Cookie Policy

Learn how cookies and similar technologies may be used on this website.

1. Introduction

This Cookie Policy explains how cookies and similar technologies may be used when you visit or use a website.

It explains:

  • what cookies are;
  • why cookies may be used;
  • the categories of cookies and similar technologies that may be used;
  • when consent may be required;
  • how third-party technologies may operate;
  • how long cookies may remain;
  • how you can manage your preferences; and
  • how to obtain further information about cookies.

This Cookie Policy should be read together with the applicable Privacy Policy.

2. What Is a Cookie?

A cookie is a small file or piece of information placed on or accessed from a device when a person visits a website.

Cookies can allow a website or service provider to recognise a device, remember information or support functions such as:

  • authentication;
  • security;
  • session management;
  • preferences;
  • analytics;
  • fraud prevention;
  • payment processing; and
  • advertising.

Cookies may contain or be associated with identifiers that can constitute personal information under applicable data-protection law.

3. Similar Technologies

This Policy also applies, where appropriate, to technologies that perform similar functions, including:

  • browser local storage;
  • session storage;
  • software development kit identifiers;
  • pixels;
  • tags;
  • tracking scripts;
  • device identifiers;
  • embedded third-party technologies; and
  • other technologies that store information on or access information from a user's device.

For simplicity, all such technologies may be referred to collectively as "cookies" in this Policy.

4. First-Party and Third-Party Cookies

First-party cookies

First-party cookies are set or accessed by the website being visited or by technology operating directly for that website.

They may support functions such as account security, preferences and website operation.

Third-party cookies

Third-party cookies are set or accessed by another organisation whose technology is integrated into a website.

Depending on the website's technology configuration, third parties may include providers supporting:

  • payments;
  • authentication;
  • website hosting;
  • analytics;
  • fraud prevention;
  • customer communications;
  • embedded media;
  • maps;
  • support tools; or
  • advertising.

Third-party providers may process information according to their own privacy policies.

5. Session and Persistent Cookies

Session cookies

Session cookies normally expire when you close your browser or end a browsing session.

They may be used for functions such as:

  • maintaining secure sessions;
  • navigating multi-step forms; or
  • preserving temporary application state.

Persistent cookies

Persistent cookies remain on a device for a specified period or until deleted.

They may be used to:

  • remember preferences;
  • recognise returning devices;
  • remember cookie choices; or
  • support approved analytics or other functions.

6. Categories of Cookies That May Be Used

6.1 Strictly Necessary Cookies

These technologies are required for a website or a service requested by the user to function securely and correctly.

They may support:

  • account login;
  • authentication;
  • fraud prevention;
  • website security;
  • application-form functionality;
  • session management;
  • load balancing;
  • payment-session functionality;
  • cookie-preference storage; and
  • protection against malicious activity.

Where applicable cookie law provides an exemption for technologies strictly necessary to provide a service requested by the user, these technologies may be used without optional consent.

They cannot normally be disabled through a cookie-preference centre because doing so may prevent essential features from working.

6.2 Functional Cookies

Functional cookies may remember optional user choices and enhance usability.

They may support:

  • language preferences;
  • interface settings;
  • remembered display preferences;
  • optional customer-support features; and
  • other convenience functions.

Where required by applicable law, these technologies will not be activated without appropriate consent.

6.3 Analytics and Performance Cookies

Analytics technologies may help understand:

  • how many people visit a website;
  • which pages are used;
  • how visitors navigate;
  • approximate traffic sources;
  • website performance;
  • errors;
  • loading times; and
  • which functions require improvement.

Analytics information may include:

  • device type;
  • browser information;
  • approximate location;
  • page views;
  • referral source;
  • event data;
  • session-related information; and
  • technical identifiers.

Where applicable law requires consent for analytics technologies, they will remain disabled until consent is provided.

6.4 Security and Fraud-Prevention Technologies

Security technologies may help:

  • detect suspicious logins;
  • prevent automated abuse;
  • identify fraudulent transactions;
  • prevent malicious requests;
  • protect uploaded documents;
  • maintain session integrity; and
  • defend a website against cyberattacks.

