Vivat Lex Web legal information
Cookie policy and consent information
Terms, policies and contact details for your use of Vivat Lex Web.
Business details
Trader, controller and contact
Trader and course provider: Stanislav Lynnyk, a sole trader trading as Vivat Lex.
Data controller: Stanislav Lynnyk, a sole trader trading as Vivat Lex.
Geographic business and address for service: 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom
Business telephone: +447442194285
Email for this document: sqe1practice@gmail.com
The SQE and SOLICITORS QUALIFYING EXAMINATION trade marks belong to the Solicitors Regulation Authority. References to SQE identify the assessment for which Vivat Lex provides independent preparation materials. Vivat Lex is not affiliated with, approved, endorsed or accredited by the Solicitors Regulation Authority.
Who we are
Vivat Lex Web is operated by Stanislav Lynnyk, a sole trader trading as Vivat Lex.
- Geographic business address
- 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom
- Address for service
- 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom
- Privacy email
- sqe1practice@gmail.com
- Telephone
- +447442194285
This policy applies only to Vivat Lex Web. It does not govern the separate iOS or Android products, and web privacy choices are not shared with either mobile product.
What this policy covers
Cookies and similar technologies include technologies that store information on, or access information from, a user’s device, including:
- Cookies.
- Local or session storage.
- IndexedDB and Cache Storage.
- Service-worker state.
- Pixels, tags and scripts.
- Link identifiers and navigational tracking.
- Embedded content.
- Device fingerprinting or combinations of device characteristics.
- Similar browser or device mechanisms.
The rules may apply even where the information is not personal data. Where personal data is processed, the Privacy Policy and applicable data-protection law also apply.
Current factual status
Public information and samples can be read without a paid course account. The sign-in, learning and checkout technologies described below apply only when the corresponding feature is available and you use it. The website does not enable optional advertising, audience-analytics or personalisation storage.
Vivat Lex application code does not write its own localStorage key. The two secure host cookies are used for requested sign-in and authenticated sessions. Two first-party sessionStorage technologies apply conditionally: a checkout-intent reference after accepted checkout creation, and an opaque unanswered-learning-attempt request handle after an answerable item is served. The learning technology may create separate bounded entries for a family and navigation reference. The Firebase SDK may use or probe browser storage for authentication, application integrity and the operational functions described below.
The inventory distinguishes the purpose and trigger of each technology. Vivat Lex sets the stated application-cookie and tab-session periods; provider-controlled storage follows the expiry or clearing rules stated for that provider.
Categories
Each technology is classified by its exact purpose and behaviour, not by a provider label.
Strictly necessary technologies
A technology is treated as strictly necessary only where its sole purpose is technically essential, from the user’s perspective, to transmit a communication or provide a service or feature the user requested.
Commercial convenience, revenue protection, general product improvement, analytics, advertising or a provider’s security label is not enough. The table below describes the purpose and trigger for each listed necessary technology.
Necessary is not a consent category. Users receive clear information, but the interface does not imply that they consented to necessary processing.
Optional analytics
Optional analytics remains off unless the user gives the required valid consent. It does not include advertising measurement, cross-service tracking, individual session replay, behavioural profiling or an undisclosed secondary purpose.
Optional personalisation
Optional personalisation remains off unless valid consent covers the exact purpose, information and recipients. A technology used only to remember a feature or appearance choice actively requested by the user is assessed separately; an exception is not assumed.
Optional advertising
Advertising, retargeting, attribution, conversion measurement, advertising profiling and related storage or access remain off unless valid consent and all territorial and provider approvals apply. Advertising is not strictly necessary merely because it funds a service.
This category is not presented as active where no verified advertising technology exists.
Narrow UK statistical or appearance exceptions
UK law includes limited exceptions for certain aggregate service-improvement statistics and certain appearance or functionality purposes, subject to strict conditions, clear information and a simple free objection mechanism.
Vivat Lex relies on such an exception only where:
- The exact technology has a legal and technical assessment.
- Its sole purpose satisfies every condition.
- No individual tracking, profiling, advertising or secondary use occurs.
- Any provider acts only in the stated role and does not combine or reuse the information.
- The objection mechanism is implemented and tested.
- The public table is complete.
- Regional enforcement prevents a UK exception from being applied in the EU, EEA or another incompatible jurisdiction.
