Get in touch

info@ostwalden.co.uk

Monday – Friday, 09:00 – 20:00
Saturday & Sunday, 09:00 – 19:00, by appointment

In an emergency call 999, or Samaritans free on 116 123.

Legal

Ostwalden Cookie Policy — Version 1.0, 22 September 2026

Last updated: 22 September 2026. Version 1.0. This policy explains what this website stores on your device, what it does not store, and what choices you have.

1. About this policy

If you need help now, this is not the page to find it on. Ostwalden is not an emergency or crisis service, and our enquiry mailbox is not monitored around the clock. If you are in danger, or you are thinking about harming yourself, call 999; or call 111 and choose the mental health option; or call Samaritans free on 116 123, at any hour of any day; or, if you would rather text than talk, text SHOUT to 85258.

Ostwalden is a trading name of OSTWALDEN LIMITED, a company registered in England and Wales, company number 17119228. Our registered office is Suite 5, 5th Floor City Reach, 5 Greenwich View Place, London E14 9NN. You can reach us about anything in this policy at info@ostwalden.co.uk. We have no telephone line; email is the way to reach us.

This policy covers this website, ostwalden.co.uk. It sits alongside our privacy notice, which explains what we do with personal information more generally, including the details you send us through the enquiry form, and our terms of use.

We have written this policy against the site as it is today. Today the site is a brochure site. There is no booking, no payment, no account, no counsellor directory, no reviews and no chat. The only thing you can do here besides read is send us an enquiry.

2. The short version

  • We do not use analytics cookies. We do not use advertising or marketing cookies. We do not track you across other websites, and we do not build a profile of you.
  • Up to five small items may be stored on your device: one that remembers you have seen our cookie notice, one short-lived token that protects our enquiry form from automated abuse, and up to three security items set by Cloudflare, the company that protects and delivers this site.
  • Every one of those is there so that the site you asked for works and stays available. The law does not require us to ask your permission before setting them. It does expect us to tell you about them, which is what this policy is for.
  • There is nothing optional here, so there is nothing to switch on or off. The notice you see on your first visit tells you what is stored; it does not ask you a question.
  • If we ever do add something optional, we will ask first, and saying no will be exactly as easy as saying yes.

3. Cookies, local storage and tokens

A cookie is a small text file that a website asks your browser to keep. Your browser sends it back the next time you visit, so the site can recognise the same browser. Cookies are not programs and cannot read anything else on your computer.

Local storage does a similar job. It is a small space in your browser where a website can keep a note for itself. Unlike a cookie, it is not sent to the server with every request. It simply stays in your browser until it is cleared.

A token is a short piece of text, signed by our server, that shows a request came from a real page on our site rather than from an automated script. It is short-lived by design. What it identifies is the page it was issued to, not the person using it; where it is tied to your IP address or to a session identifier, that is personal information, and our privacy notice explains how we treat it.

The law treats all three the same way. It does not care what the technology is called. It cares that something is being stored on your device, or read from it.

Not everything we do about spam involves your device. Our form also uses a field that is positioned off the screen and that a person will never see or fill in, a check on how quickly the form was completed, and a limit on how many submissions can come from one internet connection in a short time. None of those three stores anything on your device, so none of them appears in the table below. Our privacy notice describes them.

Server logs are different, and this policy does not cover them. Our server keeps a record of requests made to it, including IP addresses, for 14 days, so that we can investigate attacks and faults, and then deletes it. Nothing is stored on your device to do that, so it is covered by our privacy notice rather than by this policy.

4. The law, and why we do not ask your permission for these items

The rule that applies is regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, usually shortened to PECR. Regulation 6 was rewritten by the Data (Use and Access) Act 2025.

Regulation 6 begins with a prohibition. Nobody may store information on your device, or gain access to information already stored there, unless one of the exceptions listed in Schedule A1 to PECR applies. In plain terms, those exceptions are:

  • you have given your consent;
  • the storage is only there to carry a communication across a network;
  • it is strictly necessary to provide a service that you have asked for (paragraph 4);
  • it is for limited statistical purposes, and every condition in paragraph 5 is satisfied;
  • it is used to adapt how the site looks or behaves in a way you have asked for (paragraph 6); or
  • your device has asked for emergency assistance, or has shown that you need it, and the only purpose of the storage is to work out where you are so that help can be sent (paragraph 7).

The last three have nothing to do with this site. We collect no statistics, we adapt nothing to your preferences, and we are not an emergency service: this site cannot and does not locate you.

