THE AI PRACTITIONER
← All policies

Cookie Policy

Reference
AIP-PS-002 · Version 1.0
Effective
1 September 2026
Owner
Tim Parkin, Director
Next review
1 September 2027, or sooner on material change, and after any material website or supplier change
Applies to
theaipractitioner.ai and any cookies or similar technologies it uses

1. Introduction

This Cookie Policy explains how Groundframe Ltd t/a The AI Practitioner (“AIP”, “we”, “us”, “our”) uses cookies and similar technologies on theaipractitioner.ai, and the choices available to you. It should be read together with our Privacy Policy (AIP-PS-001), which explains how we handle personal data more broadly.

It is a short policy, because there is not much to describe. theaipractitioner.ai is a straightforward website: it has no accounts, no cart, no saved preferences, no advertising, no marketing tags and no embedded third-party widgets. This policy is written to comply with the UK Privacy and Electronic Communications Regulations (PECR) and UK GDPR, and it is deliberately conditional about the future — if we introduce a technology that changes the position described here, Section 9 sets out what we will do before that happens.

2. We Do Not Use Cookies for Advertising or Tracking

Our commitment

AIP does not use cookies or similar technologies for advertising, behavioural profiling, cross-site tracking, or the sale of personal data.

If this ever changes, we will update this policy and obtain any consent required before the change takes effect.

3. Definitions

TermDefinition
CookieA small text file placed on your device when you visit a website, used to make the site work, work more efficiently, or to provide information to the site owner.
First-party cookieA cookie set directly by the website you are visiting.
Third-party cookieA cookie set by a service used on the site, provided by an organisation other than the site owner.
Similar / storage-and-access technologyAny technology that stores information on, or accesses information from, your device — including pixels, local storage, session storage, and analytics beacons that do not use a traditional cookie file.
CookielessA technology that measures or functions without storing anything on, or reading anything from, your device. Cookieless does not mean no data is processed — see Section 10.
ConsentYour freely given, specific, informed and unambiguous agreement, given by a clear affirmative action, to a non-essential storage or access technology being used.
PECRThe Privacy and Electronic Communications Regulations, the UK law governing the use of cookies and similar technologies.
ICOThe Information Commissioner’s Office, the UK’s independent regulator for data protection and information rights.

4. What Cookies and Similar Technologies Are

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work, work more efficiently, and to provide information to the site owner. Some cookies are set directly by the site you are visiting (“first-party”); others are set by services the site uses (“third-party”).

Cookies are not the only way a site can store or read information on your device. Local storage, session storage, web beacons and pixels do the same kind of thing by other means, and UK law treats them the same way. This policy covers all of them.

5. How We Classify Them

We group cookies and similar technologies into four categories, in line with standard UK practice:

  • Strictly necessary — required for the site to function; cannot be switched off; does not require consent.
  • Analytics / performance — help us understand how visitors use the site; requires consent unless the tool is genuinely cookieless and does not identify individuals.
  • Functional — remember choices you make; requires consent unless strictly necessary to a service you have actively requested.
  • Marketing / advertising — used to track visitors for advertising purposes; see Section 2 — we do not use this category.

Before any new cookie or similar technology is deployed on theaipractitioner.ai, Tim Parkin, Director, classifies it against these four categories using current ICO guidance on PECR, adds it to the table at Section 6, and obtains consent where consent is required — all before it is switched on. This is the process described in Section 13.

6. What Is Actually in Use on theaipractitioner.ai

The table below reflects the technologies confirmed on the live site by the production verification described in Section 12.

TechnologyProviderWhat it doesStored on your device?Consent needed?
Cloudflare Web AnalyticsCloudflare, Inc.Aggregated measurement of site traffic and performanceNo — cookieless; nothing is stored on or read from your deviceNo
Hosting, CDN and securityCloudflare, Inc.Serves the site and protects it from attack and abuseNo cookie is set in the current configurationNo — strictly necessary in any event
Web fonts (Fraunces, Plus Jakarta Sans)Google FontsServes the site’s typefaces to your browser from Google’s font infrastructureNoNo — but the external request is disclosed in Section 7.2
Contact formAIP, via the Cloudflare /api/contact endpointReceives your enquiry and passes it to our systemsNo cookie is setNo

Because no technology in the table stores or reads anything on your device that requires consent, there is nothing here for you to accept or reject. Section 8 explains why there is no cookie banner, and Section 10 explains why “cookieless” does not mean “no data is processed”.

A note on security cookies. Cloudflare provides our hosting and security. Its current configuration on our site sets no cookie. We are not going to promise that a security platform can never set a cookie in future — if we enable a security feature that does, this policy and the table above will be updated, and Section 9 governs what happens next.

