Legal
Cookie Policy
1. About this policy
This Cookie Policy explains what cookies and similar technologies are,
which ones Schemia Ltd (“Schemia”,
“we”, “us”,
“our”) uses on the Schemia
marketing site (schemia.com,
www.schemia.com), why we use them, and
how you can control them. It supplements our
Privacy Policy — see Privacy Policy §4
for the higher-level commitment.
“Similar technologies” includes local storage, session storage, IndexedDB entries, and any other client-side technology that stores or accesses information on your device. Where this policy refers to “cookies”, treat the term as inclusive of those technologies unless the context plainly limits it.
This policy does not apply to the Schemia authoring application, to Schemia-hosted bot sites, or to customer-controlled bot-site domains — see §3 below.
2. What cookies are
A cookie is a small text file that a website places on your browser or device when you visit. Cookies can be:
- First-party — set by the site you are visiting (in
our case, by
schemia.com). - Third-party — set by a different domain whose
content is loaded on the page. We do not set third-party advertising
cookies (see §3); the only third-party cookie we knowingly
cause to be set on this site is the operational
__cf_bmcookie set by Cloudflare at our network edge. It is described in §4. - Session — deleted when you close your browser.
- Persistent — stored on your device for a defined retention period.
Under the Privacy and Electronic Communications Regulations 2003 (“PECR”) and the UK GDPR, non-essential cookies require your consent before they are set on your device. Section 4 sets out, for each category, the PECR basis (consent vs. the strictly-necessary exemption under PECR Reg 6(4)) and the UK GDPR Art 6 lawful basis for any further processing the cookie enables.
3. What this policy covers (and what it doesn’t)
In scope
-
schemia.comandwww.schemia.com— our public marketing site.
Not in scope
- The Schemia authoring application at
app.schemia.com— the authoring app sets a separate set of cookies (its own sign-in session, its own consent cookie sharing the sameschemia_consentname on the.schemia.comparent domain) and is documented in its own cookie surface when that route ships. The authoring app is not loaded from this site. - Bot sites hosted by Schemia on a customer subdomain at
{customer}.schemia.com(for exampleacme.schemia.com). Bot sites are static, bot-readable knowledge graphs published on behalf of our customers. Schemia does not set cookies on bot-site subdomains. - Bot sites hosted on customer-controlled domains
(where a Schemia customer points a domain at a Schemia-served bot
site — we recommend the prefix
schema.{their-domain}, e.g.schema.acme.com, but a customer may use any subdomain or apex they choose). If a customer-controlled domain sets cookies, the relationship is between that customer and their own visitors, not Schemia. We do not place cookies on customer-controlled domains.
Three categories the banner uses
Our consent banner groups cookies into three categories. Section 4 lists the specific cookies in each.
| Category | Consent required? | Default state in banner |
|---|---|---|
| Strictly Necessary | No (PECR Reg 6(4) exemption) | Always on — no toggle |
| Analytics | Yes | Off until you opt in |
| Functional | Yes | Off until you opt in |
We do not use third-party advertising cookies and we do not share data with advertising networks for cross-context behavioural advertising. This commitment is also given in Privacy Policy §4 and Privacy Policy §5. There is no Marketing or Advertising toggle in the banner because there are no such cookies on the Service.
4. Specific cookies and storage we set
The table below lists every cookie currently set on
schemia.com. We keep it in sync with
what is actually deployed — if we change what we set, this page
changes and the consent banner re-prompts (see §9).
