Cookie Policy
Controller: Traverse Limited Trading name / brand: DARCKED.COM Website: www.darcked.com Registered office: Nikole Spasica 3/1, 11000 Belgrade, RS Jurisdiction of establishment: RS Privacy contact: privacy@darcked.com
Version: 1.0 Effective date: 05 August 2026 Date last revised: 05 August 2026 Document language: English
TABLE OF CONTENTS
PART I — GENERAL PROVISIONS
- Purpose and Status of this Cookie Policy
- Identity of the Controller and Contact Details
- Scope
- Definitions and Technologies Covered
- Legal Framework
PART II — CONSENT 6. Legal Basis for the Use of Cookies and Similar Technologies 7. The Consent Management Mechanism 8. Withdrawal of Consent, Validity Period and Re-solicitation 9. No Cookie Walls, No Consent-or-Pay and No Detriment
PART III — CATEGORIES AND USE 10. Categories of Cookies and Similar Technologies 11. Strictly Necessary Cookies 12. Functional Cookies 13. Analytics Cookies 14. Advertising and Marketing Cookies — Not Used 15. Cookies Set in Connection with Payment and Checkout 16. Technologies Used in Connection with Digital Publications and Downloads 17. Embedded Third-Party Content and Social Media 18. Measurement Technologies in the Newsletter 19. Affiliate Links and Sponsored Material 20. Technologies the Company Does Not Use
PART IV — RECIPIENTS, TRANSFERS AND RETENTION 21. Third-Party Cookies and Recipients 22. International Transfers of Personal Data 23. Duration of Cookies and Retention of Consent Records 24. Server Logs and Processing Outside the Scope of this Cookie Policy
PART V — CONTROL, RIGHTS AND ACCESSIBILITY 25. Managing Preferences through the Consent Management Mechanism 26. Managing Cookies through Browser and Device Settings 27. Consequences of Refusal, Withdrawal or Deletion 28. Do Not Track and Opt-Out Preference Signals 29. Rights of Data Subjects 30. Children 31. Accessibility of the Consent Management Mechanism
PART VI — JURISDICTION-SPECIFIC PROVISIONS 32. European Economic Area 33. United Kingdom 34. California 35. Other United States Jurisdictions 36. Switzerland, Canada, Brazil, Australia, Japan and South Africa
PART VII — GOVERNANCE AND FINAL PROVISIONS 37. Cookie Governance, Audit and Records 38. Changes to this Cookie Policy 39. Complaints and Supervisory Authorities 40. Contact Details
ANNEXES Annex I — Cookie and Similar Technology Inventory Annex II — Glossary of Technologies Annex III — Browser and Device Management Instructions
PART I — GENERAL PROVISIONS
1. Purpose and Status of this Cookie Policy
1.1 The Company is an independent digital publisher of long-form editorial work, including literary criticism, philosophical criticism, film criticism and television criticism, digital magazines, digital books and other Digital Publications, made available through the Website by way of open access, Membership and individual purchase.
1.2 This Cookie Policy explains which cookies and similar technologies are used on the Website, the purposes for which they are used, the legal basis on which they are placed or read, the recipients of the information they generate, the periods for which they are retained, and the means by which a User may grant, refuse, adjust or withdraw consent.
1.3 This Cookie Policy is issued in fulfilment of the information obligations arising under Article 5(3) of Directive 2002/58/EC, Articles 12 and 13 of Regulation (EU) 2016/679, Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended, and comparable provisions of the other legal frameworks identified in Section 5.
1.4 This Cookie Policy forms an integral part of the Company’s legal framework. It is incorporated by reference into the Terms of Service pursuant to Section 2.3(b) of those Terms, and it supplements Section 13 of the Privacy Policy.
1.5 Order of precedence. In the event of an inconsistency between this Cookie Policy and the Privacy Policy concerning the processing of Personal Data, the Privacy Policy prevails. In respect of the technical particulars of the cookies and similar technologies deployed on the Website — their identity, provider, purpose, category and duration — this Cookie Policy is the operative document.
1.6 This Cookie Policy is published in English. Translations, where provided, are supplied for convenience only; the English text governs.
2. Identity of the Controller and Contact Details
2.1 The Company is the controller in respect of the processing of Personal Data described in this Cookie Policy, except where this Cookie Policy expressly states that a third party acts as an independent controller or as a joint controller.
| Item | Detail |
|---|---|
| Legal entity | Traverse Limited |
| Trading name / brand | DARCKED.COM |
| Registration number | 20767855 |
| VAT / tax identification number | 107171899 |
| Registered office | Nikole Spasica 3/1, 11000 Belgrade, RS |
| Website | www.darcked.com |
| General contact | official@darcked.com |
| Support contact | support@darcked.com |
| Privacy contact | privacy@darcked.com |
2.2 The Company has determined that it is not required to designate a Data Protection Officer. The representatives designated pursuant to Article 27 GDPR and Article 27 UK GDPR, where those provisions apply, are identified in Sections 2.4 and 2.5 of the Privacy Policy.
2.3 Enquiries concerning this Cookie Policy should be addressed to privacy@darcked.com.
3. Scope
3.1 This Cookie Policy applies to the Website at www.darcked.com, to all of its subdomains and associated interfaces, and to the interfaces through which the Services are made available, including Account pages, checkout pages, Membership administration pages and download pages.
3.2 This Cookie Policy also addresses, to the extent indicated in the Sections concerned:
(a) measurement technologies contained in the Newsletter (Section 18); (b) technologies applied in connection with the delivery and protection of Digital Publications (Section 16); and (c) technologies operated by third parties in connection with embedded content, payment and the Company’s social media channels (Sections 15, 17 and 21).
3.3 This Cookie Policy does not apply to:
(a) cookies and similar technologies placed by the operators of third-party platforms on their own properties, including the social media platforms referred to in Section 20 of the Privacy Policy and the third-party distribution channels referred to in Section 19 of the Privacy Policy, in respect of which those operators act as independent controllers; (b) websites, applications or services operated by third parties and accessible from the Website by hyperlink, which are governed by the cookie and privacy notices of those third parties; or (c) information that does not constitute Personal Data and is not stored on or read from a User’s terminal equipment.
3.4 Where a Digital Publication is acquired through a third-party distribution channel, including Amazon Kindle Direct Publishing, the technologies used by that channel are determined by the operator of that channel and are outside the Company’s control.
4. Definitions and Technologies Covered
4.1 Terms defined in the Terms of Service and in the Privacy Policy have the same meaning in this Cookie Policy unless otherwise stated. In addition, the following terms have the meanings set out below.
“Cookie” means a small text file placed on, or read from, a User’s terminal equipment by a website, and includes first-party cookies set by the Website and third-party cookies set by a domain other than that of the Website.
“Consent Management Mechanism” means the interface displayed to Users on first access to the Website, and accessible thereafter at any time by means of a persistent control published on the Website, through which the User grants, refuses, adjusts and withdraws consent to the placing and reading of non-essential cookies and similar technologies. The expression “consent management interface” used in Section 49 of the Terms of Service refers to the same mechanism.
“Cookie Inventory” means the record of cookies and similar technologies set out in Annex I.
“Session cookie” means a cookie that is erased when the User closes the browser.
“Persistent cookie” means a cookie that remains on the terminal equipment for a defined period, or until it is deleted by the User.