6.1 Technologies Not Used

So that nothing is described by omission, the following are not in use on theaipractitioner.ai:

  • Google Analytics or any other third-party analytics product — Cloudflare Web Analytics is the only analytics service, and no _ga, ga* or _gid cookies are set
  • Advertising or marketing pixels, conversion tags and remarketing tags
  • Social media embeds, share widgets and tracking buttons
  • A newsletter sign-up form or email marketing service — AIP does not operate a mailing list
  • An embedded booking widget — booking is a link out to a third-party page, see Section 7.1
  • CAPTCHA or bot-challenge technology
  • Local storage, session storage, web beacons and pixels

The contact form is protected from automated spam by a hidden field that genuine visitors never see or fill in. It stores nothing on your device and reads nothing from it, which is why no consent applies to it — but we would rather mention it than have you discover an unexplained field in the page and wonder what it does.

Where we link out to a third party’s own website, no AIP cookie is involved — but that third party’s own privacy and cookie practices apply once you leave theaipractitioner.ai. AIP is not responsible for the privacy or cookie practices of any third-party website linked from our site, and we encourage you to review each site’s own policy before providing personal data or accepting its cookies.

7.1 Cal.com (Booking)

We use Cal.com to manage consultation bookings, currently through its European environment at Cal.eu. Our booking link takes you to Cal.com’s own hosted booking page; the booking interface is not embedded within theaipractitioner.ai. No AIP-side cookie is set by Cal.com. Once you are on Cal.com’s page, Cal.com’s own privacy policy and cookie practices govern that page, not this policy. If we ever embed the booking widget directly in our site — for example via an iframe — this policy will be updated to list any cookies it sets, and consent will be obtained where required before that change goes live.

7.2 Google Fonts

Our typefaces are served externally by Google Fonts rather than from our own server. When a page loads, your browser makes a request to Google’s font infrastructure, which involves your IP address in the same way as any external web request. This sets no cookie and stores nothing on your device, so it does not require consent under PECR. We disclose it because it is an external request that you would not otherwise know about, not because it is used to track you.

7.3 Provider Policies

For full detail, the relevant providers’ own policies are:

There is no cookie banner on theaipractitioner.ai, and no cookie settings link in the footer. That is a deliberate and verified position, not an omission.

A consent banner exists to obtain consent for storage or access that requires it. The production verification described in Section 12 found no such technology on our site: nothing stores or reads information on your device beyond what is strictly necessary to serve you the page. With nothing to consent to, a banner would ask you to make a choice that has no effect, which is worse than not asking.

We do not treat continued browsing as consent to anything, because we are not relying on consent for anything. If that changes, Section 9 applies.

This section is a procedure, not a description of something already built. If AIP ever deploys a cookie or similar technology that requires consent, then before it is activated we will:

  • Classify the technology against the categories in Section 5 and record what it stores, what it accesses and why
  • Select and implement a consent mechanism that presents accept and reject with equal prominence, and that sets nothing non-essential before an affirmative choice is made
  • Test that mechanism across major browsers and devices, including that rejecting is genuinely as easy as accepting, and that a refusal is honoured
  • Provide a way to change or withdraw your choice at any time after it is given, and honour withdrawal going forward
  • Record the minimum auditable evidence of consent — what was shown, what was chosen, when, and the version of this policy in force
  • Update this policy, its version number and effective date, and publish the update before the technology goes live

Until all of those steps are complete, only genuinely cookieless technologies may be used on theaipractitioner.ai. No consent-management platform has been selected, because none is currently needed; one would be selected as part of the process above.

Withdrawing consent, once a consent mechanism exists, would stop the relevant technology being set or read on future visits and stop any associated third-party processing going forward. It could not retroactively undo processing that had already taken place — we cannot instruct a third party to un-process data it has already received.

10. Cookies and Personal Data Are Two Different Questions

It is worth being clear about a distinction that is easy to blur, and that we would rather state plainly than let you infer.

PECR governs storing or reading information on your device. That is the cookie question, and on theaipractitioner.ai the answer is that we do not do it beyond what is strictly necessary — which is why there is no banner.

UK GDPR governs the processing of personal data, wherever it comes from. That is a separate question with a different answer. Serving you a web page necessarily involves processing some data about the request — your IP address reaches our hosting provider, and reaches Google’s font infrastructure when your browser requests our typefaces. Cloudflare Web Analytics processes request data to produce aggregated statistics. None of that requires a cookie, and none of it identifies you to us as an individual, but it is still processing.

So “cookieless” means “nothing stored on your device”. It does not mean “no data is processed”. What is processed, why, on what lawful basis and for how long is set out in our Privacy Policy (AIP-PS-001).

11. Managing Cookies in Your Browser

Independently of anything on our site, you can control cookies through your browser: block them before they are set, delete ones already stored, or browse in a private or incognito window so that cookies from that session are discarded when you close it. Browser menus change often, so rather than reproduce menu paths that will go stale, here are the providers’ own current instructions:

Blocking or deleting cookies may affect how other websites function for you. It will not affect theaipractitioner.ai, because we do not rely on cookies to serve you the site.

