Skip to content
AIAC AI ASSURANCE COUNCIL

Policies

Cookie policy

By default these sites set no cookies. Google Analytics cookies are set only if you allow them, and this page explains what they do and how to change your choice.

Reference
AIAC/LEG/2026/03.1
Issue
3.1
Effective
29 August 2026
Next review
August 2027
Status
Current

§ 1 — Policy

1. Scope, and what these sites set by default

This policy covers both aiassurancecouncil.org and the candidate portal at portal.aiassurancecouncil.org. They are measured separately, and the choice you make on one is not carried to the other: each asks on its own.

By default, neither sets any cookie for analytics. One analytics tag always runs on both — Umami, an open-source, cookie-free analytics tool on infrastructure the operator controls. It sets no cookie, stores no identifier on your device, and reports aggregate page-view counts only; nothing is shared with an advertising company. There is no advertising pixel, no social embed, and no cross-site tracker. Fonts are served from these domains rather than a third-party font service.

2. Google Analytics — optional, with your consent

On your first visit, a banner asks whether to allow Google Analytics, which helps the Council understand how the site is used. Nothing is loaded from Google, and no Google cookie is set, unless you select OK. That selection is the only thing that turns it on: continuing to read, scrolling, or following a link does not, and if you never select it Google Analytics does not load at all. Consent is optional, and withholding it does not restrict access to any content or to the portal.

The website and the portal use separate Google Analytics properties, so a visit to one is not joined to a visit to the other. Because they are separate, each asks for consent in its own right.

If you allow it, Google Analytics sets the following cookies:

  • _ga — distinguishes one browser from another using a randomly generated identifier, so that repeat visits are not counted as new visitors. Lifetime: two years.
  • _ga_* — retains the state of the current browsing session for the Google Analytics property concerned:_ga_LEN4FQ5CSW on this website and _ga_9325W3VMZ0 on the candidate portal. Lifetime: two years.

Data collected through these cookies is processed by Google. The Council uses it for aggregate usage measurement only, not for advertising.

What Google is not told about the portal

The portal holds candidate records, so two limits apply there even after you allow Google Analytics. First, addresses that identify a person or a record — an attempt, a sitting, a credential — are stripped of that identifier before the page address is reported, and query strings are not reported at all; Google receives the shape of the page, never whose it was. Second, two areas are not measured at all: the staff panel, and a live examination sitting. Neither loads anything from Google, whatever your choice.

Withdrawing consent

Consent is stored on your device only once you have given it — nothing is written about a visitor who has not — and can be withdrawn at any time. Selecting clears the stored choice and reloads this page; the consent banner is shown again and Google Analytics does not load unless you allow it afresh. Cookies already set by Google Analytics can be removed through your browser's settings.

3. Cookies set by the candidate portal

The candidate portal runs on its own subdomain and sets its own cookies; this site itself sets none beyond the analytics cookies described above. Two are set there:

  • A strictly necessary session cookie, which keeps a signed-in candidate signed in. Its name and lifetime are listed in the portal.
  • aiac-ref, set for 30 days when a visitor arrives on a referral link so that the referral can be credited to the person who made it. It holds a referral code and nothing else, is readable only by the server, and is never used for advertising or for tracking behaviour across sites. It is a functional cookie: the portal works identically without it, and the only consequence of refusing or deleting it is that a referral goes uncredited. It is set on arrival, before any consent interaction, and a visitor who does not want it should not follow a referral link or should clear it in their browser settings.

4. Email links

If the launch-updates list is delivered by a third-party email provider, that provider may record whether a message was opened or a link followed. This happens in the email client, not on this website. The provider will be named here once selected.

5. Controlling cookies

Consent is requested before any cookie that tracks you is set, and withholding it does not degrade access to any content. The one exception isaiac-ref above, which is set on arrival from a referral link because it exists to attribute that arrival and cannot do so retrospectively; it tracks nothing about the visitor and follows them nowhere. Your consent, once given, is held in your browser's local storage under the key aiac-consent-ga; nothing is stored for a visitor who has not given it, which is why the banner appears again on a later visit. It can be changed with the reset link above, and your browser's own settings can block or delete cookies for this site at any time. The website and the portal are separate origins, so each holds its own choice under that key; withdrawing on one does not withdraw on the other.

6. Changes

This policy is version controlled. Any addition of a cookie is a material change and will be published with a new issue number and effective date. The Council may introduce strictly necessary cookies without prior consent where required to deliver a service you have requested.

Contact

Questions about this policy should be addressed to hello@aiassurancecouncil.org.