Strictly Necessary cookies (no consent required)
These cookies are necessary to deliver a service you have expressly requested — either visiting our site at all (Cloudflare edge protection) or recording the cookie choices you have made (the consent cookie itself). They are set under the PECR Reg 6(4) exemption. The further processing they enable is carried out on the basis of UK GDPR Art 6(1)(b) (performance of a contract with you, or steps prior to entering a contract — including delivery of the site you have requested) and, for the access-log telemetry Cloudflare also collects, Art 6(1)(f) (legitimate interests in operating a secure service and detecting abuse).
| Cookie | Set by | Purpose | Scope | Retention |
|---|---|---|---|---|
schemia_consent |
The @schemia/consent package
(Schemia first-party)
| Stores your category choices, a hash identifying the banner version you saw, and a flag for whether your browser sent a Global Privacy Control signal at the time of choice. Used to suppress re-prompting until either 180 days elapse or the banner-version hash changes. | .schemia.com (set on the
parent domain so a single choice covers all Schemia surfaces)
|
180 days (Max-Age), refreshed
each time you confirm a choice
|
__cf_bm
(and other managed cookies Cloudflare may set)
| Cloudflare (sub-processor) | Bot management and threat scoring at the network edge. Cloudflare’s standard managed cookies — not set by Schemia’s application code. | .schemia.com |
Per Cloudflare’s policy (typically 30 minutes for
__cf_bm).
|
Analytics cookies (consent required)
We use Plausible Analytics (Plausible Analytics OÜ,
Estonia) to count aggregate page views and referrers on
schemia.com. Plausible is
cookieless by design — it does not set any cookies
on your device and does not store anything in local storage. We list
it here under the Analytics category because the
plausible.io script does not load
unless you have opted in to the Analytics category in the
consent banner; that gate is described in §5. The data Plausible
collects (URL, referrer, country derived from a daily-rotating hash
of IP + user-agent) is aggregate, not tied to individual visitors,
and is processed in the EU. See the
Sub-processors page for the row that
names Plausible.
The PECR basis for the Plausible script tag is consent (PECR Reg 6). The UK GDPR basis for the aggregate measurement is consent (Art 6(1)(a)). Withdrawal works as described in §7.
Functional cookies (consent required)
As of the date at the top of this page, no Functional cookies are set. This category exists in the banner because we anticipate features during beta that require remembering small preferences (for example whether you have dismissed an in-product tour). When a Functional cookie is added, this section will be updated with a concrete entry and the banner-version hash will change.
When Functional cookies are added, the PECR basis will be consent (PECR Reg 6) and the UK GDPR basis will be consent (Art 6(1)(a)).
Marketing / advertising
We do not set marketing or third-party advertising cookies and we do not share data with advertising networks for cross-context behavioural advertising. There is no banner toggle for this category because the category is empty by design — see Privacy Policy §5.
5. Consent mechanism
When you first visit schemia.com, we
present a consent banner that:
- Lists the Analytics and Functional categories with a plain-English description of what each does.
- Provides an “Accept all” and a “Reject all” action of equal prominence and requiring an equal number of clicks. There is no “X” close button that defaults to acceptance, and the banner does not use a dark-pattern visual hierarchy to nudge you toward acceptance. This matches the equal-prominence commitment given in Privacy Policy §4 and follows the ICO’s published expectations for cookie banners.
- Provides a “Customize” action that expands an inline panel letting you toggle the Analytics and Functional categories independently. A “Save preferences” action commits your choice in a single click and dismisses the banner — mechanically parallel to Accept all and Reject all.
- Does not pre-tick any non-essential category.
- Does not block the page or condition access on acceptance.
We present the same banner to all visitors regardless of where you are. Where your local law does not require a banner, declining still costs you nothing.
The Strictly Necessary category and what makes a cookie strictly necessary
For each cookie in the Strictly Necessary category (§4), the cookie is strictly necessary because you have expressly requested the service the cookie enables:
-
schemia_consent— necessary to remember your choice so we don’t re-prompt you on every page. - Cloudflare managed cookies — necessary for the edge protection that keeps the site itself reachable and secure.
We do not place any other cookie in the Strictly Necessary category, and adding a cookie to Strictly Necessary is itself a material change that triggers the change-log + banner re-prompt under §9.
Accessibility
The consent banner is operable by keyboard, screen reader, and assistive technologies. The “Reject all”, “Accept all”, and “Save preferences” controls have matched tab order, action labels readable by screen readers, and equal visual prominence, so consent is freely given regardless of how you interact with the page.