Unless an approved entry appears below, the exception is not relied on and its feature remains disabled.
Your choices
Where at least one optional technology is configured, the first layer provides equally accessible and comparably prominent actions:
- Reject all optional.
- Customise.
- Accept all optional.
All optional categories are off by default. Silence, continued browsing, scrolling, closing a notice, accepting Terms, creating an account or making a payment does not activate optional technology.
Settings allow separate choices for analytics, personalisation and advertising and, where required for informed consent, provider-level control for distinct third parties. A persistent Manage privacy choices control is available from every page once a choice mechanism exists. Withdrawal or rejection is as easy as acceptance.
If the verified inventory contains no optional technology and no approved objection-based UK exception, Vivat Lex does not display a performative consent banner merely to obtain apparent agreement. Necessary-technology information remains available.
Global Privacy Control
Vivat Lex does not claim that Global Privacy Control is implemented unless the current interface and production behaviour support that statement.
Where GPC is implemented and applies:
- A positive GPC signal is treated as a privacy-protective opt-out signal, not consent.
- It denies advertising and cross-context personalisation and, under the conservative rule, optional analytics.
- A stored grant does not override a current positive signal.
- Absence of GPC communicates nothing and does not reactivate optional processing.
- The exact server and client behaviour is tested before a public claim is made.
The W3C GPC specification is a developing standard and its legal effect differs by jurisdiction; applicable country rules continue to apply.
Browser controls
Browser controls may allow deletion or blocking of site data. Blocking a genuinely necessary technology may prevent the requested feature from working.
Browser settings are supplementary. Ordinary defaults or the absence of a privacy signal are not treated as consent.
Third parties
Every third party that receives information through a storage or access technology is identified before consent with its legal name, exact purpose, information, duration and role. An open-ended reference to analytics or advertising partners is not sufficient.
A third party is introduced only after its contract, secondary use, sub-processors, retention, withdrawal and deletion behaviour and transfer position are reflected in this policy and the Privacy Policy.
International transfers
The Privacy Policy explains international processing and how to request information or a copy of the safeguards relevant to your data. A technology being listed here does not mean that every provider processes data in the UK.
Duration
Every technology table states an actual session rule, expiry or maximum lifetime. “Persistent” is not a sufficient duration.
Where a stored acceptance, rejection or objection preference is used, its disclosed maximum applies fairly to both acceptance and rejection and does not exceed six calendar months. A rejection does not expire sooner in order to create repeated pressure.
Changes and fresh choices
A material change to a purpose, category, provider, information, retention or consequence is not covered automatically by an earlier grant. Changed optional technology remains blocked until updated information and a fresh choice are provided where required.
A minor grammar or contact correction that does not affect processing need not trigger a new consent decision, but the change assessment is recorded.
Contact and complaints
Questions or complaints may be sent to sqe1practice@gmail.com, made by telephone at +447442194285 or posted to 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom. Privacy complaint duties and applicable supervisory-authority rights remain as described in the Privacy Policy.
Technology inventory
The following entries describe the technologies used by the corresponding website features, their purposes and when they are triggered. An unavailable feature does not become active merely because its technology is listed here. Optional categories remain empty while those technologies are disabled.
