- Policies
-
Terms & Conditions
- General Terms & Conditions
- Advertising Terms & Conditions
- Lead Generation Solus Email and Engagement Signal Campaigns Terms & Conditions
- Webinars, Virtual & Live Event Sponsorship Terms & Conditions
- Content and Asset Terms & Conditions
- eGOLD Terms & Conditions
- myGrapevine+ Subscription Terms & Conditions
Cookie Policy
This Cookie Policy explains how Executive Grapevine International Ltd (EGIL) uses cookies, pixels, local storage, software development kits and similar technologies across its websites, reader services, mobile applications and digital communications.
Non-essential technologies are not activated until the required consent has been obtained. Technologies used to measure behaviour, personalise content, support advertising or contribute to a named engagement signal are not treated as strictly necessary merely because they are commercially useful.
1. WHO WE ARE AND SCOPE
1) Executive Grapevine International Ltd is responsible for the use of cookies and similar technologies described in this Policy. Our registered address is Gate House, Fretherne Road, Welwyn Garden City, Hertfordshire, AL8 6NS, United Kingdom.
2) This Policy covers EGIL brands and services, including HR Grapevine, HR Grapevine Live, HR Grapevine Virtual, Executive Grapevine and myGrapevine, where this Policy is displayed or linked.
3) Our Privacy Policy explains how we use Personal Data obtained through these technologies, including profiling, professional-interest categories and named engagement signals.
4) A separate cookie settings panel available on each relevant service provides the current technology-level inventory, including provider, purpose and duration. That live inventory forms part of this Policy and takes precedence if a vendor changes a technical name or duration before this document is updated.
2. WHAT COOKIES AND SIMILAR TECHNOLOGIES ARE
1) Cookies are small files or values stored on a browser or device. Session cookies normally expire when the browser closes. Persistent cookies remain until their stated expiry or until they are deleted.
2) Similar technologies include pixels, tags, local storage, scripts, device identifiers, software development kits and links or URLs containing identifiers. The rules may apply whether or not the technology is called a cookie.
3) First-party technologies are set through an EGIL domain. Third-party technologies are provided through another organisation's domain or service. A first-party appearance does not necessarily mean that no information is received by another organisation.
4) Some technologies involve Personal Data because an identifier, IP address, account or activity can identify or be linked to a person. Aggregate reporting may still be produced from Personal Data before it is anonymised.
3. CONSENT AND EXEMPTIONS
1) We obtain consent before storing information on, or accessing information from, your device unless a PECR exemption applies.
2) Strictly necessary technologies may be used without consent only where they are essential to transmit a communication, provide a service you specifically request, secure that service or meet another applicable statutory exemption.
3) A technology is not strictly necessary simply because it supports analytics, advertising, personalisation, campaign reporting, commercial performance or EGIL's preferred way of operating the service.
4) Where legislation permits a technology without consent for limited statistical, security, appearance, functionality or similar purposes, we use the exemption only after checking that every statutory condition is satisfied. We provide clear information and any required objection mechanism.
5) Where consent is required, it must be freely given, specific, informed and unambiguous. We do not rely on continued browsing, creation of an account, acceptance of general terms, inactivity, a pre-ticked box or a control that makes rejection materially harder than acceptance.
6) Your cookie choice is separate from consent to receive marketing and separate from EGIL's UK GDPR lawful basis for subsequent Processing. Consent to one activity is not automatically consent to another.
7) We record the choice, time, policy or banner version and relevant categories for as long as needed to demonstrate and respect that choice.
