms have the following meanings. Capitalised terms not defined here have the meanings given in the Privacy Policy.

  • "Browser Storage" means the session storage and local storage facilities of a web browser.
  • "Company", "we" and "us" mean Pallarium, a prototype service run before incorporation by its founder, and, before its incorporation, its founder, as provided in Section 3.5 of the Privacy Policy.
  • "Consent Notice" means the notice displayed on the Site by which a Visitor accepts or refuses Usage Measurement.
  • "Contact Email" means [CONTACT EMAIL = hello@pallarium.com].
  • "Cookie" means a small text file placed in a User's browser by a website and returned to it with subsequent requests.
  • "Functional Item" means an Item used to preserve the state of the interface of the Site or the Service within a visit.
  • "Item" means a Cookie or an entry in Browser Storage placed or read by the Site or the Service.
  • "Privacy Policy" means the Company's Privacy Policy published on the Site.
  • "Public Service" means the Site and the Service other than any Non-Public Environment.
  • "Site" means the website at pallarium.com, its subdomains and any successor or additional domain operated by the Company for the Service.
  • "Strictly Necessary Item" means an Item without which a function of the Site or the Service expressly requested by the User cannot be provided, or which is required for the security of that function.
  • "Usage Measurement Item" means an Item used for Usage Measurement.
  • "Usage Measurement" means the measurement of the use of the Site and the Service carried out by the Company after a Visitor accepts it on the Consent Notice, as described in Annex A of the Privacy Policy.
  • "User" means any person who accesses the Site or the Service.

1.2 Headings are for convenience only. "Including" does not limit the words that precede it.

2. Scope

2.1 This Cookie Policy describes every Item that the Site and the Service place in or read from a User's browser, and forms part of the Privacy Policy.

2.2 All Items are first-party Items placed by the Site or the Service itself. No third party places or reads any Item through the Site or the Service. The Site and the Service do not load scripts, fonts, images, frames or other resources from any third party, and do not use pixels, web beacons of third parties, device fingerprinting or cross-site tracking.

2.3 No Item is used for advertising, profiling or the sale or sharing of Personal Data.

3.1 Strictly Necessary Items are placed without consent because they are strictly necessary to provide a service expressly requested by the User, or to protect its security. They cannot be switched off through the Site; a User may block them in the browser, in which case the functions that depend on them are not available.

3.2 Functional Items are held only in the User's browser, are not transmitted to the Company, and last no longer than the visit. They are placed without consent because they record a choice made by the User, or serve a function invoked by the User, within that visit. Functional Items that persist beyond the visit are placed only with consent.

3.3 Usage Measurement Items are placed only after the User accepts Usage Measurement on the Consent Notice, and are deleted when the User refuses or withdraws acceptance.

3.4 The placing and reading of Items is governed, where applicable, by Article 5(3) of Directive 2002/58/EC as implemented in the Member States of the European Economic Area, by regulation 6 of and Schedule A1 to the Privacy and Electronic Communications (EC Directive) Regulations 2003 of the United Kingdom, and by other applicable law. Personal Data obtained through Items is processed as described in the Privacy Policy.

4. Items

4.1 Cookies
NameCategoryPlaced byContentPurposeDuration
ls_consentStrictly NecessaryThe page script, when a choice is made on the Consent NoticeThe choice made (accepted or refused) and the version of the Consent Notice shownTo record the choice so that the Consent Notice is not displayed again and the choice is applied6 months
ls_idUsage MeasurementThe page script, after acceptanceA random identifier generated in the browserTo distinguish a returning visit from a first visit12 months, or until acceptance is withdrawn
ls_sUsage MeasurementThe page script, after acceptanceA random identifier for the visitTo relate the pages of one visit to each otherUntil the browser is closed, or until acceptance is withdrawn
ls_acctStrictly NecessaryThe Company's server, on sign-inA random token standing for the sign-in sessionTo keep the Authorised User signed in to the AccountUntil the browser is closed; where the User ticks "Keep me signed in for 30 days" at sign-in, 30 days from sign-in. In either case, until sign-out or the end of the session on the server, whichever is earlier
ls_codeStrictly NecessaryThe Company's server, when a sign-in code is requestedA random identifier standing for the request for a sign-in codeTo ensure that a sign-in code can be used only in the browser that requested it1 hour, or until sign-in or sign-out
ls_devStrictly NecessaryThe Company's server, on sign-inA random identifier standing for the browserTo recognise a browser from which the Account has been accessed, so that it is not locked out by code requests made by others, and to detect sign-ins from unfamiliar browsers180 days, or until "Sign out everywhere" or deletion of the Account in that browser; the server ceases to recognise it earlier where a password is set, changed or removed from another browser

