Cookie Policy

Outbreach cybersecurity experts analysing data on screen.

This policy explains how Outbreach Ltd uses cookies and similar technologies on this website, what each one does, how long it lasts, and how you can change your mind at any time. It should be read alongside our privacy policy, which covers everything else we do with personal data.

1. Who we are

Outbreach Ltd is a company registered in England and Wales under company number 15350710, with its registered office at 71 to 75 Shelton Street, Covent Garden, London WC2H 9JQ. For the cookies and similar technologies we set on this website, and for the personal data they involve, Outbreach Ltd is the data controller.

If you have a question about this policy, or you want to exercise any of the rights described below, contact us at help@outbreach.com or write to us at the registered office address.

2. What cookies and similar technologies are

A cookie is a small text file that a website asks your browser to store on your device. When you come back, the browser hands that file back, which is how a site recognises a returning visit, remembers a preference, or counts a page view.

This policy uses “cookies” as shorthand for cookies and for the other technologies that work in a comparable way, including:

  • Local storage and session storage, which hold data in the browser rather than in a cookie file.
  • Pixels and tracking images, which are tiny image files that signal a page or an email has been opened.
  • Software development kits and scripts loaded from a third party, such as an embedded video player.
  • Device fingerprinting, which infers a device from the characteristics it reports.

The law treats all of these the same way, because they all involve storing information on your device or gaining access to information already stored there.

Cookies are described as first party when they are set by outbreach.com itself, and third party when they are set by another organisation whose content or service appears on our pages, such as Google or Vimeo. They are session cookies when they are deleted as soon as you close the browser, and persistent cookies when they stay on the device for a set period.

3. The rules we follow

United Kingdom

Storing or reading information on your device is governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, known as PECR, as amended by the Data (Use and Access) Act 2025. Those amendments took effect on 5 February 2026. The general rule is that we must tell you clearly what we are doing and obtain your consent first, unless a specific exception applies.

PECR now recognises a short list of exceptions. The ones capable of applying to a site like ours are:

  • storage or access whose sole purpose is carrying out the transmission of a communication;
  • storage or access that is strictly necessary to provide a service you have asked for;
  • storage or access whose sole purpose is collecting information for statistical purposes about how the website is used, with a view to improving it;
  • storage or access whose sole purpose is adapting the appearance or function of the website to a preference you have expressed, for example a language or accessibility setting.

The last two exceptions come with conditions. We have to give you clear and comprehensive information about what is being collected and why, and we have to give you a simple, free way to object. Where personal data is involved, UK GDPR applies on top of PECR, and we then rely on our legitimate interests in running and improving the site, assessed against your interests and rights.

Even though the statistical exception now exists, we do not rely on it. Our website analytics are supplied by a third party rather than run entirely in house, so we treat them as requiring consent and we block them until you give it. That is the more protective position and it means the same behaviour applies wherever you are in the world.

Breaches of PECR can now attract fines of up to £17.5 million or 4 per cent of worldwide annual turnover, whichever is higher. We take the obligation seriously and review this policy against the ICO’s guidance.

European Economic Area and Switzerland

If you are visiting from the EEA or Switzerland, Article 5(3) of the ePrivacy Directive as implemented in your country applies, together with the EU GDPR or the Swiss Federal Act on Data Protection. There is no statistical exception equivalent to the UK one, so consent is required for everything other than strictly necessary cookies. Our banner asks for that consent before any non-essential cookie is set, and nothing in the analytics or functional categories loads until you agree.

United States

If you are a resident of California, Colorado, Connecticut, Montana, Oregon, Texas, Utah, Virginia or another state with a comprehensive privacy law, section 10 below sets out how those laws apply to what we do. In short, we do not sell your personal information, we do not share it for cross-context behavioural advertising, and we honour opt-out preference signals sent by your browser.

4. The categories we use

Our consent banner groups cookies into the four categories below. You can accept or refuse each category independently, and you can change your choice at any time.

CategoryWhat it coversSet before consent?
Strictly necessaryCookies without which the site cannot be delivered securely: page delivery, form submission, protection against automated abuse, and the record of your own consent choices.Yes, and they cannot be switched off from the banner
PreferencesCookies that remember a choice you have made, and cookies set by embedded media when you choose to play it.No
StatisticsCookies that count visits and page views so we can see which pages are useful and where the site needs work.No
MarketingAdvertising, retargeting and cross-site tracking cookies. We do not use this category at all.Not applicable

What we do not do. We do not run advertising or retargeting pixels, we do not operate social media tracking tags, we do not build advertising profiles, and we do not pass information from this website to data brokers or ad networks. We do not use cookies to make automated decisions about you.

