SecureRoot Risk Advisory LLP
Securing Your Digital Future
Legal · Data Protection

Cookie Policy

Document Reference: SRRA/LEGAL/CP/2026/10
Effective Date: 1 January 2026  |  Version: v.10
Prepared by: Legal, Compliance & Data Protection Office  |  Next Review: January 2027

1. Introduction and Scope

1.1 SecureRoot Risk Advisory LLP (“SecureRoot”, “we”, “our”, “us”) operates the website www.secureroot.co (the “Website”) and uses cookies and similar tracking technologies to enhance user experience, measure website performance, and support our business-development activities.

1.2 This Cookie Policy (“Policy”) explains what cookies are, which cookies we use, the purposes for which we use them, and your rights to control or withdraw consent to their use. It forms part of our Privacy Policy (SRRA/LEGAL/PP/2026/10) and should be read together with it.

1.3 This Policy has been prepared to comply with:

  • Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector (“ePrivacy Directive”), as implemented by EU Member States;
  • The Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) (“PECR”) as applicable in the United Kingdom;
  • Regulation (EU) 2016/679 (“GDPR”) and, as retained in UK domestic law, the UK GDPR read with the Data Protection Act 2018 (“UK GDPR”);
  • The Digital Personal Data Protection Act, 2023 (“DPDPA”) and rules made thereunder (India);
  • The California Consumer Privacy Act 2018, as amended by the California Privacy Rights Act 2020 (“CCPA/CPRA”), to the extent cookie data constitutes Personal Information of California residents;
  • Guidance from the European Data Protection Board (EDPB) on consent (Guidelines 05/2020) and on the use of cookies and similar technologies.

1.4 This Policy applies to all cookies and similar technologies deployed on www.secureroot.co. It does not apply to third-party websites that may be accessible via links on our Website.

2. What Are Cookies and Similar Technologies?

2.1 A cookie is a small text file placed on your device (computer, smartphone, or tablet) by a website when you visit it. Cookies allow the website to recognise your device on subsequent visits and perform various functions described in this Policy.

2.2 Cookies may be:

  • Session cookies: temporary cookies that expire when you close your browser. They are used to maintain session state and security during a single browsing session.
  • Persistent cookies: cookies that remain on your device for a defined period or until you delete them. They are used to remember preferences and recognise returning visitors.
  • First-party cookies: set directly by SecureRoot on www.secureroot.co.
  • Third-party cookies: set by a domain other than www.secureroot.co (e.g., analytics or advertising platforms). Their use is governed by the relevant third party’s privacy and cookie policy.

2.3 Similar Technologies. In addition to cookies, we may use the following tracking technologies, all of which are subject to the same consent requirements as cookies where they access or store information on your device:

  • Web beacons / pixel tags: small transparent images embedded in web pages or emails that record whether a page or email was opened and from which IP address.
  • Local Storage / Session Storage (HTML5): browser-based storage mechanisms used to store data on your device beyond a single session, without an expiry mechanism (Local Storage) or limited to the session (Session Storage).
  • Device fingerprinting: the collection of device attributes (browser type, OS, screen resolution, installed fonts) to identify a device without setting a cookie. Where used, explicit consent is obtained.
  • SDKs and embedded scripts: JavaScript libraries and widgets provided by third parties (e.g., analytics, chat, forms) that may themselves set cookies or collect usage data.

3. Legal Basis for Processing Cookie Data

3.1 Under the ePrivacy Directive, PECR, GDPR, and DPDPA, the following legal bases apply to our use of cookies:

Cookie CategoryePrivacy / PECR BasisGDPR / UK GDPR Basis (Art. 6)DPDPA Basis
Strictly NecessaryExemption from consent (Reg. 6(4) PECR; Art. 5(3) ePrivacy Dir.)Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest (security)Contractual necessity (§ 4(1)(b)); Legitimate use
Functional / PreferenceConsent required (Reg. 6(1) PECR)Art. 6(1)(a) — freely given, specific, informed consentConsent (§ 4(1)(a) DPDPA)
Analytics / PerformanceConsent required; anonymisation may enable legitimate interest in some jurisdictionsArt. 6(1)(a) consent (default); Art. 6(1)(f) where fully anonymisedConsent (§ 4(1)(a) DPDPA); Legitimate use if anonymised
Marketing / TargetingConsent required — always; no legitimate interest relianceArt. 6(1)(a) — explicit, unbundled, granular consentConsent (§ 4(1)(a) DPDPA)