12. Verification of the Live Site

The statements in this policy are based on a documented technical verification of the production site — an inspection of what is actually served and what is actually set, rather than an assumption about what the build was supposed to contain. That verification confirmed the position described in Sections 6 and 6.1, and the evidence is recorded in our internal Policy Evidence and Source Register.

A verification of this kind is only as current as the site it was run against. We therefore re-run it after any material change to the website or to a supplier whose technology appears in Section 6, and at each scheduled review of this policy. Where a re-scan finds something not described here, this policy is corrected — or the technology is removed — before the change is considered complete.

13. Technology Change Governance

Before we implement any new cookie or similar storage or access technology, we:

  • Classify it against the categories at Section 5, and assess what it does, what it stores or accesses, and whether it is strictly necessary or non-essential
  • Update this policy before the change takes effect
  • Obtain consent where required, following the procedure in Section 9, before the technology is activated
  • Update the version number, effective date and version history for this policy
  • Re-run the verification described in Section 12

We also periodically reconcile this policy against the live website, to confirm that every technology listed is actually in use and that nothing in use is missing from the table, removing obsolete entries and assessing anything newly introduced.

14. Changes to This Policy

We may update this policy as our tools, services, or the law change. We distinguish between minor and material changes:

  • Minor changes — corrections, clarifications, or updates that do not change what technologies are used or how consent is handled. The version number and version history are still updated.
  • Material changes — introducing a new category of technology, changing the purpose of an existing one, adding or removing a non-essential technology, or otherwise changing what visitors would be asked to consent to. A material change is approved by Tim Parkin, Director, before publication, and triggers the consent process in Section 9 where consent is required. It is never rolled out as a silent update.

The version number and status shown in the document control table above reflect the current version. All changes, minor and material, are logged in the version history below.

14.1 What Changed at Version 1.0

Version 1.0 is the outcome of the fifth and final review in this cycle, applying the v0.4 to v1.0 Update Notes of 31 August 2026. This policy was substantially rewritten around the verified production configuration. The changes were:

  • Placeholders replaced with confirmed technologies — Cloudflare hosting and Web Analytics, Google Fonts, and the site’s own contact-form endpoint.
  • Acuity Scheduling replaced throughout by Cal.com/Cal.eu, described accurately as an external linked booking page rather than an embedded component.
  • Newsletter references removed, because no newsletter service or sign-up form exists.
  • Consent sections rewritten as a procedure. The banner, withdrawal link and consent log are no longer described as deployed; Section 9 sets out what happens if a consent-requiring technology is ever introduced, and Section 8 explains why no banner exists today.
  • A new section distinguishing PECR from UK GDPR (Section 10), so that “cookieless” is not misread as “no data is processed”.
  • Browser menu paths replaced with links to each browser’s own current support page, which do not go stale.
  • Pre-launch verification gate removed and replaced with a completed production verification and a requirement to re-scan after material change.
  • Company number corrected to 09715227, and all working-draft wording removed.

This version is approved by Director approval. No external legal review has been carried out.

14.2 Version History

VersionDateAuthor / ApproverStatusSummary of change
0.112/Jul/2026Tim Parkin, DirectorWorking DraftInitial working draft prepared for internal review.
0.215/Jul/2026Tim Parkin, DirectorRevised Working DraftAdded Definitions, the no-advertising commitment, the consent standard, technology-change governance, periodic review, duration disclosure and version history.
0.317/Jul/2026Tim Parkin, DirectorRevised Working DraftRemoved speculative analytics references; named the booking provider and clarified its linked-out status; broadened scope to local and session storage and web beacons; added a classification process and a publication-readiness gate.
0.418/Jul/2026Tim Parkin, DirectorRevised Working DraftReverted the technology table to placeholder wording pending final hosting and analytics selection; made consent logging conditional; strengthened the publication-readiness gate.
1.031/Aug/2026Tim Parkin, DirectorApprovedFifth and final review. Published as Version 1.0, effective 1 September 2026. Changes are set out in full at Section 14.1.

If you have a complaint about how we use cookies or similar technologies, please contact us first at info@theaipractitioner.ai so we can try to resolve it directly. If you remain unsatisfied, you have the right to complain to the UK’s independent regulator, the Information Commissioner’s Office, at ico.org.uk or by telephone on 0303 123 1113. This is the same complaints route set out in our Privacy Policy (AIP-PS-001).

16. Contact Us

Data Controller: Groundframe Ltd t/a The AI Practitioner (company number 09715227)

Privacy contact: Tim Parkin, Director

Email: info@theaipractitioner.ai

Post: 49 Station Road, Polegate, East Sussex, BN26 6EA, United Kingdom

This policy is published by Groundframe Ltd, registered in England and Wales, company number 09715227. Questions about it go to info@theaipractitioner.ai.