Cookie Policy
What this site can store on your device, who provides it, and how long it stays. Nothing outside the strictly necessary category loads before you opt in.
Opens the preferences dialog. The same control sits in the footer of every page, so you can change or withdraw your choice at any time.
How consent works here
Not a promise about intent — a description of the order in which things happen in the code that ships with this site.
Denied before anything can ask
On every page load, consent defaults are set to denied for analytics and advertising storage before a single tag can run. Until you decide, no measurement container, analytics script or marketing pixel is requested.
A visitor who never answers the banner is never measured.
You choose, with equal weight
The banner offers “Accept all”, “Reject non-essential” and “Manage preferences” as three buttons of the same size and prominence. Rejecting costs exactly one click, the same as accepting.
Reject is never a de-emphasised text link.
Only then does anything load
The Google Tag Manager container (GTM-TXSLSRK5) is injected only once you have granted the analytics or marketing category. If you reject, it is never requested — and with JavaScript disabled, nothing optional can load at all.
No consent, no third-party request.
You can change your mind
Your decision is stored in a first-party cookie for about 182 days, after which we ask again. “Cookie settings” in the footer of every page reopens the dialog, and withdrawing is as easy as granting.
Withdrawal takes effect on the next page load.
Three switches, one locked
These are the exact categories offered in the preferences dialog — the descriptions below are the same text the dialog shows you.
- Strictly necessary Always on
- Required for the site to work: remembering your cookie choice, and protecting the contact form from abuse. These are first-party and cannot be switched off.
- Analytics Off by default
- Helps us understand which pages are useful and where people get stuck. Loaded through Google Tag Manager only after you opt in. No form contents are ever collected.
- Marketing Off by default
- Measures whether a campaign led to an enquiry. Off unless you opt in, and never used to build a profile of you across other websites.
Every cookie this site can set
One is written when you make a choice. The rest cannot exist unless you opt in to analytics.
| Cookie | Provider | Category | Purpose | Lifetime |
|---|---|---|---|---|
pontis_consent | Pontis — first party | Strictly necessary | Records your cookie decision: which categories you allowed, the version of the notice you saw, and the timestamp of the choice. Written only once you have made a decision. | ~6 months (182 days) |
_ga | Google Analytics, loaded by Google Tag Manager | Analytics | Distinguishes one visitor from another. Set only if you opt in to analytics and the container is configured to load Google Analytics. | [CONTENT REQUIRED: confirmed vendor retention periods] |
_ga_* | Google Analytics, loaded by Google Tag Manager | Analytics | Maintains session state for a specific Analytics property, where * is that property’s identifier. Same condition: analytics consent, and the tag being present in the container. | [CONTENT REQUIRED: confirmed vendor retention periods] |
Marketing. The marketing category exists in the preferences dialog, but no marketing tag ships in this site’s code. If one is ever added to the container, it is listed here before it can run — and it still cannot run until you opt in to that category specifically.
The container itself. Google Tag Manager is a container: it
loads the tags configured inside it rather than measuring anything on its
own. The tags currently live in container GTM-TXSLSRK5 are
[CONTENT REQUIRED: confirmed container tag list].
Who receives what
The consent cookie
pontis_consent is first-party — it is set by this site, not by
anyone else, and it is never sent anywhere. It carries only your category
choices, the notice version and the time you decided. It is written with
SameSite=Lax, scoped to the whole site with Path=/,
marked Secure over HTTPS, and expires after roughly six months
(182 days), at which point we ask again.
Google Tag Manager, and what it may load
The only third-party vendor this site requests is Google Tag Manager,
container GTM-TXSLSRK5, and only after you have granted analytics or
marketing. Google Tag Manager may in turn load Google Analytics, which is
what the _ga cookies in the table above belong to.
What is sent to analytics is a closed set of named events — page views and a short list of interactions such as opening a domain or submitting the contact form. The contents of any form you fill in are never included: not your message, not your email address, not your company. Errors are reported as codes, never as text you typed.
Google’s own handling of this data is described in its privacy policy (opens in a new tab) .
Retention
How long the analytics vendor keeps the data behind these cookies is set in the vendor’s own configuration, not by the browser cookie lifetime. That configuration is being confirmed as part of the pending legal review: [CONTENT REQUIRED: confirmed vendor retention periods]. The retention periods for data Pontis holds directly — contact form submissions, for example — are set out in the privacy policy.
Transfers outside the EEA
Where a processor handles data outside the European Economic Area, the safeguards relied on are listed in the privacy policy.
Turn a strategic gap into a working ecosystem.
Bring us a concrete use case, a market failure or a capability gap. We will help define the context, the stakeholders and the format needed to move it towards a decision.
For problem owners, problem solvers, capital providers and market standard-setters.