This policy explains how Cyber Defence Service Ltd (CDS, we, us) uses cookies and similar technologies on cyberdefenceservice.co.uk (the site), what they do and how you can control them. It is written in plain English for a professional audience and should be read together with our Privacy Policy, which explains more generally how we handle personal information collected through the site. This policy does not cover cookies on other websites we link to, including our product sites, which have their own policies.

This policy explains how Cyber Defence Service Ltd (CDS, we, us) uses cookies and similar technologies on cyberdefenceservice.co.uk (the site), what they do and how you can control them. It is written in plain English for a professional audience and should be read together with our Privacy Policy, which explains more generally how we handle personal information collected through the site. This policy does not cover cookies on other websites we link to, including our product sites, which have their own policies.

  1. Who we are

Cyber Defence Service Ltd is the data controller for any personal data collected through cookies on the site. We are registered in England and Wales under company number 10290462, at Greater Manchester Digital Security Hub, 2nd Floor, Heron House, 1 Lincoln Square, Manchester, M2 5LN, and with the Information Commissioner's Office (ICO) under registration ZB130773. If you have any questions about this policy, contact contact@cyberdefenceservice.co.uk or write to us at the address above.

Cyber Defence Service Ltd is the data controller for any personal data collected through cookies on the site. We are registered in England and Wales under company number 10290462, at Greater Manchester Digital Security Hub, 2nd Floor, Heron House, 1 Lincoln Square, Manchester, M2 5LN, and with the Information Commissioner's Office (ICO) under registration ZB130773. If you have any questions about this policy, contact contact@cyberdefenceservice.co.uk or write to us at the address above.

  1. What cookies and similar technologies are

Cookies are small text files that a website places on your computer, phone or tablet when you visit. They are widely used to make websites work, to remember your choices and to report information back to the website owner. Some of the technologies we use are not cookies in the strict sense but do a similar job: local storage, which is a small store inside your browser that a website can write to and read from; tags and scripts, which are small pieces of code loaded into a page; and pixels or web beacons, which are tiny images used to record that a page has been opened. The law treats all of these in the same way, so in this policy we call them all cookies unless the difference matters.

Cookies can be first party, meaning they are set by us through the site, or third party, meaning they are set by another organisation whose technology we use, such as an analytics provider. Session cookies last only until you close your browser. Persistent cookies stay on your device until they expire or you delete them; how long each one lasts is shown in section 4.

Cookies are small text files that a website places on your computer, phone or tablet when you visit. They are widely used to make websites work, to remember your choices and to report information back to the website owner. Some of the technologies we use are not cookies in the strict sense but do a similar job: local storage, which is a small store inside your browser that a website can write to and read from; tags and scripts, which are small pieces of code loaded into a page; and pixels or web beacons, which are tiny images used to record that a page has been opened. The law treats all of these in the same way, so in this policy we call them all cookies unless the difference matters.

Cookies can be first party, meaning they are set by us through the site, or third party, meaning they are set by another organisation whose technology we use, such as an analytics provider. Session cookies last only until you close your browser. Persistent cookies stay on your device until they expire or you delete them; how long each one lasts is shown in section 4.

  1. The rules we follow

In the UK, the use of cookies is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), most recently amended by the Data (Use and Access) Act 2025, which took effect for cookies on 5 February 2026. Regulation 6 of PECR allows us to store information on your device, or to read information already stored there, only if you have been given clear and comprehensive information about what we are doing and why, and you have consented. Consent is not needed where a cookie is strictly necessary to provide a service you have asked for, which includes keeping the site secure and remembering the choices you make in our cookie banner. Nor is it needed for the limited exceptions PECR now recognises, of which the two relevant to this site are the collection of statistics about how the site is used and the adaptation of how the site appears on your device. The statistics exception applies only where the information is used solely to measure and improve the site, is not shared with anyone else for their own purposes, and you have been told about it and given a simple, free way to object.

Where a cookie collects information that could identify you, even indirectly, such as an IP address or a unique identifier, that information is personal data and the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 also apply. Both sets of rules are overseen by the ICO. Consent under PECR means a clear, positive choice made by you. We do not treat continued browsing, pre-ticked boxes or browser defaults as consent, rejecting is as easy as accepting, and nothing that needs your consent is set until you give it. You can withdraw consent at any time; doing so does not affect anything done lawfully before you withdrew it.