5. Cookies we use

The tables below list the cookies and similar technologies used on this website, grouped by category. Names ending in an asterisk indicate a family of cookies with a variable suffix. Retention periods are maximums and a cookie may be deleted sooner if you clear your browser or withdraw consent.

Strictly necessary

NameProviderPurposeRetention
cmplz_banner-statusoutbreach.comRecords that you have seen and dismissed the consent banner, so it is not shown again on every page.12 months
cmplz_consenttypeoutbreach.comRecords which regional consent rules apply to your visit, so the banner behaves correctly for your location.12 months
cmplz_functional
cmplz_preferences
cmplz_statistics
cmplz_marketing
outbreach.comRecord whether you accepted or refused each category. Without them we cannot honour your choice.12 months
cmplz_saved_categories
cmplz_saved_services
cmplz_consented_services
outbreach.comRecord your consent at the level of individual services, so that only the services you agreed to are loaded.12 months
cmplz_policy_idoutbreach.comRecords the version of this policy you consented to, so we can ask again if it changes materially.12 months
wordpress_test_cookieoutbreach.comChecks whether your browser will accept cookies at all.Session
wordpress_logged_in_*
wp-settings-*
wp-settings-time-*
outbreach.comKeep an authenticated user signed in and remember their editor preferences. Set only for our own staff when signed in to the site, never for ordinary visitors.Session to 12 months
wpSGCacheBypassoutbreach.comTells the hosting cache to serve an uncached page to a signed-in user. Set only for signed-in users.Session
gform_*outbreach.comSupport the enquiry and application forms: retaining a partially completed submission and guarding against duplicate or automated entries.Session to 30 days
_GRECAPTCHAGoogleGoogle reCAPTCHA. Distinguishes a person from an automated script so our forms cannot be used to send spam or to probe the site. See the note below.6 months

A note on reCAPTCHA. Google reCAPTCHA protects the contact and application forms on this site. It loads before you make a consent choice, because without it those forms can be abused within minutes of being exposed. We treat it as strictly necessary to provide the form service you have asked for, and we use it only for that purpose. When it runs, Google receives your IP address, information about your browser and device, and your interaction with the page. Google’s handling of that data is described in its privacy policy. If you would rather not use reCAPTCHA, you can contact us directly at help@outbreach.com instead of using a form.

Statistics, set only with your consent

NameProviderPurposeRetention
_gaGoogle AnalyticsAssigns a randomly generated identifier to a browser so that repeat visits can be counted as one visitor rather than several.2 years
_ga_*Google AnalyticsHolds the state of the current session, so a visit is measured as a single journey through the site.2 years
_gat_gtag_*Google AnalyticsLimits how often data is sent to Google during a busy session.1 minute

We use Google Analytics to understand which pages people read, which routes into the site work, and where visitors give up. We have IP anonymisation enabled, we have turned off Google Signals and advertising features, and we do not use the data to identify individuals or to target advertising. Until you accept the statistics category, the Google Analytics script is blocked and none of these cookies is set.

Preferences, set only with your consent

NameProviderPurposeRetention
vuidVimeoRecords viewing statistics for embedded video and remembers playback position and quality preference.2 years
playerVimeoStores your player settings, such as volume and captions.12 months

Videos embedded on this site are hosted by Vimeo. Until you accept the preferences category, the embed is replaced with a placeholder and no connection is made to Vimeo. Vimeo’s own handling of the data is described in its privacy policy.

Marketing

None. We do not set advertising, retargeting or cross-site tracking cookies on this website.

Websites change, and a plugin or an embed can introduce a cookie we did not anticipate. Our consent management platform scans the site and maintains a live record of what is actually present. You can view that record here: 

Miscellaneous

Purpose pending investigation

Usage

Sharing data

Sharing of data is pending investigation

Purpose pending investigation

Name
cmplz_functional
Expiration
365 days
Function
Name
cmplz_statistics
Expiration
365 days
Function
Name
cmplz_preferences
Expiration
365 days
Function
Name
cmplz_marketing
Expiration
365 days
Function

6. Third parties and international transfers

Three third parties may receive data through this website: Google (analytics and reCAPTCHA), Vimeo (embedded video) and our hosting and content delivery providers, which handle the request that delivers each page to you. Each acts under its own privacy terms for the data it receives.