6. How we record your consent and when we re-prompt
What we record
When you make a choice in the consent banner, two things happen:
- A
schemia_consentcookie is set on your device (see §4 for the row). It contains your category choices, the banner-version hash you saw at the time, and a flag for whether your browser was sending a Global Privacy Control signal. - A row is written to our server-side
consent_logto evidence that consent was validly obtained — this is the record-keeping side of UK GDPR Art 7 (conditions for consent). The row contains: the timestamp, your account identifier (only if you are signed in — otherwise blank), the workspace identifier (only if you are signed in — otherwise blank), your category choices, the banner-version hash you saw, the GPC flag, and a truncated client IP address (the last octet of an IPv4 address, or the last 80 bits of an IPv6 address, are removed before storage so the address cannot be tied back to a single household). The truncation is done on our server — the banner does not transmit your IP address.
The consent_log row is not a cookie;
it is a server-side processing record. The full processing detail
(lawful basis, retention, your rights in respect of this data) is in
Privacy Policy §3 and §7. The
lawful basis for writing this row is legitimate interests
(UK GDPR Art 6(1)(f)) in being able to demonstrate that
valid consent was given — without it, we cannot meet the
accountability obligation under Art 5(2) and Art 7(1).
When we re-prompt you
We re-show the consent banner — and your previous choice is replaced by the new one — when any one of the following is true:
- No
schemia_consentcookie is present (first visit, you cleared cookies, or you visited from a browser we have not seen before). - The banner-version hash on your
schemia_consentcookie does not match the current banner. We change the hash whenever we make a material change to the categories, to what each category does, or to the copy in the banner. A material change is itself a change to this policy, and gets logged in the change history at the bottom of this page (§9). - The cookie is older than 180 days. We re-prompt at least every 180 days so your consent is current. This cycle aligns with the ICO’s published expectation that consent should be refreshed periodically; we have chosen 6 months as a conservative midpoint (there is no statutory maximum under PECR, but the ICO has criticised cycles longer than around 12 months).
A “refresh” of consent simply means the next visit shows the banner again. Your old choice does not carry over silently; you make a fresh choice. If you accept again, the 180-day clock restarts.
Global Privacy Control
Some browsers and browser extensions send a
Sec-GPC: 1 header to express an
opt-out preference. We honour this signal: if your browser sends GPC
on a visit, the banner records a rejection of
Analytics and Functional categories without prompting, and a small
“Cookies” trigger remains visible in the footer so you
can override the GPC-derived choice if you want to. The GPC flag is
stored on the consent_log row to
evidence that the rejection was based on the signal rather than on a
banner interaction.
The ICO has not formally adopted GPC as a withdrawal-of-consent mechanism under PECR; honouring it is a voluntary commitment beyond current ICO minimum requirements. We mention it here because users in California in particular expect to see it called out, even though Schemia Ltd is a UK controller.
7. Withdrawing or changing your choices
You can change or withdraw your consent at any time, using the
surface below. It updates the schemia_consent
cookie immediately and writes a new row to
consent_log so the change is
auditable.
- The “Cookies” trigger in our site footer. Clicking it re-opens the banner on the page you are currently on. This is the fastest way to change a single choice without leaving what you were doing. Analytics scripts honour the change live: if you opt out, the Plausible tag is removed from the page; if you opt in, the tag is injected without a page reload.
Withdrawal is prospective. Cookies that were already set on your device will remain there until they expire or until you clear them in your browser — but no further non-essential cookie will be set after withdrawal. You can also clear cookies and storage directly in your browser.
You do not need an account to withdraw consent. The banner is available on the marketing site without signing in, and the consent cookie is set on the marketing-site domain.