In the UK, the use of cookies is governed by the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), most recently amended by the Data (Use and Access) Act 2025, which took effect for cookies on 5 February 2026. Regulation 6 of PECR allows us to store information on your device, or to read information already stored there, only if you have been given clear and comprehensive information about what we are doing and why, and you have consented. Consent is not needed where a cookie is strictly necessary to provide a service you have asked for, which includes keeping the site secure and remembering the choices you make in our cookie banner. Nor is it needed for the limited exceptions PECR now recognises, of which the two relevant to this site are the collection of statistics about how the site is used and the adaptation of how the site appears on your device. The statistics exception applies only where the information is used solely to measure and improve the site, is not shared with anyone else for their own purposes, and you have been told about it and given a simple, free way to object.

Where a cookie collects information that could identify you, even indirectly, such as an IP address or a unique identifier, that information is personal data and the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 also apply. Both sets of rules are overseen by the ICO. Consent under PECR means a clear, positive choice made by you. We do not treat continued browsing, pre-ticked boxes or browser defaults as consent, rejecting is as easy as accepting, and nothing that needs your consent is set until you give it. You can withdraw consent at any time; doing so does not affect anything done lawfully before you withdrew it.

  1. The cookies and technologies we use

We keep the site deliberately simple. We do not run advertising, we do not track you across other websites and we do not sell information about visitors. The site is built and hosted on Framer, a website platform provided by Framer B.V. of Amsterdam, and at the date of this policy it uses the technologies described below. The banner shown on your first visit lets you accept or reject everything that is not strictly necessary, and the Cookie Settings link in the footer of every page lets you change your mind later.

We keep the site deliberately simple. We do not run advertising, we do not track you across other websites and we do not sell information about visitors. The site is built and hosted on Framer, a website platform provided by Framer B.V. of Amsterdam, and at the date of this policy it uses the technologies described below. The banner shown on your first visit lets you accept or reject everything that is not strictly necessary, and the Cookie Settings link in the footer of every page lets you change your mind later.

4.1 Strictly necessary

These entries are needed for the site to work properly and to honour your cookie choices. They do not need your consent and cannot be switched off in our banner, although you can block them in your browser (see section 6), in which case the banner will not be able to remember your choice and will appear on each visit.

These entries are needed for the site to work properly and to honour your cookie choices. They do not need your consent and cannot be switched off in our banner, although you can block them in your browser (see section 6), in which case the banner will not be able to remember your choice and will appear on each visit.

Name

Set by

What it does

Legal Basis

Name

framerCookiesConsentMode

framerCookiesDismissed

framerCookiesAutoAccepted

CDS, through the Framer cookie banner

Record that you have responded to the cookie banner and which categories you have allowed, so that your choice is applied on every page and you are not asked again on each visit

First party (browser local storage)

Until you clear your browser's site data or change your choice using Cookie Settings

4.2 Analytics

We use analytics to understand which pages are read, where visitors come from and whether the site works well on different devices. We use two tools, and they work in different ways.

Framer's built-in analytics. Framer, the platform that hosts the site, provides basic visitor statistics. It does not use cookies and stores nothing on your device. To count visits it combines your IP address and browser details with a secret value that Framer changes and deletes every day, so it cannot recognise you from one day to the next or across other websites, and we see only aggregate figures such as page views, referring sites, countries, browsers and device types. Because nothing is stored on your device and nobody is identified, we rely on the statistical purposes exception in PECR rather than asking for your consent. If you would prefer that your visits were not counted at all, you can object at any time by emailing contact@cyberdefenceservice.co.uk.

Microsoft Clarity. With your consent, we use Microsoft Clarity, a behavioural analytics service provided by Microsoft. Clarity records how visitors interact with pages, including clicks, scrolling, mouse movement and navigation between pages, and turns this into heatmaps and anonymised session replays that show us where people struggle. Anything you type into a form is masked and is never sent to Microsoft. Clarity sets the cookies listed below. It runs only if you accept analytics cookies in our banner and it stops if you later withdraw your consent. Microsoft is a data controller in its own right for the information Clarity collects, and it uses some of these cookies, notably MUID, across its own websites for advertising, analytics and operational purposes, as described in the Microsoft Privacy Statement at privacy.microsoft.com. Microsoft deletes session replays after 30 days and heatmap and click data after nine months. Clarity data is held on Microsoft's Azure servers, which may be outside the UK (see section 7).

We use analytics to understand which pages are read, where visitors come from and whether the site works well on different devices. We use two tools, and they work in different ways.