Strictly necessary
| Name/key | Type | Host/domain | Provider | Exact sole purpose | Trigger | Information | Duration | PECR route | UK GDPR basis if applicable | Recipients/transfers |
|---|---|---|---|---|---|---|---|---|---|---|
| __Host-vl_pre | First-party Secure, HttpOnly, SameSite=Lax host cookie | Current Vivat Lex Web host | Vivat Lex | Keep one short-lived sign-in attempt bound to its server-side anti-forgery and security state. | A visitor starts a protected sign-in flow. | Opaque random handle only; it does not contain an email address, provider token or entitlement. | 15 minutes | Strictly necessary to provide the secure sign-in requested by the visitor. | Legitimate interests: authentication security and abuse prevention. | Vivat Lex and its standalone-web Google Cloud hosting and database services; provider safeguards apply to any international transfer. |
| __Host-vl_sid | First-party Secure, HttpOnly, SameSite=Lax host cookie | Current Vivat Lex Web host | Vivat Lex | Maintain the authenticated web session that the visitor requested and enforce server-side revocation. | A sign-in succeeds. | Opaque random session handle only; identity and entitlement evidence remain server-side. | 12 hours, or earlier logout or revocation | Strictly necessary to provide the signed-in service requested by the visitor. | Contract steps and performance; legitimate interests in session security. | Vivat Lex and its standalone-web Google Cloud hosting and database services; provider safeguards apply to any international transfer. |
| Firebase Authentication temporary user state | Application-requested browser-memory persistence; the Firebase SDK may also probe first-party IndexedDB, localStorage or sessionStorage during initialisation | Current Vivat Lex Web origin and its standalone Firebase authentication handler | Google Firebase Authentication, for Vivat Lex | Complete a Google sign-in, or Apple sign-in if offered, and exchange the temporary provider credential for the Vivat Lex server session. | The visitor chooses an available Google sign-in, or Apple if offered, after the anti-bot check; the email one-time-code flow does not use browser Firebase Authentication. | Temporary Firebase user and provider response. The SDK may also maintain auxiliary operational storage, as described in the Firebase entries below. | Vivat Lex requests memory persistence and signs the temporary Firebase user out after server exchange; auxiliary SDK storage is provider-controlled | Strictly necessary to provide the available sign-in method selected by the visitor. | Contract steps; legitimate interests in authentication security. | Google Cloud acts under the applicable data-processing terms; provider safeguards apply to any international transfer. |
| firebase-app-check-database / firebase-app-check-store | First-party origin-scoped IndexedDB token cache | Current Vivat Lex Web origin | Google Firebase App Check, for Vivat Lex | Cache the application-attestation token needed to protect authentication and private-learning requests. | Opening enabled sign-in or entitled Learning requests App Check; automatic token refresh is enabled. | Attestation token with provider-returned issue and expiry times; no course answer or payment-card data. | Until the expiry time supplied by Google, with automatic refresh while the protected feature is in use. Expiry is determined by the token returned by the provider. | Strictly necessary to protect the requested authenticated or private-learning service. | Legitimate interests: application integrity, fraud and abuse prevention. | Google Cloud processes the attestation for Vivat Lex under Google Cloud terms; provider safeguards apply to any international transfer. |
| _GRECAPTCHA | Google-documented necessary third-party cookie when reCAPTCHA risk analysis executes; its domain, path and expiry are controlled by Google | Google reCAPTCHA domains used by the deployed App Check integration | Google Cloud reCAPTCHA Enterprise, for Vivat Lex | Assess application and automated-abuse risk so Firebase App Check can attest protected requests. | Firebase App Check executes reCAPTCHA Enterprise for a new or refreshed attestation. | Browser, device and interaction signals used for security, fraud and abuse prevention. | Provider-controlled; Google publishes no fixed cookie lifetime in its reCAPTCHA service FAQ at the verification date | Google documents this cookie as necessary for the requested risk analysis and security service. | Legitimate interests: application integrity, fraud and abuse prevention. | Google Cloud processes reCAPTCHA customer data for Vivat Lex under Google Cloud terms; provider safeguards apply to any international transfer. |
| firebase-heartbeat-database / firebase-heartbeat-store | First-party origin-scoped IndexedDB operational store | Current Vivat Lex Web origin | Google Firebase core SDK, for Vivat Lex | Retain dated Firebase SDK/version heartbeat metadata so required Firebase requests carry a compatible X-Firebase-Client header. | The application accesses Firebase Authentication or App Check. | UTC date and Firebase SDK/platform version string; not course progress, identity content or advertising data. | Sent entries are cleared; at most 30 dated entries are retained; the database and last-sent date may remain until site data is cleared | Treated as technically inherent operational metadata for the requested Firebase-backed sign-in and application-integrity service, not optional audience analytics. | Legitimate interests: provider compatibility, security and fault diagnosis. | Google Firebase receives the heartbeat header under Google Cloud terms; provider safeguards apply to any international transfer. |
