1. Introduction
This Cookie Policy explains how Groundframe Ltd t/a The AI Practitioner (“AIP”, “we”, “us”, “our”) uses cookies and similar technologies on theaipractitioner.ai, and the choices available to you. It should be read together with our Privacy Policy (AIP-PS-001), which explains how we handle personal data more broadly.
It is a short policy, because there is not much to describe. theaipractitioner.ai is a straightforward website: it has no accounts, no cart, no saved preferences, no advertising, no marketing tags and no embedded third-party widgets. This policy is written to comply with the UK Privacy and Electronic Communications Regulations (PECR) and UK GDPR, and it is deliberately conditional about the future — if we introduce a technology that changes the position described here, Section 9 sets out what we will do before that happens.
2. We Do Not Use Cookies for Advertising or Tracking
Our commitment
AIP does not use cookies or similar technologies for advertising, behavioural profiling, cross-site tracking, or the sale of personal data.
If this ever changes, we will update this policy and obtain any consent required before the change takes effect.
3. Definitions
| Term | Definition |
|---|---|
| Cookie | A small text file placed on your device when you visit a website, used to make the site work, work more efficiently, or to provide information to the site owner. |
| First-party cookie | A cookie set directly by the website you are visiting. |
| Third-party cookie | A cookie set by a service used on the site, provided by an organisation other than the site owner. |
| Similar / storage-and-access technology | Any technology that stores information on, or accesses information from, your device — including pixels, local storage, session storage, and analytics beacons that do not use a traditional cookie file. |
| Cookieless | A technology that measures or functions without storing anything on, or reading anything from, your device. Cookieless does not mean no data is processed — see Section 10. |
| Consent | Your freely given, specific, informed and unambiguous agreement, given by a clear affirmative action, to a non-essential storage or access technology being used. |
| PECR | The Privacy and Electronic Communications Regulations, the UK law governing the use of cookies and similar technologies. |
| ICO | The Information Commissioner’s Office, the UK’s independent regulator for data protection and information rights. |
4. What Cookies and Similar Technologies Are
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, work more efficiently, and to provide information to the site owner. Some cookies are set directly by the site you are visiting (“first-party”); others are set by services the site uses (“third-party”).
Cookies are not the only way a site can store or read information on your device. Local storage, session storage, web beacons and pixels do the same kind of thing by other means, and UK law treats them the same way. This policy covers all of them.
5. How We Classify Them
We group cookies and similar technologies into four categories, in line with standard UK practice:
- Strictly necessary — required for the site to function; cannot be switched off; does not require consent.
- Analytics / performance — help us understand how visitors use the site; requires consent unless the tool is genuinely cookieless and does not identify individuals.
- Functional — remember choices you make; requires consent unless strictly necessary to a service you have actively requested.
- Marketing / advertising — used to track visitors for advertising purposes; see Section 2 — we do not use this category.
Before any new cookie or similar technology is deployed on theaipractitioner.ai, Tim Parkin, Director, classifies it against these four categories using current ICO guidance on PECR, adds it to the table at Section 6, and obtains consent where consent is required — all before it is switched on. This is the process described in Section 13.
6. What Is Actually in Use on theaipractitioner.ai
The table below reflects the technologies confirmed on the live site by the production verification described in Section 12.
| Technology | Provider | What it does | Stored on your device? | Consent needed? |
|---|---|---|---|---|
| Cloudflare Web Analytics | Cloudflare, Inc. | Aggregated measurement of site traffic and performance | No — cookieless; nothing is stored on or read from your device | No |
| Hosting, CDN and security | Cloudflare, Inc. | Serves the site and protects it from attack and abuse | No cookie is set in the current configuration | No — strictly necessary in any event |
| Web fonts (Fraunces, Plus Jakarta Sans) | Google Fonts | Serves the site’s typefaces to your browser from Google’s font infrastructure | No | No — but the external request is disclosed in Section 7.2 |
| Contact form | AIP, via the Cloudflare /api/contact endpoint | Receives your enquiry and passes it to our systems | No cookie is set | No |
Because no technology in the table stores or reads anything on your device that requires consent, there is nothing here for you to accept or reject. Section 8 explains why there is no cookie banner, and Section 10 explains why “cookieless” does not mean “no data is processed”.
A note on security cookies. Cloudflare provides our hosting and security. Its current configuration on our site sets no cookie. We are not going to promise that a security platform can never set a cookie in future — if we enable a security feature that does, this policy and the table above will be updated, and Section 9 governs what happens next.
6.1 Technologies Not Used
So that nothing is described by omission, the following are not in use on theaipractitioner.ai:
- Google Analytics or any other third-party analytics product — Cloudflare Web Analytics is the only analytics service, and no _ga, ga* or _gid cookies are set
- Advertising or marketing pixels, conversion tags and remarketing tags
- Social media embeds, share widgets and tracking buttons
- A newsletter sign-up form or email marketing service — AIP does not operate a mailing list
- An embedded booking widget — booking is a link out to a third-party page, see Section 7.1
- CAPTCHA or bot-challenge technology
- Local storage, session storage, web beacons and pixels
The contact form is protected from automated spam by a hidden field that genuine visitors never see or fill in. It stores nothing on your device and reads nothing from it, which is why no consent applies to it — but we would rather mention it than have you discover an unexplained field in the page and wonder what it does.