Google and Vimeo are based in the United States and may process data there or in other countries. Where a provider is certified under the EU to US Data Privacy Framework and its UK extension, we rely on that certification for the transfer. Where it is not, we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment. You can ask us for more detail about the safeguards in place at help@outbreach.com.

7. Your choices, and how to change them

The consent banner

When you first arrive, the banner lets you accept everything, refuse everything, or open the preferences panel and decide category by category. Refusing is as easy as accepting, and refusing does not stop you using the site.

To review or change your choice at any time: open your cookie settings. Withdrawing consent stops any further use of the affected cookies. It does not undo processing that already took place while your consent was in force.

Browser signals

We recognise and act on the Global Privacy Control signal and the Do Not Track header. If your browser or extension sends either of them, we treat that as a refusal of all non-essential cookies and we will not ask you again on that browser.

Browser and device controls

You can also block or delete cookies in your browser. Blocking all cookies will break parts of most websites, including this one. The relevant instructions are here:

Opting out of Google Analytics everywhere

Google publishes a browser add-on that prevents Google Analytics from collecting data on any website you visit.

8. How long your choice lasts

We keep your consent choice for 12 months, after which the banner appears again. We will also ask again sooner if we add a new cookie or service, if we change the purpose of an existing one, or if we make a material change to this policy. We keep a record of consents given and withdrawn so that we can demonstrate compliance if asked.

9. Your rights in the United Kingdom and the EEA

Where cookies involve personal data, you have the right to be informed, to ask for a copy of the data we hold, to have inaccurate data corrected, to ask for erasure, to ask us to restrict processing, to data portability where it applies, and to object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time without giving a reason.

To exercise any of these rights, contact help@outbreach.com. We respond within one month.

If you are not satisfied with our response, you can complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, by telephone on 0303 123 1113, or at ico.org.uk. If you are in the EEA or Switzerland, you can complain to the supervisory authority in your country of residence or work. Complaining to a regulator does not affect any other legal remedy available to you.

10. Notice for United States residents

This section applies if you are a resident of a US state with a comprehensive consumer privacy law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act.

Categories of information collected through cookies. Identifiers, including a cookie identifier and an IP address; internet or other electronic network activity information, including pages viewed, the page that referred you and how long you stayed; and coarse geolocation inferred from an IP address. We collect this from your interaction with the website itself.

Why we collect it. To deliver the site securely, to protect our forms from abuse, to remember your preferences and to measure how the site is used so we can improve it. We do not use it to build a profile of you, and we do not use sensitive personal information for the purpose of inferring characteristics.

Sale and sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding 12 months, and we do not knowingly collect or sell the personal information of anyone under 16.

Retention. Cookie data is retained for the periods shown in the tables above. Analytics data held in Google Analytics is retained for 14 months from collection.

Your rights. Subject to the law of your state, you may have the right to know what personal information we collect and how we use it, to obtain a copy of it, to correct inaccurate information, to delete it, to opt out of any sale or sharing and of targeted advertising, to limit the use of sensitive personal information, to appeal a refusal, and not to be discriminated against for exercising a right. Because we do not sell or share personal information and do not conduct targeted advertising, there is nothing for you to opt out of, but you can still refuse all non-essential cookies through your cookie settings.

Opt-out preference signals. We treat the Global Privacy Control signal as a valid request to opt out of any sale or sharing, applied to the browser that sends it.

Making a request. Email help@outbreach.com. We verify a request by matching the information you give us against what we hold, and we may ask for more information where we cannot verify you from what is already available. An authorised agent may act for you if they provide written permission. We do not charge for this.

11. Children

This website is aimed at businesses and their advisers. It is not directed at children, and we do not knowingly collect personal information from anyone under 16 through cookies or any other means. If you believe we have, contact us and we will delete it.

12. Changes to this policy

We review this policy at least once a year, and whenever we change the technology on the site or the law changes. The effective date and version number at the top show when it was last updated. Where a change is material, we will reset the consent banner so you can make a fresh choice.

13. Contact us

Outbreach Ltd
71 to 75 Shelton Street, Covent Garden, London WC2H 9JQ
Email: help@outbreach.com

You can also read our privacy policy for a fuller account of how we handle personal data.

Under Attack?

Call our 24/7 Operations Centre for rapid onboarding and support