Cookies and comparable technologies operate quietly, and a visitor to a website has no natural means of discovering what has been placed on the device, by whom, for how long, or to what end. The present Policy supplies that information for the website published at https://tradingerpconsulting.com, operated by B&B Consulting LLC under the trading name Trading ERP Consulting, and describes the controls through which a visitor may accept, refuse, or subsequently alter the position.
Two documents govern the treatment of personal data on the website. The present Policy addresses storage upon, and access to information already stored upon, the terminal equipment of the visitor. The Privacy Policy addresses the subsequent handling of the personal data thereby obtained, including the purposes, the recipients, the retention periods, and the rights of the individual. Reading both is recommended.
Consent to non-essential storage on terminal equipment is governed, for visitors located in the European Economic Area, by Article 5(3) of Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector, as transposed into the law of each member state, read together with the consent standard established by Articles 4(11) and 7 of Regulation (EU) 2016/679. For visitors located in the United Kingdom, regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 applies, read together with the United Kingdom General Data Protection Regulation.
For visitors located in the United Arab Emirates, Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data governs the processing of any personal data collected through the technologies described below. Consent obtained under the federal statute must be specific, informed, and expressed by a clear affirmative act, and may be withdrawn at any time. The Implementing Regulations to that statute have not been issued as at the date of the present Policy, and we apply the European standard uniformly to every visitor as a matter of policy, which offers protection at least equivalent to that which the federal framework requires.
A cookie is a small text file placed on the device of a visitor by a website and returned to that website, or to another party, upon subsequent requests. Cookies set by the domain the visitor is viewing are described as first-party; those set by a different domain are described as third-party. A cookie that expires when the browser is closed is a session cookie; one that survives that event until a stated expiry is a persistent cookie.
Comparable technologies achieve similar results by different means. Local storage and session storage retain data within the browser without transmission upon every request. Pixels, which are transparent images of negligible size, signal to a server that a page has been rendered. Software development kits embedded within third-party components may read device characteristics. Every such technology is treated in the present Policy on the same footing as a cookie, since the legal test concerns storage on and access to terminal equipment rather than the technical form employed.
Four categories are distinguished on the website, and the consent interface described at section 6 permits the visitor to decide upon each independently.
Tables below record the position as at the date stated at the head of the document, subject to one qualification. Identifiers generated by the consent management platform depend upon the product finally deployed, and the entry describing the consent record should be reconciled against the live position at each scan performed under section 9. Expiry periods reflect the values configured by the provider; browsers increasingly cap the effective lifetime of first-party cookies at approximately four hundred days, with the consequence that an item nominally set to expire after two years may in practice be discarded sooner. Cookie names generated dynamically are shown with a wildcard.
| Name | Provider | Purpose | Type and duration |
|---|---|---|---|
| cmplz_* or equivalent consent record | Trading ERP Consulting (first party) | Records the categories accepted or refused by the visitor, so that the choice is honoured and the banner is not presented again on every page | HTTP cookie, 12 months |
| PHPSESSID | Trading ERP Consulting (first party) | Maintains the state of the session on the server during a visit | HTTP cookie, session |
| wordpress_test_cookie | Trading ERP Consulting (first party) | Verifies that the browser accepts cookies | HTTP cookie, session |
| elementor | Trading ERP Consulting (first party) | Supports the correct rendering of pages built with the Elementor page builder | Local storage, persistent |
Google Analytics 4 is deployed through Google Tag Manager and is withheld until analytics consent has been recorded. Google acts as our processor in respect of the analytics data and as controller in respect of certain of its own purposes, as described in its documentation. Internet protocol addresses are neither logged nor stored within Google Analytics 4. The address accompanying a request is used transiently in order to derive a coarse geographic indication and is then discarded, and traffic originating in the European Union is collected through domains and servers situated within the Union before the data are forwarded for processing. Identifiability is thereby reduced, although the client identifier described below continues to distinguish one visitor from another across sessions.
| Name | Provider | Purpose | Type and duration |
|---|---|---|---|
| _ga | Distinguishes one visitor from another by storing a randomly generated client identifier | HTTP cookie, 2 years from the last interaction | |
| _ga_<container-id> | Retains session state and the event data associated with the analytics property | HTTP cookie, 2 years from the last interaction | |
| _gid | Distinguishes visitors within a short window, where the configuration causes it to be set | HTTP cookie, 24 hours | |
| _gat or _gat_gtag_* | Limits the rate at which requests are sent to the analytics servers | HTTP cookie, 1 minute |
Google Tag Manager is a container that governs the deployment of tags and does not, of itself, set cookies. Configuration of the container determines which technologies fire and upon which conditions, and the container on the present website is configured so that no analytics tag is released before the corresponding consent signal has been received.