“Similar technologies” means any technology by means of which information is stored on, or accessed from, a User’s terminal equipment, or by means of which a User or terminal equipment is identified or distinguished, including local storage, session storage, IndexedDB, cache-based storage, software development kits, pixels and web beacons, tracking parameters appended to hyperlinks and electronic mail links, and device or browser characteristics used for identification purposes.
“Terminal equipment” means the computer, mobile device, tablet, electronic reader or other equipment by means of which a User accesses the Website or opens a Digital Publication or the Newsletter.
4.2 This Cookie Policy is technology-neutral. Every reference to a cookie is to be read as including any similar technology performing an equivalent function, consistent with the position adopted by the European Data Protection Board in Guidelines 2/2023 on the Technical Scope of Article 5(3) of the ePrivacy Directive.
4.3 References to legislation include that legislation as amended, extended, consolidated or re-enacted from time to time, and any subordinate legislation made under it.
5. Legal Framework
5.1 The use of cookies and similar technologies by the Company is governed by two distinct sets of rules, which apply cumulatively:
(a) rules governing the storing of information on, and the gaining of access to information stored in, a User’s terminal equipment. These rules apply irrespective of whether the information concerned constitutes Personal Data; and
(b) rules governing the processing of Personal Data subsequently derived from or associated with that information.
5.2 The principal instruments applicable to the Company’s activities are:
| Framework | Principal provisions |
|---|---|
| European Union | Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive), as amended by Directive 2009/136/EC, as transposed into the national law of each Member State; Articles 4(11), 6, 7, 12, 13, 21, 25 and 32 of Regulation (EU) 2016/679 (the GDPR) |
| United Kingdom | Regulation 6 of and Schedule A1 to the Privacy and Electronic Communications (EC Directive) Regulations 2003, as substituted and inserted by section 112 of and Schedule 12 to the Data (Use and Access) Act 2025 with effect from 5 February 2026; the UK GDPR; the Data Protection Act 2018 |
| United States — California | The California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and the regulations made under it |
| United States — other states | The comprehensive consumer privacy statutes identified in Section 31 of the Privacy Policy |
| Switzerland | The Federal Act on Data Protection; Article 45c(b) of the Telecommunications Act |
| Canada | The Personal Information Protection and Electronic Documents Act; the Act respecting the protection of personal information in the private sector (Quebec), as amended |
| Brazil | Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018) |
| Australia | The Privacy Act 1988 (Cth) and the Australian Privacy Principles |
| Japan | The Act on the Protection of Personal Information; the external transmission rules under the Telecommunications Business Act |
| South Africa | The Protection of Personal Information Act, 2013; the Electronic Communications and Transactions Act 25 of 2002 |
5.3 The Company also has regard to the guidance of the competent supervisory authorities, including the European Data Protection Board Guidelines 05/2020 on consent, Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive, the report of the Cookie Banner Taskforce, and the guidance of the Information Commissioner’s Office on the use of storage and access technologies.
5.4 The Company applies the principles established by the Court of Justice of the European Union, including in Case C-673/17, Planet49, to the effect that consent is not validly constituted by a pre-ticked box or by inactivity, and in Case C-40/17, Fashion ID, concerning responsibility for third-party technologies embedded in a website.
5.5 The Company monitors legislative developments affecting this field, including the proposals of the European Commission of 19 November 2025 to consolidate the rules on terminal equipment within the GDPR. Those proposals had not been adopted as at the date of this Cookie Policy, and this Cookie Policy is drafted by reference to the law in force. The Company will revise this Cookie Policy in accordance with Section 38 upon any material change in the applicable framework.
PART II — CONSENT
6. Legal Basis for the Use of Cookies and Similar Technologies
6.1 The Company distinguishes, in respect of each technology used, between the act of storing or accessing information on the User’s terminal equipment and any subsequent processing of Personal Data.
6.2 Storing and accessing information on terminal equipment.
(a) Strictly necessary cookies are placed and read without consent, in reliance upon the exemption in Article 5(3) of the ePrivacy Directive, Regulation 6(2)(b) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended, and the corresponding national provisions, on the ground that they are strictly necessary for the provision of a service expressly requested by the User.
(b) Cookies used solely for the purpose of transmitting a communication over an electronic communications network are placed in reliance upon the corresponding communication exemption.
(c) All other cookies and similar technologies, including functional cookies and analytics cookies, are placed and read only after the User has given prior consent by a clear affirmative act performed through the Consent Management Mechanism. Section 33 sets out the position applicable in the United Kingdom following the amendment of Regulation 6 with effect from 5 February 2026.
6.3 Subsequent processing of Personal Data. Where information generated by a cookie constitutes Personal Data, the Company processes it on the following legal bases:
| Category | Purpose | Legal basis for the subsequent processing |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing, recording of consent, enforcement of download entitlements | Performance of a contract — Article 6(1)(b); legitimate interests — Article 6(1)(f); compliance with a legal obligation — Article 6(1)(c) in respect of the retention of consent records |
| Functional | Recording of language, display, reading and library preferences | Consent — Article 6(1)(a); performance of a contract — Article 6(1)(b) where the preference forms part of the Service requested |
| Analytics | Audience measurement and measurement of editorial performance | Consent — Article 6(1)(a) in respect of the storing of and access to information on the terminal equipment; legitimate interests — Article 6(1)(f) in respect of the subsequent analysis, as described in Section 9 of the Privacy Policy |
| Advertising and marketing | Not applicable — see Section 14 | Not applicable |
6.4 Consent obtained through the Consent Management Mechanism is freely given, specific, informed and unambiguous, is granular by category and, where a third-party technology is concerned, is obtained by reference to the identity of that third party. Consent is recorded in a manner enabling the Company to demonstrate compliance in accordance with Article 7(1) GDPR.
6.5 Reliance on legitimate interests is not, and is not treated by the Company as, an alternative to consent in respect of the storing of or access to information on terminal equipment.
7. The Consent Management Mechanism
7.1 On first access to the Website, and thereafter whenever consent has expired or has been withdrawn, the Consent Management Mechanism is displayed before any non-essential cookie or similar technology is placed or read.
7.2 The Consent Management Mechanism provides, on its first layer:
(a) a clear statement that the Website uses cookies and similar technologies, together with a description of the purposes concerned; (b) an option to accept all non-essential technologies; (c) an option to refuse all non-essential technologies, presented with equal prominence, requiring no greater number of actions than acceptance, and not distinguished from the acceptance option by any design, colour, contrast or typographic treatment intended to influence the choice; (d) an option to access granular settings by category; (e) a statement that consent may be withdrawn at any time and an indication of the means of doing so; and (f) a link to this Cookie Policy and to the Privacy Policy.
7.3 On its second layer, the Consent Management Mechanism enables the User to grant or refuse consent separately for each category of non-essential technology, and identifies, for each category, the purposes pursued, the third parties concerned and the duration of the technologies deployed.
7.4 No non-essential cookie is placed, and no information is read from the User’s terminal equipment for a non-essential purpose, before the User has performed an affirmative act. Continued browsing, scrolling, the closing of the interface and inactivity do not constitute consent. No option within the Consent Management Mechanism is pre-selected, save in respect of strictly necessary cookies, which cannot be disabled and are identified as such.
7.5 Where consent is refused in whole or in part, the Company gives effect to that refusal immediately and does not place the technologies concerned.