4.1.1 The "Keep me signed in for 30 days" box is not ticked by default.

4.1.2 Cookies placed by the Company's server are marked HttpOnly and SameSite=Strict, are stored by the server only in hashed form, and are marked Secure on the Public Service. ls_code and ls_dev are returned by the browser only to the sign-in addresses of the Service. Cookies placed by the page script are marked SameSite=Lax and, on the Public Service, Secure. Requests to the Public Service over an unencrypted connection are redirected to an encrypted connection before any Cookie is placed. Non-Public Environments may be accessed without encryption, in which case the Secure attribute is not set.

4.2 Browser Storage
KeyStorageCategoryContentPurposeDuration
acct_draftSession storageStrictly NecessaryThe email address and the state of the acceptance box entered in the sign-in formTo preserve the sign-in form when the User leaves it to read the Terms or the Privacy Policy and returnsUntil sign-in, or until the tab is closed
acct_waitSession storageStrictly NecessaryThe email address to which a sign-in code was sent, and the state of the acceptance boxTo keep the code entry field available after the page is reloadedUntil sign-in, or until the tab is closed
acct_nudgeSession storageFunctionalAn indicator that the invitation to open an Account was closedNot to display the invitation again during the visitUntil the tab is closed
geo_openSession storageFunctionalAn indicator of whether a panel was left openTo restore the panel on return to the pageUntil the tab is closed
back_fromSession storageFunctionalThe address of the calculation page from which the User opened a document pageTo return the User to that calculationUntil the tab is closed

4.2.1 Entries in Browser Storage are not transmitted to the Company. No entry is placed in local storage.

4.3 Access Credentials for Non-Public Environments

4.3.1 Non-Public Environments are protected by access credentials. Where a User enters them, the browser retains them in accordance with its own settings. The Company does not place or read them other than for access control.

5.1 The Consent Notice offers acceptance and refusal of Usage Measurement as options of equal prominence. No Usage Measurement Item is placed and no Measurement Data is collected before acceptance.

5.2 A browser that transmits a Global Privacy Control or Do Not Track signal is treated as having refused Usage Measurement. The Consent Notice is not displayed to it as a request.

5.3 A User may change or withdraw the choice at any time through the link displayed at the foot of every page of the Site. Refusal or withdrawal deletes ls_id and ls_s immediately and causes the deletion of the Measurement Data recorded under the Visitor Identifier. Withdrawal does not affect the lawfulness of processing carried out before it.

5.4 The Company keeps a Consent Record of each choice for 1,100 days, as described in the Privacy Policy. On withdrawal the Visitor Identifier is removed from the Consent Record.

6. Control by the User

6.1 A User may delete Items and block their placement through the settings of the browser. Blocking Strictly Necessary Items prevents sign-in and the use of Accounts. Clearing the Site's data removes all Items, including the record of the choice on the Consent Notice.

6.2 A User may object to Functional Items by closing the tab, by clearing the Site's data or by writing to the Contact Email.

7. Changes

7.1 The Company may amend this Cookie Policy at any time. The version and effective date appear at the top of this Cookie Policy. Where the Company introduces an Item of a new category or for a new purpose that requires consent, consent is requested before that Item is placed.

8. Contact

8.1 Pallarium, hello@pallarium.com; before its incorporation, the founder of Pallarium. Contact Email: [CONTACT EMAIL = hello@pallarium.com].