Register operational · Records verified against workshop evidence
Login
Governance framework · Instrument

Cookie and Local Storage Policy

What the Register stores on a user's device, on what legal basis, for how long, and how it may be controlled or removed.

Document reference
NVSR-CKP-001
Version
1.0
Status
In force
Effective date
1 August 2026

1.Scope and basis

1.1

This Policy applies to cookies, local storage, session storage and any equivalent technology used on this website. It supplements the Privacy and Data Protection Policy (NVSR-GDPR-001).

1.2

Storage of and access to information on a user's device is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Consent is required except where the storage is strictly necessary to provide a service the user has requested.

1.3

The Register operates a deliberately minimal position: it sets no advertising, profiling, cross-site tracking or third-party marketing cookies, and sells no data to any party.

2.Schedule of storage in use

ItemTypePurposeDurationBasis
Authentication session tokenLocal storageKeeps a signed-in user authenticated across pages and refreshes the session.Until sign-out or expiryStrictly necessary
Session refresh tokenLocal storageRenews an expiring session without forcing repeated sign-in.Until sign-out or expiryStrictly necessary
Security and abuse controlsSession storageRate limiting and protection of form submission endpoints.Browser sessionStrictly necessary
Interface preferenceLocal storageRemembers non-identifying interface state such as a chosen search mode.12 monthsStrictly necessary

Table 1 — Storage in use at the effective date of this Policy. Any addition is published here before deployment.

3.What the Register does not use

  • No advertising or retargeting cookies.
  • No cross-site tracking pixels, social media trackers or advertising identifiers.
  • No profiling of users for commercial purposes, and no automated decision-making producing legal effects.
  • No sale, rental or brokerage of user data to third parties.

4.Server logs

4.1

The hosting and database infrastructure records operational logs, including IP address, timestamp, request path and user agent, for security monitoring, abuse prevention and fault diagnosis. This is a legitimate interest in the security and integrity of a public register.

4.2

Operational logs are retained in accordance with the Data Retention and Disposal Schedule (NVSR-DRP-001) and are not used to build profiles of users.

5.Controlling storage

5.1

All modern browsers allow cookies and site storage to be viewed, blocked and deleted, either generally or for an individual site. Clearing storage for this website signs the user out and removes interface preferences.

5.2

Because the items in Table 1 are strictly necessary, blocking them prevents sign-in and the operation of the account, workshop and administration areas. Public search, record viewing and certificate verification remain available.

6.Changes and correspondence

6.1

Where the Register introduces any storage that is not strictly necessary, this Policy will be revised, a new version issued, and consent obtained before that storage is set.

6.2

Questions about this Policy are submitted through the contact form under category C5. The Register publishes no general email address.

Document control
Reference
NVSR-CKP-001
Version
1.0
Classification
Public
Review
Annually