7.6 The Consent Management Mechanism is provided by [TO BE COMPLETED — identify the consent management platform, its legal entity, its role as Processor, the location of processing and the applicable transfer safeguards]. Where the Consent Management Mechanism is operated by a third party, that party acts as a Processor on behalf of the Company under a written data processing agreement complying with Article 28 GDPR.
7.7 The Company records, in respect of each consent: the identifier assigned to the consent record; the date and time at which consent was given, adjusted or withdrawn; the categories accepted and refused; the version of this Cookie Policy and of the Consent Management Mechanism then in force; and the means by which consent was expressed. Consent records are retained in accordance with Section 23.
8. Withdrawal of Consent, Validity Period and Re-solicitation
8.1 Consent may be withdrawn at any time, without detriment and without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. Withdrawal is effected through the Consent Management Mechanism, which remains accessible at all times from the Website by means of a persistent control.
8.2 Withdrawing consent is no more difficult, and requires no greater number of actions, than granting it.
8.3 Upon withdrawal of consent, the Company ceases to place the technologies concerned and instructs the relevant Processor to cease the corresponding processing. Cookies already placed on the terminal equipment are deleted or, where deletion is not technically possible from the Company’s side, rendered inoperative; the User may in addition delete them by means of the browser settings described in Section 26 and Annex III.
8.4 Consent is not perpetual. The Consent Management Mechanism re-solicits consent upon the earlier of:
(a) the expiry of a period of [twelve (12)] months from the date on which consent was last given or confirmed; (b) a material change to the purposes for which non-essential technologies are used, to the categories deployed, or to the identity of the third parties concerned; and (c) the deletion by the User of the cookie in which the consent preference is stored.
8.5 In France, consent is re-solicited at intervals not exceeding six (6) months, in accordance with the recommendation of the Commission nationale de l’informatique et des libertés.
8.6 Where a User has refused consent, the Company does not display the Consent Management Mechanism again in a manner amounting to the repeated solicitation of consent for the same purpose, and in any event does not re-solicit consent within a period of six (6) months from the refusal, save where the User accesses the Consent Management Mechanism voluntarily or where paragraph 8.4(b) applies.
9. No Cookie Walls, No Consent-or-Pay and No Detriment
9.1 Access to the Website and to Free Content is not conditional upon consent to non-essential cookies or similar technologies. The Company does not operate a cookie wall.
9.2 The Company does not operate a “consent or pay” model. A Membership is not offered as an alternative to consent to tracking, and the price of a Membership or of a Digital Publication does not vary according to the consent choices of the User.
9.3 The withdrawal or refusal of consent does not affect:
(a) access to Free Content; (b) access to Paid Content or to Digital Publications to which the User is entitled under a Membership or a purchase; or (c) the quality, level or functionality of the Services, save to the extent described in Section 27.
9.4 The Company does not discriminate against a User by reason of the exercise of any right under this Cookie Policy, the Privacy Policy or applicable law.
PART III — CATEGORIES AND USE
10. Categories of Cookies and Similar Technologies
10.1 The Company classifies the technologies used on the Website into the following categories:
(a) Strictly necessary — Section 11; (b) Functional — Section 12; (c) Analytics — Section 13; (d) Advertising and marketing — not used; Section 14.
10.2 The Company applies these classifications restrictively. A technology is classified as strictly necessary only where the Service expressly requested by the User could not be provided without it. Technologies that are useful, convenient or commercially advantageous but not indispensable are not classified as strictly necessary.
10.3 The Cookie Inventory in Annex I identifies, for each technology deployed, its name, the provider setting it, whether it is a first-party or third-party technology, its purpose, its category, its type and its duration.
11. Strictly Necessary Cookies
11.1 Strictly necessary cookies are required for the operation of the Website and for the provision of the Services expressly requested by the User. They are placed without consent and cannot be disabled through the Consent Management Mechanism.
11.2 The purposes for which strictly necessary cookies and equivalent technologies are used are:
(a) Authentication and session management — establishing and maintaining a signed-in session, recognising the Account through which the User is signed in, and preventing the need to re-authenticate on each page; (b) Security — detecting and preventing unauthorised access, credential sharing, automated abuse, brute-force attempts, cross-site request forgery and other attacks against the Website and the Accounts; (c) Load balancing and technical routing — distributing requests across the Company’s hosting infrastructure and maintaining session continuity; (d) Entitlement verification — determining whether a User is entitled to access particular Paid Content or to download a particular Digital Publication, and enforcing any applicable limit on the number of downloads, as described in Section 21.3 of the Terms of Service; (e) Checkout and order continuity — maintaining the integrity of the order process, retaining the contents of an order between pages and preventing the duplication of transactions; (f) Fraud prevention at the point of payment — as described in Section 15; (g) Recording of consent preferences — storing the User’s cookie preferences so that they may be given effect and so that the User is not asked repeatedly; and (h) User interface state necessary to the requested service — retaining, for the duration of a session, information required to display the requested page correctly.
11.3 Strictly necessary cookies are first-party cookies, save for those set by the payment providers in the circumstances described in Section 15 and those set by the hosting and content delivery provider for security and routing purposes.
11.4 Where a strictly necessary cookie processes Personal Data, that processing is carried out on the legal bases identified in Section 6.3.
12. Functional Cookies
12.1 Functional cookies record preferences expressed by the User in order to improve the experience of using the Website. They are placed only with the User’s prior consent, subject to Section 33.
12.2 Functional cookies are used for the following purposes:
(a) recording the language and display preferences of the User; (b) recording accessibility preferences, including text size and contrast settings, where such settings are offered; (c) recording reading progress within an item of Editorial Content or a Digital Publication, where that feature is provided; (d) recording saved items, bookmarks and library entries, where those features are provided; and (e) recording that an informational notice has been read, so that it is not displayed repeatedly.
12.3 Functional preferences may be stored by means of local storage or session storage rather than by means of a cookie. Where they are, the same consent requirement applies.
12.4 Where the User refuses functional cookies, the Website remains usable, but preferences are not retained between sessions and must be re-expressed on each visit.
13. Analytics Cookies
13.1 The Company uses Google Analytics, a web analytics service provided by Google Ireland Limited for Users in the European Economic Area, the United Kingdom and Switzerland, and by Google LLC for Users elsewhere (together, “Google”), in order to understand how the Website and the Editorial Content are used and to improve them.
13.2 Analytics cookies and equivalent identifiers are placed only after the User has given prior consent by means of the Consent Management Mechanism, subject to Section 33.
13.3 The information processed by means of analytics technologies comprises Technical and Device Data and Content Access and Usage Data, including a truncated Internet Protocol address, the pages viewed, the duration of the session, the referral source, the approximate geographic location at country, region or city level, and the characteristics of the device and browser.
13.4 The Company applies the following measures in respect of Google Analytics:
(a) analytics technologies are activated only following consent, and Google Consent Mode is implemented so that the signals transmitted are adjusted in accordance with the User’s consent choices; (b) Internet Protocol address truncation or anonymisation is enabled, so that the full Internet Protocol address is not stored; (c) data sharing with Google for advertising purposes, Google Signals and advertising personalisation features are disabled, and analytics data is not used for advertising; (d) analytics data is not combined with Identity and Account Data for the purpose of identifying individual Users, and is not used to take decisions concerning individual Users; (e) data retention within Google Analytics is configured to the shortest period consistent with the Company’s analytical requirements, as specified in Annex II to the Privacy Policy; and (f) a data processing agreement incorporating the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 and, in respect of the United Kingdom, the International Data Transfer Addendum, is in place with Google.
