Cookie
Policy

Effective Date: 10 November 2025

Version: 1.0

Jurisdiction: United Kingdom

Operated by: 9Eons Limited

Company No. 06393882

1 Introduction

This Cookie Policy explains how TISA (tisa.one), operated by 9Eons Limited, a company registered in England and Wales under company number 06393882, with its registered office at Luminous House, 300 South Row, Milton Keynes, MK9 2FR, United Kingdom, uses cookies and similar tracking technologies on our website at https://tisa.one (the “Website”) and our mobile application (the “App”) (collectively, the “Services”).

This Cookie Policy should be read alongside our Privacy Policy and our Terms and Conditions.

In summary: We use strictly necessary cookies without consent (as permitted by PECR). All other cookies — including analytics, functionality, and advertising cookies — are only set after you give your explicit, informed consent via our cookie banner.

2 What Are Cookies and Similar Technologies?

Cookies are small text files that are placed on your device (such as a computer, smartphone, or tablet) when you visit a website or use an app. They are widely used to make websites and apps work more efficiently and to provide information to the owners of the site or app.

We also use similar technologies, including:

  • Local storage — data stored in your browser that persists between sessions
  • Device identifiers — unique identifiers assigned to your device
  • Tracking pixels (also known as web beacons) — tiny invisible images embedded in emails or web pages that confirm whether content has been accessed

These technologies enable our Services to:

  • Keep you signed in
  • Remember your preferences
  • Improve performance and functionality
  • Deliver relevant content

References to “cookies” in this policy include all similar technologies listed above, unless stated otherwise.

3 Legal Framework

We are committed to complying with all applicable data protection and electronic communications laws, including:

  • The Privacy and Electronic Communications Regulations 2003 (PECR), as amended — which requires consent before setting non-essential cookies or similar technologies on your device (Regulation 6). Non-compliance may result in fines of up to £17.5 million or 4% of global annual turnover.
  • The UK General Data Protection Regulation (UK GDPR) — which governs the processing of personal data collected through cookies. Consent under PECR must meet the UK GDPR standard: freely given, specific, informed, and unambiguous.
  • The Data Protection Act 2018 — the UK’s implementation of the UK GDPR framework.
  • The Data (Use and Access) Act 2025 (DUAA) — which introduces limited exceptions to the consent requirement for certain strictly necessary, statistical (aggregated only), and preference cookies. We will update this policy as the ICO publishes finalised guidance on these exceptions.

ICO Guidance: In line with the Information Commissioner’s Office (ICO) guidance, we do not use “cookie walls” that block access to the Services unless consent is given, and we do not treat continued browsing or scrolling as valid consent. Pre-ticked boxes are not used. Your consent is obtained through a clear, affirmative action.

4 Types of Cookies We Use

Category Purpose Duration Consent Required?
Strictly Necessary Essential for the operation of the Services (e.g., authentication, security, session management, and core functionality such as login and checkout). These cookies cannot be switched off. Session or up to 1 year No (PECR Reg. 6(4) exemption)
Performance / Analytics Collect anonymised data on how users interact with the Services to measure performance, identify errors, and improve user experience (e.g., Google Analytics with IP anonymisation enabled). Up to 2 years Yes
Functionality Remember your preferences and settings (e.g., language selection, previously viewed subscription bundles, display preferences). Up to 1 year Yes
Targeting / Advertising Deliver personalised advertisements and measure their effectiveness. Deployed only with your explicit consent. Up to 90 days Yes

Retention justification: Performance/Analytics cookies (up to 2 years) are retained at these durations to accurately measure long-term user retention, assess the effectiveness of service updates, and ensure consistent functionality across sessions. Functionality cookies (up to 1 year) ensure your preferences persist between visits. We review all cookie lifespans regularly to ensure they remain proportionate.

5 Specific Cookies Used on the Services

Cookie Name Provider Category Purpose Expiry
session_id TISA (tisa.one) Strictly Necessary Maintains your authenticated session End of browser session
csrf_token TISA (tisa.one) Strictly Necessary Protects against cross-site request forgery attacks End of browser session
cookie_consent TISA (tisa.one) Strictly Necessary Records your cookie consent preferences 1 year
_ga Google Analytics Performance / Analytics Distinguishes unique users (IP anonymisation enabled) 2 years
_gid Google Analytics Performance / Analytics Distinguishes unique users for 24-hour reporting 24 hours
_gat Google Analytics Performance / Analytics Throttles request rate to limit data collection 1 minute
preferred_plan TISA (tisa.one) Functionality Remembers your last viewed subscription bundle 30 days
ad_id Meta / Google Ads Targeting / Advertising Enables personalised advertising (consent-based only) 90 days
_fbp Meta (Facebook) Targeting / Advertising Identifies browsers for advertising and site analytics 90 days

Note: The cookie_consent cookie is classified as strictly necessary because it is required to record and honour your consent choices, as recommended by ICO guidance. It does not track your activity.

We keep this list under regular review. If we introduce new cookies, this policy will be updated and, where required, fresh consent will be obtained before they are set.

6 Targeted Advertising and Profiling

Where you have given explicit consent, cookies set by advertising partners such as Meta and Google may be used to facilitate cross-site tracking and profiling. This allows us to deliver targeted advertising based on your usage patterns both on and off our Services.

When personal data is shared with these third parties for advertising purposes:

  • Meta (Facebook Pixel / Conversions API): In line with the CJEU ruling in Fashion ID (C-40/17), we act as joint controllers with Meta for the collection and transmission of data via the Facebook Pixel and similar technologies. Meta processes the data it receives as an independent controller for its own purposes. A joint controller arrangement under UK GDPR Article 26 governs this relationship.
  • Google (Analytics / Ads): Google acts as an independent Data Controller for the data it receives. We act as a Data Controller for the data we collect and transmit to Google. Google processes the data in accordance with its own privacy policy.