Framer's built-in analytics. Framer, the platform that hosts the site, provides basic visitor statistics. It does not use cookies and stores nothing on your device. To count visits it combines your IP address and browser details with a secret value that Framer changes and deletes every day, so it cannot recognise you from one day to the next or across other websites, and we see only aggregate figures such as page views, referring sites, countries, browsers and device types. Because nothing is stored on your device and nobody is identified, we rely on the statistical purposes exception in PECR rather than asking for your consent. If you would prefer that your visits were not counted at all, you can object at any time by emailing contact@cyberdefenceservice.co.uk.

Microsoft Clarity. With your consent, we use Microsoft Clarity, a behavioural analytics service provided by Microsoft. Clarity records how visitors interact with pages, including clicks, scrolling, mouse movement and navigation between pages, and turns this into heatmaps and anonymised session replays that show us where people struggle. Anything you type into a form is masked and is never sent to Microsoft. Clarity sets the cookies listed below. It runs only if you accept analytics cookies in our banner and it stops if you later withdraw your consent. Microsoft is a data controller in its own right for the information Clarity collects, and it uses some of these cookies, notably MUID, across its own websites for advertising, analytics and operational purposes, as described in the Microsoft Privacy Statement at privacy.microsoft.com. Microsoft deletes session replays after 30 days and heatmap and click data after nine months. Clarity data is held on Microsoft's Azure servers, which may be outside the UK (see section 7).

Name

Set by

What it does

Type

How long it lasts

_clck

Microsoft Clarity

Stores a Clarity user ID and preferences that are unique to this site, so that visits from the same browser are attributed to the same anonymous user

First party

1 year

_clck

Microsoft Clarity

Links the pages viewed during a single visit into one session replay

First party

1 day

CLID

Microsoft (clarity.ms)

Records when Clarity first saw this browser on any website that uses Clarity

Third party

1 year

ANONCHK

Microsoft (c.clarity.ms)

Indicates whether the MUID identifier is transferred to ANID, a Microsoft advertising cookie. Clarity does not use ANID, so this is always set to 0

Third party

10 minutes

MR

Microsoft (c.clarity.ms and c.bing.com)

Indicates whether the MUID identifier should be refreshed

Third party

7 days

MUID

Microsoft (clarity.ms and bing.com)

Identifies unique web browsers visiting Microsoft websites. Microsoft uses it for advertising, site analytics and other operational purposes across its services

Third party

1 year

SM

Microsoft (c.clarity.ms)

Synchronises the MUID identifier across Microsoft domains

Third party

Session

4.3 Preferences and marketing

We do not use preference cookies, which remember settings such as language or layout, or marketing cookies, which build a profile of your interests or measure advertising. If that changes we will update this policy and ask for your consent before any such cookie is set.

We do not use preference cookies, which remember settings such as language or layout, or marketing cookies, which build a profile of your interests or measure advertising. If that changes we will update this policy and ask for your consent before any such cookie is set.

4.4 Other technologies that store nothing on your device

A few things happen when you load a page that involve other organisations but do not set cookies or store anything on your device. We describe them here so that you have the full picture.

Hosting and content delivery. The site's pages, images and code are delivered by Framer and its content delivery network, Amazon CloudFront. Their servers see your IP address and the pages you request as part of delivering them, and keep short-term technical logs for security and reliability, as described in our Privacy Policy.

Fonts. The site's typefaces are loaded from Google Fonts. Your browser requests the font files from Google's servers, which receive your IP address and browser details in the process. Google states that these requests are unauthenticated, involve no cookies and are kept separate from any Google account, and that the service is designed to limit the collection, storage and use of visitor data to what is needed to serve fonts efficiently, with only aggregate figures about the popularity of each font being kept. This falls within the PECR exception for adapting the appearance of a website.

Contact form. Our contact form is provided by Framer. Submitting it sends us what you have typed and does not set cookies. What we do with your enquiry is explained in our Privacy Policy.

A few things happen when you load a page that involve other organisations but do not set cookies or store anything on your device. We describe them here so that you have the full picture.

Hosting and content delivery. The site's pages, images and code are delivered by Framer and its content delivery network, Amazon CloudFront. Their servers see your IP address and the pages you request as part of delivering them, and keep short-term technical logs for security and reliability, as described in our Privacy Policy.

