Cookie and Storage Technology Policy
This document is currently under legal review and may be updated.
Last updated: 27 July 2026
1. About this policy
This policy explains how Fox Healey & Co uses cookies and similar technologies on:
- foxhealey.co.uk;
- the client portal at foxhealey.co.uk/portal; and
- any related online forms or digital services that link to this policy.
In this policy:
- “Fox Healey”, “we”, “us” or “our” means Fox Healey Ltd;
- “Website” means the public Fox Healey website;
- “Portal” means the secure Fox Healey client portal; and
- “Services” means the Website, Portal and related online services.
Our company information is:
Fox Healey Ltd Registered in England and Wales Company number: 17368719 Registered office: Bartle House, 9 Oxford Court, Manchester, M2 3WQ Email: hello@foxhealey.co.uk
2. What are cookies?
Cookies are small text files placed on a computer, phone, tablet or other device when someone visits a website or uses an online service.
Cookies may be used to:
- maintain a secure login session;
- authenticate a user;
- protect forms and accounts;
- remember selections;
- support website functionality;
- understand how a service is used; or
- enable third-party functionality.
Some cookies are deleted when the browser is closed. These are commonly referred to as session cookies.
Other cookies remain on the device for a defined period or until they are deleted. These are commonly referred to as persistent cookies.
Cookies may be:
- first-party cookies, set by Fox Healey’s Website or Portal; or
- third-party cookies, set by another service integrated with or accessed through our Services.
3. Similar technologies
The rules applying to cookies may also apply to other technologies that store information on, or access information from, a user’s device.
These may include:
- local storage;
- session storage;
- tracking pixels;
- scripts and tags;
- device identifiers;
- link-tracking technologies;
- software-development-kit technologies; and
- device-fingerprinting techniques.
References to cookies in this policy include these similar storage and access technologies where appropriate.
4. Our current approach
We aim to keep the use of cookies and similar technologies to a minimum.
At the date of this policy, our intention is to use only technologies that are necessary to:
- operate the Website and Portal;
- authenticate authorised Portal users;
- maintain secure sessions;
- prevent fraud or misuse;
- protect accounts and forms;
- support security verification;
- remember essential user selections; and
- deliver functionality expressly requested by the user.
We do not currently intend to use cookies for:
- targeted advertising;
- behavioural advertising;
- cross-site tracking;
- social-media profiling;
- building advertising audiences;
- selling visitor information; or
- monitoring individuals across unrelated websites.
5. Strictly necessary cookies
Strictly necessary cookies are essential to provide a service requested by the user or to maintain the security and proper operation of that service.
These may include cookies used for:
- user authentication;
- maintaining a secure Portal session;
- protecting against cross-site request forgery;
- preventing or detecting fraud;
- identifying technical faults;
- secure invitation acceptance;
- email verification;
- password-reset processes;
- multi-factor authentication;
- load balancing;
- secure form submission; and
- recording essential consent or privacy selections.
Because these cookies are necessary to provide the requested service, they cannot normally be disabled through a Fox Healey preference control.
Users can block them through their browser, but doing so may prevent the Website or Portal from functioning correctly.
6. Cookies and technologies currently used
| Cookie or technology | Provider | Purpose | Type | Typical duration |
|---|---|---|---|---|
| portal_session | Fox Healey | Authenticates the user and maintains a secure Portal session after sign-in | Strictly necessary | Up to 7 days |
| portal_2fa_pending | Fox Healey | Supports multi-factor or security-code verification during sign-in and secure account invitation acceptance | Strictly necessary | Approximately 10 minutes |
| _ga / ga* | Google Analytics — helps us understand how visitors use the Website and Portal in aggregate. Set only if you accept analytics cookies. | Analytics (consent required) | Up to 13 months | |
| fh-cookie-consent (local storage) | Fox Healey | Records whether you accepted or declined analytics cookies so we do not ask again | Strictly necessary | Until changed or cleared |
No advertising, targeting or other third-party cookies are used. Google Analytics is loaded only after you accept it through the cookie banner; you can change your choice at any time using the "Cookie Settings" link in the Website footer or the Portal sidebar.
7. Authentication and Portal sessions
When a user signs in to the Portal, we may set an authentication or session cookie.
This allows the Portal to:
- recognise the signed-in user;
- apply the correct account permissions;
- maintain access while the user moves between Portal pages;
- prevent repeated login requests; and
- protect Organisation information from unauthorised access.
A session may end when:
- the user signs out;
- the session expires;
- the browser session ends, where applicable;
- the account is suspended;
- the password or security credentials are changed; or
- we end the session for security reasons.