| Cloudflare Turnstile challenge token | Short-lived single-use third-party widget token; the tested widget has no pre-clearance and therefore does not issue cf_clearance through that feature | challenges.cloudflare.com and the current Vivat Lex Web page | Cloudflare Turnstile, for Vivat Lex | Check that a sign-in bootstrap is not automated before the server accepts it. | Opening enabled sign-in renders the security widgets; requesting an email code or selecting an available Google sign-in, or Apple if offered, sends the returned token to server-side Siteverify. | Challenge result and browser/network signals used for security and bot detection; Vivat Lex sends the token to Cloudflare Siteverify. | 5 minutes; single use | Strictly necessary to protect the visitor's requested sign-in flow from automated abuse. | Legitimate interests: service security and abuse prevention. | Cloudflare processes the validation request under its applicable data-processing terms; provider safeguards apply to any international transfer. |
| vivatLexCheckoutIntentId | First-party sessionStorage key; conditional and set only after the server accepts checkout creation | Current Vivat Lex Web origin | Vivat Lex | Reconnect the checkout processing/status page to the server-owned checkout intent; this browser value is not payment or entitlement authority. | Only after Vivat Lex accepts the checkout request and returns a valid checkout reference. | Opaque Vivat Lex checkout-intent identifier. | Current browser-tab session. The application removes an invalid reference; removes it after a failed, payment-resolved-without-contract, expired, suspended or revoked outcome; or removes it after paid active or scheduled status, receipt and reconciliation are all confirmed. A refund-pending or otherwise unresolved status reference remains until the tab or window closes or site data is cleared. | Strictly necessary to provide the checkout status flow requested by the visitor once checkout is enabled. | Contract steps and performance; legitimate interests in reliable payment-status handling. | Vivat Lex and its standalone-web Google Cloud hosting and database services; the identifier is resolved only against server-side Commerce records under the provider safeguards described in the Privacy Policy. |
| vivatLexLearningAttemptRequest:v1:* | First-party sessionStorage key family; conditional and set only for an answerable private-learning item | Current Vivat Lex Web origin | Vivat Lex | Restore the same unanswered learning item after a page reload, without counting it twice or duplicating progress. | Only after the server successfully serves an answerable private-learning item with an attempt identifier. | A random, pseudonymous opaque request identifier. The storage-key suffix contains a protected learning-format family identifier (a separate axis from the twelve FLK1 and FLK2 course subjects) and either an opaque navigation cursor or the word ‘first’. The value and key contain no course body, question, answer, explanation, name, email, contact detail, payment value, entitlement identifier, release content or progress count; the opaque handle may be linkable to protected server records. | Current browser-tab session. The application removes the relevant handle after a successful answer, invalid or conflicting-request recovery, or successful logout; otherwise the browser clears it when the tab or window closes or site data is cleared. | Strictly necessary for the visitor-requested function of restoring an unanswered private-learning item after reload, idempotent item opening and accurate progress. Course access authority does not rely on this browser value. | Contract performance; legitimate interests in reliable private-learning delivery and progress integrity. | Vivat Lex and its standalone-web Google Cloud hosting and database services; the reference is matched only to protected learning records and is accepted only while the signed-in account, device, course access, current course item and active learning session are valid. |
Optional analytics
| Name/key | Type | Host/domain | Provider | Exact purpose | Trigger | Information | Duration | Consent category | Recipients/transfers | Last verified |
|---|
No optional analytics entry is active unless listed here and valid choice controls are operating.
Optional personalisation
| Name/key | Type | Host/domain | Provider | Exact purpose | Trigger | Information | Duration | Consent category | Recipients/transfers | Last verified |
|---|
No optional personalisation entry is active unless listed here and valid choice controls are operating.
Optional advertising
| Name/key | Type | Host/domain | Provider | Exact purpose | Trigger | Information | Duration | Consent category | Recipients/transfers | Last verified |
|---|
No optional advertising entry is active unless listed here and valid choice controls are operating.
Approved UK statistical-purpose exception
| Name/key | Type | Host/domain | Provider | Sole aggregate-improvement purpose | Aggregation/deletion point | Objection control | Duration | Provider role | Transfers | Assessment reference | Last verified |
|---|
No UK statistical-purpose exception is relied on unless an approved entry appears here.
Approved UK appearance or functionality exception
| Name/key | Type | Host/domain | Provider | Sole appearance/function purpose | Information | Objection control | Duration | Secondary-use controls | Transfers | Assessment reference | Last verified |
|---|
No UK appearance or functionality exception is relied on unless an approved entry appears here.
Version and effective date
- Document version
- 2026-09-12.5
- Effective and last reviewed
- 12 September 2026
The version accepted at checkout is recorded with the order and forms part of the customer's durable confirmation. A later publication does not retrospectively replace that accepted version or reduce any mandatory consumer right.
Legal information