3.2 Consent Standard. Where consent is required, it must satisfy all of the following criteria derived from Art. 4(11) GDPR and EDPB Guidelines 05/2020 on Consent:

  • Freely given: consent must not be a condition of accessing the Website. Cookie walls that prevent access unless all cookies are accepted are not compliant.
  • Specific: consent must be obtained separately for each purpose category. Bundled or pre-ticked boxes do not constitute valid consent.
  • Informed: the user must be provided with clear information about which cookies are used, by whom, and for what purpose, before consenting.
  • Unambiguous: consent must be indicated by a clear affirmative act. Continued browsing or scrolling does not constitute valid consent.
  • Withdrawable: the user must be able to withdraw consent as easily as it was given, at any time, without detriment.
Legal note: The CJEU in Planet49 GmbH v Bundesverband der Verbraucherzentralen (C-673/17) confirmed that pre-ticked boxes do not constitute valid consent under the ePrivacy Directive and GDPR. SecureRoot’s CMP is designed to meet these standards.

4. Cookies and Similar Technologies We Use

4.1 The following tables set out the cookies currently deployed on www.secureroot.co. The list is updated whenever material changes are made.

4.1 Strictly Necessary Cookies

Essential for the Website to function. No consent required.

Cookie NameProviderPurposeTypeDurationData Outside India/EU?
PHPSESSIDSecureRoot (1st party)Maintains session state. Prevents session fixation.SessionSession endNo
_csrf_tokenSecureRoot (1st party)CSRF protection token. Validates form submissions.SessionSession endNo
cookielawinfo-checkbox-*SecureRoot / CMPStores user cookie consent choices per category.Persistent12 monthsNo
viewed_cookie_policySecureRoot / CMPRecords whether user has viewed cookie notice banner.Persistent12 monthsNo

4.2 Functional / Preference Cookies

Enhanced functionality and personalisation. Consent required.

Cookie NameProviderPurposeTypeDurationData Outside India/EU?
wp-settings-*WordPress (1st party)Stores user preferences for WordPress admin interface.Persistent1 yearNo
wp-settings-time-*WordPress (1st party)Records the time wp-settings were last updated.Persistent1 yearNo
language_prefSecureRoot (1st party)Remembers selected language across sessions.Persistent6 monthsNo
HubSpotUtkHubSpot (3rd party)Tracks visitor identity for HubSpot CRM forms.Persistent13 monthsYes — US (SCCs / EU-US DPF)

4.3 Analytics / Performance Cookies

Help us measure and improve Website performance. Consent required.

Cookie NameProviderPurposeTypeDurationData Outside India/EU?
_gaGoogle AnalyticsUnique ID for visitor statistical data. IP anonymisation enabled.Persistent2 yearsYes — US
_ga_*Google AnalyticsPersists GA4 session state and measurement ID.Persistent2 yearsYes — US
_gidGoogle AnalyticsUnique ID for usage statistics. Expires after 24 hours.Persistent24 hoursYes — US
_gat_gtag_*Google Tag ManagerThrottles request rate to Google Analytics.Session1 minuteYes — US
_hjSessionUser_*Hotjar (if activated)Identifies new user session. Heatmaps / session recordings.Persistent365 daysYes — EU
_hjSession_*Hotjar (if activated)Contains current Hotjar session data.Session30 minutesYes — EU

4.4 Marketing / Targeting Cookies

May be set by advertising partners. Consent always required and unbundled.

Cookie NameProviderPurposeTypeDurationData Outside India/EU?
_fbpMeta (Facebook) PixelAd delivery / retargeting. Only with consent.Persistent3 monthsYes — US
li_fat_idLinkedIn Insight TagMember identifier for LinkedIn conversion tracking.Persistent30 daysYes — US
UserMatchHistoryLinkedInAd-matching cookie for retargeting and frequency capping.Persistent30 daysYes — US
IDEGoogle DoubleClickReports on user actions after viewing Google ads.Persistent13 monthsYes — US
Note: Marketing cookies are not currently active on www.secureroot.co unless you have provided explicit consent via the cookie banner. This table reflects potential future deployment.