If none of those applies, consent is required, and consent has a demanding meaning. It is defined by the UK GDPR as a freely given, specific, informed and unambiguous indication of your wishes, made by a clear positive action. Continuing to browse is not consent. A box that is already ticked is not consent. And under Article 7(3) of the UK GDPR, withdrawing consent must be as easy as giving it.

Strictly necessary is judged from your point of view, not ours. It covers what genuinely has to happen for the page you asked for to reach you, and for the thing you asked to do to work. Keeping the site available when it is under attack, and stopping our enquiry form being flooded by automated scripts, fall inside that. Measuring how you move around the site does not. The site would work in exactly the same way without measurement, so measurement is something we would have to ask you for.

That is the whole reason this site sets so little.

Paragraph 4(2) of Schedule A1 spells out the kinds of storage Parliament had in mind: protecting information connected with providing the service; making sure the security of the service and of your own equipment is not harmed; preventing or detecting fraud; preventing or detecting technical faults; authenticating you automatically; and keeping a record of the selections you have made on a website. Every row in the table below falls inside one of those, and the table says which.

Being exempt from asking does not mean we should stay silent. Where these items involve personal information, the UK GDPR requires us to explain them, and the Information Commissioner's Office expects a site to list what it stores even where no consent is needed. That is what the next section does.

5. What this site stores on your device

Name Set by, and what kind of thing it is What it does, and how long it lasts Which PECR exception applies
ostwalden_cookie_choice Ostwalden, in your browser's local storage Remembers that you have seen our cookie notice, so that it does not reappear on every page. Kept for 12 months, after which the notice is shown again. It goes sooner if you clear your browser storage. It never reaches our server. Schedule A1, paragraph 4: strictly necessary for the service you asked for. Paragraph 4(2) gives keeping a record of the selections you have made on a website as an example. No consent is required.
No name — nothing is stored Ostwalden. Not a cookie and not local storage: a value held in the page itself. When you open the enquiry page, the page asks our server for a signed, single-use token and keeps it in a hidden field. It is sent back with your enquiry so the server can tell a real submission from an automated one. It is never written to your device, and it disappears the moment you close or reload the page. Nothing is stored on your device, so regulation 6 of PECR is not engaged at all and no consent is required.
__cf_bm Cloudflare, our security provider. A cookie, served from ostwalden.co.uk. Helps Cloudflare tell automated traffic apart from real visitors, so that the site stays available. 30 minutes. Schedule A1, paragraph 4: strictly necessary. Paragraph 4(2) covers storage that keeps the security of the service, and of your own device, from being harmed. No consent is required.
cf_clearance Cloudflare, our security provider. A cookie, served from ostwalden.co.uk. Records that your browser has already passed a security check, so that you are not challenged again on every page. It is set only if you are challenged. How long it lasts is a setting in our Cloudflare account; at the date at the top of this page that setting is 30 minutes. Schedule A1, paragraph 4: strictly necessary. Paragraph 4(2) covers storage that keeps the security of the service, and of your own device, from being harmed. No consent is required.
_cfuvid Cloudflare, our security provider. A cookie, served from ostwalden.co.uk. Lets Cloudflare apply a rate limit to a single browser, so that one source cannot overwhelm the site. Deleted when you close your browser. Schedule A1, paragraph 4: strictly necessary. Paragraph 4(2) covers storage that keeps the security of the service, and of your own device, from being harmed. No consent is required.

Three points about that table.

First, Cloudflare's items are not all set on every visit. Some belong to the standing protection in front of the site; cf_clearance appears only if that protection asks your browser to complete a security check, which can happen at any time and which you may have to pass before a page will load or the form will send. Cloudflare publishes its own description of these cookies at developers.cloudflare.com.

Second, we do not use Cloudflare Turnstile on the enquiry form today. If we switch it on, it will set its own items on your device, and we will add them to this table and say so in our privacy notice before it goes live.

Third, we have named each item deliberately. You can see every one of them for yourself in your browser's own settings or developer tools, and a policy that described them only in general terms would not be telling you anything useful. What we do not publish is how the enquiry token is generated or checked, because that is the part that would help someone abuse the form.

This is the list as at the date at the top of this page. Cloudflare's protection is configured by us, so what it sets can change if we change those settings; we check the list against the live site before we publish a new version of this policy, and we change the date when we do. If you find something on your device from this site that is not listed here, tell us at info@ostwalden.co.uk and we will either explain it or remove it. Just tell us the name of the item and the page you were on. You do not have to explain why you looked.

6. What we do not use

It is worth being specific about the absences, because most cookie policies are vague about them.