13.5 Google acts as a Processor in respect of the analytics processing described in this Section. Google may act as an independent controller in respect of certain limited processing carried out for the purposes of maintaining and securing its own services. Information concerning Google’s practices is available in Google’s privacy policy and in Google’s business data terms.
13.6 A User may prevent analytics collection by refusing or withdrawing consent through the Consent Management Mechanism, or by installing the browser add-on made available by Google for that purpose.
13.7 The Company uses analytics information only in aggregate, for the purposes of audience measurement, the assessment of editorial performance and the planning of the publishing programme, as described in Sections 8 and 9 of the Privacy Policy. The Company does not draw inferences from analytics information concerning the philosophical, religious or political beliefs of any User.
13.8 The Company does not currently use any additional analytics, performance monitoring, error reporting, session recording or heat-mapping service beyond that identified in this Section.
14. Advertising and Marketing Cookies — Not Used
14.1 The Website does not use advertising or marketing cookies. The Company does not permit third-party advertising networks, demand-side platforms, data management platforms, identity resolution providers or data brokers to place cookies or similar technologies on the Website.
14.2 The Company does not participate in the IAB Europe Transparency and Consent Framework or in any equivalent industry framework for the transmission of consent signals to advertising partners.
14.3 The Company does not engage in cross-context behavioural advertising or targeted advertising, does not construct advertising profiles of Users, does not carry out retargeting, and does not sell or share Personal Data within the meaning of the California Consumer Privacy Act or of the other United States state privacy statutes identified in Section 31 of the Privacy Policy.
14.4 The Company does not display third-party advertising on the Website. Accordingly, the obligations arising under Articles 26 and 28 of Regulation (EU) 2022/2065 in respect of advertising presented on online platforms, including the prohibition of advertising based on profiling using special categories of Personal Data and the prohibition of advertising based on profiling directed at minors, do not give rise to any processing on the Website.
14.5 Should the Company introduce advertising, sponsored material or any technology falling within this category, it will amend this Cookie Policy in accordance with Section 38, will update the Cookie Inventory, and will obtain prior consent through the Consent Management Mechanism before deploying any such technology.
15. Cookies Set in Connection with Payment and Checkout
15.1 Payments in respect of Memberships and one-time purchases of Digital Publications are processed by Stripe, PayPal and Paddle, as described in Section 15 of the Privacy Policy and Section 23 of the Terms of Service.
15.2 Where a User initiates a payment, the relevant payment provider may place cookies or similar technologies on the User’s terminal equipment, or read information from it, for the purposes of processing the transaction, maintaining the integrity of the payment session, detecting and preventing payment fraud, and complying with the obligations to which the provider is subject, including obligations relating to strong customer authentication, anti-money laundering and sanctions screening.
15.3 Technologies deployed for those purposes are strictly necessary to the payment service expressly requested by the User and are not used by the Company for analytics, profiling or advertising purposes.
15.4 The payment providers act as independent controllers, or as joint controllers with the Company in respect of clearly defined processing operations, in relation to the processing they carry out for their own purposes, as described in Section 15.4 of the Privacy Policy. Where Paddle acts as merchant of record, Paddle is the seller of record for the transaction concerned and processes the purchaser’s Personal Data as a controller for the purposes described in Section 15.5 of the Privacy Policy.
15.5 Users are advised to consult the cookie and privacy notices published by the relevant payment provider. The technologies known to be deployed at checkout are identified in Annex I.
15.6 Where a payment page is hosted by a payment provider on that provider’s own domain, the technologies placed on that page are governed by that provider’s notices and are outside the scope of this Cookie Policy.
16. Technologies Used in Connection with Digital Publications and Downloads
16.1 Digital Publications are supplied in PDF format and, where announced, in EPUB format, by direct download through the Account or by means of a download link transmitted to the User.
16.2 In connection with downloads, the Company uses strictly necessary technologies to verify entitlement, to authenticate the download request, to enforce any applicable limit on the number of downloads or on the validity period of a download link, and to detect systematic or automated downloading, as described in Section 18 of the Privacy Policy.
16.3 Identifying marks. A Digital Publication supplied to a User may contain a personalised identifying mark linking the copy to the Account through which it was obtained, as described in Section 18.3 of the Privacy Policy and Section 35 of the Terms of Service. Such a mark is embedded within the file itself. It is not a cookie, does not store information on or read information from the User’s terminal equipment after delivery, and does not report on the User’s subsequent reading of the file.
16.4 The Company does not embed within Digital Publications any tracking pixel, remote resource call, beacon, telemetry function or other technology by means of which the opening, reading or transmission of a Digital Publication is reported to the Company or to any third party after the file has been delivered. A Digital Publication, once downloaded, may be read offline without any communication to the Company.
16.5 Where a Digital Publication is read through a reading interface provided on the Website rather than downloaded, the strictly necessary and, subject to consent, functional technologies described in Sections 11 and 12 apply.
17. Embedded Third-Party Content and Social Media
17.1 The Editorial Content may include material embedded from third-party services, including video, audio and content published on the Company’s social media channels on Instagram, Facebook, X, LinkedIn, YouTube and Pinterest.
17.2 Embedded content is capable of transmitting information, including the Internet Protocol address of the User and the address of the page on which the content is displayed, to the operator of the third-party service, and of causing that operator to place cookies on the User’s terminal equipment.
17.3 The Website does not embed social media plug-ins that transmit information to a platform operator before the User has given consent. Embedded third-party content is loaded only where:
(a) the User has performed a prior affirmative action activating the content, by means of a two-stage activation mechanism which displays a placeholder together with information concerning the transmission that activation will occur; or (b) the content is loaded in an enhanced privacy mode limiting the setting of cookies, in which case any technology set upon playback is disclosed in Annex I.
17.4 Where video content published on YouTube is embedded, the Company uses the privacy-enhanced embedding mode, under which cookies are set by the platform operator only after the User has initiated playback.
17.5 Where the Company and a third-party operator jointly determine the purposes and means of processing carried out by means of embedded content, they act as joint controllers within the meaning of Article 26 GDPR, consistent with the judgment of the Court of Justice of the European Union in Case C-40/17, Fashion ID, and, in respect of page statistics, in Case C-210/16, Wirtschaftsakademie Schleswig-Holstein. The allocation of responsibilities is described in Section 20.3 of the Privacy Policy.
17.6 The Company does not control, and accepts no responsibility for, the cookies placed by a platform operator on that operator’s own properties. Users are advised to consult the cookie and privacy notices and the settings of the relevant platforms.
18. Measurement Technologies in the Newsletter
18.1 The Newsletter is distributed by electronic mail by the newsletter distribution provider identified in Section 17.7 of the Privacy Policy. The Newsletter is distributed by electronic mail through Hostinger Reach, a service provided by Hostinger International Ltd. Personal Data is processed in accordance with the provider’s Privacy Policy and applicable data processing arrangements. Processing may take place within the European Economic Area, the United Kingdom and other jurisdictions where necessary for the provision of the service. Where Personal Data is transferred outside the European Economic Area or the United Kingdom, appropriate transfer safeguards, including the European Commission’s Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum or other lawful transfer mechanisms, are applied. Newsletter engagement measurement, where enabled, may include information concerning message delivery, opening, clicks and unsubscribe events.