Fonts. The site's typefaces are loaded from Google Fonts. Your browser requests the font files from Google's servers, which receive your IP address and browser details in the process. Google states that these requests are unauthenticated, involve no cookies and are kept separate from any Google account, and that the service is designed to limit the collection, storage and use of visitor data to what is needed to serve fonts efficiently, with only aggregate figures about the popularity of each font being kept. This falls within the PECR exception for adapting the appearance of a website.

Contact form. Our contact form is provided by Framer. Submitting it sends us what you have typed and does not set cookies. What we do with your enquiry is explained in our Privacy Policy.

  1. Links, social media and embedded content

The site links to other websites, including our product sites, our LinkedIn, Instagram and X profiles and a Google Maps link for our office. These are ordinary links rather than embedded plug-ins, so nothing is set on your device until you click through, at which point the other site's own cookie and privacy policies apply. We do not currently embed videos, maps or social media feeds from third parties. If we do so in future we will update this policy and, where the law requires it, ask for your consent before the content loads.

The site links to other websites, including our product sites, our LinkedIn, Instagram and X profiles and a Google Maps link for our office. These are ordinary links rather than embedded plug-ins, so nothing is set on your device until you click through, at which point the other site's own cookie and privacy policies apply. We do not currently embed videos, maps or social media feeds from third parties. If we do so in future we will update this policy and, where the law requires it, ask for your consent before the content loads.

  1. How to control cookies

Our banner. On your first visit the banner offers you the choice to accept or reject the cookies that need your consent. Strictly necessary entries are always on. If you reject, or do not respond, only strictly necessary entries are used.

Changing your mind. You can revisit your choice at any time using the Cookie Settings link in the footer of every page. Withdrawing consent stops the relevant cookies being set or read from then on. Cookies already on your device remain until they expire or you delete them, which you can do through your browser.

Your browser. Most browsers let you see which cookies are stored, delete them individually or all at once, and block cookies from particular sites or from all sites. Instructions for the most common browsers are published by their makers: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. Blocking all cookies may stop parts of the site, and of other websites, working properly.

Microsoft. Because Microsoft uses the MUID cookie across its own services, you can also manage Microsoft's use of your data for personalised advertising at account.microsoft.com/privacy/ad-settings.

Browser signals. Some browsers can send a Do Not Track or Global Privacy Control signal. UK law does not yet set out how websites must respond to these signals and the site does not currently act on them, so please use the banner and the Cookie Settings link to record your choice.

Our banner. On your first visit the banner offers you the choice to accept or reject the cookies that need your consent. Strictly necessary entries are always on. If you reject, or do not respond, only strictly necessary entries are used.

Changing your mind. You can revisit your choice at any time using the Cookie Settings link in the footer of every page. Withdrawing consent stops the relevant cookies being set or read from then on. Cookies already on your device remain until they expire or you delete them, which you can do through your browser.

Your browser. Most browsers let you see which cookies are stored, delete them individually or all at once, and block cookies from particular sites or from all sites. Instructions for the most common browsers are published by their makers: Google Chrome, Microsoft Edge, Mozilla Firefox and Apple Safari. Blocking all cookies may stop parts of the site, and of other websites, working properly.

Microsoft. Because Microsoft uses the MUID cookie across its own services, you can also manage Microsoft's use of your data for personalised advertising at account.microsoft.com/privacy/ad-settings.

Browser signals. Some browsers can send a Do Not Track or Global Privacy Control signal. UK law does not yet set out how websites must respond to these signals and the site does not currently act on them, so please use the banner and the Cookie Settings link to record your choice.

  1. Personal data, international transfers and retention

Most of the information collected through the cookies described above is technical and is not used to identify you by name. Some of it, such as your IP address and the identifiers held in cookies, is personal data under the UK GDPR because it could be combined with other information to single you out. Where that is the case, our lawful basis for processing it is your consent for the Microsoft Clarity cookies, and our legitimate interest in running, securing and improving the site for the strictly necessary entries, for Framer's cookieless statistics and for the technical data described in section 4.4.

Framer B.V. is based in the Netherlands and processes data on our behalf under a written contract. The UK Government recognises the European Economic Area as providing adequate protection for personal data, so no further safeguard is needed for that transfer. Microsoft processes Clarity data in the United States and other countries. For those transfers we rely on Microsoft's certification under the UK Extension to the EU-US Data Privacy Framework and, where that does not apply, on the ICO's international data transfer agreement or its addendum to the EU standard contractual clauses.