Persistent login sessions last up to 7 days, after which the user must sign in again.
8. Security verification
Short-lived cookies or storage technologies may be used during:
- multi-factor authentication;
- email-address verification;
- invitation acceptance;
- password-reset processes;
- suspicious-login checks; and
- other account-security procedures.
These technologies are used only to complete or protect the relevant security process and should expire once that process is completed or after a short defined period.
9. Essential form and security controls
The Website and Portal may use technologies that support:
- secure form submission;
- protection against automated spam;
- rate limiting;
- prevention of duplicate submissions;
- detection of malicious requests; and
- prevention of cross-site request forgery.
Where a third-party anti-spam or fraud-prevention service is used, we will review whether it places cookies or accesses device information.
If the technology is not covered by an applicable exception, it will not be activated until any required consent has been obtained.
10. Analytics and service measurement
We use Google Analytics on the Website and Portal to understand, in aggregate, how our Services are used. Google Analytics:
- is activated only after you accept analytics cookies through the cookie banner;
- remains fully disabled (with consent defaults set to "denied") until you accept;
- can be switched off at any time via the "Cookie Settings" link in the Website footer or the Portal sidebar; and
- is not used for advertising, profiling or cross-site tracking.
We do not use advertising analytics or technologies that track identifiable users across websites.
We use, or may in future use, limited service-measurement technologies to understand matters such as:
- total page visits;
- which pages are accessed;
- broad user journeys;
- browser and device categories;
- page-loading performance;
- errors;
- aggregate use of Website or Portal functions; and
- how users reached the Website.
Before introducing such technology, we will determine whether:
- consent is required;
- a statistical-purpose exception applies;
- the information is used only to improve the Website or Portal;
- the resulting information is aggregate and non-identifying;
- individual-level information is deleted promptly;
- the provider acts only on our instructions; and
- users are provided with any required consent or objection control.
Analytics used for advertising, profiling, identifying individual visitors, linking Website use with advertising campaigns or tracking people across different services will not be activated without any consent required by law.
11. Preference and appearance technologies
We may use limited technologies to remember preferences expressly selected by a user, such as:
- display settings;
- accessibility selections;
- language;
- theme;
- table layout; or
- other Portal appearance settings.
Where we rely on an applicable preference or appearance exception, we will provide clear information and a simple, free way for the user to object.
These technologies will not be used to profile users or personalise content based on inferred interests without any consent required by law.
12. Third-party services
The Website or Portal may connect to third-party services, including:
- authentication providers;
- cloud hosting providers;
- HubSpot or another CRM;
- Microsoft Bookings or Calendly;
- Microsoft 365 or Google Workspace;
- email-delivery providers;
- file-storage providers;
- document and PDF services;
- video-conferencing services;
- payment providers, if introduced;
- embedded media providers; and
- security or anti-spam providers.
A third-party service may set cookies or use similar technologies if:
- its content is embedded in our Website or Portal;
- its script or software is loaded;
- a user interacts with its functionality; or
- the user follows a link to the third party’s website.
Where possible, we will:
- avoid loading unnecessary third-party technologies;
- use privacy-preserving settings;
- use external links rather than automatic embeds;
- prevent non-essential technologies loading before any required choice is made; and
- explain the relevant third-party use in this policy.
If a user follows a link to another website, cookies set after leaving our Services are governed by that website’s own cookie and privacy information.
13. Booking services
We may use Microsoft Bookings, Calendly or another provider to arrange:
- initial conversations;
- Commercial Performance Snapshot interviews;
- quarterly reviews;
- client meetings; or
- other appointments.
Where the booking service is accessed through an external link, the provider may set its own cookies after the user opens that service.
If a booking interface is embedded directly within the Website or Portal, we will assess the technologies it uses and prevent any non-exempt cookies from loading until the necessary choice has been made.
14. CRM forms and meeting tools
We may connect Website forms, meeting links or lead information to HubSpot or another CRM.
A server-to-server transfer of form information does not necessarily require a cookie.
However, embedded CRM forms, chat tools, tracking scripts, marketing pixels or visitor-identification features may set cookies or access device information.
We will not activate non-essential CRM tracking technologies unless:
- they have been identified;
- their purpose is documented;
- users receive clear information; and
- any required consent has been obtained.
15. Embedded videos, maps and social-media content
We may provide links to videos, maps or social-media pages.
Where content is embedded, the relevant provider may attempt to set cookies or collect information about the user’s interaction.
Where practical, we will:
- use privacy-enhanced embedding options;
- avoid loading the embedded service automatically;
- display a placeholder before the user chooses to load it; or
- use an external link instead.