18.2 The Newsletter may contain a transparent image or equivalent remote resource, and hyperlinks containing tracking parameters, by means of which the Company is able to determine whether a message has been opened and whether links within it have been selected.
18.3 Such measurement constitutes access to information stored in, and the storing of information on, the recipient’s terminal equipment within the meaning of Article 5(3) of the ePrivacy Directive, and is carried out only where the recipient has given consent to it, where consent is required under applicable law. Consent to receive the Newsletter and consent to engagement measurement are obtained separately, and the withdrawal of consent to measurement does not affect the delivery of the Newsletter.
18.4 The resulting information is used only to assess the effectiveness of editorial communications and to maintain list hygiene, as described in Section 17.6 of the Privacy Policy. It is not used for profiling, for the differentiation of prices, or for the construction of individual reader profiles.
18.5 A recipient may limit such measurement by configuring the electronic mail client to prevent the automatic loading of remote images, and may in every case unsubscribe by means of the link contained in every Newsletter or by contacting support@darcked.com.
18.6 Service communications relating to an Account, a Membership, a purchase, a renewal, a payment failure or a change to the legal framework are not marketing communications, are sent on the basis described in Section 44.6 of the Terms of Service, and do not contain engagement measurement technologies other than those necessary to confirm delivery.
19. Affiliate Links and Sponsored Material
19.1 Where the Company publishes an affiliate link, a sponsored item or other commercial communication, that material is clearly and prominently identified as such in accordance with Section 47 of the Terms of Service.
19.2 The Website does not currently use affiliate links, referral programmes or affiliate marketing networks. No affiliate tracking technologies are deployed on the Website, no affiliate cookies are placed on Users’ devices, and no affiliate attribution technologies are used. Should the Company introduce affiliate or referral programmes in the future, this Cookie Policy, Annex I and the Privacy Policy shall be updated accordingly, and any affiliate tracking technologies requiring consent shall not be activated before the User has provided valid consent through the Consent Management Mechanism.
19.3 Pending completion of paragraph 19.2, the Company confirms that no affiliate or referral tracking technology is placed on the Website, and that the selection by a User of any hyperlink to a third-party destination is governed by the cookie and privacy notices of that destination.
20. Technologies the Company Does Not Use
20.1 For the avoidance of doubt, the Company does not use, and does not permit any third party to use on the Website:
(a) advertising, retargeting or cross-site tracking technologies; (b) device or browser fingerprinting, canvas fingerprinting, or any technique intended to identify or distinguish a User by reference to the characteristics of the terminal equipment otherwise than for the security purposes described in Section 11.2(b); (c) session recording, session replay, keystroke logging, mouse-movement capture or heat-mapping technologies; (d) chat, support or engagement widgets that record the content of interactions for purposes other than responding to the enquiry. The Website does not deploy any live chat, customer support or engagement widget. Users may contact the Company exclusively by electronic mail using the contact details provided on the Website; (e) technologies enabling the matching of a User to an offline identity or to a third-party identity graph; (f) email address hashing for the purposes of identity resolution or advertising; (g) social media conversion pixels, including those of Meta Platforms, X Corp., LinkedIn Corporation or Pinterest, Inc.; (h) technologies that determine or influence the price offered to an individual User; or (i) technologies deployed for the training of artificial intelligence or machine learning models. The Company’s commitments in this regard are set out in Section 21 of the Privacy Policy and in Section 14 of the Terms of Service.
20.2 The statements in this Section are made as at the effective date of this Cookie Policy and are maintained by means of the governance measures described in Section 37.
PART IV — RECIPIENTS, TRANSFERS AND RETENTION
21. Third-Party Cookies and Recipients
21.1 Information generated by cookies and similar technologies is disclosed only to the following categories of recipient:
(a) the hosting, infrastructure, content delivery and backup provider identified in Annex I to the Privacy Policy, acting as a Processor; (b) the membership and subscription system operated within the Company’s own hosting infrastructure, as described in Section 16.4 of the Privacy Policy; (c) the analytics provider identified in Section 13, acting as a Processor; (d) the newsletter distribution provider identified in Section 18, acting as a Processor; (e) the provider of the Consent Management Mechanism identified in Section 7.6, acting as a Processor; (f) the payment providers identified in Section 15, in the capacities described in that Section; and (g) the operators of third-party services from which content is embedded, in the circumstances described in Section 17.
21.2 Each Processor is engaged under a written contract complying with Article 28 GDPR and Article 28 UK GDPR, is bound by confidentiality, may process Personal Data only on the Company’s documented instructions, and is subject to appropriate technical and organisational measures.
21.3 The Company does not disclose information generated by cookies to any third party for that third party’s own marketing purposes, and does not sell such information.
21.4 Disclosure to public authorities, courts, regulators and law enforcement bodies is made only in the circumstances and subject to the safeguards described in Section 24.1(f) of the Privacy Policy.
22. International Transfers of Personal Data
22.1 Certain of the recipients identified in Section 21 process Personal Data outside the European Economic Area, the United Kingdom or Switzerland, including in the United States.
22.2 Where Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a third country, the Company ensures that the transfer is made on the basis of one or more of the mechanisms identified in Section 25.2 of the Privacy Policy, including an adequacy decision, the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 together with the International Data Transfer Addendum issued by the Information Commissioner and, in respect of transfers from Switzerland, the Standard Contractual Clauses as adapted by the Federal Data Protection and Information Commissioner, certification under the EU–US Data Privacy Framework, the UK Extension to that Framework or the Swiss–US Data Privacy Framework, or a derogation under Article 49 GDPR.
22.3 Where the Standard Contractual Clauses are relied upon, the Company carries out a transfer impact assessment in accordance with the recommendations of the European Data Protection Board and implements supplementary measures where necessary.
22.4 The transfer mechanism applicable to each recipient is identified in Annex I to the Privacy Policy and, in respect of technologies deployed on the Website, in Annex I to this Cookie Policy.
22.5 A copy of the safeguards applied to a particular transfer may be obtained, subject to the redaction of commercially confidential information, by contacting privacy@darcked.com.
23. Duration of Cookies and Retention of Consent Records
23.1 The duration of each cookie is stated in Annex I. Session cookies expire when the browser is closed. Persistent cookies expire on the date stated, unless earlier deleted by the User.
23.2 The Company applies the following limits to non-essential technologies placed on the Website:
(a) the lifespan of a cookie placed on the basis of consent does not exceed thirteen (13) months, and the cookie is not renewed automatically on each visit without a fresh act of consent; and (b) information generated by such a cookie is retained for no longer than twenty-five (25) months, after which it is deleted or irreversibly anonymised.
23.3 Consent records are retained for twelve (12) months from the date on which consent was given or last confirmed, and the record of consent is thereafter retained for the duration of the applicable limitation period for the purposes of demonstrating compliance, in accordance with Annex II to the Privacy Policy.
23.4 Analytics information held within Google Analytics is retained for the period specified in Annex II to the Privacy Policy.
23.5 Server logs and security records are retained in accordance with Annex II to the Privacy Policy.
24. Server Logs and Processing Outside the Scope of this Cookie Policy
24.1 The Company’s hosting infrastructure generates server logs recording, among other information, the Internet Protocol address of the requesting device, the date and time of the request, the resource requested, the response status and the user agent string. Such logs are generated in the ordinary course of the transmission of a communication and do not involve the storing of information on, or the reading of information from, the User’s terminal equipment. They are therefore outside the scope of the consent requirement described in Section 6.
