Cookie notice
The privacy notice runs a card per type of data. This page runs a card per way something can be written to your device by visiting yyysoftware.co.uk, and answers the same questions about each one.
1. The whole answer, in four lines
Our own code writes nothing to your device. There is no analytics product on this site, no advertising, no tag manager, no pixel and no social widget. The only cookies you can meet here come from the security layer in front of the site, they appear when traffic looks automated, and they are strictly necessary in the sense the regulations use. One outside request happens on every page, for the lettering, and section 6 explains it.
The rest of this page is the detail behind those four lines, because a summary you cannot check is only a claim.
2. What the rule actually says
A cookie is a small text file a website asks your browser to keep and hand back on the next request. It is how a site recognises that two page loads came from the same browser.
In the United Kingdom the governing rule is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, usually shortened to PECR. It is written to cover any storage on your equipment, not just cookies, which is why sections 5 and 6 below exist.
The rule has two limbs. You must be told clearly what is being stored and why. And you must consent before it is stored, unless the storage is strictly necessary to deliver the service you asked for, which is the exemption in regulation 6(4)(b). Strictly necessary is narrow on purpose: it means the site genuinely cannot do the thing you asked for without it. Wanting to measure visitors has never qualified, and neither has finding it convenient.
Where consent is needed, PECR borrows the UK GDPR standard: a real choice, taken by an affirmative act, as easy to withdraw as to give. A pre-ticked box is not consent, and neither is scrolling.
Cookies from our own code
- Written to your device
- No. Not one, on any page of this site.
- Linked to you
- Not applicable.
- What it would be for
- Nothing we need. The site has no login, no basket and no preference to remember.
- Who else sees it
- Nobody.
- Consent position
- None sought, because nothing is stored.
These pages are static files. There is no database behind them, no session to hold open and no state to carry from one page to the next, which removes the usual reasons a site reaches for a cookie.
The one piece of script on the site opens and closes the menu on a narrow screen. It reads nothing and stores nothing, and you can confirm that in about a minute: open your browser's developer tools, look at the storage panel, and load every page here.
Security cookies from the hosting network
- Written to your device
- Possibly, and only if the security layer decides your request needs checking.
- Linked to you
- No. Neither value identifies a person to us, and we cannot read either.
- What it is for
- Telling a browser apart from a machine, and remembering a passed challenge.
- Who else sees it
- Cloudflare, as our hosting and security processor.
- Consent position
- Strictly necessary under regulation 6(4)(b). No consent required.
This site is served through Cloudflare, whose network sits in front of it, delivers the files and absorbs attacks. Where its protection layer judges that a request looks automated or hostile, it may store a value to distinguish a genuine browser from a script, or to record that a challenge has already been passed so you are not stopped again on the next page.
| Name | Purpose | Type and life | Position under PECR |
|---|---|---|---|
| __cf_bm | Bot management: separates a person's browser from automated traffic so the site can be served safely | First party; gone 30 minutes after your last request | Strictly necessary, regulation 6(4)(b). Not analytics, not advertising |
| cf_clearance | Records that a security challenge was completed, so you are not challenged over and over. Stored only where a challenge was actually shown to you | First party; life comes from the security configuration, usually no more than 30 days | Strictly necessary, regulation 6(4)(b) |
Most visitors will go their whole life on this site without meeting either, because both are responses to suspicious traffic rather than a routine part of a page load. Neither carries an identifier we can read, neither feeds a profile of you, and neither goes to an advertiser. Cloudflare's own analytics products are switched off for this site, so no measurement cookie is set from that direction either.
Local storage and other device storage
- Written to your device
- No. Not local storage, session storage, IndexedDB or a service worker.
- Linked to you
- Not applicable.
- What it would be for
- Nothing on a site with no state to keep.
- Who else sees it
- Nobody.
- Consent position
- None sought, because nothing is stored.
PECR covers storage of any kind on your equipment, which is why this card exists at all. Plenty of sites hold nothing in a cookie while holding an identifier in local storage, and describe themselves as cookie-free. That would be true and misleading at the same time.