Some security technologies may qualify as strictly necessary depending on their exact function.

6.5 Payment Technologies

When payment functionality is used, a payment provider may set or access cookies or similar technologies to:

  • establish a payment session;
  • authenticate transactions;
  • prevent fraud;
  • process payments;
  • manage risk;
  • remember relevant payment states; or
  • satisfy security requirements.

Some payment technologies may be strictly necessary for a payment requested by the user, while others may require consent depending on their function and applicable law.

The payment provider's own cookie and privacy policies may also apply.

6.6 Customer-Support and Communication Technologies

If a website integrates live chat, messaging tools or support platforms, those providers may set or access technologies when the relevant service is used or loaded.

Where required, optional technologies will be subject to the appropriate consent settings.

6.7 Advertising and Marketing Cookies

If advertising or remarketing technologies are used, these may be used to:

  • measure advertising effectiveness;
  • attribute enquiries to campaigns;
  • create advertising audiences;
  • limit repeated advertisements; or
  • display advertising based on user interactions.

Advertising and behavioural-tracking cookies will be treated as optional where applicable law requires consent.

They should not be enabled before the required consent has been provided.

7. Cookies That May Not Require Consent

Depending on applicable law, consent may not be required for technology that is genuinely necessary to:

  • transmit communications;
  • secure an online service requested by the user;
  • maintain authentication;
  • keep an application form working;
  • remember items during a transactional process;
  • process a requested payment;
  • remember cookie preferences; or
  • provide another essential website function.

Whether a technology is "strictly necessary" depends on what it actually does, not simply whether it is useful.

8. Consent

Where applicable law requires consent before a non-essential cookie or similar technology is used, an appropriate choice should be obtained before activating that technology.

Valid consent should be:

  • freely given;
  • informed;
  • specific;
  • based on a clear affirmative action; and
  • capable of being withdrawn.

Simply continuing to browse a website should not be treated as consent where applicable law requires an affirmative action.

9. Cookie Banner

Where required, visitors should be presented with a cookie-management interface.

A recommended initial banner structure is:

We use necessary cookies to keep this website secure and functional. With your permission, we may also use analytics and other optional technologies to understand website usage and improve the website. You can accept optional cookies, reject them or manage your preferences.

The banner should provide equally accessible options such as:

Accept Optional Cookies

Reject Optional Cookies

Manage Preferences

Strictly necessary technologies may remain active.

10. No Pre-Enabled Optional Categories

Where consent is required, optional categories should not be enabled by default.

For example, the following should normally remain off until consent is provided where applicable law requires it:

  • analytics;
  • advertising;
  • behavioural tracking;
  • non-essential third-party integrations; and
  • optional marketing measurement.

11. Cookie Preference Centre

Where available, a cookie-preference centre should allow users to:

  • see categories of cookies;
  • understand their purposes;
  • enable optional categories;
  • disable optional categories;
  • change previous choices; and
  • withdraw consent.

The preference centre should remain reasonably accessible after the initial banner has disappeared.

A footer link such as:

Cookie Settings

is recommended.

12. Withdrawing Consent

You may withdraw optional-cookie consent at any time through the available cookie settings.

Withdrawal will prevent future optional use covered by that consent.

It does not necessarily remove data previously lawfully collected.

You may also delete existing cookies through your browser settings.

13. Browser Controls

Most browsers allow users to:

  • view cookies;
  • delete cookies;
  • block cookies;
  • block third-party cookies;
  • clear site data;
  • disable storage;
  • control tracking settings; or
  • browse using a private mode.

Browser controls vary.

Blocking all cookies may cause functions such as login, application forms or payment sessions to stop working correctly.

14. Analytics

If analytics services are used, an assessment should determine whether those services use:

  • cookies;
  • local storage;
  • fingerprinting;
  • unique identifiers; or
  • cookie-free measurement.

A provider describing a service as "analytics" does not automatically make it strictly necessary.

Where applicable law requires consent for the analytics configuration in use, analytics will be disabled until the appropriate consent is obtained.

15. Payment Providers

Payment providers may use security, fraud-prevention and transaction technologies when you initiate a payment.