24.2 Server logs are processed on the basis of the Company’s legitimate interests in the security, availability and technical integrity of the Website, as described in Sections 8 and 9 of the Privacy Policy, and are retained in accordance with Annex II to that Policy.
24.3 The Company does not use server log information for analytics, profiling or advertising purposes, and does not combine it with analytics information for the purpose of identifying individual Users.
PART V — CONTROL, RIGHTS AND ACCESSIBILITY
25. Managing Preferences through the Consent Management Mechanism
25.1 The Consent Management Mechanism is the primary means by which a User grants, refuses, adjusts and withdraws consent. It is accessible at all times from the Website by means of a persistent control displayed at the bottom of each page. The control remains continuously available while the User navigates the Website.
25.2 Through the Consent Management Mechanism the User may:
(a) accept all non-essential technologies; (b) refuse all non-essential technologies; (c) accept or refuse each category separately; (d) review the identity, purpose, provider and duration of each technology within a category; and (e) withdraw a consent previously given.
25.3 Preferences expressed through the Consent Management Mechanism are stored on the terminal equipment on which they are expressed. A User accessing the Website from a different device or browser, or after deleting cookies, will be asked to express preferences again.
26. Managing Cookies through Browser and Device Settings
26.1 Independently of the Consent Management Mechanism, a User may configure the browser or device to block, restrict or delete cookies, to refuse third-party cookies, to delete cookies on closing the browser, or to browse in a private or incognito mode. Instructions for the principal browsers are set out in Annex III.
26.2 Browser controls operate at the level of the browser and are not communicated to the Company, save where they take the form of an opt-out preference signal within the meaning of Section 28. A User who deletes cookies by means of the browser will also delete the record of preferences expressed through the Consent Management Mechanism, and will be asked to express those preferences again on the next visit.
26.3 Local storage, session storage and other similar technologies are managed through the same browser controls, ordinarily under a heading referring to site data or storage rather than to cookies.
27. Consequences of Refusal, Withdrawal or Deletion
27.1 Refusal of, or withdrawal of consent to, non-essential technologies has the following consequences:
| Category refused | Consequence |
|---|---|
| Functional | Preferences such as language, display settings, reading progress, saved items and library entries are not retained between sessions and must be re-expressed on each visit |
| Analytics | The visit is not included in the Company’s audience measurement. Access to Editorial Content, Digital Publications and the Services is unaffected |
27.2 Strictly necessary cookies cannot be refused through the Consent Management Mechanism. Where a User blocks them by means of the browser, the Website may not function correctly; in particular, it may not be possible to sign in to an Account, to complete a purchase, to access Paid Content or to download a Digital Publication.
27.3 The refusal or withdrawal of consent does not affect any entitlement arising under a Membership or a purchase, and does not affect the Company’s ability to send service communications necessary for the performance of the contract or required by law.
28. Do Not Track and Opt-Out Preference Signals
28.1 There is at present no uniform industry or legal standard for responding to “Do Not Track” browser signals. The Website does not respond to Do Not Track signals.
28.2 The Website recognises and gives effect to opt-out preference signals transmitted by a browser, extension or device in a manner complying with applicable law, including the Global Privacy Control. Where such a signal is received, the Company treats it as a valid request to opt out of the sale and sharing of personal information and of targeted advertising, notwithstanding that the Company does not engage in such activities, and, where technically feasible, applies it to the setting of non-essential cookies.
28.3 Where an opt-out preference signal is received from a User who has separately expressed preferences through the Consent Management Mechanism, the Company applies whichever configuration is more protective of the User, save where the User subsequently expresses a contrary preference through the Consent Management Mechanism in the knowledge of the signal.
28.4 The Company gives effect to universal opt-out mechanisms recognised under the laws of the United States jurisdictions identified in Section 35, to the extent that those mechanisms are technically supported and applicable to the Company.
29. Rights of Data Subjects
29.1 Where information generated by a cookie or similar technology constitutes Personal Data, the data subject may exercise the rights described in Section 29 of the Privacy Policy, including the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent.
29.2 The right to object to processing carried out on the basis of legitimate interests, on grounds relating to the data subject’s particular situation, applies to the analysis of analytics information described in Section 13.7 and to the security processing described in Section 24.2.
29.3 Requests may be submitted to privacy@darcked.com. The Company responds within the periods stated in Sections 29.13 and 30.7 of the Privacy Policy.
29.4 The exercise of these rights is free of charge and does not affect access to the Website or to the Services.
30. Children
30.1 The Website and the Services are directed to adults and are not intended for children, as stated in Section 5 of the Terms of Service and Section 12 of the Privacy Policy.
30.2 The Company does not knowingly place cookies or similar technologies on the terminal equipment of a child in circumstances requiring consent that the child is not competent to give, and does not knowingly process information generated by such technologies in relation to a child.
30.3 The Company does not carry out any profiling of Users and does not deploy any technology directed at children or intended to influence their behaviour.
30.4 A parent or guardian who believes that a child has provided Personal Data to the Company, or that Personal Data relating to a child has been collected by means of the technologies described in this Cookie Policy, should contact privacy@darcked.com. The Company will delete that data without undue delay.
31. Accessibility of the Consent Management Mechanism
31.1 The Consent Management Mechanism is designed so as to be operable by Users relying on assistive technologies, consistent with the Company’s accessibility commitments under Section 50 of the Terms of Service, with the Web Content Accessibility Guidelines (WCAG) 2.1 at Level AA, and, in respect of the European Union, with the accessibility requirements set out in Annex I to Directive (EU) 2019/882 and the harmonised standard EN 301 549.
31.2 In particular, the Consent Management Mechanism is operable by keyboard, is compatible with screen readers, does not rely upon colour alone to convey the distinction between options, maintains sufficient contrast, and does not trap keyboard focus.
31.3 A User who encounters an accessibility barrier in the Consent Management Mechanism may contact accessibility@darcked.com and will be provided with an alternative means of expressing preferences.
PART VI — JURISDICTION-SPECIFIC PROVISIONS
32. European Economic Area
32.1 In the European Economic Area, the storing of information on, and the gaining of access to information stored in, the terminal equipment of a User is governed by Article 5(3) of the ePrivacy Directive as transposed into the national law of each Member State, and the subsequent processing of Personal Data is governed by the GDPR.
32.2 The Company applies the standard of consent established by Article 4(11) and Article 7 GDPR, and complies with the national implementing provisions and supervisory guidance applicable in each Member State, including:
(a) Germany — section 25 of the Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG), and the arrangements for recognised consent management services made under the Einwilligungsverwaltungsverordnung; (b) France — the deliberations and recommendation of the Commission nationale de l’informatique et des libertés concerning trackers, including the requirement that refusal be as straightforward as acceptance and the recommendation as to the validity period of consent reflected in Section 8.5; (c) Italy — the guidelines of the Garante per la protezione dei dati personali concerning cookies and other tracking tools; (d) Spain — the guidance of the Agencia Española de Protección de Datos concerning the use of cookies; (e) The Netherlands — Article 11.7a of the Telecommunicatiewet; and (f) the equivalent provisions in force in the other Member States.
32.3 Where the requirements of a Member State are more stringent than those described in this Cookie Policy, the more stringent requirement is applied to Users in that Member State.