Your browser's ordinary HTTP cache is a different animal. It holds copies of the pages, the stylesheet and the images so a repeat visit is quick, it is managed by your browser rather than by us, and it carries no identifier. Regulation 6(4)(a) exempts storage whose sole purpose is transmitting the communication, and a plain cache falls squarely inside that.
The lettering request
- Written to your device
- No cookie. The font files themselves are cached by your browser.
- Linked to you
- No. Google sees a connection, not a visitor we have named.
- What it is for
- Fetching the two typefaces this site is set in.
- Who else sees it
- Google Ireland Limited and Google LLC, as a separate controller.
- Consent position
- No storage, so regulation 6 is not engaged. The connection is disclosed here for honesty rather than because a rule compels it.
The type on these pages is served from Google's font hosts rather than from our own server. Loading a page therefore means your browser opening a connection to those hosts, and a connection reveals an IP address and a browser string to whoever answers it.
Google publishes what it does with that: the font service does not set cookies, and the request data is used to keep the service running rather than to build an advertising profile. Google is a separate controller for that exchange, not our processor, which is why it appears in section 23 of the privacy notice in its own row.
Avoiding the connection is straightforward if you would rather not make it. Any extension that blocks third-party requests will stop it, and the pages fall back to the system serif and the system sans without breaking. The content security policy on this site names those two hosts and nothing else, so no other outside connection is possible from a page here.
7. Why no banner stands in your way
Consent is needed for storage that is not strictly necessary. Every card above is either nothing at all or strictly necessary, which leaves no decision for you to make and nothing for a banner to ask.
Putting one up anyway would be worse than pointless. It would suggest a choice that does not exist, train you to dismiss a box without reading it, and cover the page you came for. The Information Commissioner's guidance is clear that a banner is not a substitute for having nothing to consent to, and it is not decoration to be worn for appearances.
If that ever changes, the change comes with the ask. Anything on this site that later needs consent will be blocked until you give it, through a control that is as easy to decline as to accept and as easy to reverse afterwards, and this page will describe it before it appears.
8. Clearing and blocking, yourself
Nothing here depends on you trusting the page. Your browser will show you exactly what is stored, and let you remove it.
Looking
Open developer tools with F12 or the equivalent menu item, find the storage or application panel, and read the cookie list for this domain while you click around. What you see is the truth, and it beats any assurance in a policy.
Clearing and blocking
Every browser offers this under privacy settings, usually as a way to clear stored data for one site and a way to block cookies from any site. On Safari, look for Manage Website Data under Privacy. On Chrome and Edge, look under cookies and site data. On Firefox, look under Cookies and Site Data. Private or incognito browsing discards everything on closing the window.
Blocking cookies for this domain outright costs you nothing at all. Every page reads and behaves the same, because nothing here depends on a stored value. On a site with a login you would be locking yourself out; here you are simply removing a security convenience.
Do Not Track headers are honoured by almost nothing on the web, which is worth knowing rather than relying on. Since nothing here tracks you, sending one changes nothing about your visit.
9. Inside an app, this page does not apply
This notice is about a browser visiting a website. An application is a different environment: it has no cookie jar in the browser sense, and what it keeps lives in the storage area the operating system hands it.
The equivalent disclosures for an app are the cards in the privacy notice, the App Privacy labels on an Apple listing, and the Data Safety panel on a Google Play listing. Card 12 of the privacy notice covers the identifiers most often used for tracking inside apps, and section 21 there explains why no tracking prompt appears.
10. Changes, and where to write
This page changes when the site does. Adding anything that stores something new means updating a card, moving the date at the top, and where consent becomes necessary, putting the control in place before the thing goes live rather than after.
Questions about any of it, or a discrepancy between this page and what your browser is showing you, are worth an email. The second one especially: if your storage panel disagrees with a card here, we want to know inside the hour.
YYY SOFTWARE LTD
Email: [email protected]
Company number 16938311, England and Wales
Complaints about storage on your device can also go to the Information Commissioner's Office, which enforces PECR as well as data protection law. Its address and helpline are in section 32 of the privacy notice.