Cookie and Storage Notice

What Proof stores or accesses on your device, why it is used and how you can control it.

Version 1.0Effective 27 August 2026Last reviewed 27 August 2026PROOF AG LTD

NecessaryUsed to operate and secure Proof.
StatisticalUsed only for qualifying aggregate service improvement. You can object. None currently runs.
Appearance and functionalityUsed where needed to remember or apply requested preferences. You can object where required. None currently runs.
OptionalOff until you choose to enable them. Proof currently uses none.

Proof does not use advertising or cross-site behavioural tracking.

This notice explains how proof.ag and browser-based Proof services use cookies and other technologies that store information on, or access information from, your device.

We use only the technologies needed to operate, secure and improve Proof, remember choices you make and provide functionality you request.

Proof does not use advertising cookies, cross-site behavioural tracking or advertising profiles.

1. What this notice covers

This notice applies to storage and access technologies used on:

  • proof.ag;
  • pages hosted by Proof;
  • browser-based Proof applications that link to this notice;
  • forms and services embedded directly into Proof pages.

It covers more than traditional cookies.

Storage and access technologies can include:

  • cookies;
  • local storage;
  • session storage;
  • scripts and tags;
  • tracking pixels;
  • link-decoration technologies;
  • device or browser information;
  • similar technologies that store information on, or access information from, a device.

Where one of these technologies also processes personal information, the relevant Proof privacy notice also applies.

2. Our approach

Proof follows four rules.

Use less

We do not add a tracking technology merely because it is commonly used by websites.

Explain what is used

The current technology inventory on this page identifies what Proof uses, why it is used and how long it operates.

Give people meaningful control

Where consent is required, the technology remains disabled until you choose to allow it.

Where Proof relies on an exception that requires a right to object, we provide a simple and free way to turn that use off.

Do not turn website behaviour into a product

Proof does not sell browsing information or use it to create advertising profiles.

5. The technologies Proof uses

This is the authoritative inventory of storage and access technologies used by Proof.

It reflects an audit of every page of this website carried out on 27 August 2026, and is re-verified against the deployed site before every material release.

Strictly necessary

Cloudflare TurnstileNecessary
NameCloudflare Turnstile (turnstile/v0/api.js)
ProviderCloudflare, Inc., acting for Proof. Third party.
PurposeDistinguishes people from automated abuse so that a Contact, Careers, Record enquiry, Data protection complaint or security report form submission can be accepted.
TypeScript with short-lived challenge state on the device.
Where it runsOn the Contact and Careers pages, and on the Proof Record Rules, Data Protection Complaints and Security pages only when the relevant form is opened or used. It is not loaded anywhere else on proof.ag.
InformationBrowser and device characteristics needed to assess whether the visitor is a person, and a short-lived challenge token.
DurationThe challenge token expires after a few minutes. Proof sets no long-lived identifier.
PECR treatmentStrictly necessary. The technology loads only where a form exists and its sole purpose is protecting the submission service the visitor is using.
How to control itBlocking it in your browser prevents form submission. The forms explain the protection, and ct@proof.ag remains available as an alternative route.

Proof’s own pages set no cookies and use no browser storage. There are currently no first-party cookies, no local storage, no session storage, no tracking pixels and no analytics scripts on proof.ag.

The hosting platform can apply its own security measures at the network edge. A scan of the deployed site confirms whether any storage is involved, and this inventory is corrected before the affected release goes live.

These technologies cannot be switched off through Proof’s privacy controls where they are genuinely necessary to provide a requested service.

You can still block them using your browser, but parts of the service may stop working.

Statistical

None currently used.

Proof runs no statistical measurement on proof.ag.

If qualifying statistical technologies are introduced, each one will be listed here and an Object to statistical measurement control will be available in Privacy settings at all times, before measurement starts. Using it will switch that measurement off.

Appearance and functionality

None currently used.

If such technologies are introduced, each one will be listed here and, where an objection choice is required, an Object to optional appearance and functionality storage control will be available in Privacy settings before use begins.

Consent-based technologies

None.

Proof currently uses no technology that requires consent, so nothing is waiting for your permission.

Any technology that requires consent must remain off until permission is given.