4. CATEGORIES OF TECHNOLOGY
1) We organise technologies into the following categories. The current cookie settings panel identifies the category applied to each live technology.
|
Category |
Purpose |
Consent position |
|
Strictly necessary |
Authentication, requested settings, load balancing, fraud prevention, consent storage and security essential to a service you request. |
No consent where a PECR exemption applies. |
|
Analytics and measurement |
Understand visits, navigation, reading, performance, errors and campaign delivery. Data may include identifiers, IP, pages, clicks, scroll depth and time. |
Consent unless a specific statutory exemption has been assessed and all conditions are met. |
|
Personalisation and engagement |
Remember non-essential preferences, recommend content, link activity across sessions, create professional-interest segments or measure meaningful engagement. |
Consent where device storage or access is involved and no exemption applies; separate UK GDPR assessment for subsequent profiling. |
|
Advertising and marketing |
Deliver, cap, retarget or measure advertising; connect activity with advertising platforms; or support cross-site or cross-service marketing. |
Consent. Additional US opt-out rights may also apply. |
|
Payments |
Create a payment session, prevent payment fraud and process a transaction through a payment provider. |
No consent only to the extent strictly necessary for the payment service you request; otherwise consent. |
2) If one technology has several purposes, we apply the category and consent treatment required for its most privacy-intrusive active purpose. We do not classify behavioural measurement as functionality to avoid obtaining consent.
5. TECHNOLOGIES CURRENTLY USED
1) The following reflects the technologies presently identified by EGIL. It must be read with the live cookie settings panel and verified against regular technical scans because names, providers and durations can change.
1. EGIL session, authentication and security: Names: csrf_cookie, egsession, egdevice, egtoken, mytoken. Provider: EGIL. Duration: Session or stated persistent period. Category: Strictly necessary only where required for the service requested.
2. Cloudflare load balancing and security: Names: __cflb and applicable Cloudflare security cookies. Provider: Cloudflare. Duration: Session or provider-configured period. Category: Strictly necessary only where used for security or delivery.
3. Google Analytics: Names: _ga, _gid and related configured identifiers. Provider: Google. Duration: Up to the duration shown in cookie settings. Category: Analytics and measurement.
4. Microsoft Clarity: Names: _clck, _clsk and related configured identifiers. Provider: Microsoft. Duration: Session or the duration shown in cookie settings. Category: Analytics and measurement.
5. EGIL engagement technology: Names: gilt_cid, gilt_did, gilt_sid. Provider: EGIL or an EGIL service provider. Duration: Session or configured period. Category: Personalisation and engagement.
6. Google advertising: Names: __gads and other configured advertising identifiers. Provider: Google. Duration: Up to the duration shown in cookie settings. Category: Advertising and marketing.
7. Marketing automation: Names: visitor_id, visitor_id-hash and related configured identifiers. Provider: Pardot or Salesforce. Duration: Up to the duration shown in cookie settings. Category: Advertising and marketing or analytics, depending on configuration.
8. Stripe payments: Names: __stripe_mid, __stripe_sid and related payment-security identifiers. Provider: Stripe. Duration: Session or provider-configured period. Category: Payments.
2) LinkedIn, embedded media, event platforms, social features or other third parties may set additional technologies only when the relevant feature is used and the required consent has been obtained. The live settings panel must identify every active provider and technology.
3) EGIL will not publish an exact duration that has not been validated. The cookie settings panel must state a specific duration for each live technology rather than relying only on terms such as 'persistent'.
6. BEHAVIOURAL MEASUREMENT AND NAMED ENGAGEMENT SIGNALS
1) With the required consent, we may use analytics or engagement technologies to measure pages viewed, clicks, scroll depth, reading time, return visits and interaction with clearly identified client content.
2) Cookie consent allows the relevant device technology to operate. It does not by itself permit EGIL to disclose your name to a client. Any named disclosure must also satisfy the Privacy Policy, the applicable UK GDPR lawful basis and the specific conditions for a Named Engagement Signal.
3) A routine page impression, advertisement impression, brief visit, background page load or accidental click is not a Named Engagement Signal.
4) Where activity may contribute to a Named Engagement Signal, the client must be clearly identified before the qualifying engagement and a prominent notice must explain the possible disclosure. EGIL also provides a separate right to object to named signals.
5) Rejecting or withdrawing analytics, personalisation or marketing cookies prevents future use of those device technologies. It does not automatically erase server-side account information already lawfully collected, which is governed by the Privacy Policy and your data protection rights.
7. THIRD PARTIES AND INTERNATIONAL TRANSFERS
1) Some technologies are supplied by third parties such as Cloudflare, Google, Microsoft, Salesforce or Pardot, LinkedIn, Stripe and event or media-platform providers.
2) Depending on the service and configuration, a third party may act as EGIL's Processor, as an independent Controller or in another legally recognised role. We do not state that a third party acts only on our instructions unless our contract and technical configuration support that statement.
3) The cookie settings panel links to available provider information and identifies the purpose for which EGIL enables the technology. A provider may describe additional Processing for which it is independently responsible.
4) Where Personal Data is transferred outside the United Kingdom, we use an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses or another lawful safeguard, as explained in our Privacy Policy.
5) Consent to cookies is not the legal safeguard for an international transfer. We assess transfer requirements separately.
8. EMAIL PIXELS AND LINK MEASUREMENT
1) Some emails can contain a small image or pixel that reports an open, or a personalised link that reports a click. This may reveal the recipient, time, device, IP address and interaction.
2) We do not activate an email-open pixel or another non-essential device-access technology unless the required PECR consent has been obtained. Consent to receive an email is not automatically consent to hidden open tracking.
3) We may record that a link was requested through our server where this does not store or access information on the recipient's device. We still apply UK GDPR, explain the use and provide a right to object where legitimate interests is relied upon.
4) An email open or isolated click is not by itself a Named Engagement Signal and is not disclosed to a client as a request for contact.
5) You can unsubscribe from marketing using the link in each message. You can also contact [email protected] about email measurement or related Personal Data.
9. MANAGING YOUR CHOICES
1) You can use 'Cookie Settings' in the website footer to accept, reject or change non-essential categories at any time. Rejecting all non-essential technologies must be available at the same level as accepting them.
2) Withdrawing consent applies to future storage or access. We update the consent record promptly, although a page refresh may be required to remove or stop a technology already loaded in the current session.
3) You may also delete or block cookies through browser or device settings. Browser controls may remove the cookie that remembers your consent choice, in which case we may ask again.
4) Blocking strictly necessary technologies may prevent login, security, payment or another feature you request from working. Rejecting other categories must not prevent access to core editorial content unless that optional feature genuinely depends on the technology.
5) Where required by applicable US privacy law, we also provide a 'Your Privacy Choices' or 'Do Not Sell or Share My Personal Information' control and honour recognised browser-based opt-out preference signals, including Global Privacy Control.
10. RETENTION AND SECURITY
1) Each cookie or similar technology has the duration shown in the live settings panel. A cookie's expiry does not necessarily determine how long related Personal Data is retained after collection.
2) Personal Data produced through analytics and engagement technologies is retained in accordance with the periods and purposes in our Privacy Policy. We do not extend a technology's duration merely because a user previously consented.
3) We use reasonable technical and organisational measures to protect cookie and engagement information, including access controls, secure configuration, vendor review and limits on access and retention.
11. CHANGES TO THIS POLICY
1) We review our technologies regularly and update this Policy and the live inventory when providers, purposes, durations or legal requirements change.
2) We ask for consent again where a new purpose is materially different, a new category is introduced, the earlier consent is no longer sufficiently specific or the law otherwise requires renewal.
3) A minor provider, wording or technical update does not automatically require renewed consent where the purpose and privacy impact remain within the consent already given.
12. CONTACT AND COMPLAINTS
1) Questions, objections and rights requests may be sent to [email protected] or Data Protection Team, Executive Grapevine International Ltd, Gate House, Fretherne Road, Welwyn Garden City, Hertfordshire, AL8 6NS, United Kingdom.
2) You may complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint. You are not required to contact us before approaching the ICO.
Executive Grapevine International Ltd
Registered in England & Wales: 2789779 | VAT: 6259453 20
Gate House, Fretherne Road, Welwyn Garden City, AL8 6NS, United Kingdom | +44 (0)1707 351451
Last reviewed by: Helen Fish, Director, 11 September 2026