  • No analytics. We do not use Google Analytics or any other measurement tool. We do not count visits, sessions, page views or scroll depth on your device, and we do not rely on the statistical exception in Schedule A1.
  • No advertising or marketing cookies. We do not run advertising pixels, retargeting tags or conversion tracking, and we do not share anything with advertising networks.
  • No social media buttons or embeds, which set their own cookies wherever they appear.
  • No embedded video, maps or comment systems.
  • No cross-site tracking and no device fingerprinting. We do not try to identify your device by its settings, fonts or screen size.
  • No fonts, scripts or images loaded from anyone else's servers. Everything this page needs is served from ostwalden.co.uk, so your browser is not quietly asking Google, or anyone else, for a font every time you open a page.
  • No selling or sharing of your information for anyone else's marketing. Not now, and not later.

We say this because of what this site is. People come here at difficult points in their lives. Whatever else we are uncertain about, we are not uncertain about that.

7. The notice you see, and what happens if we ever add anything optional

You will see a short notice the first time you visit, telling you what this site stores and linking to this page. It has one button, which dismisses it. It is not a consent request, because there is nothing here that needs your consent: every item in the table above sits inside paragraph 4 of Schedule A1 to PECR. We would rather tell you plainly what is set than ask you a question we could not act on either way.

If we ever add anything optional, that notice becomes a consent banner, shown before the optional item is set rather than after. It will carry an Accept button and a Reject button of the same size, the same colour and the same prominence, with nothing pre-selected; nothing optional will be set if you reject it, close it or ignore it; and a Cookie settings link in the footer of every page will let you change your mind in one click, as easily as you agreed, without telling us why.

You can reopen this page at any time from the Cookie settings link in the footer. Until there is something optional to choose, that is all the link does.

Two honest caveats. Nothing you do on this page can remove the strictly necessary items in the table above, because the site cannot be delivered safely without them; if you want those gone, the place to do it is your browser, and section 8 explains what happens if you do. And if you clear your browser storage, you will clear the record of the notice along with it, so the notice will appear again. The only way to stop the notice reappearing is to store the fact that you have seen it.

8. Controlling cookies in your browser

Your browser gives you controls that work across every site you visit, and they override anything we do.

  • You can see, and delete, every cookie and storage entry a site has set. In most browsers this is under Settings, then Privacy and security.
  • You can block all cookies, or delete everything automatically each time you close the browser. Blocking only third-party cookies will not remove the Cloudflare items in the table above: Cloudflare sits in front of this site rather than beside it, so its cookies arrive from ostwalden.co.uk and your browser counts them as ours.
  • You can use a private or incognito window, which discards cookies and local storage when you close it.

Your browser's own help pages explain exactly where these settings are, and they change from version to version, so we would rather point you there than guess. The Information Commissioner's Office also publishes plain guidance on cookies for the public at ico.org.uk.

If you block the strictly necessary items, please expect the site to work less well. The cookie notice will reappear on every page, because we will have no way to remember that you have seen it. Cloudflare's protection may challenge you repeatedly, or may not let the page load at all. Most importantly, the enquiry form may stop working, because our server will have no way to tell your submission apart from an automated one. That is not us being difficult; it is the cost of a form that is not overwhelmed by spam. If it happens, please email us directly at info@ostwalden.co.uk instead. Ordinary email goes through none of these checks. You should never have to accept a cookie to reach us.

Some browsers send a Do Not Track or Global Privacy Control signal. We do not currently act on those signals, for the simple reason that we do not do any of the things they are designed to stop. If that ever changes, this policy will change with it.

9. If you share a device with someone else

Nothing on this page stops your own browser recording that you visited this site. Browsing history, saved passwords and autocomplete are usually a much bigger exposure than any cookie, and they are outside our control.

If you are worried about someone else seeing that you have been here, a private or incognito window is the simplest protection, because it keeps no history and discards storage when you close it. Clearing your history afterwards also works.

You can reach us from any device and any email address, including one that is not your usual one. If it would not be safe for our reply to arrive in the inbox you write from, say so in your message: we will agree a different way to answer you, or not reply at all if that is what you want.

10. Cloudflare, Singapore, and where information goes

Cloudflare is the only other company that sets anything on your device through this site. Cloudflare, Inc. is a United States company operating a worldwide network. It sits in front of our website as a content delivery network, a domain name service and a web application firewall, which is why its cookies are security cookies rather than commercial ones.

Cloudflare acts as our processor. Our contract with it includes the data protection terms required by Article 28 of the UK GDPR, so it may handle what it sees only on our instructions and not for its own purposes, and we have enabled no Cloudflare feature used for advertising or audience measurement.

Two of the journeys your visit makes leave the United Kingdom, and you should not have to open another document to find out which.

