Skip to main content

BrandHire

Home  >  About Us  >  Cookie Policy

BrandHire Cookie Policy

Last Updated: 10 May 2026

cookie policy

1. Purpose and Scope

1.1 This Cookie Policy sets out, in a complete and audit-ready form, the basis upon which Brand Hire Ltd (“the Company”) deploys cookies and similar technologies on its website located at www.brandhire.co.uk (“the Website”).

1.2 This Policy applies to all individuals accessing or interacting with the Website, including candidates, employers, and general visitors within the United Kingdom and, where applicable, internationally.

1.3 This Policy is designed to meet the requirements of regulatory scrutiny, enterprise procurement due diligence, investor review, and third-party compliance assessment.

2. Definition of Cookies and Similar Technologies

2.1 A cookie is a small text file placed on a user’s terminal equipment when accessing a website.

2.2 Cookies enable recognition of a device, maintenance of session state, storage of user preferences, and recording of interaction data.

2.3 Similar technologies include local storage objects, tracking pixels, scripts, tags, and other device access technologies capable of storing or retrieving information from a user’s device.

2.4 References to “cookies” within this Policy shall include such technologies where they perform equivalent functions involving storage or access to information on a user’s device.

3. Legal Framework and Regulatory Context

3.1 The storage of, or access to, information on a user’s device is governed by the Privacy and Electronic Communications Regulations 2003.

3.2 The processing of personal data derived from cookies is governed by the UK General Data Protection Regulation and the Data Protection Act 2018.

3.3 This Policy is aligned with guidance and enforcement expectations issued by the Information Commissioner’s Office, including requirements relating to valid consent, transparency, and user control.

3.4 The Policy further reflects principles arising under the Consumer Rights Act 2015, the Human Rights Act 1998, the Online Safety Act 2023, and the Data (Use and Access) Act 2025, including fairness, proportionality, and reasonable expectations of privacy.

4. Distinction Between PECR Consent and UK GDPR Lawful Basis

4.1 The Company maintains a strict and operational distinction between:

4.1.1 consent required under PECR for the storage of, or access to, information on a user’s device; and
4.1.2 lawful bases under UK GDPR for the subsequent processing of any personal data obtained through such technologies.

4.2 Consent under PECR is obtained prior to the placement of any non-essential cookies.

4.3 The processing of personal data arising from cookies is undertaken in accordance with UK GDPR and is supported by the following lawful bases, as applicable:

4.3.1 strictly necessary cookies: legitimate interests in ensuring network security, service integrity, and functionality;
4.3.2 form submission and session cookies: performance of a contract or steps taken at the request of the data subject;
4.3.3 analytics cookies: consent, in accordance with the Privacy and Electronic Communications Regulations 2003 where such technologies involve the storage of, or access to, information on a user’s device, and, where personal data is processed, such processing is carried out on the basis of consent under the UK General Data Protection Regulation.

4.4 Consent under PECR does not constitute a lawful basis under UK GDPR.

5. Timing and Deployment of Cookies

5.1 Strictly necessary cookies are deployed upon access to the Website where required to provide a service explicitly requested by the user.

5.2 All other cookies are blocked by default and are not deployed unless and until the user has provided valid, informed, and granular consent.

5.3 No non-essential cookies, scripts, or tracking technologies are executed prior to the user providing consent.

5.4 The Company does not rely on implied consent, continued browsing, inactivity, or pre-ticked options as a valid form of consent.

5.5 Refusal of non-essential cookies does not prevent access to the core functionality of the Website.

5.6 The Company implements technical controls, including script blocking and conditional loading mechanisms, to ensure that no third-party scripts, tags, pixels, or network requests associated with non-essential cookies are loaded, executed, or permitted to transmit data from the user’s device prior to the receipt of valid consent, and that any such technologies remain inactive unless and until consent is obtained.

5.7 The Company ensures that no personal data derived from non-essential cookies is transmitted to third parties, including analytics or service providers, prior to the user providing valid consent.

5.8 The Company ensures that the refusal of non-essential cookies is as straightforward as the acceptance of such cookies and that users are not subject to any detriment, manipulation, or unequal experience when declining consent.

6. Categories of Cookies

6.1 Cookies deployed on the Website are categorised as follows:

6.2 Strictly necessary cookies are limited to those essential for security, authentication, session continuity, and the delivery of services explicitly requested by the user.

6.3 Functional cookies enable the Website to remember user preferences and enhance usability and are deployed only with user consent.

