LOADING…
Platform  /  Cookie Policy
COOKIE POLICY

Cookies,explained clearly.

How E2E Security Consulting uses cookies and similar technologies across our website and the E2ERisk platform - what each category does, when we ask for consent, and how to manage your choices.

Last updated: June 2026

1. Purpose

This Cookies Policy explains how E2E Security Consulting Ltd ("E2E SC", "we", "us" or "our") uses cookies and similar storage or access technologies on the E2E SC public website and the E2ERisk Platform.

The purpose of this policy is to give website visitors, customers, authorised users and invited third parties clear information about the technologies we use, why we use them, when consent is required, and how cookie preferences can be managed. It should be read alongside our Privacy Notice, which explains how we process personal data more generally. It does not replace any data processing agreement or customer contract applicable to the E2ERisk Platform.

2. Scope and application

This policy applies to cookies and similar technologies used on E2E SC websites, portals, customer-facing digital services and the E2ERisk Platform, including any subscribed modules made available to customers.

The E2ERisk Platform is a modular SaaS platform. Modules may include Supplier Assurance, Secure by Design, Threat Assessment, Business Impact Assessment, Data Protection / Privacy Impact Assessment, NCSC CAF, Governance Library, Risk Assessment and other modules made available from time to time. Cookies and similar technologies may vary depending on the features enabled, authentication method, support tools and integrations used.

3. Cookies and similar technologies

Cookies are small text files placed on, or read from, a device such as a computer, tablet or mobile phone when a person visits a website or uses an online service. Cookies are used to make websites and platforms work, remember preferences, keep users signed in, protect accounts and understand how services are used.

This policy also covers similar technologies that store information on, or access information from, a user device. These may include local storage, session storage, tracking pixels, tags, software development kits, device identifiers and scripts.

We do not use fingerprinting for advertising or cross-site tracking. Where device or browser signals are used for security, fraud prevention, authentication or service integrity, they are limited to those purposes and treated as strictly necessary where applicable.

4. Legal basis and consent

The Privacy and Electronic Communications Regulations (PECR) apply where cookies or similar technologies store information on, or access information from, a user device. PECR sits alongside the UK GDPR and Data Protection Act 2018. Where PECR applies, the PECR rules must be considered before the UK GDPR lawful basis for any associated personal data processing.

Strictly necessary cookies may be used without consent where they are essential to provide a service requested by the user, such as maintaining a secure logged-in session, remembering cookie preferences, protecting against security attacks, routing requests or supporting core platform functionality. Non-essential cookies, such as analytics, functional preference cookies and marketing cookies, are used only where consent is required and has been provided through the cookie banner or cookie settings tool. Consent can be withdrawn or changed at any time.

CategoryPurposeConsent required?UK GDPR lawful basis
Strictly necessaryEnable core website or platform functionality, security, authentication, consent management and service delivery.No, where the PECR strict necessity exception applies.Legitimate interests and/or performance of contract where applicable.
AnalyticsHelp us understand usage, performance and service improvement opportunities.Yes, unless a specific exemption applies and the technology is configured within that exemption.Consent where required.
FunctionalRemember optional preferences and support enhanced features.Yes, unless strictly necessary for a requested service.Consent where required.
MarketingSupport advertising, campaign measurement or remarketing on public websites or campaign pages.Yes.Consent.

5. Cookie categories used by E2E SC

The tables below describe the main categories of cookies and similar technologies used by E2E SC. Cookie names, providers and durations may change where services are updated, replaced or reconfigured. Current optional cookie choices are managed through the cookie banner or cookie settings tool where implemented.

5.1 Strictly necessary cookies

Strictly necessary cookies are essential for website and platform operation. They cannot be switched off through the cookie preference tool because the website or platform cannot function properly without them. These cookies are not used for advertising.

Cookie / technologyProviderTypeDurationPurpose
e2e_sessionE2E SCSessionSessionMaintains a secure user session while using the website or E2ERisk Platform.
csrf_tokenE2E SCSessionSessionProtects forms and platform requests against cross-site request forgery.
cookie_consentE2E SC / consent toolPersistentUp to 12 monthsRecords cookie consent preferences.
lb_stickyE2E SC / hosting providerSessionSessionSupports load balancing and routes requests to the appropriate service instance.
sec_ctxE2E SCSessionSessionSupports authentication, API security and platform session integrity.
auth_state / mfa_stateE2E SC / identity providerSession or persistentSession or configured periodSupports secure sign-in, multi-factor authentication and account protection.

5.2 Analytics cookies

Analytics cookies help us understand how the public website and, where enabled, the platform are used, to improve performance, content, usability and reliability. They are only set where consent is required and has been provided. Where used, we configure analytics tools to minimise personal data where practicable, including aggregation, restricted retention and IP masking or equivalent privacy settings where supported.

Cookie / technologyProviderTypeDurationPurpose
_gaGoogle Analytics, where enabledPersistentUp to 2 yearsDistinguishes users for aggregate analytics.
_ga_*Google Analytics, where enabledPersistentUp to 2 yearsMaintains Google Analytics 4 session state.
_gidGoogle Analytics, where enabledPersistentUp to 24 hoursDistinguishes users for short-term analytics.
_gatGoogle Analytics, where enabledPersistentUp to 1 minuteThrottles analytics request rates.
hjSession / hjSessionUserHotjar or similar, where enabledSession or persistent30 minutes to 1 yearSupports consented user-experience analytics such as heatmaps or session analytics.