6. Technologies Proof does not use

Unless this notice is updated before the technology is introduced, Proof does not use:

  • advertising cookies;
  • Meta Pixel;
  • LinkedIn Insight Tag;
  • X advertising pixels;
  • Google Ads conversion tracking;
  • cross-site behavioural tracking;
  • advertising retargeting;
  • third-party advertising profiles;
  • device fingerprinting for advertising;
  • session replay used to monitor identifiable visitors;
  • social-media tracking widgets that automatically transmit browsing activity;
  • data-broker tracking.

Links to Proof’s LinkedIn and X profiles are ordinary external links.

They do not load LinkedIn or X tracking code merely because the visitor views a Proof page.

7. Analytics

Proof may use privacy-conscious analytics to understand whether the website and services are useful. No analytics currently run on proof.ag.

Where Proof relies on the statistical-purpose exception rather than consent:

  • measurement must be limited to service improvement;
  • the provider must act on Proof’s behalf;
  • outputs must be aggregate;
  • identifiable visitor profiles must not be created;
  • analytics information must not be reused for advertising;
  • individual-level information must not be retained after it is needed for aggregation;
  • Proof must provide an easy objection mechanism.

If an analytics configuration does not meet those conditions, Proof must obtain consent before enabling it.

What Proof may measure

Examples include:

  • total page views;
  • popular pages;
  • general paths through the website;
  • average engagement;
  • device and browser categories;
  • page performance;
  • errors;
  • broad referral sources.

What Proof does not use analytics for

Proof does not use website analytics to:

  • identify which individual farmer viewed a page;
  • infer agricultural interests about an individual;
  • build sales scores;
  • create advertising audiences;
  • monitor a named person across the internet;
  • decide whether someone receives a particular commercial offer.

8. Privacy settings

You can review and change your Proof privacy settings at any time.

The panel shows:

Necessary

Always active where genuinely necessary.

Statistical

Where Proof relies on the statistical-purpose exception, the control shown here is an objection control rather than a consent request.

No statistical measurement currently runs, so there is nothing to object to yet. The control appears before any measurement starts.

Appearance and functionality

An objection control appears here where an objection choice is required. None is currently needed.

Optional technologies

Off by default. Enabled only after valid consent. Proof currently uses none.

Changing your choice will always be as straightforward as making it.

Proof applies a changed preference without requiring you to create an account or provide an email address.

9. Remembering your privacy choice

Proof may store a limited preference record so that it can remember the privacy choice made on that browser.

The preference record may contain:

  • the categories selected;
  • the version of the privacy controls shown;
  • the date or time of the choice.

It must not be repurposed for advertising or visitor profiling.

Because no optional or statistical technology currently runs, there is no choice to remember and no preference record is currently stored.

Proof may ask again where:

  • the preference expires;
  • the technology use materially changes;
  • the law requires a new choice;
  • Proof can no longer reliably determine what the earlier choice covered.

10. Embedded content

Proof avoids third-party embedded content that automatically sends information to another company when a page loads. Apart from the form-protection service listed inthe inventory, no third-party content is embedded in proof.ag pages.

Where third-party content is useful, Proof prefers:

  1. a normal external link; or
  2. a privacy-protective placeholder that loads the third-party content only after the user chooses to activate it.

For example, a hosted video would appear as a placeholder explaining that playing it may allow the host to store or access information on your device and receive information about your viewing, with a deliberate Load video action.

Where the user chooses to activate the content, Proof explains what will happen before it loads.

Proof uses the most privacy-protective embed configuration available.

11. Social media

Proof links to its LinkedIn and X accounts.

Ordinary links do not require Proof to embed social-media tracking code.

Proof does not use social-media plugins that automatically transmit information about visitors simply because they visit proof.ag.

If this changes, this notice and the privacy controls will be updated before the technology is enabled.

12. Fonts and other external resources

Where practicable, Proof self-hosts:

  • fonts;
  • icons;
  • core scripts;
  • visual assets.

This reduces unnecessary third-party requests and avoids disclosing visitor information solely to render the site.

The typefaces on proof.ag are served from Proof’s own hosting. Viewing a page sends no font request to a third party.

Where an external provider is used, Proof assesses:

  • what information is transmitted;
  • why;
  • whether a storage or access technology is involved;
  • the provider’s role;
  • whether an exception applies;
  • whether consent or an objection mechanism is required;
  • international-transfer implications where personal information is involved.

