Citizen Centric · Cookie and Similar Technologies Policy · Version 1.0 · Effective 15 August 2026
Cookie and Similar Technologies Policy
How cookies, app storage and similar technologies are used.
About this document
Citizen Centric Cookie and Similar Technologies Policy
Effective Date: 15 August 2026
Last Updated: 15 August 2026
Version: 1.0
About this policy
Politis Ltd (company number 13661766), whose registered office is The Old Courthouse, Orsett Road, Grays, Essex, England, RM17 5DD, operates Citizen Centric. Politis Ltd is registered with the Information Commissioner's Office under reference ZB738312.
This policy explains how cookies and similar technologies may be used on the Citizen Centric public website, researcher-facing web services and participant mobile application. It should be read with the applicable privacy notice and, for research participants, the study-specific participant information and privacy information provided by the relevant research organisation.
The technologies actually used may differ between the website, researcher services and mobile application. Citizen Centric will not describe an analytics, advertising or other optional technology as active unless it is actually deployed.
1. Cookies and similar technologies
Cookies are small data files stored by a website in a browser. Similar technologies can include browser local storage, application storage, software development kits (SDKs), device permissions and other mechanisms used to maintain sessions, remember settings, provide security or support application functions.
The Citizen Centric mobile application does not necessarily use browser cookies. It may use secure device storage and local application storage for functions such as maintaining an authenticated session, retaining drafts, supporting offline operation and safely retrying queued submissions. These functions should not be described as advertising or analytics cookies merely because information is stored on a device.
2.1 Strictly necessary
Strictly necessary technologies are used where required to provide a service requested by the user or to protect the service. Depending on the relevant Citizen Centric service, these may include session/authentication mechanisms, security controls and essential local application storage.
Where the PECR strictly-necessary exemption applies, consent is not required for that storage or access. The exemption is applied narrowly and does not automatically cover analytics or convenience features.
2.2 Functional
Functional technologies may remember choices or support features that are not strictly necessary to deliver the requested service. Whether consent is required depends on the technology, its purpose and the applicable PECR rules. Citizen Centric will classify each deployed technology by reference to its actual purpose.
2.3 Analytics and performance
If Citizen Centric deploys non-essential analytics or performance cookies, SDKs or similar technologies, they will not be activated before any consent required by PECR has been obtained. Consent must be capable of being refused or withdrawn as easily as it is given.
Citizen Centric currently uses operational diagnostics, security logging and service-performance telemetry to maintain the reliability and security of the platform. This is not used for advertising, behavioural profiling or cross-site marketing. Google Analytics and marketing/advertising SDKs are not currently used in the participant mobile application. If any non-essential analytics technology requiring consent is introduced, it will be disabled by default until valid consent is obtained where PECR requires it.
2.4 Marketing and targeting
Citizen Centric does not assume that marketing or advertising technologies are used. If any marketing, advertising or cross-site tracking technology is introduced, it must be added to the register and any required consent obtained before activation.
Citizen Centric currently uses no marketing, advertising, attribution or cross-site tracking cookies or SDKs.
3. Mobile application storage and permissions
The participant mobile application may store limited information locally to provide the participant service. This may include a secure session credential, draft participant material, queued submissions and information required to show whether an item is waiting to sync. Local information should be limited to what is necessary for the relevant function and handled in accordance with the applicable privacy notice.
Camera, microphone, photo-library or file access is controlled through operating-system permissions where those features are used. Granting an operating-system permission is not the same as consenting to unrelated analytics or marketing. Citizen Centric should request permissions only when needed for the participant-selected function.
Participant material must not be sent directly from the mobile application to an AI provider. Any authorised server-side AI processing is governed separately by the applicable privacy information and AI Services arrangements.
4. Cookie and technology register
The register must reflect technologies actually deployed in production. Placeholder or planned services must not be presented as active.
Technology · Provider · Service · Purpose · Duration · Status / consent
Secure device storage · Politis Ltd / device OS · Participant app · Protect session credentials · Session / until cleared · Necessary app security; confirm implementation
Local application storage · Politis Ltd / device OS · Participant app · Drafts, queue, offline/sync state · Until sent/cleared under app logic · Classify by actual purpose
Operational diagnostics / performance telemetry · Microsoft Azure / Politis Ltd · Web/app/backend · Security, reliability, error diagnosis and service performance · Only as long as necessary under the operational retention schedule · Necessary operational telemetry where applicable; no advertising/marketing use
Marketing / advertising tracking · None · None · Not used · N/A · Not active
5. Managing choices
Where non-essential cookies or similar technologies require consent, users should be given a clear choice before those technologies are activated. Rejecting non-essential technologies should not prevent access to core Citizen Centric services unless a particular optional feature genuinely depends on the technology.
Where a preference centre is provided, users should be able to revisit and change their choices. Browser controls can also delete or block browser cookies. Mobile operating systems provide separate controls for permissions such as camera, microphone, photos and notifications.
A preference centre is required only if non-essential cookies or similar technologies are deployed. At version 1.0, no participant-mobile marketing or advertising technologies are active; any future non-essential analytics will require an accessible consent/preference mechanism before activation.
6. Third parties and international transfers
Where a third party receives personal data through a cookie, SDK or similar technology, the applicable privacy notice must identify the relevant processing and explain any international transfer safeguards where required. The actual service configuration and processing locations must be verified.
Operational diagnostics and security telemetry are provided through Microsoft Azure-hosted platform services. Citizen Centric is configured so that personal data is stored and processed in the United Kingdom and/or the European Union/European Economic Area. Politis Ltd does not intentionally transfer Study Data outside the UK/EU/EEA. If a restricted transfer becomes necessary, it must be documented and protected by an applicable UK GDPR transfer mechanism before the processing begins.
7. Retention
Cookies and similar technologies are retained only for as long as necessary for their stated purpose. Session/security technologies expire when no longer required for the session or security function, and non-essential technologies, if introduced, will have a documented expiry in the production technology register. Personal data is kept only for as long as it is necessary for the purpose for which it was collected, in line with the UK GDPR storage-limitation principle. There is no single fixed retention period prescribed by UK GDPR. Study Data must have a controller-approved, study-specific retention period recorded before a study is launched. Politis Ltd follows that documented instruction when acting as processor, subject to legal, regulatory, security, dispute-resolution or backup obligations that require limited further retention.
8. Changes to this policy
Politis Ltd may update this policy when technologies, services or legal requirements change. Material changes affecting choices or privacy will be communicated through an appropriate channel. The effective and last-updated dates should be maintained when the policy is published.
9. Contact
Questions about this policy or Citizen Centric's use of cookies and similar technologies can be sent to:
Politis Ltd
The Old Courthouse, Orsett Road, Grays, Essex, England, RM17 5DD
ICO reference: ZB738312
Email: info@politisconsulting.co.uk
Individuals may also raise data-protection concerns with the Information Commissioner's Office. The applicable privacy notice should contain the current complaints information and contact route.
Related legal information
Return to the Legal Centre. For questions about a particular study, use the contact details in that study's participant information.
Politis Ltd · Company No. 13661766 · ICO ZB738312 · info@politisconsulting.co.uk
Researcher sign in