33. United Kingdom
33.1 In the United Kingdom, Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 was substituted, and a new Schedule A1 inserted, by section 112 of and Schedule 12 to the Data (Use and Access) Act 2025, with effect from 5 February 2026. In addition to the retained communication and strictly necessary exceptions, consent is no longer required in respect of certain technologies used for statistical purposes, for adapting the appearance or functionality of a service to the preferences of the user, or for enabling emergency assistance, in each case subject to the conditions prescribed by that Schedule.
33.2 Where the Company relies upon an exception in Schedule A1, it provides clear and comprehensive information about the purposes of the storage or access and offers a simple means of objecting, free of charge, in accordance with the conditions attaching to that exception.
33.3 Notwithstanding paragraph 33.1, the Company continues to obtain prior consent from Users in the United Kingdom in respect of the analytics technologies described in Section 13. The statistical purposes exception is not relied upon in respect of Google Analytics, because that service is provided by a third party and the Company does not treat the conditions of the exception as reliably satisfied where information is transmitted to a third-party provider. This position is kept under review in the light of the guidance of the Information Commissioner’s Office on the use of storage and access technologies.
33.4 Functional technologies described in Section 12 are likewise placed on the basis of consent, notwithstanding the appearance exception, so that a single and consistent standard applies to Users in the United Kingdom and in the European Economic Area.
33.5 The subsequent processing of Personal Data derived from cookies is governed by the UK GDPR and the Data Protection Act 2018.
34. California
34.1 Cookies and similar technologies may generate personal information within the meaning of the California Consumer Privacy Act, including identifiers, internet or other electronic network activity information, and approximate geolocation data. The categories collected, the sources, the purposes and the recipients are set out in Section 30.2 of the Privacy Policy.
34.2 The Company does not sell personal information and does not share personal information for cross-context behavioural advertising. Accordingly, no “Do Not Sell or Share My Personal Information” link is required. The Company nevertheless gives effect to opt-out preference signals as described in Section 28.
34.3 The Company does not use or disclose sensitive personal information for purposes other than those permitted by Cal. Civ. Code § 1798.121(a) and the regulations made under it, and does not infer characteristics concerning any consumer.
34.4 The Company does not use session recording, keystroke logging or comparable technologies, and does not permit any third party to intercept or record communications between a User and the Website for that third party’s own purposes.
34.5 California residents may exercise the rights described in Section 30.6 of the Privacy Policy by contacting privacy@darcked.com.
35. Other United States Jurisdictions
35.1 Residents of the United States jurisdictions identified in Section 31 of the Privacy Policy have the rights described in that Section, including, where applicable, the right to opt out of the processing of personal data for the purposes of targeted advertising, the sale of personal data and profiling in furtherance of decisions producing legal or similarly significant effects.
35.2 The Company does not engage in targeted advertising, does not sell personal data and does not carry out such profiling. The rights described in paragraph 35.1 therefore do not give rise to any processing from which a consumer needs to opt out.
35.3 The Company gives effect to universal opt-out mechanisms recognised under the laws of those jurisdictions, as described in Section 28.
35.4 Residents of Nevada may submit a request that the Company not sell certain covered information, as defined in Nevada Revised Statutes Chapter 603A. The Company does not engage in such sales.
36. Switzerland, Canada, Brazil, Australia, Japan and South Africa
36.1 Switzerland. The Company processes Personal Data relating to individuals in Switzerland in accordance with the Federal Act on Data Protection. Information concerning the processing of data on terminal equipment, and the means of refusing it, is provided in accordance with Article 45c(b) of the Telecommunications Act. Data subjects may lodge a complaint with the Federal Data Protection and Information Commissioner.
36.2 Canada. The Company processes personal information relating to individuals in Canada in accordance with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation. In respect of Quebec, the Company confirms that any technology used to identify, locate or profile a User is deactivated by default, and that the Company informs Users of the means of activating such technologies; the Company does not, in any event, deploy profiling technologies. Individuals may complain to the Office of the Privacy Commissioner of Canada or to the Commission d’accès à l’information du Québec.
36.3 Brazil. The Company processes Personal Data relating to individuals in Brazil in accordance with Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018) and has regard to the guidance of the Autoridade Nacional de Proteção de Dados concerning cookies. Consent to non-essential technologies is obtained in the manner described in Section 7.
36.4 Australia. The Company processes personal information relating to individuals in Australia in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Individuals may complain to the Office of the Australian Information Commissioner.
36.5 Japan. The Company processes personal information relating to individuals in Japan in accordance with the Act on the Protection of Personal Information, including the provisions concerning personally referable information transmitted to third parties, and provides the information required in respect of the external transmission of information under the Telecommunications Business Act.
36.6 South Africa. The Company processes Personal Data relating to individuals in South Africa in accordance with the Protection of Personal Information Act, 2013 and the Electronic Communications and Transactions Act 25 of 2002. Data subjects may complain to the Information Regulator.
36.7 Other jurisdictions. Where the Company provides the Services to Users in other jurisdictions, it complies with applicable local law governing the storing of information on, and access to information stored in, terminal equipment. Where local law confers rights more extensive than those set out in this Cookie Policy, those rights apply.
PART VII — GOVERNANCE AND FINAL PROVISIONS
37. Cookie Governance, Audit and Records
37.1 The Company maintains the Cookie Inventory in Annex I as a record of the technologies deployed on the Website.
37.2 The Company carries out a technical scan of the Website in order to verify the Cookie Inventory:
(a) before the publication of this Cookie Policy; (b) at intervals not exceeding [three (3)] months; and (c) upon any material change to the Website, to the Services, to the providers engaged or to the technologies deployed.
37.3 No new cookie or similar technology is deployed on the Website before it has been assessed for classification, added to the Cookie Inventory and, where it is not strictly necessary, integrated into the Consent Management Mechanism so that it is placed only following consent.
37.4 The Company maintains records of processing activities in accordance with Article 30 GDPR, and records of consent in accordance with Article 7(1) GDPR, in respect of the technologies described in this Cookie Policy.
37.5 Where a third party engaged by the Company deploys a technology not disclosed in the Cookie Inventory, the Company will require its removal or its integration into the Consent Management Mechanism, and will update this Cookie Policy accordingly.
38. Changes to this Cookie Policy
38.1 The Company may amend this Cookie Policy in order to reflect changes to the Website, to the Services, to the providers engaged, to the technologies deployed, or to applicable law or regulatory guidance.
38.2 The version number, the effective date and the date of the most recent revision are stated at the head of this document. Superseded versions are archived and made available on request.
38.3 Where an amendment introduces a new category of technology, a new purpose, a new recipient or a change to the legal basis relied upon, the Company will re-solicit consent through the Consent Management Mechanism before the amendment is given effect, in accordance with Section 8.4(b).
38.4 Continued use of the Website following the effective date of an amendment constitutes acknowledgement of the amended Cookie Policy, save in respect of any technology for which consent is required, which will not be deployed without that consent.
39. Complaints and Supervisory Authorities
39.1 The Company invites Users to raise any concern regarding the use of cookies and similar technologies with the Company in the first instance, by contacting privacy@darcked.com. The Company will investigate and respond without undue delay.
39.2 Data subjects nevertheless have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. In the United Kingdom, complaints may be made to the Information Commissioner’s Office. The supervisory authorities competent in the other jurisdictions addressed in this Cookie Policy are identified in Sections 32 and 36 of the Privacy Policy.
