Skip to content
TMLZEE

Bench notebook

Cookie notice

Eleven short entries about what this website puts on your device, which comes to one security cookie our host may write and nothing at all of ours. Nothing below has to be taken on trust: a minute with the tooling already built into your browser will confirm it or contradict it.

Notebook: the storage entries of TMLZEE GROUP LTD, kept with the privacy entries and written to be verified.

Opened: 7 August 2026. Nothing amended since.

Bench it covers: every page served from tmlzee.co.uk.

Law the entries answer to: PECR, being the 2003 regulations on privacy in electronic communications, sitting alongside the UK GDPR.

1.Entry — the short answer

Entered 7 August 2026. If you read one entry, read this one.

This company writes no cookie to your device from this website. Nothing here counts you, follows you, records your session or builds a picture of you. No banner asks your permission either, because these pages hold nothing that permission is owed for.

Two things do reach past the edge of the page, and each has an entry below. Our host may write one security cookie when its shield engages, and your browser collects the faces this site is set in from Google's type service. Neither is under our control in the way a first-party cookie would be, so both are explained rather than glossed over.

2.Entry — the rule behind it

Entered 7 August 2026. The law has not moved since it was written.

A cookie is a small piece of text a site puts in your browser to be handed back on a later visit. Local storage, session storage and tracking pixels achieve much the same by other means, and the regulations treat them all the same way, which is why this entry talks about storage rather than about cookies alone.

The provision that bites here is regulation 6 of PECR, read with the UK GDPR. Putting information onto somebody's device, or reading what is already sitting there, calls for a clear explanation and a freely given yes.

One exemption exists and it is narrow. Where the storage is strictly necessary for something the visitor deliberately asked the site to do, no permission is owed. The Information Commissioner reads it tightly. Security and load balancing fall inside; measurement, advertising and whatever an operator simply finds handy fall outside.

3.Entry — why there is no banner

Entered 7 August 2026. A design decision as much as a legal one.

Banners exist to collect permission for storage the exemption does not reach. None of that happens here, so a banner would be harvesting your agreement to precisely nothing.

That is not a neutral thing to do. It trains people to dismiss by reflex a control that matters a great deal elsewhere, and it hints at behaviour this site has not got. So there is no overlay, no preference centre, and nothing to dismiss before you can read a page.

Should anything the exemption does not cover ever be introduced, the order is fixed: this notice is rewritten and redated first, a real choice reaches you second, and the new component runs only once you have made that choice. Saying no will take exactly as few clicks as saying yes.

4.Entry — what may reach your device

Entered 7 August 2026. One row, and a row saying there is nothing else.

These pages are flat files. Nothing signs in, nothing goes into a basket, no session is opened and no form posts anywhere, which leaves a cookie of ours with nothing whatever to remember.

Storage that may appear when you visit
WhatWritten byWhat it is forConsent
A Cloudflare bot-management cookie, usually named __cf_bm Cloudflare, which hosts and delivers this site Telling an automated client apart from a person, so that the site stays reachable while it is being hammered. Written only when that protection actually engages Not required. It is strictly necessary to keep a service you asked for available and secure
Nothing else whatsoever — Not a single cookie is defined here, and neither local nor session storage is ever written to —

Its name and its lifetime are Cloudflare's to set rather than ours, which is why this entry describes the job it does instead of quoting a duration nobody here could stand behind.

5.Entry — checking it yourself

Entered 7 August 2026. Please do; a claim you can test is worth more than one you cannot.

Open the developer tools in whatever browser you use, find the panel listing storage for the current site, then load a page from here. What should appear is an empty cookie list, or one Cloudflare entry and nothing more, with local and session storage bare. That takes a minute and it settles the question far better than this paragraph does.

If the screen disagrees with this page, write and say what appeared and how you got there. Either the site gets corrected or this page does. Getting this wrong in public would be worse for us than the small convenience any tracking could ever buy.

6.Entry — what this site never does

Entered 7 August 2026. Every line below can be confirmed in the developer tools panel.

  • Measurement of any kind, whether hosted elsewhere or run on our own machines, and including the privacy-preserving sort. Visitor numbers here are unknown to us, and we have made our peace with that.
  • Advertising, ad networks, retargeting and conversion pixels.
  • Social buttons, embeds and share widgets.
  • Embedded video, maps and comment systems.
  • Fingerprinting, session replay, heatmaps and split testing.
  • Any sharing or sale of information about you, to anyone, for any purpose.
  • A chat bubble in the corner of the screen.

7.Entry — the one outward request

Entered 7 August 2026. Changes on the day the faces are served from our own domain.

As a page renders, your browser goes out for the faces the site is set in: fonts.googleapis.com for the stylesheet describing them, then fonts.gstatic.com for the files themselves.

Nothing is stored on your device by that, but your address and the usual headers are disclosed to Google LLC, and the disclosure leaves the United Kingdom. Google states that font traffic is not turned into advertising profiles. Verifying such a statement is beyond us, so the honest course is to say the request is made and let you weigh it.

A content security policy travels with every response, permitting those two hosts and refusing all others, which caps what any page here could ever ask for. It is visible in the response headers. Hosting the faces on our own domain would end the request entirely, and that job sits on the list.

8.Entry — logs are a different thing

Entered 7 August 2026. The distinction that confuses people most.

Delivering a page produces a line in a log at our host. The line lives on their server. Nothing was put on your machine, so PECR is not the rule in play. It remains personal data all the same, and the privacy notice deals with it fully.

Such a line records the request and little else: an address, a time, the path asked for, the response code, the browser string and the page you came from. It keeps the site running and lets abuse be investigated. It is not joined up with anything else and nobody is profiled from it.

9.Entry — taking control in your browser

Entered 7 August 2026. You need no permission from us for any of this.

Any browser released this decade will let you look at site storage, block it and clear it, without asking anyone's leave. In Chrome and Edge the controls sit under the privacy section of settings, with per-site options a level deeper. Safari keeps them under privacy as well, where website data can be managed one site at a time and cross-site tracking is prevented by default. Firefox groups them under privacy and security, alongside its tracking protection.

Block the Cloudflare cookie from entry four and you may be challenged more often, since the check you already passed has nowhere to be remembered. Past that, no page here leans on storage at all, so blocking everything changes nothing about how the site behaves.

Anything that blocks requests to other origins will also block the type. Pages then render in whatever faces your system provides, which the layout was drawn to survive, so everything stays readable.

10.Entry — browser privacy signals

Entered 7 August 2026. Included so nobody is left wondering.

A few browsers still emit Do Not Track; others send the newer signal called Global Privacy Control. No settled standard says what a site must do when either turns up.

Here the question has nothing to bite on. No tracking happens whether a signal is sent or not, so honouring one and ignoring one produce an identical result. We mention it only because its absence from a cookie page tends to look like an evasion.

11.Entry — if this changes, and complaints

Entered 7 August 2026. The commitment that makes the rest of the page worth anything.

This entry describes the site as it stands today. Should anything ever be added that writes to your device past the strictly necessary, this entry is rewritten, the date moves, and a real choice goes live before that component runs even once. Nothing gets added quietly on the strength of a page amended months earlier.

Questions reach us at [email protected]; the word Cookies at the front of a subject line gets them to the right desk, and a person answers.

A complaint can also go to the Information Commissioner's Office, which supervises PECR and data protection alike in the United Kingdom: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, or the complaint form published at ico.org.uk. Going straight there is your right; we would just rather be given the chance to fix it first.

Back to the home page