We keep the record of your cookie choice in your browser until you clear it or change it. Microsoft keeps Clarity session replays for 30 days and heatmap and click data for nine months. The aggregate statistics produced by Framer's analytics do not identify anyone and are kept for as long as they are useful to us.

Your rights over personal data, including the rights to withdraw consent, to object, to access a copy of your data and to have it erased, and how to exercise them, are set out in the Your rights section of our Privacy Policy.

Most of the information collected through the cookies described above is technical and is not used to identify you by name. Some of it, such as your IP address and the identifiers held in cookies, is personal data under the UK GDPR because it could be combined with other information to single you out. Where that is the case, our lawful basis for processing it is your consent for the Microsoft Clarity cookies, and our legitimate interest in running, securing and improving the site for the strictly necessary entries, for Framer's cookieless statistics and for the technical data described in section 4.4.

Framer B.V. is based in the Netherlands and processes data on our behalf under a written contract. The UK Government recognises the European Economic Area as providing adequate protection for personal data, so no further safeguard is needed for that transfer. Microsoft processes Clarity data in the United States and other countries. For those transfers we rely on Microsoft's certification under the UK Extension to the EU-US Data Privacy Framework and, where that does not apply, on the ICO's international data transfer agreement or its addendum to the EU standard contractual clauses.

We keep the record of your cookie choice in your browser until you clear it or change it. Microsoft keeps Clarity session replays for 30 days and heatmap and click data for nine months. The aggregate statistics produced by Framer's analytics do not identify anyone and are kept for as long as they are useful to us.

Your rights over personal data, including the rights to withdraw consent, to object, to access a copy of your data and to have it erased, and how to exercise them, are set out in the Your rights section of our Privacy Policy.

  1. Changes to this policy

We will update this policy when the cookies we use or the law changes. The current version, with its effective date and version number, will always be published on the site, and where a change means we need your consent again the banner will ask for it. This is the first standalone cookie policy for the site and it supplements our Privacy Policy dated 21 August 2026.

We will update this policy when the cookies we use or the law changes. The current version, with its effective date and version number, will always be published on the site, and where a change means we need your consent again the banner will ask for it. This is the first standalone cookie policy for the site and it supplements our Privacy Policy dated 21 August 2026.

  1. Contact and complaints

If you have a question about this policy or about cookies on the site, email contact@cyberdefenceservice.co.uk or write to Cyber Defence Service Ltd, Greater Manchester Digital Security Hub, 2nd Floor, Heron House, 1 Lincoln Square, Manchester, M2 5LN. If you wish to complain about the way we have handled your personal data you can do so by the same routes; we will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, although we would welcome the chance to put things right first.

If you have a question about this policy or about cookies on the site, email contact@cyberdefenceservice.co.uk or write to Cyber Defence Service Ltd, Greater Manchester Digital Security Hub, 2nd Floor, Heron House, 1 Lincoln Square, Manchester, M2 5LN. If you wish to complain about the way we have handled your personal data you can do so by the same routes; we will acknowledge your complaint within 30 days and tell you the outcome without undue delay. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, although we would welcome the chance to put things right first.

Effective date: 21 August 2026. Version 1.0.

Effective date: 21 August 2026. Version 1.0.

Ready to see what’s ahead?

Talk to our team and discover how we can strengthen your security posture.

© 2026 Cyber Defence Service Ltd

NCSC For Startups Alumni
HMGCC Accelerate Alumni
Cyber Runway Scale Alumni
Cyber Essentials Plus Certified

Registered no. 10290462

VAT GB341182528. NCAGE U1SZ6. D-U-N-S® Number: 221951035

Ready to see what’s ahead?

Talk to our team and discover how we can strengthen your security posture.

© 2026 Cyber Defence Service Ltd

NCSC For Startups Alumni
HMGCC Accelerate Alumni
Cyber Runway Scale Alumni
Cyber Essentials Plus Certified

Registered no. 10290462

VAT GB341182528. NCAGE U1SZ6. D-U-N-S® Number: 221951035

Ready to see what’s ahead?

Talk to our team and discover how we can strengthen your security posture.

© 2026 Cyber Defence Service Ltd

NCSC For Startups Alumni
HMGCC Accelerate Alumni
Cyber Runway Scale Alumni
Cyber Essentials Plus Certified

Registered no. 10290462

VAT GB341182528. NCAGE U1SZ6. D-U-N-S® Number: 221951035