5.3 Functional cookies

Functional cookies remember optional choices, preferences and feature states to support a more consistent user experience. They are only used where consent is required and has been provided, unless the relevant function is strictly necessary for a service requested by the user.

Cookie / technologyProviderTypeDurationPurpose
e2e_prefsE2E SCPersistentUp to 6 monthsStores optional display, notification or interface preferences.
e2e_regionE2E SCPersistentUp to 12 monthsRemembers selected region, locale or site preference.
intercom-id-*Intercom or support provider, where enabledPersistentUp to 9 monthsIdentifies a browser or user for support chat functionality.
intercom-sessionIntercom or support provider, where enabledPersistentUp to 1 weekMaintains support chat session continuity.

5.4 Marketing cookies

Marketing cookies may be used on public websites or campaign pages to measure campaign performance, support advertising and understand referral sources. They are not required to access the E2ERisk Platform and are not used within authenticated platform areas unless expressly stated and consented to.

Cookie / technologyProviderTypeDurationPurpose
_fbp / _fbcMeta, where enabledPersistentUp to 3 months / 2 yearsSupports advertising measurement and conversion tracking.
li_fat_idLinkedIn, where enabledPersistentUp to 30 daysSupports LinkedIn campaign conversion tracking.
AnalyticsSyncHistory / UserMatchHistoryLinkedIn, where enabledPersistentUp to 30 daysSupports LinkedIn ads synchronisation and measurement.
_uetsid / _uetvidMicrosoft Ads, where enabledSession or persistentSession to 16 daysSupports Microsoft advertising measurement and conversion tracking.

6. Cookies in the E2ERisk Platform

When users sign in to the E2ERisk Platform, strictly necessary cookies and similar technologies are used to authenticate users, maintain sessions, protect accounts, prevent fraud, preserve platform security, route traffic, enforce access controls and support core platform functionality.

The platform may process operational events, access logs, audit logs and security signals. These are distinct from optional marketing cookies and are required to provide a secure SaaS service, maintain tenant separation, investigate security events and support customer auditability. Optional analytics or support technologies in the authenticated platform are used only where configured, lawful and appropriate. E2E SC does not use authenticated platform activity for third-party advertising.

7. Managing cookie preferences

Where optional cookies are used, the cookie banner or cookie settings tool allows users to accept all optional cookies, reject non-essential cookies, or manage choices by category. Strictly necessary cookies remain enabled because they are required for the requested website or platform service.

Cookie choices are normally stored for up to 12 months, after which users may be asked to confirm preferences again. Users may also be asked again if they clear browser cookies, use a different device or browser, or if E2E SC materially changes the cookies used. You can also manage cookies through browser settings, including blocking cookies, deleting cookies, blocking third-party cookies or clearing cookies when the browser closes. Some features may not operate correctly if strictly necessary cookies are blocked.

8. Third-party technologies and integrations

E2E SC may use third-party technologies to provide analytics, hosting, identity, customer support, communications, advertising measurement or security functions. Third parties may set their own cookies where their services are embedded or used, subject to consent requirements where applicable. We periodically review third-party technologies and update this policy or the cookie settings tool where material changes are made. Where third-party processing involves personal data, we manage this through appropriate contractual, security and transfer arrangements as described in the Privacy Notice and, where applicable, the customer data processing agreement.

9. Cookies and children

The E2E SC website and E2ERisk Platform are intended for business, public-sector, supplier assurance, governance, risk, security and compliance purposes. They are not directed at children. Platform users must be authorised by their organisation or by E2E SC.

10. Retention of cookie data

Cookie durations vary depending on the purpose of the cookie. Session cookies expire when the browser session ends. Persistent cookies remain for a defined period or until deleted by the user. Cookie-derived personal data is retained only for as long as necessary for the relevant purpose, subject to the Privacy Notice and applicable retention procedures.

Cookie categoryGeneral retention approach
Strictly necessarySession duration or configured period required for security, consent records or service operation, usually up to 12 months for consent records.
AnalyticsAggregate or pseudonymous analytics retained according to the analytics configuration, normally no longer than necessary for service improvement and reporting.
FunctionalRetained for the duration needed to remember the relevant preference or feature setting.
MarketingRetained according to the advertising provider configuration and only where consent has been provided.

11. Your rights

Where cookies or similar technologies involve personal data, individuals have the rights described in the E2E SC Privacy Notice. These may include rights of access, rectification, erasure, restriction, objection and data portability, depending on the context and legal basis. Individuals may also complain to the Information Commissioner's Office (ICO) at ico.org.uk.

12. Changes to this policy

We review this Cookies Policy periodically and may update it to reflect changes in cookies, platform functionality, third-party services, legal requirements or regulatory guidance. The date above indicates when this policy was last revised. Where changes are material, we may notify users through the cookie banner, website notice, platform notification, customer communication or other appropriate method.

13. Contact us

Contact pointDetails
Emailprivacy@e2esc.co.uk
Websitewww.e2esc.co.uk
OrganisationE2E Security Consulting Ltd (company no. 16563415)
Postal addressData Protection, E2E Security Consulting Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

Governed by UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended.