Legal
Cookies and local storage
Two items, both written by this site, both held on your own device. They are listed below by name, with what is inside each one.
This page is called a cookie policy because that is the name people look for, but the law it answers to — regulation 6 of the UK Privacy and Electronic Communications Regulations, and Article 5(3) of the ePrivacy Directive — covers anything stored on or read from your device, whatever the technology is called. Dunara's site happens to use local storage rather than cookies, so that is what this page describes.
Nothing here is shared with anyone. Neither item leaves your device: the site reads them in your browser and acts on them there.
What the two words mean
A cookie is a small piece of text a site asks your browser to keep and hand back on every single request to that site, including requests for images and fonts. It has an expiry date set by the site, and it travels with the request whether the page needs it or not.
Local storage is a small store in your browser that belongs to one site. It is never attached to a request; the page has to ask for it in code when it wants it. It has no expiry date, so it stays until you clear it or the site removes it.
For the two things this site needs to remember, local storage is the better fit. A language preference and a record of your own choice should not ride along on every request for a photograph, and neither of them needs a server to see it.
The strictly-necessary tier
Both of the items below sit in the strictly-necessary tier, and both are exempt from the requirement to ask your consent — not as a convenience, but because of what they contain.
The first stores your own choice about the optional tiers. A record of a person's preference is exempt in its own right: it would be a circular exercise to ask consent to remember that consent was declined. The second stores a language tag — en, de, it, es or pt — and nothing else — no identifier, no counter, no timestamp, nothing that could distinguish you from another reader of the same language.
They are still listed here, in full, because the exemption removes the need to ask. It does not remove the need to tell you.
Everything this site stores on your device
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| cm.consent.v1 | Dunara — this domain, first party | Your choice about the two optional tiers, held as a version number, the moment you made the choice, and one true-or-false value per tier. | Local storage | Until you withdraw it or clear your browser's data for this site. A new version of the preference model replaces it and the choice is asked again. |
| cm.locale | Dunara — this domain, first party | The language you picked from the switcher, as a two-letter tag: en, de, it, es or pt. | Local storage | Until you clear your browser's data for this site. |
The table is complete at two rows. The first item is written when you answer the banner, the second when you choose a language, and neither one before.
The two optional tiers, and why they are empty
The preference dialog offers two optional tiers, Analytics and Personalisation. Both arrive switched off and both are currently empty: there is nothing behind either one to switch on.
They exist because the honest way to build this is to put the machinery in before the need, not after. If we ever add something that belongs in one of them — a measurement tool, or a remembered suite preference — the preference model gains a version number, your stored record no longer matches it, and you are asked again from scratch. A tier cannot quietly fill up under a consent you gave for something else.
Until then, turning Analytics or Personalisation on changes nothing at all, and we would rather say so than let a toggle imply otherwise.
Changing or withdrawing your choice
Cookie settings in the footer of every page reopens the preference dialog. Rejecting is one click, in the same place and at the same visual weight as accepting — the two buttons are the same size and sit side by side, which is the point.
Withdrawing deletes the preference record from your device and brings the banner back, so the next page view starts from a clean position rather than a remembered one.
Every current browser has a per-site control for cookies and site data, usually reached from the padlock or the site icon beside the address, or from the privacy section of the settings. Clearing site data for this domain removes both items in the table above.
Because neither item carries an identifier, clearing them has exactly two visible effects: the site forgets which language you chose, and the banner asks again.
Private windows and strict privacy settings can refuse local storage. Every write on this site is wrapped so that a refusal is handled rather than thrown, and the site works normally without either item: the language comes from the address of the page you are on, and the banner appears each session.
Where this site's files come from
Every script, stylesheet, font, photograph and drawing on this site is served from this domain. The two typefaces, Cormorant Garamond and Jost, are self-hosted, so loading a page tells no font service that you are reading it.
The estate plans and sections are drawn as SVG and placed inline in the page, which is why they take the colours of the page around them and can be read aloud by assistive technology. They are not images fetched from a drawing service.
There is no embedded video player, no map frame, no social widget, no chat bubble and no advertising tag. The content security policy this server sends with every response permits scripts, styles, fonts, images, form posts and connections from this domain only — so a third-party tag could not run here even if one were added to the page by accident.
The forms post to this domain and are handled by this site's own service. The same response headers tell your browser that this site will not ask for your location, camera or microphone, and will not take part in interest-based advertising cohorts.
How we know whether the site works
From the server's own request counts, aggregated by the provider that serves the site: how many times a page was requested, which responses were errors, how long the edge took to answer. None of it carries an identifier we could tie to a person, and none of it is joined to anything you submit.
That is enough to tell us a page is broken, a translation is missing, or an image is too heavy. It is not enough to tell us anything about you, which is the trade we have chosen to make.
The rest of the picture
The privacy notice covers the data a form creates, who sees it, and the period after which each kind is deleted.