Social-media advertising pixels or tracking plugins will not be activated without any consent required by law.
16. Email links
Emails sent by Fox Healey may contain links to:
- activate an account;
- verify an email address;
- reset a password;
- begin or continue an assessment;
- book a meeting;
- view a report; or
- access another secure Portal function.
These links may contain short-lived security tokens.
A security token in a link is not necessarily a cookie, but it may work with a strictly necessary session cookie when the relevant page is opened.
Marketing-email measurement, including open or click tracking, is addressed in our Privacy Notice and the relevant email preference information.
17. When we need consent
Where a cookie or similar technology is not covered by an applicable exception, we will:
- explain its purpose before it is activated;
- identify relevant third parties;
- obtain a clear, positive choice;
- provide an equally accessible way to refuse;
- avoid setting it before the required consent;
- record the user’s choice where appropriate; and
- allow the choice to be changed or withdrawn.
Continuing to browse the Website will not by itself be treated as consent to non-essential technologies.
18. The cookie banner and changing your choice
Because we use Google Analytics, which requires consent, a cookie banner is shown on your first visit to the Website and Portal. It offers an equally simple Accept and Decline choice, and no analytics technology is activated before you accept.
Your choice is remembered on the device you used. You can change it at any time using the "Cookie Settings" link in the Website footer or the Portal sidebar, which reopens the banner.
This does not remove our responsibility to:
- identify the technologies used;
- explain their purposes;
- state their providers;
- state their duration;
- keep the information accurate; and
- review the position when the Website or Portal changes.
If we introduce technologies requiring consent, we will implement an appropriate consent mechanism before activating them.
If we rely on another exception that requires a simple means of objecting, we will provide that objection mechanism.
19. Managing cookies through your browser
Most browsers allow users to:
- view stored cookies;
- delete some or all cookies;
- block all cookies;
- block third-party cookies;
- clear cookies when the browser closes; and
- use private or incognito browsing.
Browser settings vary. Users should refer to the help information provided by their browser.
Blocking all cookies may prevent:
- signing in to the Portal;
- maintaining a secure session;
- completing account verification;
- submitting forms;
- saving assessment progress;
- accessing published reports; or
- using other secure functionality.
20. Portal sign-out and shared devices
Users accessing the Portal on a shared or public device should:
- avoid selecting any persistent sign-in option;
- sign out when finished;
- close the browser; and
- avoid saving passwords in the browser.
Deleting authentication cookies will normally end the Portal session on that device.
21. Personal information
Some cookies and similar technologies may involve the processing of personal information, including:
- an account identifier;
- an authentication status;
- an IP address;
- device or browser information;
- security events; or
- information about use of the Website or Portal.
Further information about how we process personal information, the purposes of processing, service providers, retention and individual rights is contained in our Privacy Notice.
22. Retention
We retain cookies and information accessed through them only for as long as reasonably necessary for the stated purpose.
The appropriate period depends on the type of technology.
For example:
- security-verification technologies should be short lived;
- session cookies may expire when the session ends;
- persistent authentication cookies may remain for a defined login period;
- preference records may remain until they expire or are changed;
- aggregate statistical information may be retained separately from individual-level data; and
- security records may be retained for a reasonable period for fraud prevention, investigation and audit purposes.
23. Cookie and technology audits
We will periodically review the Website and Portal to identify:
- first-party cookies;
- third-party cookies;
- local and session storage;
- scripts and tags;
- pixels;
- embedded services;
- cookie durations;
- providers;
- purposes;
- whether consent is required;
- whether an exception applies; and
- whether the technology remains necessary.
We will also review cookie use when:
- the Website or Portal is materially updated;
- a new provider is introduced;
- a new integration is enabled;
- analytics is introduced;
- embedded content is added; or
- the law or regulatory guidance changes.
24. Changes to this policy
We may update this policy to reflect:
- changes to the Website or Portal;
- new integrations;
- changes to cookies or similar technologies;
- changes to our service providers;
- changes to the law or regulatory guidance; or
- improvements to our privacy and security practices.
The current version will be published with the applicable “last updated” date.
Where a material change affects registered Portal users, we may also provide notice through the Portal or by email.
25. Contact us
Questions about this policy or the technologies used by the Website and Portal should be sent to:
Fox Healey Ltd Email: hello@foxhealey.co.uk Privacy email: privacy@foxhealey.co.uk [WHEN ESTABLISHED] Registered office: Bartle House, 9 Oxford Court, Manchester, M2 3WQ