Cookie Policy
- Document reference
- FGL-LEG-05
- Version date
- 1 July 2026
- Applies to
- Fratres Limited
1.Interpretation and definitions
In this Cookie Policy the following capitalised terms bear the meanings given to them below. Terms defined in the UK GDPR and not otherwise defined here bear the meanings given to them in that instrument.
- Company
- Fratres Limited, a private company limited by shares incorporated and registered in England and Wales, being the operator of the Website and the controller in respect of Personal Data processed through it.
- Website
- The website published at fratresgroup.com, together with every subdomain, sub-directory and page operated by or on behalf of the Company under that domain.
- Cookie
- A small file, typically containing text, that is stored on Terminal Equipment when the Website is accessed and that may subsequently be read by the party that placed it.
- Similar Technology
- Any technique other than a Cookie by which information is stored on, or access to information stored on, Terminal Equipment is obtained, including local storage, session storage, indexed database storage, pixel tags and web beacons, script-based storage, software development kits and device or browser fingerprinting techniques.
- Consent Tool
- The cookie preference mechanism made available on the Website through which a Visitor may give, refuse, review and withdraw Consent by category, and which is reachable at any time from the persistent control in the Website footer.
- Consent
- Consent within the meaning of Article 4(11) of the UK GDPR, being a freely given, specific, informed and unambiguous indication of the Visitor’s wishes by which the Visitor, by a statement or by a clear affirmative action, signifies agreement to the storage of, or access to, information on Terminal Equipment.
- PECR
- The Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended.
- UK GDPR
- Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, read together with the Data Protection Act 2018.
- Personal Data
- Personal data as defined in Article 4(1) of the UK GDPR, which expressly includes online identifiers such as those carried by Cookies.
- Strictly Necessary Cookie
- A Cookie or Similar Technology falling within the exemption in regulation 6(4) of PECR, being one used for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or one strictly necessary for the provision of an information society service explicitly requested by the Visitor.
- Terminal Equipment
- The computer, tablet, mobile telephone or other device used by a Visitor to access the Website, and the browser or application software running on it.
- Business Day
- Any day other than a Saturday, Sunday or public holiday in England and Wales.
- Visitor
- Any person who accesses the Website, whether or not that person subsequently makes an enquiry or enters into any relationship with the Company. References in this Policy to “you” are references to the Visitor.
2.Purpose and scope
3.Legal framework
4.What cookies and similar technologies are
- —local storage and session storage, in which values are held by the browser and read back by scripts served from the Website;
- —indexed database storage, used to hold structured data on Terminal Equipment;
- —pixel tags and web beacons, being small transparent image or script requests whose retrieval records that a page or element has been loaded;
- —software development kits embedded within applications; and
- —device and browser fingerprinting, in which a combination of configuration characteristics is used to recognise Terminal Equipment without storing anything on it.
5.Categories of cookies used
- (a)routing requests and maintaining the integrity and continuity of a browsing session across page requests;
- (b)security functions, including the generation and validation of the token that protects the enquiry form against cross-site request forgery;
- (c)detecting and limiting abusive or automated traffic, including rate limiting and the mitigation of denial-of-service activity;
- (d)balancing load between servers so that a Visitor’s requests are served consistently;
- (e)recording the Consent choices made through the Consent Tool, so that those choices persist and are honoured on subsequent page requests; and
- (f)recording that an informational notice has been read and dismissed, so that it is not shown repeatedly.
The name, provider, category, stated purpose and storage duration of every individual Cookie in use at any given time are set out in the Consent Tool, which is reachable from the persistent control in the Website footer. That register is generated from the Website as it is actually configured and is therefore the authoritative record; this Policy describes the categories and purposes that the register is permitted to contain.
6.First party and third party cookies
7.Consent and how it is obtained
- (a)no box, slider or toggle relating to a non-essential category is pre-ticked, pre-enabled or otherwise set to accept by default;
- (b)the option to reject all non-essential categories is presented with the same prominence, and requires no more effort to select, than the option to accept them;
- (c)the visual design does not use emphasis, colour, sequencing or wording to steer the Visitor toward acceptance;
- (d)Consent may be given to one category and refused for another, so that Consent is specific to each purpose;
- (e)access to the Website is not conditional on Consent, and the Company operates no cookie wall; and
- (f)the information required by regulation 6(2)(a) of PECR is presented before, not after, the choice is made.
8.Withdrawing or changing consent
9.Lawful basis for processing
10.Duration, storage and retention
11.Browser and device controls
- —view the Cookies and stored site data currently held, by site;
- —delete individual Cookies, all Cookies for a given site, or all Cookies stored;
- —block all Cookies, or block third party Cookies only;
- —clear Cookies and site data automatically when the browser is closed;
- —set permissions on a per-site basis, allowing storage for some sites and refusing it for others;
- —browse in a private or incognito mode, in which storage is discarded at the end of the session; and
- —send an automated preference signal of the kind described in clause 13.
12.Consequences of blocking or deleting
Declining analytics and preference Cookies costs a Visitor nothing. Every page of substantive content on this Website, and the enquiry form itself, is fully available to a Visitor who accepts only strictly necessary Cookies.
13.Do Not Track and preference signals
14.Rights of individuals
15.Enquiries and complaints
16.Review, amendment and status
This Policy should be read with the Privacy Policy, which describes all processing of Personal Data by the Company; the Data Retention and Records Management Policy, which sets the periods for which records are held; the International Data Transfer Statement, which governs transfers outside the United Kingdom; and the Terms and Conditions of Website Use, which govern access to the Website generally. All are published in the legal register.