39.3 The exercise of the right to lodge a complaint is without prejudice to any other administrative or judicial remedy.
40. Contact Details
| Purpose | Contact |
|---|---|
| Cookies, data protection and privacy matters | privacy@darcked.com |
| Exercise of data subject rights | privacy@darcked.com |
| Accessibility of the Consent Management Mechanism | accessibility@darcked.com |
| User support | support@darcked.com |
| General correspondence | official@darcked.com |
| Postal correspondence | official@darcked.com |
ANNEX I — COOKIE AND SIMILAR TECHNOLOGY INVENTORY
Note. This Annex must be verified against a technical scan of the Website before publication, and re-verified at the intervals stated in Section 37.2. Entries marked [TO BE COMPLETED] must be populated with the actual name, provider and duration of each technology as deployed. Durations stated for third-party technologies are those published by the provider concerned and are subject to change by that provider.
A. Strictly necessary — placed without consent
| Name | Provider / domain | First or third party | Purpose | Type | Duration |
|---|---|---|---|---|---|
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Session identifier; maintenance of the session between requests | Cookie | Session |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Authentication of a signed-in Account | Cookie | [TO BE COMPLETED] |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Protection against cross-site request forgery and form abuse | Cookie | Session |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Verification of entitlement to Paid Content and to Digital Publication downloads; enforcement of download limits | Cookie / local storage | [TO BE COMPLETED] |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Storage of cookie consent preferences | Cookie | [twelve (12) months — TO BE COMPLETED] |
| [TO BE COMPLETED] | Hostinger International Ltd. | Third party | Load balancing, technical routing, protection against automated abuse | Cookie | [TO BE COMPLETED] |
| [TO BE COMPLETED] | Provider of the Consent Management Mechanism (Section 7.6) | Third party | Operation of the Consent Management Mechanism | Cookie / local storage | [TO BE COMPLETED] |
B. Functional — placed only with consent
| Name | Provider / domain | First or third party | Purpose | Type | Duration |
|---|---|---|---|---|---|
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Language and display preferences | Cookie / local storage | [TO BE COMPLETED — not exceeding thirteen (13) months] |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Reading progress, saved items and library entries | Local storage | [TO BE COMPLETED — not exceeding thirteen (13) months] |
| [TO BE COMPLETED] | Traverse Limited (darcked.com) | First party | Accessibility preferences | Cookie / local storage | [TO BE COMPLETED — not exceeding thirteen (13) months] |
C. Analytics — placed only with consent
| Name | Provider / domain | First or third party | Purpose | Type | Duration |
|---|---|---|---|---|---|
_ga | Google Ireland Limited / Google LLC | Third party (set on the Website domain) | Distinguishes Users for the purposes of audience measurement | Cookie | Up to 2 years as configured by the provider — [TO BE COMPLETED: confirm the period configured by the Company, which should not exceed thirteen (13) months] |
_ga_[container identifier] | Google Ireland Limited / Google LLC | Third party (set on the Website domain) | Maintains the session state for audience measurement | Cookie | Up to 2 years as configured by the provider — [TO BE COMPLETED] |
| [TO BE COMPLETED — any further Google Analytics identifiers detected on scan] | Google Ireland Limited / Google LLC | Third party | Audience measurement | Cookie / local storage | [TO BE COMPLETED] |
D. Advertising and marketing
None. See Section 14.
E. Set by payment providers at the point of payment — strictly necessary to the payment service requested
| Name | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
__stripe_mid | Stripe | Fraud prevention and detection | Cookie | 1 year (as published by the provider) |
__stripe_sid | Stripe | Fraud prevention and detection during the payment session | Cookie | 30 minutes (as published by the provider) |
| [TO BE COMPLETED] | PayPal | Payment session integrity and fraud prevention | Cookie | [TO BE COMPLETED — see PayPal’s published cookie statement] |
| [TO BE COMPLETED] | Paddle | Payment session integrity, merchant-of-record checkout and fraud prevention | Cookie / local storage | [TO BE COMPLETED — see Paddle’s published cookie statement] |
F. Set by third parties upon activation of embedded content
| Name | Provider | Purpose | Type | Duration | Condition |
|---|---|---|---|---|---|
| [TO BE COMPLETED] | Google LLC (YouTube, privacy-enhanced mode) | Playback of embedded video; measurement of playback by the platform operator | Cookie | [TO BE COMPLETED] | Placed only after the User activates playback |
| [TO BE COMPLETED] | [TO BE COMPLETED — any further embedded service] | [TO BE COMPLETED] | [TO BE COMPLETED] | [TO BE COMPLETED] | Placed only after prior affirmative activation by the User |
ANNEX II — GLOSSARY OF TECHNOLOGIES
Cookie. A small text file placed on the terminal equipment by a website and returned to the server on subsequent requests. A first-party cookie is set by the domain the User is visiting; a third-party cookie is set by another domain.
Session cookie. A cookie erased when the browser is closed.
Persistent cookie. A cookie that remains until its stated expiry date or until deleted.
Local storage and session storage. Browser facilities enabling a website to store information on the terminal equipment. Local storage persists until deleted; session storage is erased when the tab or browser is closed. Both fall within the same legal rules as cookies.
Pixel or web beacon. A small transparent image or equivalent remote resource embedded in a page or an electronic mail message which, when loaded, causes a request to be sent to a server, thereby signalling that the page has been displayed or the message opened.
Software development kit (SDK). A body of code incorporated into an application which may store or read information on the terminal equipment.
Tracking parameter. Information appended to a hyperlink which identifies the source of the navigation or the recipient of a message.
Fingerprinting. The identification or distinguishing of a User by reference to the configuration and characteristics of the terminal equipment, without the storing of information on it. The Company does not use fingerprinting for identification purposes; see Section 20.1(b).
Consent Management Mechanism. The interface through which consent is granted, refused, adjusted and withdrawn; see Section 4.1.
Opt-out preference signal. A signal transmitted by a browser, extension or device communicating a User’s decision to opt out of specified processing, including the Global Privacy Control.
ANNEX III — BROWSER AND DEVICE MANAGEMENT INSTRUCTIONS
A User may manage cookies and similar technologies through the settings of the browser or device. The relevant settings are ordinarily found as follows.
| Browser | Location of the settings |
|---|---|
| Google Chrome | Settings → Privacy and security → Third-party cookies / Site data |
| Mozilla Firefox | Settings → Privacy & Security → Cookies and Site Data |
| Apple Safari (macOS) | Settings → Privacy → Manage Website Data / Block all cookies |
| Apple Safari (iOS / iPadOS) | Settings → Apps → Safari → Advanced → Website Data |
| Microsoft Edge | Settings → Cookies and site permissions → Manage and delete cookies and site data |
| Opera | Settings → Privacy & security → Cookies and other site data |
| Brave | Settings → Shields / Privacy and security → Cookies |
The Company does not control these settings, and the location of a setting may change following an update issued by the provider of the browser. A User who blocks all cookies, including strictly necessary cookies, may be unable to sign in to an Account, to complete a purchase or to download a Digital Publication, as described in Section 27.2.
Deleting cookies by means of the browser will also delete the record of preferences expressed through the Consent Management Mechanism. The Consent Management Mechanism will be displayed again on the next visit.
End of Cookie Policy.
© DARCKED.COM. All rights reserved. This document is published as the Cookie Policy applicable to the Website and the Services and does not constitute legal advice to any User.
