Information about cookies
Cookies are small identification tokens placed on a user's web browser that provide a web application with some basic information about the current visitor's browsing session.
As the web has grown, some companies have used these tokens to track user behaviour across multiple websites — often used for the purposes of serving targeted advertising or other services — in a way that many think is abusive and contrary to a user's privacy online.
As a consequence, a number of legal instruments have been passed in order to make people more aware of the existence of cookies, how they can be misused, and to provide users with mechanisms for making an informed choice as to whether they wish to accept these terms.
To find out how to manage, control, delete cookies, see your browser's help section or your mobile device manual. Or you can visit www.allaboutcookies.org, where you can find detailed information on cookies. Please be aware that restricting cookies may impact on the functionality of our website.
Key principle: informed consent
The key provision is that of informed choice: users cannot make an informed choice if:
- the cookie banner does not show, or is not otherwise legible (in a language that the user does not understand, covered by other page elements, etc.);
- the cookie banner does not either explicitly list all cookies currently used by your site (in the format outlined below) or, more commonly, contain a link to a page that does (Cookie Policy or Privacy Policy. We recommend having both, as their intent is often different);
- you place cookies that are not listed in the Cookie Policy;
- cookies are placed on the user's device prior to them explicitly accepting them.
The above does not apply to Essential Cookies, except that Essential Cookies should be listed in the Cookie Policy, and provide justification as to why they are essential (in the legal definition of the term). No tracking cookie is ever essential: a cookie for maintaining a user's login session is essential, for instance, but it would not be legal for that session cookie to act as a key for tracking user behaviour.
Essential Cookies
Cookies also serve useful purposes, such as:
- maintaining a "session key" which is required in order to allow users to log in to websites and portals;
- assigning unique security keys that protect user privacy by ensuring that users' form submissions are not hijacked by hackers;
- maintaining a server key so that, in multi-server environments, users are not randomly jumped between servers such that they are forced to repeatedly login.
These kinds of cookies are broadly known as "Essential Cookies", i.e. they are absolutely required in order to allow the operation of the application and to protect the privacy and data of users, and these have a special meaning with the UK GDPR.
How does this website use cookies?
By default, we use only one Essential Cookie, which is called JSESSIONID: this cookie is destroyed at the end of a user's session, i.e. when a user logs out and leaves the site, or after 20 minutes of inactivity on our site.
The cookies used by this website do not contain any of your personal information, and we cannot use them to find out who you are. We do not make any attempt to find out the identities of those visiting our website and do not track users across sites, and JSESSIONID does not enable any functionality except the three items listed above.
JSESSIONID is an Essential Cookie — it is absolutely required for the operation of the solution and for the protection of users' data and security. For this reason, it cannot be switched off and users cannot opt out.
We also use VOPECRA, a long-term non-tracking cookie that is only placed on the user's browser when the user accepts or declines cookies via the Cookie Banner: VOPECRA is the cookie that remembers the user's cookie preferences.
Finally, we may use a Firewall-generated session management cookie that maintains the user's context across multiple servers: this has the format TS0xxxxxxx. Once a user has made a cookie choice, the Firewall may generate a new session management cookie.
So, by default our site will have JSESSIONID and TS0xxxxxxx. Depending on configuration and user choices, VOPECRA, and a second TS0xxxxxxx may be used.
By moving further from the front page to other sections of the Trust website, you are consenting to the use of these cookies.
Third Party Cookies
Many organisations legitimately seek information on how people use their websites and digital solutions, so that they can genuinely improve their service to their users. We do this through two mechanisms:
- the ability to enter a Google Analytics (GA) ID at site level;
- the ability to enter any other third party code (which may or may not include cookies) through the Code Droplets Module.
You do not have to accept these cookies — in which case, you can press ‘Decline’. If you are happy to accept these cookies, however, then please press the ‘Accept optional cookies’ button.
Videos
We sometimes embed video content from websites such as YouTube. As a result, when you visit a page containing such content, you may be presented with cookies from these websites. The Trust does not control the dissemination of these cookies and you should check the relevant third party's website for more information.
Sharing content
You may also see embedded ‘share’ buttons on our web pages. These enable you to share content with your friends through popular social networks. When you click on one of these buttons, a cookie may be set by the service you have chosen to share content through. Again, the Trust does not control the dissemination of these cookies, and you are advised to check the relevant third party’s website for more information.
Google Maps
In addition, we sometimes embed content from Google Maps to help you plan a route to the location you need as easily as possible. As a result, when accessing Google Maps via this site, you may be presented with additional cookies. The Trust does not control the dissemination of these cookies and you should check the Google Maps website for more information.
Technical information
| Name | Duration | Function | Size |
| JSESSIONID | Session | Essential cookie for software functionality including session management for authentication, form submission validation, load-balancer configuration. Secured and does not track across websites (domain-specific). Expires at explicit session end (i.e. explicit log out) or 20 minutes of inactivity. | 44B |
| VOPECRA | Configurable duration | Remembers that a user has accepted or declined cookies from a specific website, enabling cookies from GA and Code Droplets (where configured). Secured and does not track across websites (domain-specific). Duration is configurable in VerseOne DXP (default is 6 months). | 8B |
| TS0xxxxxxx | Session | Essential cookie for maintaining context across multiple high-availability application servers and secure Web Application Firewall (WAF). Secured and does not track across websites (domain-specific). Expires at explicit session end (i.e. explicit log out) or 20 minutes of inactivity. | 116B |
Third party cookies
We use Google Analytics, a web analytics service, to help us improve:
- the information we publish
- your experience on our site
- our website's performance.
These cookies will be stored when you click accept cookies.
_ga, _ga_*, and ___utmvc
Google Analytics use these cookies to gather information about the way visitors use our site, which includes number of visitors, where visitors have come to the site from, and the pages they visit.
- _ga expires after two years.
- _ga_* expires after one year
- ___utmvc expires after two years.
Further information
If you have any further questions about how we protect the confidentiality of information that we hold about you, then contact our Information Governance Department at lg.ig@nhs.net.