5. Consent Management Platform (CMP) and How We Obtain Consent

5.1 SecureRoot deploys a Consent Management Platform (CMP) on www.secureroot.co. The CMP presents a layered consent notice to all users on their first visit and whenever consent preferences are to be renewed or updated.

5.2 The CMP is configured to meet the following technical and operational requirements:

  • Layered presentation: a first layer (banner) provides high-level information and category-level consent choices. A second layer (preference centre) provides granular per-cookie and per-purpose controls.
  • No pre-ticked boxes: all non-essential cookie categories are off by default (opt-in).
  • No cookie walls: the Website is fully accessible regardless of the user’s cookie choices.
  • Consent logging: each consent decision is recorded with a timestamp, the CMP version number, the categories consented to, and a consent ID. Records retained for a minimum of 3 years.
  • Consent renewal: consent is renewed at least every 12 months, or when the cookie inventory materially changes.
  • Withdraw mechanism: users may update or withdraw consent at any time by clicking the “Cookie Preferences” link in the Website footer.

5.3 Where a user’s browser sends a Global Privacy Control (GPC) signal or similar opt-out signal, SecureRoot’s Website will treat this as a withdrawal of consent for non-essential cookies and will not activate such cookies for that session.

5.4 Consent is specific to the device and browser from which it is given. If you use multiple devices or browsers, you will need to manage your preferences on each separately.

6. Third-Party Cookies and Data Transfers

6.1 Several cookies on our Website are set by third-party providers. SecureRoot does not control the data collection and use practices of these third parties. Their use of any data collected through their cookies is governed by their own privacy and cookie policies.

6.2 Key third-party providers and their applicable policies:

ProviderServicePrivacy / Cookie Policy URLTransfer Safeguard
Google LLCGoogle Analytics, Tag Manager, Google Adspolicies.google.com/privacyEU-US Data Privacy Framework; SCCs
Meta Platforms Ireland Ltd.Facebook Pixel (if activated)www.facebook.com/privacy/policySCCs; EU-US DPF
LinkedIn Ireland Unlimited CompanyLinkedIn Insight Tag (if activated)www.linkedin.com/legal/privacy-policySCCs
HubSpot Inc.CRM forms, email trackinglegal.hubspot.com/privacy-noticeSCCs; EU-US DPF
Hotjar Ltd.Heatmaps, session recordings (if activated)www.hotjar.com/legal/policies/privacySCCs; data residency EU option
Cloudflare Inc.CDN, security, bot protectionwww.cloudflare.com/privacypolicySCCs; EU-US DPF
WordPress.org / AutomatticCMS infrastructureautomattic.com/privacySCCs; EU-US DPF

6.3 International Transfers. Some of the third-party cookies listed above involve the transfer of personal data to the United States or other jurisdictions outside India and the EU/EEA/UK. SecureRoot ensures appropriate safeguards are in place for such transfers, as set out in Section 8 of the Privacy Policy.

7. How to Control and Manage Cookies

7.1 Via Our CMP

The most reliable way to manage your cookie preferences on our Website is via our Consent Management Platform. Click “Cookie Preferences” in the Website footer at any time to view or update your choices. Changes take effect immediately for that browsing session.

7.2 Via Your Browser Settings

All major browsers allow you to control cookies through their settings:

  • Google Chrome: Settings > Privacy and Security > Cookies and other site data
  • Mozilla Firefox: Options > Privacy & Security > Cookies and Site Data
  • Apple Safari: Preferences > Privacy > Manage Website Data
  • Microsoft Edge: Settings > Cookies and site permissions
  • Opera: Settings > Advanced > Privacy & Security > Site Settings > Cookies

Note: Blocking all cookies via browser settings will affect your experience of our Website and may prevent certain features from functioning.

7.3 Opt-Out Tools Provided by Third Parties

  • Google Analytics opt-out: tools.google.com/dlpage/gaoptout
  • Google Ad personalisation: adssettings.google.com
  • LinkedIn Ad opt-out: www.linkedin.com/psettings/guest-controls
  • Network Advertising Initiative (NAI) opt-out: optout.networkadvertising.org
  • Your Online Choices (EU): www.youronlinechoices.eu
  • Digital Advertising Alliance (DAA — US): optout.aboutads.info

7.4 Do Not Track and Global Privacy Control

Some browsers include a “Do Not Track” (DNT) feature. There is currently no universal standard for DNT signals, and most websites (including ours via standard analytics tools) do not respond to DNT browser signals. However, SecureRoot’s Website does recognise and honour Global Privacy Control (GPC) signals, treating them as withdrawal of consent for non-essential cookies.

