Cookie Policy
Last updated: 10 May 2026
Scope of this Policy
Transparent Digital Services Limited ("we", "us" or "our") uses cookies and similar storage and access technologies when you visit our website, transparentdigitalservices.com (the "Website"), and when clients and employees access the Lupe client portal at lupe.transparentdigitalservices.com (the "Portal").
This policy explains what these technologies are, why we use them, and your rights regarding their use. It applies between you, the user, and us, Transparent Digital Services Limited, the owner and operator of these services.
This policy has been updated to reflect the requirements of the Privacy and Electronic Communications Regulations (PECR), the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA), including changes that came into force on 5 February 2026 and the ICO's finalised guidance on storage and access technologies published on 29 April 2026.
This policy should be read alongside our Privacy Policy, which can be found at: transparentdigitalservices.com/privacy-policy/
What Are Cookies and Storage Technologies?
A cookie is a small text file placed on your device when you visit a website. We also use other storage and access technologies that work similarly, including web storage (localStorage and sessionStorage), pixels, and session tokens. This policy covers all such technologies collectively.
Cookies and similar technologies serve a range of purposes, including making websites function correctly, remembering your preferences, keeping your session secure, and (where consent has been given) understanding how visitors use our services.
These technologies do not usually contain information that personally identifies you directly. However, where personal data is involved, we process it in accordance with our Privacy Policy and the UK GDPR.
Types of Cookies We Use
The following table summarises the categories of cookies and technologies used across our Website and Portal, their purpose, and the legal basis under which they are used.
| Category | Purpose | Where Used | Legal Basis |
|---|---|---|---|
| Strictly Necessary | Essential for the service to function — login sessions, security tokens, CSRF protection, session management | Website & Portal | Exempt from consent — strictly necessary under PECR |
| Security & Authentication | httpOnly session cookies for authenticated Portal users, JWT refresh tokens, 2FA state management, account lockout enforcement | Portal only | Exempt from consent — strictly necessary for service security |
| Functional / Preference | Remembering user preferences such as language or display settings | Website & Portal | Consent |
| Analytics DUAA 2025 | Aggregate, anonymised understanding of how visitors use the Website (e.g. pages visited, traffic sources). No individual profiling. | Website only | Exempt from consent under DUAA 2025 aggregate analytics exception — opt-out available |
| Targeting / Advertising | We do not currently use targeting or advertising cookies on our Website or Portal. | Not used | N/A |
Cookies Specific to the Lupe Client Portal
The Portal is a private, authenticated application accessible only to registered clients and authorised TDS employees. It uses the following specific technologies:
Session Authentication Cookies
When you log in to the Portal, we set a secure, httpOnly cookie containing your session refresh token. This cookie:
- Is strictly necessary for maintaining your authenticated session
- Cannot be read by JavaScript running in your browser, protecting it from common web attacks
- Expires automatically after 90 minutes of inactivity
- Is flagged as Secure and SameSite=Strict — only sent over HTTPS and cannot be used in cross-site requests
- Is immediately invalidated when you log out or change your password
Inactivity Timeout
For security purposes, Portal sessions expire automatically after 90 minutes of inactivity. You will be shown a notification explaining that your session has ended and prompted to log in again. This is a strictly necessary security measure and does not require your consent.
Two-Factor Authentication State
During the two-step login process, a temporary session state is maintained to track which stage of authentication you have completed. This is discarded once login is complete or abandoned and does not persist beyond your login session.
Legal Basis for Processing
Under UK PECR and UK GDPR, we rely on the following bases for our use of storage and access technologies:
Strictly necessary / exempt: Cookies that are essential to deliver the service you have requested do not require your consent under PECR. This includes login session cookies, security tokens, and Portal authentication cookies. Under the Data (Use and Access) Act 2025, aggregate analytics technologies that do not identify individuals also benefit from a consent exemption, provided users are informed and given a simple means to object.
Consent: For any non-essential cookies (such as functional preference cookies), we will ask for your consent before setting them. Consent is obtained via our cookie banner, which presents a genuine choice. You can withdraw consent at any time.
We do not use cookie walls or require acceptance of non-essential cookies as a condition of accessing our services.
Your Rights and How to Control Cookies
You have the following rights regarding cookies and storage technologies:
Withdraw Consent
You can withdraw consent for non-essential cookies at any time by clicking the "Cookie Preferences" link in the footer of our Website. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
Object to Analytics
Where we rely on the DUAA 2025 aggregate analytics exemption, you have the right to object. You can do this via our Cookie Preferences panel. We will honour your objection and stop setting those technologies on your device.
Browser Controls
Most browsers allow you to refuse or delete cookies through their settings. Please note that disabling strictly necessary cookies may prevent the Website or Portal from functioning correctly. You can find guidance on managing cookies at:
Do Not Track
Our Website currently does not respond to Do Not Track signals from browsers as there is no universally accepted standard. We rely instead on our cookie consent mechanism.
Cookie Duration and Data Retention
The table below sets out the typical lifetime of the cookies and session technologies we use:
| Technology | Duration | Notes |
|---|---|---|
| Portal session refresh token | 90 min idle / 24hr max | Deleted immediately on logout or password change |
| Portal login state (2FA) | Session only | Discarded when login completes or is abandoned |
| Preference cookies | 12 months | Renewed on each visit if consent is maintained |
| Analytics (aggregate) | Up to 13 months | Aggregated data only — no individual profiles retained |
Third-Party Technologies
Our Website and Portal do not currently embed third-party advertising or social media tracking technologies. Where we use any third-party service that sets cookies or accesses storage on your device, we will update this policy and obtain consent where required.
The Portal is hosted on DigitalOcean infrastructure in London, United Kingdom. Database services are provided by DigitalOcean's managed PostgreSQL service, also in the UK region. No Portal authentication data is processed outside the United Kingdom.
Data (Use and Access) Act 2025 — What Changed
The Data (Use and Access) Act 2025 (DUAA) received Royal Assent on 19 June 2025 and key provisions came into force on 5 February 2026. The most relevant changes for visitors to our Website are:
- Three new categories of storage and access technologies are now exempt from the requirement to obtain prior consent, where certain conditions are met. These include technologies used solely for aggregate statistical analysis (anonymised analytics) and those used to maintain the appearance of a service.
- PECR fines have increased significantly — the maximum penalty is now up to £17.5 million or 4% of global annual turnover, whichever is higher.
- Organisations must have a formal data protection complaints procedure. Details of how to raise a concern are set out in the Contact Details section below.
The ICO published its finalised guidance on storage and access technologies on 29 April 2026, which we have taken into account in updating this policy.
Changes to this Policy
Transparent Digital Services Limited reserves the right to update this cookie policy as required by law or as our use of technologies changes. Any updates will be posted on this page with a revised date at the top. Where changes are material, we will notify registered Portal users by email.
Complaints and Data Protection
If you have a concern about how we use cookies or handle your personal data, you can raise it with us directly using the contact details below. We operate a formal data protection complaints procedure and will respond within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Contact Details
The Website and Portal are operated by Transparent Digital Services Limited, incorporated in England and Wales.
Registered office: 303 The Pillbox, London, E2 6GG
Email: contact@transparentdigitalservices.com
For data protection queries specifically, please mark your correspondence: FAO Data Protection.