  • Cloudflare, in the United States. Your request is handled at whichever of Cloudflare's locations is nearest to you, and Cloudflare, Inc. is a US company. The United States is covered by UK adequacy regulations only in part: the cover extends to organisations holding an active certification under the UK Extension to the EU-US Data Privacy Framework, and only for the categories of information they have registered to receive. We check a provider's entry on that list rather than assuming it. Where the certification does not cover the transfer, we use the safeguard described below.
  • Our own server, in Singapore. The server your request finally reaches is in Singapore. Singapore is not covered by UK adequacy regulations. There is no finding that Singapore protects personal information to a standard equivalent to the United Kingdom's, and we are not going to imply that there is.

Where adequacy regulations do not cover a transfer, we rely on a safeguard under Article 46 of the UK GDPR: the UK Addendum to the EU standard contractual clauses where the provider already offers those clauses, and the standalone International Data Transfer Agreement issued by the ICO where it does not. Article 46 also requires us to be satisfied that the data protection test is met, meaning that the protection your information would receive there is not materially lower than the protection it has here. We have carried out that assessment, we have recorded it, and we keep it on file.

Section 7 of our privacy notice sets this out recipient by recipient, and you can ask us for a copy of the safeguards at info@ostwalden.co.uk.

11. Our emails

When you send an enquiry, we reply from our own mailbox, which is hosted by Namecheap Private Email. We do not put tracking pixels in our replies and we do not use tracked links, so we do not know whether you have opened a message or clicked anything in it.

We intend, in future, to send automatic messages through a specialist email provider based in the United States, [to be confirmed] — an acknowledgement that your enquiry has arrived, for example. That is not in use today, and nothing of the kind is sent. We will name the provider here, and in our privacy notice, before the first message goes out, and open and click tracking will be switched off in its settings.

12. What will change when bookings open

We intend to let clients book and pay for sessions on this site in future. None of that exists today, and we have not written this policy as though it does.

When it is built, it will need things this site does not have: a cookie to keep you signed in to your account, and cookies set by our payment provider. A cookie that keeps you signed in is strictly necessary in the same way as the items above. Our payment provider's cookies are a separate question: some will be strictly necessary to take a payment and to stop fraud, and some will not be. We will work out which is which, and say so here, before the first payment page goes live, rather than assume the answer now.

We may also want to understand how people use the booking pages. If we do, we will either ask for your consent properly, with the reject option as prominent as the accept option and nothing set until you choose, or we will rely on the statistical exception in Schedule A1 only if we can meet every one of its conditions. We will tell you here which of the two we are doing, and give you a simple free way to object.

We will update this policy before any of that goes live, not afterwards.

13. Questions and complaints

If anything here is unclear, or you want to know more about a particular item, please email info@ostwalden.co.uk and ask. It is a fair question and you will get a straight answer.

If you are unhappy with how we have handled your personal information, you have a right under section 164A of the Data Protection Act 2018 to complain to us directly. Please email info@ostwalden.co.uk. You do not have to use any particular form of words or any particular route; however your complaint reaches us, we will accept it. We will acknowledge it within 30 days of receiving it, respond without undue delay, and tell you the outcome.

We should be straight with you about who will look at it. Ostwalden has no employees. Our sole director will read your complaint and answer it. We cannot offer you an independent review inside this company, and we are not going to pretend we can. That is one reason the route below matters, and you can use it at any point.

You can complain to the Information Commissioner's Office, which regulates both data protection and the cookie rules in PECR. A complaint about the personal information involved in these items is made under section 165 of the Data Protection Act 2018; a complaint about what this site stores on your device is a PECR complaint, which the ICO takes through the same route. You can do either at ico.org.uk/make-a-complaint. Coming to us first does not affect that right, and you do not need our permission.

We are completing our registration with the Information Commissioner's Office and paying the data protection fee. Our registration number will be published here as soon as it is issued: [to be confirmed]. We will note the change in section 14 when it happens.

14. Changes to this policy

We review this policy whenever we change how the website is built, and at least once a year. If we change it, we will change the date and the version number at the top, and where the change matters to you we will explain what has changed rather than leave you to compare two versions.

This is version 1.0, published on 22 September 2026. It is the first version of this policy, so there is nothing yet to compare it with; every later version will carry its own number and a note of what changed. It is governed by the law of England and Wales, and nothing here takes away your right to bring a claim in the courts of the part of the United Kingdom where you live.

OSTWALDEN LIMITED, registered in England and Wales, company number 17119228. Registered office: Suite 5, 5th Floor City Reach, 5 Greenwich View Place, London E14 9NN. Email info@ostwalden.co.uk.