7. External Services and Links
Where we link out to a third party’s own website, no AIP cookie is involved — but that third party’s own privacy and cookie practices apply once you leave theaipractitioner.ai. AIP is not responsible for the privacy or cookie practices of any third-party website linked from our site, and we encourage you to review each site’s own policy before providing personal data or accepting its cookies.
7.1 Cal.com (Booking)
We use Cal.com to manage consultation bookings, currently through its European environment at Cal.eu. Our booking link takes you to Cal.com’s own hosted booking page; the booking interface is not embedded within theaipractitioner.ai. No AIP-side cookie is set by Cal.com. Once you are on Cal.com’s page, Cal.com’s own privacy policy and cookie practices govern that page, not this policy. If we ever embed the booking widget directly in our site — for example via an iframe — this policy will be updated to list any cookies it sets, and consent will be obtained where required before that change goes live.
7.2 Google Fonts
Our typefaces are served externally by Google Fonts rather than from our own server. When a page loads, your browser makes a request to Google’s font infrastructure, which involves your IP address in the same way as any external web request. This sets no cookie and stores nothing on your device, so it does not require consent under PECR. We disclose it because it is an external request that you would not otherwise know about, not because it is used to track you.
7.3 Provider Policies
For full detail, the relevant providers’ own policies are:
- Cloudflare — cloudflare.com/privacypolicy
- Google (including Google Fonts) — policies.google.com/privacy
- Cal.com — cal.com/privacy
8. Why There Is No Cookie Banner
There is no cookie banner on theaipractitioner.ai, and no cookie settings link in the footer. That is a deliberate and verified position, not an omission.
A consent banner exists to obtain consent for storage or access that requires it. The production verification described in Section 12 found no such technology on our site: nothing stores or reads information on your device beyond what is strictly necessary to serve you the page. With nothing to consent to, a banner would ask you to make a choice that has no effect, which is worse than not asking.
We do not treat continued browsing as consent to anything, because we are not relying on consent for anything. If that changes, Section 9 applies.
9. If We Introduce a Technology That Requires Consent
This section is a procedure, not a description of something already built. If AIP ever deploys a cookie or similar technology that requires consent, then before it is activated we will:
- Classify the technology against the categories in Section 5 and record what it stores, what it accesses and why
- Select and implement a consent mechanism that presents accept and reject with equal prominence, and that sets nothing non-essential before an affirmative choice is made
- Test that mechanism across major browsers and devices, including that rejecting is genuinely as easy as accepting, and that a refusal is honoured
- Provide a way to change or withdraw your choice at any time after it is given, and honour withdrawal going forward
- Record the minimum auditable evidence of consent — what was shown, what was chosen, when, and the version of this policy in force
- Update this policy, its version number and effective date, and publish the update before the technology goes live
Until all of those steps are complete, only genuinely cookieless technologies may be used on theaipractitioner.ai. No consent-management platform has been selected, because none is currently needed; one would be selected as part of the process above.
Withdrawing consent, once a consent mechanism exists, would stop the relevant technology being set or read on future visits and stop any associated third-party processing going forward. It could not retroactively undo processing that had already taken place — we cannot instruct a third party to un-process data it has already received.
10. Cookies and Personal Data Are Two Different Questions
It is worth being clear about a distinction that is easy to blur, and that we would rather state plainly than let you infer.
PECR governs storing or reading information on your device. That is the cookie question, and on theaipractitioner.ai the answer is that we do not do it beyond what is strictly necessary — which is why there is no banner.
UK GDPR governs the processing of personal data, wherever it comes from. That is a separate question with a different answer. Serving you a web page necessarily involves processing some data about the request — your IP address reaches our hosting provider, and reaches Google’s font infrastructure when your browser requests our typefaces. Cloudflare Web Analytics processes request data to produce aggregated statistics. None of that requires a cookie, and none of it identifies you to us as an individual, but it is still processing.
So “cookieless” means “nothing stored on your device”. It does not mean “no data is processed”. What is processed, why, on what lawful basis and for how long is set out in our Privacy Policy (AIP-PS-001).
11. Managing Cookies in Your Browser
Independently of anything on our site, you can control cookies through your browser: block them before they are set, delete ones already stored, or browse in a private or incognito window so that cookies from that session are discarded when you close it. Browser menus change often, so rather than reproduce menu paths that will go stale, here are the providers’ own current instructions:
- Google Chrome — support.google.com/chrome
- Apple Safari — support.apple.com
- Mozilla Firefox — support.mozilla.org
- Microsoft Edge — support.microsoft.com
Blocking or deleting cookies may affect how other websites function for you. It will not affect theaipractitioner.ai, because we do not rely on cookies to serve you the site.
