Cookie policy

OSP Advisory Ltd · Company No. 17126049 · 16 Ability Plaza, Arbutus Street, London E8 4DT
Version 1.0 · Effective date: 1 April 2026

1. Introduction

This Cookie Policy explains how OSP Advisory Ltd (“we”, “us”, “OSP”) uses cookies and similar tracking technologies on our website at https://ospadvisory.uk and our client platform at app.ospadvisory.uk (together, the “Platform”).

This policy should be read alongside our Privacy Notice, which explains how we process personal data more broadly. We comply with the Privacy and Electronic Communications (EC Directive) Regulations 2003 (as amended) (“PECR”), in particular Regulation 6, and the UK General Data Protection Regulation (“UK GDPR”) in our use of cookies.

2. What are cookies?

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to the website operator. Similar technologies include local storage, session storage, and tracking pixels. References to “cookies” in this policy include all such technologies unless stated otherwise.

3. Legal basis

Under PECR Regulation 6, we must:

Strictly necessary cookies do not require consent under PECR. All other cookies require your prior, informed consent. Where cookies process personal data, we rely on consent (UK GDPR Article 6(1)(a)) as our lawful basis. For strictly necessary cookies, consent under PECR is not required (Regulation 6(4)); to the extent these cookies process personal data, the lawful basis under UK GDPR is legitimate interests (Article 6(1)(f)) — namely, the provision of the service you have requested.

4. Cookie categories

4.1 Strictly necessary cookies

These cookies are essential for the Platform to function. Without them, you would not be able to log in, navigate securely, or use core features. They cannot be disabled.

Cookie / technologyProviderPurposeDuration
__session / __clerk_* / __client_uatClerk (clerk.com)Authentication — identifies your logged-in session, manages tokens, and enforces role-based access controlSession / up to 7 days
__cf_bmCloudflareBot detection and DDoS protection (if Cloudflare is enabled on our infrastructure)30 minutes
__stripe_mid / __stripe_sidStripe (stripe.com)Fraud prevention on billing pages onlySession / 1 year
CSRF tokensOSP AdvisoryPrevents cross-site request forgery attacksSession
__next_*OSP Advisory (Next.js)Framework session cookies required for application routing and server-side renderingSession
Cookie consent preferenceOSP AdvisoryStores your cookie consent choices so we do not ask you repeatedly12 months

Legal basis: these cookies are exempt from consent under PECR Regulation 6(4) — they are strictly necessary for the provision of the service you have requested.

4.2 Analytics cookies

These cookies help us understand how visitors use the Platform. All analytics data is aggregated and does not identify individual users.

Cookie / technologyProviderPurposeDuration
_ga, _ga_*Google Analytics 4 (if enabled)Measures website traffic, page views, session duration, and user journeys. IP anonymisation is enabled by default in GA4.Up to 2 years

Legal basis: consent. These cookies are only placed after you provide affirmative consent via our cookie banner. We may not enable Google Analytics at launch; if analytics cookies are not active, this category will not appear in the cookie banner. We will update this policy before enabling any analytics service.

4.3 Functional cookies

These cookies enable enhanced functionality and personalisation, such as remembering your display preferences.

Cookie / technologyProviderPurposeDuration
Local storage preferencesOSP AdvisoryRemembers UI preferences (sidebar state, table column widths, dark mode preference)Persistent until cleared
Sentry session replay (if enabled)Sentry (sentry.io)Error tracking and session replay for debugging purposes. Captures anonymised interaction data when errors occur. Personal information is scrubbed before transmission.Session

Legal basis: consent. Sentry’s core error-tracking functionality (capturing unhandled exceptions with stack traces) operates without cookies and is classified as strictly necessary for maintaining service reliability under PECR Regulation 6(4). Session replay, if enabled, requires consent and falls under this functional category.

5. Consent mechanism

When you first visit the Platform, you will see a cookie banner that:

Non-essential cookies are not loaded by default. Silence, scrolling, or continued browsing does not constitute consent. You can change your cookie preferences at any time via the “Cookie preferences” link in the footer, or by clearing cookies in your browser settings. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

6. How to manage cookies in your browser

Most web browsers allow you to control cookies through their settings (Chrome: Settings → Privacy; Firefox: Preferences → Privacy; Safari: Preferences → Privacy; Edge: Settings → Cookies). Please note that blocking strictly necessary cookies may prevent you from logging in to or using the Platform.

7. Third-party cookies

ProviderServiceTheir privacy policy
Clerk (clerk.com)Authentication and user managementclerk.com/privacy
Sentry (sentry.io)Error monitoring and performance trackingsentry.io/privacy
Stripe (stripe.com)Payment processing (on billing pages only)stripe.com/privacy
Google (google.com)Analytics (if enabled)policies.google.com/privacy

We have Data Processing Agreements in place with each of these providers where they act as data processors on our behalf. Some of these providers process data outside the UK; where personal data is transferred to a country not covered by a UK adequacy decision, we rely on appropriate safeguards.

8. Do Not Track

Some browsers transmit a “Do Not Track” signal. There is no industry standard for how websites should respond to these signals. We do not currently alter our practices in response to them, but we do not place non-essential cookies without your affirmative consent regardless.

9. Changes to this policy

We may update this Cookie Policy from time to time. Material changes will be communicated via the cookie banner and/or a notice on the Platform. The effective date at the top of this policy indicates when it was last updated.

10. Contact

Questions about our use of cookies: privacy@ospadvisory.uk or OSP Advisory Ltd, 16 Ability Plaza, Arbutus Street, London E8 4DT. You also have the right to lodge a complaint with the Information Commissioner’s Office: ico.org.uk · 0303 123 1113.

Command Palette

Search for a command to run...