Effective date: 12 August 2026 | Version 1.0
1. What this notice covers
This notice explains cookies and other storage or access technologies used on www.thelax.art, including pixels, tags, local storage and similar identifiers. It must be read with the Privacy Notice.
2. Consent and exceptions
2.1 We place or access a non-exempt technology only after you take a clear positive action. Accept all and Reject all are equally prominent on the first layer, and Customise provides granular controls. No non-essential switch is pre-selected.
2.2 Continued browsing, scrolling, silence or closing the banner is not consent.
2.3 Technology that is strictly necessary to provide a service you request may operate without consent. A narrow statutory exception, such as qualifying aggregate statistical analytics or appearance/functionality, is used only if every legal condition is met, users receive clear information and any required easy objection is available. An internal label of “analytics” does not by itself create an exception.
3. Categories
- Strictly necessary: security, session, checkout, load balancing and remembering a privacy choice where genuinely required.
- Preferences/functionality: optional features and settings that are not essential.
- Analytics: measurement of use and performance. Consent is obtained unless a verified exception applies.
- Advertising: remarketing, ad measurement, profiling, cross-site or cross-device tracking and advertising personalisation. Consent is required.
4. Live inventory
The inventory below is the approved production inventory for this release. The preference centre and this page must display the same live information. If a vendor, cookie name, purpose or duration changes, update both before deployment.
| Name / technology | Provider | Purpose | Category / legal position | Party | Duration | Data destination | Control |
|---|---|---|---|---|---|---|---|
| PHPSESSID | London Art Exchange | Secure account, form and checkout session | Strictly necessary | First party | Session | UK website hosting | Always active |
| lax_cookie_preferences | London Art Exchange | Remember consent choice and notice version | Strictly necessary preference | First party | 90 days | UK website hosting | Always active |
| popup preference | London Art Exchange | Remember a user-dismissed catalogue prompt | Optional functionality | First party | 30 days | UK website hosting | Functional opt-in or direct user request |
| _ga | Google Analytics | Distinguish visitors for website measurement | Analytics; consent required | First party; Google recipient | Up to 2 years | Google services; protected transfer where applicable | Analytics opt-in |
| _ga_YGZCF5FD67 | Google Analytics | Maintain session state for GA4 property G-YGZCF5FD67 | Analytics; consent required | First party; Google recipient | Up to 2 years | Google services; protected transfer where applicable | Analytics opt-in |
| _gcl_au / _gcl_aw | Google Ads | Conversion measurement and advertising attribution | Advertising; consent required | First party; Google recipient | Up to 90 days | Google services; protected transfer where applicable | Advertising opt-in |
| SalesIQ cookies / local storage | Zoho SalesIQ | User-requested live chat and optional visitor/session continuity | Functionality; consent required before widget loads | Zoho-hosted | Session; any permitted persistent identifier no more than 12 months | Zoho EU services; protected transfer where applicable | Functional opt-in |
The former 10-year cookie_client_id, popup_shown_v2 and accept_cookies_i implementations must be removed before this notice goes live. The replacement consent record is limited to 90 days. PHPSESSID remains session-only and must use Secure, HttpOnly and SameSite=Lax or SameSite=Strict as appropriate.
5. Changing your choice
You can reopen Cookie preferences from the footer of every page and withdraw or change consent as easily as you gave it. Withdrawal stops future non-exempt access and is passed to relevant tags and partners. It does not make earlier consented processing unlawful.
6. Consent records and refresh
We record the choice, timestamp, consent-policy version, categories and a pseudonymous identifier needed for proof. We do not retain proof longer than necessary. We ask again when purposes or vendors materially change, consent is no longer valid, or the approved refresh period is reached. A rejection is not repeatedly nagged at every page view.
7. Browser controls
Browser controls may block or delete technologies, but they are not a substitute for our consent controls. Blocking strictly necessary storage may prevent requested checkout or security features.


