Legal · draft

Cookies, browser storage and consent

Document
cookie-and-consent-note
Version
cookie.draft-0
Status
Draft — not in force
Jurisdiction
Kenya

Document id: cookie-note Draft version: cookie.draft-0 Applies to: the website at {{SITE_ORIGIN}} Companion: privacy-policy.md, which governs. This note gives the detail behind its short answer on cookies.


This site sets no cookies. Not first-party, not third-party, not “strictly necessary”, not analytics, not advertising. Nothing.

It also loads nothing from anybody else: no analytics, no tag manager, no advertising pixel, no session recorder, no A/B testing tool, no chat widget, no embedded video, no embedded map, no social button, and no font or stylesheet from a content delivery network. Typefaces are served from our own site rather than fetched from a font service, which is a privacy decision as much as a performance one.

The reason there is no consent banner is not that we decided consent was unnecessary. It is that there is nothing to ask you about.

2. The one thing stored in your browser

WhatWhereValueSet whenSent to a server?Purpose
reconesys-themeYour browser’s local storage, first-partylight or darkOnly when you click the light/dark toggle yourselfNo. It is read by the page on your own device and never transmitted anywhereSo the site opens in the theme you chose last time

That is the complete list.

It is not a cookie, it is never sent with any request, it contains no identifier, and it tells us nothing — we cannot read it, because it never reaches us. Clearing your browser’s site data removes it, and the site works exactly as before, defaulting to your operating system’s own light or dark preference.

[COUNSEL: confirm the position under Kenyan law. Kenya has no separate cookie-consent statute of the ePrivacy kind, so we take the view that (a) a light/dark preference stored on the visitor's own device and never transmitted is not personal data and needs no consent, and (b) the Data Protection Act's consent requirements attach to processing personal data, which this is not. If you disagree, tell us and we will remove the toggle rather than add a banner — the feature is not worth a consent dialogue.]

3. The one request that can go to somebody else

If — and only if — you choose to use the optional password check, your own browser makes one request to api.pwnedpasswords.com, a public breach index operated by a third party.

  • It carries five characters of a fingerprint computed on your device, and nothing else.
  • It is sent with no cookies, no credentials and no referring page.
  • Because your browser makes it directly, that service sees your IP address and your user agent, as any website you visit does. It does not see your password, the full fingerprint, your domain or your email address.
  • We are not part of it. Nothing about it reaches us or is linked to your request.

The service is named on the page itself, next to the check, before you use it — you cannot meaningfully consent to a third party you were not told about. If you would rather that request never happened, do not run the check. Nothing else on the site depends on it.

The full technical description is in data-processing-note.md section 8.

4. What our server records when you load a page

Ordinary web-server request logs, and nothing more. Those logs are described in privacy-policy.md sections 3.2, 7 and 10: no IP address is retained in raw form, no user agent is written into an application log, and logs are kept for 30 days.

Loading a page does not create a record about you in our database. Only submitting the intake form does.

Consent on this site is captured in one place: the intake form, at the moment you ask us for a report. It is not inferred from browsing, from scrolling, or from continuing to use the site.

Five separate statements, each its own checkbox, each recorded separately:

StatementRequiredDefault
Send me my report — that we may use your email address and domain to prepare and send the report, and to contact you about itYesUnticked
I am authorised to request an assessment of this domain on behalf of the business that owns itYesUnticked
I understand this is not a penetration test — that we will read only public records and will not connect to your systems unless you authorise it separately, in writingYesUnticked
Send me occasional practical guidance on data protection and security in KenyaNoUnticked
You may refer to our business as a case study, if we ask first and you agree in writingNoUnticked

Every box starts empty, including the optional ones. A pre-ticked optional box is not a choice, and under the Data Protection Act it is not consent either.

No box is bundled with another. Agreeing to receive your report does not sign you up to anything else, and refusing the marketing box does not affect your report.

For each of the five we store: whether you agreed, the exact time, and the version identifier of the exact wording you were shown. The wording is held in a catalogue that a build check compares against the rendered page, so the version we record is provably the sentence you actually saw. We also store which version of the Terms of Service and of this Privacy Policy were in force at that moment.

The confirmation we send back to your browser repeats what we recorded, item by item, so the claim “we keep a record of your consent” is something you can check at the moment you make it, rather than something you have to take on trust.

Two of these are not preferences

The second and third statements carry legal weight. The first is the basis on which we are willing to look at a domain at all; the second bounds what we said we would do. If we are ever asked who authorised an assessment, that stored record — with its timestamp and its exact wording — is the whole answer. That is why it is kept for longer than the rest, as privacy-policy.md section 7 sets out.

Withdrawing

Withdrawal is recorded as a new entry, not as an edit of the old one. We do not quietly rewrite what you agreed to in the past; we record that you changed your mind, and when.

  • Marketing guidance: one click on any such email, or write to {{CONTACT_EMAIL}}.
  • Everything else: write to {{CONTACT_EMAIL}}. Withdrawing the service-delivery consent means we stop, and your rights under privacy-policy.md section 11 apply.

Withdrawal takes effect from when we receive it. It does not undo what was lawfully done before.

[COUNSEL: confirm this satisfies the Act's requirements that consent be freely given, specific, informed and unambiguous, and as easy to withdraw as to give. In particular, is an email address an adequate withdrawal route for the non-marketing consents, or must there be a one-click mechanism for those as well? We can build one; we would rather know before launch than after.]

6. If we ever add analytics

We have no analytics account and no plan to open one before launch. If that changes, the following must all be true before anything ships, and this note and privacy-policy.md are updated in the same release:

  1. It is named here and in the Privacy Policy, with its lawful basis and its location.
  2. It never receives your domain, your email address, or any value from the intake form.
  3. It is never loaded on, and never observes, the password-check panel.
  4. It is self-hosted or first-party wherever the vendor allows, so that giving up this site’s “no external requests” property is a deliberate decision taken each time rather than a default.
  5. Where consent is required, it is asked for properly — a real choice, with refusing as easy as accepting, and nothing loading before the answer.

7. How to check all of this yourself

You do not need to trust this note:

  • Open your browser’s developer tools, go to the storage or application panel, and look at cookies for {{SITE_ORIGIN}}. It is empty.
  • Look at local storage. There is one key, reconesys-theme, and only after you have used the toggle.
  • Watch the network panel while you load and read any page. Every request goes to {{SITE_ORIGIN}}. The only exception is the password check, and only if you run it.

If you find something on this site that contradicts any of the above, tell us at {{CONTACT_EMAIL}} — that would be a defect, and we would want to fix it the same day.


{{LEGAL_ENTITY}}, {{POSTAL_ADDRESS}} · {{CONTACT_EMAIL}} · {{PHONE}} · ODPC registration {{ODPC_NUMBER}}