12. Verification of the Live Site
The statements in this policy are based on a documented technical verification of the production site — an inspection of what is actually served and what is actually set, rather than an assumption about what the build was supposed to contain. That verification confirmed the position described in Sections 6 and 6.1, and the evidence is recorded in our internal Policy Evidence and Source Register.
A verification of this kind is only as current as the site it was run against. We therefore re-run it after any material change to the website or to a supplier whose technology appears in Section 6, and at each scheduled review of this policy. Where a re-scan finds something not described here, this policy is corrected — or the technology is removed — before the change is considered complete.
13. Technology Change Governance
Before we implement any new cookie or similar storage or access technology, we:
- Classify it against the categories at Section 5, and assess what it does, what it stores or accesses, and whether it is strictly necessary or non-essential
- Update this policy before the change takes effect
- Obtain consent where required, following the procedure in Section 9, before the technology is activated
- Update the version number, effective date and version history for this policy
- Re-run the verification described in Section 12
We also periodically reconcile this policy against the live website, to confirm that every technology listed is actually in use and that nothing in use is missing from the table, removing obsolete entries and assessing anything newly introduced.
14. Changes to This Policy
We may update this policy as our tools, services, or the law change. We distinguish between minor and material changes:
- Minor changes — corrections, clarifications, or updates that do not change what technologies are used or how consent is handled. The version number and version history are still updated.
- Material changes — introducing a new category of technology, changing the purpose of an existing one, adding or removing a non-essential technology, or otherwise changing what visitors would be asked to consent to. A material change is approved by Tim Parkin, Director, before publication, and triggers the consent process in Section 9 where consent is required. It is never rolled out as a silent update.
The version number and status shown in the document control table above reflect the current version. All changes, minor and material, are logged in the version history below.
14.1 What Changed at Version 1.0
Version 1.0 is the outcome of the fifth and final review in this cycle, applying the v0.4 to v1.0 Update Notes of 31 August 2026. This policy was substantially rewritten around the verified production configuration. The changes were:
- Placeholders replaced with confirmed technologies — Cloudflare hosting and Web Analytics, Google Fonts, and the site’s own contact-form endpoint.
- Acuity Scheduling replaced throughout by Cal.com/Cal.eu, described accurately as an external linked booking page rather than an embedded component.
- Newsletter references removed, because no newsletter service or sign-up form exists.
- Consent sections rewritten as a procedure. The banner, withdrawal link and consent log are no longer described as deployed; Section 9 sets out what happens if a consent-requiring technology is ever introduced, and Section 8 explains why no banner exists today.
- A new section distinguishing PECR from UK GDPR (Section 10), so that “cookieless” is not misread as “no data is processed”.
- Browser menu paths replaced with links to each browser’s own current support page, which do not go stale.
- Pre-launch verification gate removed and replaced with a completed production verification and a requirement to re-scan after material change.
- Company number corrected to 09715227, and all working-draft wording removed.
This version is approved by Director approval. No external legal review has been carried out.
14.2 Version History
| Version | Date | Author / Approver | Status | Summary of change |
|---|---|---|---|---|
| 0.1 | 12/Jul/2026 | Tim Parkin, Director | Working Draft | Initial working draft prepared for internal review. |
| 0.2 | 15/Jul/2026 | Tim Parkin, Director | Revised Working Draft | Added Definitions, the no-advertising commitment, the consent standard, technology-change governance, periodic review, duration disclosure and version history. |
| 0.3 | 17/Jul/2026 | Tim Parkin, Director | Revised Working Draft | Removed speculative analytics references; named the booking provider and clarified its linked-out status; broadened scope to local and session storage and web beacons; added a classification process and a publication-readiness gate. |
| 0.4 | 18/Jul/2026 | Tim Parkin, Director | Revised Working Draft | Reverted the technology table to placeholder wording pending final hosting and analytics selection; made consent logging conditional; strengthened the publication-readiness gate. |
| 1.0 | 31/Aug/2026 | Tim Parkin, Director | Approved | Fifth and final review. Published as Version 1.0, effective 1 September 2026. Changes are set out in full at Section 14.1. |
15. Cookie-Related Complaints
If you have a complaint about how we use cookies or similar technologies, please contact us first at info@theaipractitioner.ai so we can try to resolve it directly. If you remain unsatisfied, you have the right to complain to the UK’s independent regulator, the Information Commissioner’s Office, at ico.org.uk or by telephone on 0303 123 1113. This is the same complaints route set out in our Privacy Policy (AIP-PS-001).
16. Contact Us
Data Controller: Groundframe Ltd t/a The AI Practitioner (company number 09715227)
Privacy contact: Tim Parkin, Director
Email: info@theaipractitioner.ai
Post: 49 Station Road, Polegate, East Sussex, BN26 6EA, United Kingdom