Loading...
Legal
This Cookie Policy explains how Pericls Ltd ("Pericls", "we", "us", or "our") uses cookies and similar storage technologies on our regulatory compliance intelligence platform at https://app.pericls.com and our website at https://www.pericls.com (together, the "Service").
This Cookie Policy should be read alongside our Privacy Policy, which provides further detail on how we collect and process personal data.
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. They are widely used to make websites work more efficiently and to provide information to the website operator. Cookies can be "persistent" (they remain on your device until they expire or are manually deleted) or "session" cookies (they are deleted when you close your browser).
In addition to cookies, we use other client-side storage mechanisms:
These technologies are collectively referred to as "cookies and similar technologies" throughout this policy.
We use cookies and similar technologies for the following purposes:
We classify the cookies and storage technologies used on the Service into the following categories:
These cookies are essential for the operation of the Service. They enable core functionality such as authentication, security, and payment processing. The Service cannot function properly without them, and they cannot be disabled.
Legal basis: Exempt from consent under Regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) and Article 5(3) of the ePrivacy Directive — these cookies are strictly necessary for the provision of a service explicitly requested by the user.
| Name | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
refresh_token | Pericls | HTTP-only secure cookie | Stores the refresh token for authentication. Used to issue new access tokens without requiring the user to re-enter credentials. Set with HttpOnly, Secure, and SameSite=Lax flags, scoped to the /api/auth path. | 7 days (refreshed on use) |
pericls-cookie-consent | Pericls | localStorage | Stores your cookie consent choices so we can respect them on subsequent visits. | Persistent (until cleared) |
__stripe_mid | Stripe | Third-party cookie | Stripe fraud prevention — provides a unique identifier for the device to detect fraudulent payment activity. | 1 year |
__stripe_sid | Stripe | Third-party cookie | Stripe fraud prevention — session identifier used to maintain payment session integrity during checkout. | 30 minutes |
These cookies enable enhanced functionality and personalisation. They remember your preferences and settings so you do not have to re-enter them each time you use the Service.
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) for localStorage items essential to UI function; consent for non-essential functional cookies.
| Name | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
pericls-ui-storage | Pericls | localStorage | Stores user interface state such as sidebar collapse/expand, table column widths, sort preferences, and panel positions. Ensures a consistent experience across sessions. | Persistent (until cleared) |
pericls-assessment | Pericls | localStorage | Preserves compliance assessment progress (current step, selected answers) so you can resume an interrupted assessment without data loss. | Persistent (until cleared or assessment completed) |
These cookies help us understand how visitors interact with the Service by collecting information about pages visited, features used, and user journeys. This data is used to improve the Service's functionality and user experience.
Legal basis: Consent (Article 6(1)(a) GDPR). Analytics tracking is disabled by default and is activated only after you provide consent through our cookie consent banner. If you decline or withdraw consent, PostHog storage entries are removed.
| Name | Provider | Type | Purpose | Duration |
|---|---|---|---|---|
ph_phc_*_posthog | PostHog | localStorage | Primary PostHog analytics storage entry. Stores a unique identifier for the user and session metadata. Used to track page views, feature interactions, and user journeys within the Service. | Persistent (until cleared or consent withdrawn) |
ph_* (other entries) | PostHog | localStorage | Supporting PostHog entries such as the distinct user identifier and session identifier, used to associate events with a user profile and group interactions into sessions. | Persistent (until cleared or consent withdrawn) |
PostHog data processing: PostHog analytics data is hosted in the United States (PostHog Cloud). We have a Data Processing Agreement in place with PostHog. For more information, see PostHog's Privacy Policy and our Sub-Processor List.