Important: Advertising cookies are never set without your explicit, informed consent. You can withdraw consent at any time (see Section 7). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Relevant third-party privacy policies:

7 Managing Your Cookie Preferences

7.1 On First Interaction

When you first access the Services, you will be presented with a cookie consent banner offering the following options:

  • Accept All — permits all cookies (analytics, functionality, and advertising)
  • Reject Non-Essential — permits only strictly necessary cookies
  • Manage Preferences — allows granular control over each non-essential cookie category

In accordance with ICO guidance, Reject Non-Essential is given equal prominence to Accept All. We do not use dark patterns, nudging, or confusing language to influence your choice.

7.2 Subsequent Changes

You can manage or withdraw your consent at any time using:

  • Website Cookie Preference Centre — accessible via the cookie icon or “Cookie Settings” link in the website footer.
  • TISA App Settings — navigate to App Settings > Privacy > Cookies within the application.

When you withdraw consent, we will delete or disable the relevant cookies as soon as technically practicable. Some cookies may persist in your browser until they expire; however, they will no longer be read or processed by us.

8 Browser-Level Controls

Most browsers allow you to manage cookies through their settings. You can typically find these under “Privacy” or “Security” in your browser’s preferences. Common browser instructions:

Browser How to Manage Cookies
Google Chrome Settings > Privacy and security > Cookies and other site data
Mozilla Firefox Settings > Privacy & Security > Cookies and Site Data
Apple Safari Preferences > Privacy > Manage Website Data
Microsoft Edge Settings > Privacy, search, and services > Cookies and site permissions
Safari (iOS) Settings > Safari > Advanced > Website Data

You can also opt out of Google Analytics tracking across all websites by installing the Google Analytics Opt-out Browser Add-on.

We use Google Consent Mode V2 to ensure that Google tags respect your consent choices. When you decline analytics or advertising cookies, Google tags operate in a restricted, cookieless mode that does not store identifiers on your device.

Please note: Disabling strictly necessary cookies via your browser may prevent essential features of the Services (e.g., login, checkout, or security protections) from functioning correctly. We recommend using our Cookie Preference Centre rather than browser-level blocking for the best experience.

9 Third-Party Cookies and Partners

Certain cookies are placed by trusted third-party service providers who process data on our behalf or as independent controllers. We ensure that appropriate contractual safeguards are in place.

Third Party Purpose Privacy Policy
Google Analytics Performance and usage analytics (IP anonymisation enabled; data processed in the EU/UK) View
Google Ads Advertising measurement and conversion tracking (consent-based only) View
Meta (Facebook) Advertising measurement and audience building (consent-based only) View
Revolut Checkout Secure payment processing (strictly necessary for transactions) View
Cloudflare Security, DDoS protection, and performance optimisation View

We do not permit third-party tracking for profiling purposes without your explicit consent. Where a third party processes personal data as an independent controller, their own privacy policy governs that processing.

10 Data Retention

Data collected through cookies is retained only for as long as necessary to fulfil the purposes described in this policy:

Cookie Category Maximum Retention Period
Strictly Necessary Session to 1 year (depending on the specific cookie)
Performance / Analytics Up to 2 years (aggregated/anonymised data may be retained longer)
Functionality Up to 1 year
Targeting / Advertising Up to 90 days
Consent records Up to 12 months (consent is re-prompted at least annually to ensure ongoing validity)

After the relevant retention period, cookie data is automatically deleted or anonymised. Where you withdraw consent, cookies are disabled immediately and data is deleted as soon as technically practicable.

11 Your Data Protection Rights

Under the UK GDPR, in relation to personal data collected through cookies, you have the following rights:

  • Right to withdraw consent — for non-essential cookies at any time (via the methods described in Section 7). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right of access — you may make a Subject Access Request (SAR) to obtain a copy of data collected about you via cookies.
  • Right to rectification — you may request correction of inaccurate data.
  • Right to erasure — you may request deletion of cookie data where applicable.
  • Right to object — you may object to processing for analytics or advertising purposes.
  • Right to restrict processing — you may request that we limit how we process your cookie data in certain circumstances.
  • Right to data portability — where processing is based on consent and carried out by automated means.

To exercise any of these rights, please contact our Data Protection Officer at [email protected] or email [email protected]. We will respond within one calendar month of receiving your request, as required by UK GDPR Article 12(3).

Right to complain: If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

12 Children’s Data

Our Services are not directed at children under the age of 16. We do not knowingly set non-essential cookies or collect personal data through cookies from children under 16. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

In accordance with the ICO’s Age Appropriate Design Code (Children’s Code), we ensure that tracking and profiling cookies are not used in contexts where children may be affected.

13 Updates to This Policy

We may update this Cookie Policy from time to time to reflect:

  • New features or technologies introduced on the Services
  • Changes in applicable law or regulatory guidance (including ICO updates)
  • Improvements in clarity or transparency
  • Addition or removal of cookies or third-party partners

The updated version will be published on our Website with a revised effective date. Where changes are material (e.g., introduction of a new cookie category or a new advertising partner), we will re-prompt for consent as required by PECR.

We encourage you to review this policy periodically.

14 Contact & Complaints

General Enquiries

Postal Address

9Eons Limited
Luminous House
300 South Row
Milton Keynes, MK9 2FR
United Kingdom

Supervisory Authority

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.