6.4 Analytics cookies measure usage, interactions, and performance of the Website and are not strictly necessary.

6.5 The Company deploys marketing and advertising technologies, including tracking pixels and tags, which enable the measurement of campaign performance and the delivery of targeted advertising across third-party platforms; such technologies are not strictly necessary and are deployed only where the user has provided prior consent.

6.6 The Company distinguishes strictly necessary cookies from analytics, behavioural tracking, and advertising technologies and ensures that no such technologies are classified as strictly necessary, and that all non-essential technologies are subject to appropriate consent controls in accordance with regulatory requirements.

7. Detailed Cookie Inventory

7.1 The cookies currently deployed are as follows:

Cookie / TechnologyProviderCategoryPurposeDurationFirst/Third Party
Session cookiesBrandHireStrictly NecessaryMaintain session integrity and navigationSessionFirst-party
CSRF tokensBrandHireStrictly NecessaryProtect against unauthorised form submissionsSessionFirst-party
Consent preferenceBrandHireStrictly NecessaryRecord consent choices for compliance purposes12 monthsFirst-party
Security and network cookiesCloudflareStrictly NecessaryEnsure secure content delivery, traffic routing, and protection against malicious activitySession / PersistentThird-party
Form cookiesTally.soStrictly NecessaryEnable secure submission of candidate and employer dataSessionThird-party
Analytics measurementTWIPLAAnalyticsMeasure website usage and interactions using techniques that may not rely on traditional cookies but may involve processing of IP-derived or pseudonymised data; deployed subject to assessment under the Privacy and Electronic Communications Regulations 2003 and, where required, user consentConfigurableThird-party
Analytics cookiesGoogle AnalyticsAnalyticsMeasure website usage, traffic sources, and user interactions; may involve identifiers and device informationUp to 2 yearsThird-party
Behaviour analyticsHotjarAnalyticsRecord user interactions such as clicks, scrolling, and session replay for usability analysisConfigurableThird-party
Behaviour analyticsMicrosoft ClarityAnalyticsProvide session recordings and heatmaps to analyse user behaviourConfigurableThird-party
Advertising and trackingMeta PlatformsMarketingTrack user behaviour across websites for advertising and attribution purposesConfigurableThird-party
Advertising and trackingGoogle AdsMarketingEnable conversion tracking and targeted advertisingConfigurableThird-party
Advertising and trackingLinkedInMarketingTrack conversions and enable targeted B2B advertisingConfigurableThird-party
Advertising and trackingTikTokMarketingTrack user behaviour and enable targeted advertisingConfigurableThird-party
Embedded contentYouTubeFunctional / MarketingEnable video playback and may set tracking cookies where embedded content is accessedConfigurableThird-party
Web fontsGoogle FontsFunctionalDeliver web fonts and may involve requests to external serversSessionThird-party
Email trackingMailchimpMarketingTrack email engagement where applicable (e.g. opens, clicks) and link to website behaviourConfigurableThird-party

7.2 Certain analytics technologies, including TWIPLA, may operate in a manner that does not rely on traditional cookies but may nevertheless involve access to, or processing of, information relating to a user’s device or network, including IP-derived data; the Company assesses such technologies against the requirements of the Privacy and Electronic Communications Regulations 2003 and deploys them only where they do not involve storage of, or access to, information on a user’s device requiring consent, or otherwise ensures that such technologies are subject to prior user consent.

7.3 The Company does not represent analytics data as anonymous unless it has been irreversibly anonymised.

7.4 The Company maintains a continuously updated internal cookie audit register.

7.5 The Company ensures that any analytics or measurement functionalities provided by third-party platforms, including TWIPLA, are technically suppressed and do not operate prior to user consent, and that only strictly necessary infrastructure components are active by default.

8. Third-Party Cookies and Providers

8.1 Third-party technologies integrated into the Website include analytics providers, advertising networks, embedded content platforms, and infrastructure providers, each of which may place cookies, deploy tracking technologies, or otherwise access information on a user’s device.

8.2 Such providers, including TWIPLA and Tally, typically act as independent data controllers in respect of personal data collected through their own technologies, determining the purposes and means of processing independently of the Company.

8.3 The Company determines the purposes of integration but does not control independent processing undertaken by such providers.

8.4 Where data is collected through third-party technologies, such data may be transmitted directly to those providers and processed by them for their own purposes, including analytics and advertising, in accordance with their respective roles as independent controllers and their applicable privacy policies.