7.5 Mobile Device Controls

On mobile devices, you can control interest-based advertising through your device settings: iOS: Settings > Privacy > Tracking; Android: Settings > Google > Ads > Opt out of Ads Personalisation. In-app SDKs are governed by the respective app’s privacy notice.

8. Data Subject Rights in Relation to Cookie Data

8.1 Cookie data that constitutes Personal Data (e.g., IP addresses, device identifiers, browsing history linked to an identifiable individual) is subject to the full range of Data Subject rights set out in the Privacy Policy (SRRA/LEGAL/PP/2026/10), Section 11.

8.2 Specifically relevant rights:

  • Right to withdraw consent (Art. 7(3) GDPR; § 6(4) DPDPA): withdrawal may be effected at any time via the CMP or by emailing privacy@secureroot.co. Withdrawal does not affect the lawfulness of prior processing.
  • Right of access (Art. 15 GDPR; § 11 DPDPA): you may request information about the Personal Data collected through cookies.
  • Right to erasure (Art. 17 GDPR; § 13 DPDPA): you may request deletion of Personal Data collected through cookies.
  • Right to object (Art. 21 GDPR): for cookies relying on legitimate interests, you may object to processing at any time.
  • CCPA opt-out right (Cal. Civ. Code § 1798.120): where cookie data constitutes Personal Information of California residents that is “shared” for cross-context behavioural advertising, you may opt out via the CMP.

9. Data Retention and Cookie Lifespan

9.1 The lifespan of each individual cookie is set out in the cookie inventory tables in Section 4. Persistent cookies will be automatically deleted from your device after the specified duration unless you delete them earlier through your browser or device settings.

9.2 Where cookie data is processed as Personal Data by SecureRoot, it is retained in accordance with the retention schedule in the Privacy Policy. In summary:

  • Analytics data (identified/pseudonymised): 26 months from collection, after which it is anonymised or deleted.
  • CMP consent records: minimum 3 years from the date of consent or last update, for audit purposes.
  • Marketing/remarketing data: until the relevant cookie expires on the user’s device or consent is withdrawn, whichever is earlier.

10. Security of Cookie Data

10.1 SecureRoot implements appropriate technical and organisational measures to protect Personal Data collected through cookies against unauthorised access, disclosure, alteration, or destruction.

10.2 Specific security measures for cookie data include:

  • The Secure flag is set on all cookies containing session identifiers or authentication tokens, ensuring they are transmitted only over HTTPS connections.
  • The HttpOnly flag is set on session and authentication cookies to prevent access by client-side JavaScript, mitigating cross-site scripting (XSS) risk.
  • The SameSite=Strict or SameSite=Lax attribute is applied where appropriate to mitigate cross-site request forgery (CSRF) attacks.
  • Session cookies are regenerated on login/logout to prevent session fixation.
  • Cookie values do not contain unencrypted Personal Data.

11. Updates to This Cookie Policy

11.1 SecureRoot reviews this Cookie Policy at least annually, and whenever: (a) new cookies are deployed or existing ones are materially changed; (b) new third-party providers are onboarded; (c) applicable law or regulatory guidance changes.

11.2 The “Effective Date” and version number at the top of this document indicate when it was last revised. Material changes will be notified via the CMP banner and, where appropriate, by email to registered users. Upon material change, consent will be renewed where required.

11.3 The current version of this Policy is always available at www.secureroot.co/cookie-policy.

12. Contact and Complaints

For questions, to exercise your rights, or to manage your cookie preferences, please contact our Data Protection function:

SecureRoot Risk Advisory LLP — Data Protection & Privacy Team
Email: privacy@secureroot.co
Phone: +91 73071 48874
Website: www.secureroot.co
Head Office: 305, 3rd Floor, Krishna Tower, 15/63, Civil Lines, Kanpur – 208001, Uttar Pradesh
Corporate Office: Greater Noida, Uttar Pradesh, India

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority: India — Data Protection Board of India; EU/EEA — supervisory authority of your Member State; UK — ICO (ico.org.uk); California (US) — California Privacy Protection Agency (cppa.ca.gov).

Speak With Our Experts