This Cookie Policy explains how First Responder, operated by MKCIT LIMITED, uses cookies, tokens, and similar local-storage technologies. It should be read with our Privacy Policy (slug privacy-policy).
The short version: we use only essential and functional storage needed to make the Service work and keep it secure. We do not use advertising, analytics, or tracking cookies, and we do not embed any third-party advertising or analytics SDKs.
1. What we use, and where
The Service has three surfaces, and each stores only what it needs to function:
- The native app (iOS / Android) — does not use advertising cookies. It uses the device's secure storage (iOS Keychain / Android Keystore) to hold authentication tokens and an encryption key for the local data store. These are essential to keep you signed in and your cached data encrypted on the device.
- The web application (Laravel) — uses essential cookies only: a session cookie, an authentication cookie, and a CSRF/security cookie.
- The marketing website (WordPress) — uses essential/functional cookies only (e.g. session and security cookies). It does not run advertising, analytics, or third-party tracking. If any analytics or marketing functionality is ever added, this policy and an appropriate consent mechanism will be revisited (see §4).
2. Cookies and storage by purpose
| Purpose | Surface | Type | Why | Consent needed? |
|---|---|---|---|---|
| Session | Web (Laravel), WordPress | Cookie | Maintains your signed-in session and request continuity | No — strictly necessary |
| Authentication | Web (Laravel); native app uses a token in secure storage | Cookie / token | Keeps you signed in securely | No — strictly necessary |
| Security (CSRF) | Web (Laravel), WordPress | Cookie | Protects against cross-site request forgery and abuse | No — strictly necessary |
| Functional preferences | Web / app | Cookie / local storage | Remembers choices such as theme or language | No — strictly necessary to the feature you chose |
| Local data encryption key | Native app | Secure storage (Keychain / Keystore) | Encrypts cached personal/clinical data at rest on the device | No — strictly necessary |
The web application sets a session cookie (named for the application) and a CSRF-protection cookie (XSRF-TOKEN). The marketing website sets only essential WordPress cookies (for example a session or security cookie) and no advertising, analytics, or tracking cookies.
We do not set: advertising identifiers, cross-site tracking cookies, analytics cookies, or social-media/marketing pixels.
3. Strictly-necessary cookies and consent
Under the Privacy and Electronic Communications Regulations (PECR), cookies that are strictly necessary to provide a service the user has requested do not require prior consent. The cookies and storage described above fall into that category — they exist only to deliver the sign-in, security, and core functionality you have asked for. We therefore do not show a consent banner, because there is nothing non-essential to consent to.
4. If this changes
If we ever introduce non-essential cookies or storage (for example optional analytics), we will update this policy and put in place an appropriate consent mechanism before doing so, so that such cookies are only set with your prior consent where required.
5. Managing storage
You can clear or block cookies through your browser settings, and clear app storage through your device settings. Blocking strictly-necessary cookies or clearing app secure storage may sign you out and stop parts of the Service working.
6. Changes
We may update this Cookie Policy from time to time. The current version and effective date are always shown at the top of this page.
7. Contact
MKCIT LIMITED, 9 Hatfield Court, Reading, RG31 7AL — hello@first-responder.uk. Data-protection enquiries: privacy@eventris.uk (ICO registration ZC116358).