Legal
Cookie policy
Version 1.0 · Last updated 1 August 2026
This site does not use cookies. Here is exactly what that means, and what we checked to be able to say it.
Summary
Last updated: 1 August 2026.
Last verified against the live site: 1 August 2026.
This website sets no cookies.
That is true whichever way you answer the banner: the optional analytics described below is cookieless, so accepting it does not create a cookie either. We use no tracking pixels and no fingerprinting scripts.
One thing is written to your device — the record of your own cookie choice, held in local storage so that we can honour it and stop asking you. It never leaves your browser.
Nothing on this site is loaded from another company's servers. The typefaces are downloaded once when we build the site and then served from www.toleris.co, so your browser never contacts Google Fonts; and if you allow analytics, that script is served from www.toleris.co too rather than from the provider's own domain.
We have not enabled any hosting feature that would set a cookie. If our hosting provider's bot protection ever had to challenge your request, it could set a single short-lived security cookie to record that the challenge passed. That would be strictly necessary, exempt from consent, and listed here.
The page does respond to a few display settings your browser already advertises to every site it loads: the width of your window, whether your device has a fine pointer such as a mouse, and whether you have asked your operating system to reduce motion. Section 3 explains what we do with those, and how to object.
That is why you were not shown a cookie banner.
You do not have to take our word for any of this. Open your browser's developer tools, look at the Application (or Storage) tab and the Network tab, and reload the page.
What this policy covers
This policy covers the Toleris marketing website, served at www.toleris.co. Visits to toleris.co are redirected there and are covered by this policy too.
This page deals with one narrow question: what is, and is not, stored on or read from your device. For what we do with personal data, see our privacy notice at www.toleris.co/privacy.
The Toleris application at app.toleris.co is a separate, signed-in product with its own accounts, its own database and its own processing. It is not covered here. If you are a customer or are evaluating the product, the data protection terms for the application form part of your contract — email privacy@toleris.co for a copy.
What happens when you visit this site
None of the following stores anything on your device. It is set out here for completeness.
Your request reaches our host. This site is hosted by Vercel, who act as our data processor. It is a set of static pages plus one form endpoint; the marketing site has no database of its own. Like any web server, Vercel's receives your IP address and browser user-agent as part of delivering the page, and records them in its operational logs. We rely on our legitimate interests under Article 6(1)(f) of the UK GDPR: keeping this site available, secure and free from abuse. We have assessed that this does not override your interests, because the data is not used to profile you, to build a picture of you across sites, or to market to you. These logs are short-lived: they are held for our hosting provider's standard retention period and then deleted automatically. Ask us and we will tell you the period currently applying to our account. We do not copy them anywhere else.
Where that information goes. Vercel is a United States company and its infrastructure sits outside the UK, so the log data described above is transferred internationally. Where our provider is certified under the UK Extension to the EU–US Data Privacy Framework, we rely on that certification, which the UK has recognised under Article 45A of the UK GDPR. Where it is not, we rely on the Information Commissioner's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. You can obtain a copy of the safeguards we rely on, free of charge, by emailing privacy@toleris.co.
The demo form. The "Book a demo" form is the only place this site collects personal details. What we ask for, why, who receives it, where it goes and how long it is kept are all set out in our privacy notice at www.toleris.co/privacy.
Abuse protection on that form. To stop the form being flooded, our server counts how many submissions come from one IP address and refuses more than five in any 60-second window. We rely on our legitimate interests under Article 6(1)(f) in preventing abuse of the form. That address is held only in the memory of the server instance handling your request. It is never written to a database, never included in the email we receive, and is lost when that instance is replaced, which happens routinely as our host starts and stops instances. The point is that it is never written to durable storage at any stage, on your device or ours, so there is no copy to retain or delete.
Where links take you
This site links outward in one place: the sign-in link to app.toleris.co. That is our own application, not a third party. It is a separate signed-in service and it does use cookies, because you cannot hold a login session without them. What it sets, and why, is covered by the data protection terms for the application rather than by this page.
If we add links to other sites later, those sites will set their own cookies and run their own tracking once you arrive, and we have no control over what they do. Read their cookie and privacy information.
If this ever changes
We may add site statistics or embedded content later. If we do, this page is updated before the change goes live, and the update names the provider, says what it does and what it stores, and links to the control that switches it off.
Where such statistics meet the conditions of the audience-measurement exception in PECR — used solely to produce aggregate figures about how this site is used, never to track or profile individuals, and never for advertising — they do not require your consent, but they do require us to tell you clearly what we are doing and to give you a simple, free way to object. We would name the provider here and ship a working opt-out at the same time as the statistics, not afterwards. If a provider or a purpose fell outside those conditions, we would ask for your consent instead and set nothing until you gave it.
Two commitments hold whichever route we take. Nothing that tracks you across sites, records your session, builds a profile or serves advertising will load unless you have first agreed to it: no pre-ticked boxes, no consent implied from continued browsing, no purposes switched on under a different legal basis so that we do not have to ask you, and refusing will take exactly as many clicks as accepting. Any embedded third party, such as a video, map or chat widget, will sit behind a placeholder and load only once you choose to load it.
A single control, labelled Cookie preferences, will appear in the footer of every page from the moment there is anything to choose about, and will stay there. It will carry both the consent choices and any opt-out for statistics that do not require consent. Withdrawing will take no more effort than giving consent did.
If you withdraw, we will stop loading the technology immediately and delete the record of your choice. Where a provider has already stored something on your device, or collected information under that consent, we will ask them to delete it and confirm to you what has been removed. We will not add a service unless we can do that.
If you say no, we will record that and we will not re-ask in the hope of a different answer. We would ask again only if we changed what we use, or after about six months, which is the interval the ICO treats as reasonable for refreshing a choice. If your browser blocks us from storing your choice, we cannot remember it between visits; nothing optional runs in that case either. And if we ever do introduce something optional, we will record your choice in your browser's local storage under the key toleris.consent so that we can honour it — this page will say so before that happens.
Who we are, your rights and complaints
This website is operated by Toleris Ltd, registered in England and Wales (company number 17259283), registered office Viglen House Business Centre, Alperton Lane, Wembley, England, HA0 1HD. We are the data controller for the personal data described in this policy and in our privacy notice.
Questions about this policy, or about anything on this site: privacy@toleris.co.
You have rights over the personal data described in this policy. You can ask for a copy of it, ask us to correct or erase it, ask us to restrict how we use it, object to our using it, and ask for it in a portable form. Because we rely on our legitimate interests for the processing described above, you have a specific right to object under Article 21 of the UK GDPR: tell us and we will stop, unless we can show compelling grounds that override your interests. Where we ever rely on your consent, you can withdraw it at any time, and doing so does not affect anything we did before you withdrew. To exercise any of these rights, email privacy@toleris.co. Our privacy notice sets them out in full.
If you are unhappy with how we handle your personal data, you can complain to us directly at that address, under section 164A of the Data Protection Act 2018. We will acknowledge your complaint within 30 days and respond without undue delay. You can also complain at any time to the Information Commissioner's Office: ico.org.uk/make-a-complaint, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
If this policy changes, the date at the top changes with it, and any change affecting what is stored on or read from your device is published here before it takes effect.