8.5 Users interacting with embedded third-party services do so subject to the privacy and cookie policies of those providers.

9. International Data Transfers

9.1 Personal data derived from cookies may be transferred outside the United Kingdom where third-party providers operate infrastructure internationally.

9.2 Such transfers may include transfers to the United States and other jurisdictions where providers including Google, Meta, LinkedIn, TikTok, and Mailchimp operate infrastructure or process data.

9.3 Where such transfers occur, the Company ensures that appropriate safeguards are implemented, including:

9.3.1 UK adequacy regulations where available;
9.3.2 the International Data Transfer Agreement (IDTA) or UK Addendum to Standard Contractual Clauses; and
9.3.3 transfer risk assessments addressing legal and technical risks.

9.4 Transfers are conducted in a manner that preserves the level of protection required under UK law.

10. Consent Mechanism and Controls

10.1 The Website operates a consent management platform designed to meet regulatory requirements.

10.2 Users are provided with granular, category-specific controls enabling separate consent decisions for strictly necessary, functional, and analytics cookies.

10.3 Options to accept and reject non-essential cookies are presented with equal prominence and without manipulation or bias.

10.4 No options are pre-selected.

10.5 Consent is recorded, timestamped, and retained as part of the Company’s compliance records.

10.6 Consent is obtained on a granular basis and is not bundled across categories of cookies, such that users are able to provide or refuse consent independently for each category of non-essential cookies.

11. Withdrawal of Consent

11.1 Users may withdraw or modify their consent at any time through the “Cookie Settings” mechanism available on the Website.

11.2 Withdrawal is implemented promptly and without detriment to access to core Website services.

11.3 Upon withdrawal, non-essential cookies are disabled and removed where technically feasible.

12. Data Protection Principles Applied to Cookies

12.1 The Company applies the principles of lawfulness, fairness, and transparency to all cookie-related processing.

12.2 Data collection is limited to what is necessary and proportionate for specified purposes.

12.3 Data obtained through cookies is retained only for as long as necessary for its intended purpose and, in any event, no longer than the lifespan of the relevant cookie unless a shorter retention period is required or justified in accordance with data minimisation and storage limitation principles.

12.4 The Company ensures accountability through documented governance, audit trails, and periodic reviews.

13. Security Measures

13.1 Cookies are configured using appropriate security controls, including Secure, HttpOnly, and SameSite attributes where applicable.

13.2 The Company implements technical and organisational measures to protect against unauthorised access, disclosure, alteration, or loss.

13.3 Security measures are proportionate to the sensitivity and risk profile of the data processed.

14. Impact on User Rights

14.1 Individuals have rights under UK GDPR in respect of personal data derived from cookies, including rights of access, rectification, erasure, restriction, objection, and data portability where applicable.

14.2 The use of cookies does not override or limit these rights.

14.3 Requests may be exercised through the contact details provided in this Policy.

15. Browser Controls

15.1 Users may control cookies through browser settings; however, such controls operate independently of the Website’s consent mechanism.

15.2 Browser settings do not constitute a primary mechanism for obtaining valid consent under PECR and operate only after Website-level controls.

16. Children and Safeguarding

16.1 The Website is not directed at children.

16.2 The Company does not knowingly deploy cookies for profiling or behavioural tracking of individuals under the age of 18.

16.3 Reasonable steps are taken to avoid the collection of data relating to minors through cookies, and any such data identified is handled in accordance with applicable safeguarding and data protection obligations.

17. Policy Updates and Consent Refresh

17.1 This Policy is reviewed periodically and updated to reflect changes in law, regulatory guidance, or technological deployment.

17.2 Where material changes to cookie usage occur, consent mechanisms are refreshed to ensure continued validity.

18. Contact Details

18.1 The Company may be contacted as follows:

Brand Hire Ltd
Email: privacy@brandhire.co.uk
Website: www.brandhire.co.uk

19. Audit and Compliance Positioning Statement

19.1 This Policy has been drafted to align with the requirements and expectations of the Information Commissioner’s Office and applicable UK legislation.

19.2 The Company maintains demonstrable compliance through technical controls, consent records, cookie audits, and governance documentation.

19.3 Cookie deployment is subject to ongoing review to ensure alignment with evolving legal standards, enforcement practices, and technological developments.

19.4 This Policy is intended to withstand regulatory investigation, enterprise due diligence, investor scrutiny, and third-party compliance review and forms part of the Company’s wider data protection accountability framework.