This document is a draft

It has not been reviewed by a qualified legal adviser. It is published so that it can be read and commented on before it takes effect, and it should not be relied on in its current form.

Corrections and comments: legal@cmsinfosec.com

cmsinfosec.com sets no cookies.

Not strictly necessary ones, not analytics, not marketing. There is no consent banner on this site because there is nothing to consent to, and a banner that asks permission for nothing is worse than no banner: it trains people to click “accept” without reading.

Why there are none

This site is a set of static HTML, CSS, font and image files. There is no account, no session, no basket, no form and no personalisation. None of those things exist, so none of them needs to remember you between page loads.

We also embed nothing from anyone else. No analytics tag, no advertising pixel, no embedded video, no social media widget, no hosted font. Third-party embeds are where most sites’ cookies actually come from, and the way to not have them is to not have the embeds.

How to check

You do not have to take our word for it. In any current browser, open developer tools with F12, go to the Application (Chrome, Edge) or Storage (Firefox, Safari) tab, and look at Cookies, Local Storage and Session Storage for this domain. They will be empty.

If you find something there, we would genuinely like to know: privacy@cmsinfosec.com.

What our host records

Setting no cookies is not the same as recording nothing. Our host keeps ordinary server request logs (IP address, timestamp, page requested and browser user-agent) so it can serve pages and defend against attack. That is not cookie access and does not require consent under the Privacy and Electronic Communications Regulations, but it is personal data, and the website privacy notice explains what happens to it.

Our products are different

Cyber Made Simple is a web application with accounts, sign-in and billing, and it necessarily sets cookies. Its own cookie controls and cookie policy govern that, and they are on its site rather than here.

CMS SecureMe is a mobile app rather than a website. It uses on-device storage instead of cookies, and its privacy notice sets out what it keeps and where.

Changes

If this site ever needs a cookie, and we would rather it did not, this notice will change before the cookie is set, a consent mechanism will appear, and the “Last updated” date at the top of this page will move.