13. Forms

The Contact, Careers, Record enquiry, Data protection complaint and security report forms may use security technologies to:

  • prevent spam;
  • detect abuse;
  • protect submissions;
  • maintain submission integrity.

Proof prefers protections that do not require advertising or cross-site profiling.

If a CAPTCHA or anti-bot provider stores or accesses information on the visitor’s device, the technology is assessed and included in this notice.

Proof does not automatically describe all anti-bot technologies as strictly necessary. The actual configuration must justify the applicable exception.

On the current site, the only such technology is Cloudflare Turnstile, listed inthe inventory. It loads only where a form exists, and on the Proof Record Rules, Data Protection Complaints and Security pages only when the relevant form is opened or used. It exists solely to protect the submission service the visitor is using.

Submitting a form sends the information you entered, including any attached CV, to Proof’s form-processing provider over the network. No information is stored on your device. How that personal information is handled is described in theWebsite, Enquiries and Recruitment Privacy Notice.

14. Logged-in Proof services

When a person signs into a Proof service, additional strictly necessary technologies may be used for:

  • authentication;
  • maintaining a secure session;
  • preventing cross-site request forgery;
  • security;
  • recording a user-requested preference.

These technologies will be included in the current inventory once the relevant production service is live. No logged-in Proof service currently exists on proof.ag.

Authentication technologies must not be reused for advertising or unrelated tracking.

15. Third parties

A third-party technology does not become compliant merely because the supplier calls it a “necessary cookie” or “privacy-friendly analytics”.

Proof is responsible for understanding the technology it chooses to place on its service.

Before using a third-party technology, Proof establishes:

  • who operates it;
  • what it stores or accesses;
  • its purposes;
  • whether the provider uses information for its own purposes;
  • whether information is combined with other data;
  • how long information is retained;
  • whether personal information is processed;
  • the parties’ data-protection roles;
  • whether information leaves the UK;
  • whether consent or another PECR condition is required.

16. Personal information

Storage and access technologies may also involve personal information.

Where they do, UK data-protection law applies in addition to the electronic-communications rules.

For information about:

  • purposes;
  • lawful bases;
  • recipients;
  • international transfers;
  • retention;
  • security;
  • your rights;

read the Website, Enquiries and Recruitment Privacy Notice or, for platform use, theProof Platform Privacy Notice.

17. How long technologies operate

Proof keeps the duration of each storage or access technology proportionate to its purpose.

The lifetime of every technology is shown in the current inventory.

Proof prefers:

  • session-only storage where persistence is unnecessary;
  • short retention for security and technical information;
  • limited preference periods;
  • prompt aggregation of individual-level statistical information;
  • deletion when the purpose ends.

A technology must not be given an arbitrary long expiry merely because the provider uses one by default.

18. Browser controls

Most browsers allow you to:

  • view cookies;
  • delete cookies;
  • block cookies;
  • restrict third-party storage;
  • clear site data.

Blocking necessary technologies may prevent parts of Proof from working properly.

Browser controls are additional to, not a substitute for, Proof’s own privacy controls where Proof is required to provide them.

19. Do Not Track and browser privacy signals

Proof monitors the development of recognised browser privacy signals and applicable legal requirements.

Where a browser or device provides a clear preference that Proof is legally required or technically able to honour reliably, Proof aims to respect it.

Proof does not claim support for a particular privacy signal until that support has been implemented and tested.

20. Changes to this notice

Proof reviews its storage and access technologies regularly.

We will update this notice where:

  • a new technology is introduced;
  • a provider changes;
  • a purpose changes;
  • a retention period changes materially;
  • the legal basis or applicable PECR exception changes;
  • a technology begins processing information differently.

Where a new use requires consent, it will not be enabled for existing visitors merely because this notice has been updated.

Where an existing consent no longer covers the new use, Proof will request a new choice before enabling it.

Previous versions will be available at /legal/archive.

21. Contact

Questions about storage, cookies or privacy can be sent to:

Emailct@proof.ag · subjectPrivacy enquiry
Registered officePROOF AG LTD
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB
Company number17211914
ICO registrationZC145363
Material changesVersion 1.0 · initial publication · no previous versions.
Accessible formatsContact ct@proof.ag if you need this notice in another accessible format.