The following table provides a comprehensive list of all client-side storage keys used by the Service:
| Key | Category | Purpose | Data Stored |
|---|---|---|---|
pericls-cookie-consent | Strictly necessary | Cookie consent record | JSON object containing your consent choices per cookie category and the date consent was given |
pericls-ui-storage | Functional | UI state persistence (Zustand store) | JSON object containing sidebar state, table preferences, panel positions, and other UI settings |
pericls-assessment | Functional | Assessment progress | JSON object containing assessment step index, selected answers, and partial form data |
ph_phc_*_posthog and other ph_* keys | Analytics (consent required) | PostHog analytics persistence | Anonymous/distinct identifiers, session metadata, feature flags |
The Service does not currently use sessionStorage for any persistent data. Transient session data is managed through in-memory state and server-side sessions.
Some cookies on the Service are placed by third-party services that we use. We do not control these cookies. Below is a summary of third-party cookie providers:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Stripe | Payment processing and fraud prevention | https://stripe.com/privacy |
| PostHog | Product analytics and usage tracking | https://posthog.com/privacy |
Stripe cookies are classified as strictly necessary because they are integral to the secure processing of payments. PostHog cookies are classified as analytics and require your consent.
When you first visit the Service, you will see a cookie consent banner that allows you to:
Your consent preference is stored and respected on subsequent visits. You can change your preferences at any time by clicking the "Cookie Preferences" link in the Service footer.
Most web browsers allow you to manage cookies through their settings. You can typically:
Instructions for common browsers:
To clear localStorage data set by the Service:
https://app.pericls.comAlternatively, clearing your browser data/cache for the site will remove all localStorage entries.
Analytics capturing is off by default: PostHog does not record any events until you grant analytics consent through the cookie consent banner. In addition to using the banner, you can opt out of PostHog analytics by:
Disabling certain cookies may affect your experience with the Service:
| Cookie Category | Impact of Disabling |
|---|---|
| Strictly Necessary | You will be unable to sign in or use the Service. Payment processing will not function. These cookies cannot be disabled while using the Service. |
| Functional | Your preferences (UI layout, table settings) will not persist between sessions. Assessment progress will not be saved if you leave the page. You will need to reconfigure preferences on each visit. |
| Analytics | No impact on Service functionality. We will be unable to analyse usage patterns, which may affect our ability to identify and fix issues or improve features. |
The Service takes a consent-first approach to analytics rather than relying on browser "Do Not Track" signals:
| Duration Type | Description |
|---|---|
| Session | Deleted when you close your browser |
| 30 minutes | Expires 30 minutes after being set (or last renewed) |
| 7 days | Expires 7 days after being set (or last renewed) |
| 1 year | Expires 1 year after being set |
| Persistent (localStorage) | Remains until explicitly deleted by the application or by the user |
The Pericls API at https://api.pericls.com sets the following cookies:
| Name | Type | Purpose | Flags | Duration |
|---|---|---|---|---|
refresh_token | HTTP-only cookie | Authentication refresh token | HttpOnly, Secure, SameSite=Lax, Path=/api/auth | 7 days |
This cookie is set on the API domain and is not accessible to JavaScript running in the browser (due to the HttpOnly flag). It is transmitted only over HTTPS connections (due to the Secure flag) and only on same-site or top-level navigation requests (due to the SameSite=Lax flag).
We may update this Cookie Policy from time to time to reflect changes in the cookies we use, changes in technology, or changes in applicable law. When we make material changes:
We encourage you to review this Cookie Policy periodically.
This Cookie Policy forms part of our broader data protection framework. For further information, please refer to:
If you have any questions about this Cookie Policy or our use of cookies, please contact us:
Data Protection Officer:
Email: dpo@pericls.com
General Enquiries:
Email: legal@pericls.com
Customer Support:
Email: support@pericls.com
Postal Address:
Pericls Ltd
Charterhouse Millburgh Hall, Graffham, Petworth
England, GU28 0QH
| Date | Version | Change Description |
|---|---|---|
| 4 April 2026 | 1.0 | Initial publication |
| 5 July 2026 | 1.1 | Corrected authentication cookie name (refresh_token); documented pericls-cookie-consent storage; PostHog entries reclassified as localStorage; removed unused theme preference key; replaced Do Not Track section with consent-first analytics description |
This Cookie Policy is provided in English. If there is any conflict between a translated version and the English version, the English version shall prevail.