Booking a consultation takes the visitor to a scheduling page operated by a third party. Cookies set on those pages are governed by the documentation of the provider concerned, and the visitor is subject to them upon arrival at the destination rather than upon browsing our own pages. Where a scheduling widget is embedded within our pages, release is conditional upon functional consent.
| Service | Provider | Purpose | Further information |
|---|---|---|---|
| Calendly | Calendly LLC | Presents available consultation slots, records the booking, and issues confirmation and reminder messages | https://calendly.com/privacy |
| Google Calendar appointment scheduling | Alternative booking pathway performing an equivalent function | https://policies.google.com/privacy | |
| Google Fonts | Supplies typefaces used in the presentation of the website. Where the font files are requested from Google infrastructure upon page load, the address of the visitor reaches the provider before any choice has been registered, a result inconsistent with the treatment of the category. Local hosting of the files removes the transmission altogether, and the present entry falls to be revised once that measure has been applied. | https://policies.google.com/privacy |
No advertising, remarketing, or audience-building technology is deployed at present. Should one be introduced, the cookie register maintained under section 9 will be updated, the present Policy amended, and consent sought before any such technology is released.
On a first visit, a banner is presented before any non-essential technology is released. Three controls appear with equal prominence: Accept All, Reject All, and Manage Preferences. Refusing is no more onerous than accepting, and no design device is used to steer the visitor towards acceptance. Continuing to browse, scrolling, or closing the banner does not constitute consent, and where the visitor performs none of the three available actions, no non-essential technology is released.
Selecting Manage Preferences opens a preference centre in which each category is presented with its own control, defaulted to the off position save for the strictly necessary category, which is described as always active and cannot be disabled. Category descriptions state the purpose served, and the full list of technologies within each category is available from the same screen.
A choice once made is recorded for twelve months, after which the banner is presented again so that the position may be reconsidered. Withdrawal or alteration is available at any moment through a persistent control published in the footer of every page under the heading Cookie Preferences. Upon withdrawal, the corresponding technologies cease to be released, and cookies already placed by the categories concerned are removed so far as the browser permits.
Records of consent, comprising the identifier of the consent record, the categories accepted, the version of the interface presented, and the date and time of the action, are retained for the purpose of demonstrating that the obligation has been discharged.
Independently of the interface described above, every principal browser offers controls through which cookies may be blocked, restricted to first-party origin, or deleted. Instructions are published by each provider, among them https://support.google.com/chrome/answer/95647 for Chrome, https://support.mozilla.org/kb/cookies-information-websites-store-on-your-computer for Firefox, https://support.apple.com/en-gb/guide/safari/sfri11471/mac for Safari, and https://support.microsoft.com/en-us/microsoft-edge for Edge.
Blocking cookies indiscriminately carries consequences. Strictly necessary items would be caught alongside the rest, with the result that the enquiry form may fail to submit and the record of the cookie preference itself may not persist, causing the banner to reappear upon every page. Use of the preference centre is accordingly the more precise instrument.
Where a browser transmits a Global Privacy Control signal, we treat the signal as an objection to non-essential storage and withhold the corresponding technologies. The older Do Not Track header is not honoured, since no common interpretation of it was ever settled and the specification has been abandoned by its authors.
Plugins, embedded components, and updates to third-party services introduce technologies without announcement, and a cookie table left unattended ceases to describe the website it purports to describe. A scan of the website is accordingly performed at intervals of no more than six months, and following any material change to the site, and the register of technologies is reconciled against the result. Annex C to the present Policy, delivered as a separate document entitled Annexes and Cookie Banner Wording, sets out the format of the register, which is maintained separately from the present Policy so that operational changes may be recorded without amendment of the Policy itself, and which is available on request addressed to info@tradingerpconsulting.com.
Each version of the present Policy carries a number and a date. Where an amendment introduces a new category of technology or otherwise materially alters the position of the visitor, the consent record is reset and consent is sought afresh. Questions may be addressed to info@tradingerpconsulting.com.
The register is maintained separately from the present Policy in order that additions and removals may be recorded promptly, with a dated version history, without the Policy itself requiring amendment upon every operational change. Column headings are fixed as follows, and a scan of the website should be performed at intervals of no more than six months, and after any material change, in order to reconcile the register against the live position.
| Column | Content to be recorded |
|---|---|
| Identifier | Cookie name, storage key, or pixel identifier, with a wildcard where the value is generated dynamically |
| Provider | Legal name of the entity that sets or receives the item |
| Category | Strictly necessary, functional, analytics, or marketing |
| Purpose | Function performed, expressed in language a visitor can understand |
| Type | HTTP cookie, local storage, session storage, pixel, or software development kit |
| Duration | Expiry configured by the provider, and session where applicable |
| Party | First party or third party |
| Processing location | Territory or territories in which the provider processes the data |
| Transfer safeguard | Mechanism relied upon where the destination lies outside the European Economic Area or the United Kingdom |
| Documentation | Address of the privacy or cookie documentation published by the provider |
| Date added | Date on which the item first appeared on the website |
| Date removed | Date on which the item ceased to be deployed, retained for the audit trail |
Version control applies to the register in the same manner as to the present Policy. Superseded versions are archived rather than overwritten, so that the state of the website at any past date may be reconstructed should a question arise.