8. “Do Not Track”
Do Not Track (DNT) is a deprecated browser signal. We do not respond to DNT headers, because the standard was never finalised, was implemented inconsistently across browsers, and is no longer maintained. The ICO has confirmed it holds no documented position on DNT (Freedom of Information disclosure IC-293148-Q4K6, April 2024).
The successor signal, Global Privacy Control, is honoured by Schemia — see §6 above.
9. Changes to this policy
We update this Cookie Policy as our cookie footprint evolves — for example when we add an analytics provider, when we change what a category does, or when we change the banner copy or category labels. We also update it when the legal landscape moves (PECR, UK GDPR, ICO guidance, the Data (Use and Access) Act 2025 implementing regulations).
How material changes flow through
A “material change” is any change that affects what the banner asks you, what choosing a category means, what cookies are set, or how long they last. For every material change:
- We update this page (the table in §4 is the source of truth for the current state).
- We update the Last updated date at the top.
- We add an entry to the Changes list below.
- We update the banner-version hash so the consent banner re-prompts you on your next visit (see §6).
- Where the change introduces a new sub-processor, we also update the Sub-processors page and the 30-day notice mechanism on that page applies.
Non-material changes (typo fixes, formatting, clarifying wording without changing meaning) do not trigger a re-prompt and are noted in the Changes list but flagged as non-material.
Changes
| Date | Version | Type | Summary |
|---|---|---|---|
| 21 May 2026 | v1-beta.3 | Material |
Analytics category description in the banner now names
Plausible Analytics OÜ concretely; the previous wording
(“Schemia uses no analytics today”) was stale
post-Plausible-wiring. Sub-processors page updated to
v1-beta.2 to add Plausible Analytics OÜ (Estonia, cookieless)
and Google Ireland Limited (Google Workspace, EU data
region) rows. Banner-version-hash bumped to
2026-05-21.1; users who
consented under 2026-05-20.1
will re-prompt once. Scope narrative reconciled to
schemia.com only (the authoring app at
app.schemia.com will be
covered by its own cookie surface).
|
| 20 May 2026 | v1-beta.3 | Material |
Plausible Analytics OÜ (Estonia, cookieless) named as an
analytics consumer gated behind explicit consent.
Banner-version-hash bumped to
2026-05-20.1: persisted
schemia_consent records under
2026-05-19.1 are treated as
stale; existing consented users re-prompted once. Plausible
loader is a separate consumer of the consent state (script
does NOT inject unless
selection.analytics === true).
|
| 20 May 2026 | v1-beta.2.1 | Non-material |
Bot-site naming convention corrected throughout
(Schemia-hosted bot sites use
{customer}.schemia.com;
customer-controlled domains may use the recommended
schema.{their-domain}
prefix or any subdomain or apex the customer chooses).
§3 wording on customer-controlled domains rewritten to
use consistent third-person for the customer-controller (the
reader of this policy is the visitor). No change to banner,
categories, cookies, or retention — no banner re-prompt.
|
| 20 May 2026 | v1-beta.2 | Material |
Drafting rewrite to match the consent banner shipped under
Builder S24. Categories reduced from four to three (Strictly
Necessary / Analytics / Functional). Concrete cookie
inventory added. Consent-record mechanism described
(schemia_consent cookie +
server-side consent_log
row). 180-day re-consent cycle stated. Global Privacy
Control handling stated.
|
| 19 May 2026 | v1-beta.1 | Material | Audit-revision against ICO 2024-2026 enforcement and Privacy Policy v1-beta.1 §4 commitment. |
| 19 May 2026 | v1-beta | Initial | Initial in-house draft. |
We will redraft this policy to v2-public ahead of public launch.
10. Contact
- Cookie and privacy queries: privacy@schemia.com
- Legal notices: legal@schemia.com
If you believe we are not handling cookies or your personal data in accordance with this policy or applicable law, you have the right to complain to a supervisory authority — for users in the UK, that is the Information Commissioner’s Office at ico.org.uk. See Privacy Policy §8 for the equivalent regulators for users in the EEA, California, Canada, and Australia.