Because the precise technologies used may depend on the provider, browser, location and payment method, you should also review the payment provider's privacy and cookie information.

Material payment-related third parties should be identified where required.

16. Authentication Technologies

If account authentication is provided through a third-party technology, information may be stored or accessed on your device to:

  • keep you signed in;
  • verify your session;
  • prevent account takeover;
  • support multi-factor authentication; or
  • maintain secure application state.

Technologies essential to secure an authentication service requested by you may qualify as strictly necessary.

Any optional analytics or marketing capability provided by the same supplier should be assessed separately.

17. Local Storage and Session Storage

A website may use browser local storage or session storage instead of, or in addition to, traditional cookies.

These technologies may store information such as:

  • session state;
  • form progress;
  • authentication state;
  • preferences; or
  • consent choices.

Cookie and privacy requirements may apply to these technologies even though they are not technically cookies.

18. Application Forms

An application process may use necessary browser technologies to:

  • move between application steps;
  • remember temporary form state;
  • maintain a secure session;
  • prevent duplicate submissions; or
  • associate uploaded information with the correct account or application.

Where such technology is essential to a service actively requested by the applicant, it may be classified as strictly necessary.

19. Embedded Content

Web pages may include content from another provider, such as:

  • video;
  • maps;
  • social media;
  • scheduling systems;
  • payment interfaces; or
  • live-chat tools.

That provider may place or access cookies.

Where the embedded service uses non-essential technologies requiring consent, the service may be blocked or delayed until the user has consented.

20. Advertising and Conversion Tracking

If advertising technologies such as advertising pixels or conversion-tracking tags are introduced, this Cookie Policy should be updated.

Where required by applicable law, such technologies will not operate until the user has provided the appropriate consent.

Rejecting advertising cookies should not prevent access to the core website or ordinary services.

21. Do Not Sell Personal Information

Website visitor information is not sold to data brokers or advertisers merely through the use of cookies.

If a business model or legal obligation in a particular jurisdiction requires additional disclosures relating to "sale", "sharing" or targeted advertising, those disclosures and controls should be provided where applicable.

22. Sensitive Information

Where services involve sensitive application information, including identity, licensing or health-related documents, sensitive uploaded document content should not intentionally be used for behavioural advertising.

Uploaded application documents should not be used to create advertising profiles.

23. Retention

Cookie identifiers should not be retained longer than reasonably necessary for their stated purpose.

Retention depends on the technology, including whether it is:

  • session-based;
  • authentication-related;
  • preference-related;
  • analytics-related; or
  • set by a third party.

24. Third-Party Retention

Third-party cookie durations and subsequent processing may be determined by the third-party provider.

Where required, information identifying relevant providers should be provided so users can review their policies.

25. International Processing

Cookie and analytics providers may process information in countries other than the country from which you access a website.

Where cookie-derived information constitutes personal data, international processing should be addressed in the applicable Privacy Policy and subject to data-protection requirements.

26. Security

Reasonable technical and organisational measures should be used to protect information generated through a website.

However, no internet-based system can be guaranteed to be completely secure.

27. Children's Data

Professional and licensing websites are generally intended for adults.

Advertising technologies should not intentionally be used to profile children through such websites.

28. Changes to Cookie Use

The technologies used by a website may change as:

  • features are added;
  • providers change;
  • payment systems change;
  • analytics tools change;
  • security requirements change; or
  • applicable law develops.

Cookie configurations should be reviewed periodically.

Where a material change affects optional technologies, this Policy should be updated and fresh consent should be obtained where required.

29. Changes to This Cookie Policy

This Cookie Policy may be updated from time to time.

The most recent revision date appears at the top and bottom of this page.

Users are encouraged to review the Policy periodically.

30. Privacy Policy

For information about:

  • personal data collected through a website;
  • why it is processed;
  • who it is shared with;
  • international transfers;
  • retention;
  • security; and
  • privacy rights,

please review the applicable Privacy Policy.

31. Contact

Questions or requests concerning cookies or website privacy should be directed through the contact details made available on the relevant website.


Last Updated: 11 September 2026