Skip to main content

Vivat Lex Web legal information

Cookie policy and consent information

Terms, policies and contact details for your use of Vivat Lex Web.

Business details

Trader, controller and contact

Trader and course provider: Stanislav Lynnyk, a sole trader trading as Vivat Lex.

Data controller: Stanislav Lynnyk, a sole trader trading as Vivat Lex.

Geographic business and address for service: 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom

Business telephone: +447442194285

Email for this document: sqe1practice@gmail.com

The SQE and SOLICITORS QUALIFYING EXAMINATION trade marks belong to the Solicitors Regulation Authority. References to SQE identify the assessment for which Vivat Lex provides independent preparation materials. Vivat Lex is not affiliated with, approved, endorsed or accredited by the Solicitors Regulation Authority.

Who we are

Vivat Lex Web is operated by Stanislav Lynnyk, a sole trader trading as Vivat Lex.

Geographic business address
32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom
Address for service
32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom
Privacy email
sqe1practice@gmail.com
Telephone
+447442194285

This policy applies only to Vivat Lex Web. It does not govern the separate iOS or Android products, and web privacy choices are not shared with either mobile product.

What this policy covers

Cookies and similar technologies include technologies that store information on, or access information from, a user’s device, including:

  • Cookies.
  • Local or session storage.
  • IndexedDB and Cache Storage.
  • Service-worker state.
  • Pixels, tags and scripts.
  • Link identifiers and navigational tracking.
  • Embedded content.
  • Device fingerprinting or combinations of device characteristics.
  • Similar browser or device mechanisms.

The rules may apply even where the information is not personal data. Where personal data is processed, the Privacy Policy and applicable data-protection law also apply.

Current factual status

Public information and samples can be read without a paid course account. The sign-in, learning and checkout technologies described below apply only when the corresponding feature is available and you use it. The website does not enable optional advertising, audience-analytics or personalisation storage.

Vivat Lex application code does not write its own localStorage key. The two secure host cookies are used for requested sign-in and authenticated sessions. Two first-party sessionStorage technologies apply conditionally: a checkout-intent reference after accepted checkout creation, and an opaque unanswered-learning-attempt request handle after an answerable item is served. The learning technology may create separate bounded entries for a family and navigation reference. The Firebase SDK may use or probe browser storage for authentication, application integrity and the operational functions described below.

The inventory distinguishes the purpose and trigger of each technology. Vivat Lex sets the stated application-cookie and tab-session periods; provider-controlled storage follows the expiry or clearing rules stated for that provider.

Categories

Each technology is classified by its exact purpose and behaviour, not by a provider label.

Strictly necessary technologies

A technology is treated as strictly necessary only where its sole purpose is technically essential, from the user’s perspective, to transmit a communication or provide a service or feature the user requested.

Commercial convenience, revenue protection, general product improvement, analytics, advertising or a provider’s security label is not enough. The table below describes the purpose and trigger for each listed necessary technology.

Necessary is not a consent category. Users receive clear information, but the interface does not imply that they consented to necessary processing.

Optional analytics

Optional analytics remains off unless the user gives the required valid consent. It does not include advertising measurement, cross-service tracking, individual session replay, behavioural profiling or an undisclosed secondary purpose.

Optional personalisation

Optional personalisation remains off unless valid consent covers the exact purpose, information and recipients. A technology used only to remember a feature or appearance choice actively requested by the user is assessed separately; an exception is not assumed.

Optional advertising

Advertising, retargeting, attribution, conversion measurement, advertising profiling and related storage or access remain off unless valid consent and all territorial and provider approvals apply. Advertising is not strictly necessary merely because it funds a service.

This category is not presented as active where no verified advertising technology exists.

Narrow UK statistical or appearance exceptions

UK law includes limited exceptions for certain aggregate service-improvement statistics and certain appearance or functionality purposes, subject to strict conditions, clear information and a simple free objection mechanism.

Vivat Lex relies on such an exception only where:

  • The exact technology has a legal and technical assessment.
  • Its sole purpose satisfies every condition.
  • No individual tracking, profiling, advertising or secondary use occurs.
  • Any provider acts only in the stated role and does not combine or reuse the information.
  • The objection mechanism is implemented and tested.
  • The public table is complete.
  • Regional enforcement prevents a UK exception from being applied in the EU, EEA or another incompatible jurisdiction.

Unless an approved entry appears below, the exception is not relied on and its feature remains disabled.

Your choices

Where at least one optional technology is configured, the first layer provides equally accessible and comparably prominent actions:

  • Reject all optional.
  • Customise.
  • Accept all optional.

All optional categories are off by default. Silence, continued browsing, scrolling, closing a notice, accepting Terms, creating an account or making a payment does not activate optional technology.

Settings allow separate choices for analytics, personalisation and advertising and, where required for informed consent, provider-level control for distinct third parties. A persistent Manage privacy choices control is available from every page once a choice mechanism exists. Withdrawal or rejection is as easy as acceptance.

If the verified inventory contains no optional technology and no approved objection-based UK exception, Vivat Lex does not display a performative consent banner merely to obtain apparent agreement. Necessary-technology information remains available.

Global Privacy Control

Vivat Lex does not claim that Global Privacy Control is implemented unless the current interface and production behaviour support that statement.

Where GPC is implemented and applies:

  • A positive GPC signal is treated as a privacy-protective opt-out signal, not consent.
  • It denies advertising and cross-context personalisation and, under the conservative rule, optional analytics.
  • A stored grant does not override a current positive signal.
  • Absence of GPC communicates nothing and does not reactivate optional processing.
  • The exact server and client behaviour is tested before a public claim is made.

The W3C GPC specification is a developing standard and its legal effect differs by jurisdiction; applicable country rules continue to apply.

Browser controls

Browser controls may allow deletion or blocking of site data. Blocking a genuinely necessary technology may prevent the requested feature from working.

Browser settings are supplementary. Ordinary defaults or the absence of a privacy signal are not treated as consent.

Third parties

Every third party that receives information through a storage or access technology is identified before consent with its legal name, exact purpose, information, duration and role. An open-ended reference to analytics or advertising partners is not sufficient.

A third party is introduced only after its contract, secondary use, sub-processors, retention, withdrawal and deletion behaviour and transfer position are reflected in this policy and the Privacy Policy.

International transfers

The Privacy Policy explains international processing and how to request information or a copy of the safeguards relevant to your data. A technology being listed here does not mean that every provider processes data in the UK.

Duration

Every technology table states an actual session rule, expiry or maximum lifetime. “Persistent” is not a sufficient duration.

Where a stored acceptance, rejection or objection preference is used, its disclosed maximum applies fairly to both acceptance and rejection and does not exceed six calendar months. A rejection does not expire sooner in order to create repeated pressure.

Changes and fresh choices

A material change to a purpose, category, provider, information, retention or consequence is not covered automatically by an earlier grant. Changed optional technology remains blocked until updated information and a fresh choice are provided where required.

A minor grammar or contact correction that does not affect processing need not trigger a new consent decision, but the change assessment is recorded.

Contact and complaints

Questions or complaints may be sent to sqe1practice@gmail.com, made by telephone at +447442194285 or posted to 32/1 Tudsbery Avenue, Edinburgh, EH16 4GX, United Kingdom. Privacy complaint duties and applicable supervisory-authority rights remain as described in the Privacy Policy.

Technology inventory

The following entries describe the technologies used by the corresponding website features, their purposes and when they are triggered. An unavailable feature does not become active merely because its technology is listed here. Optional categories remain empty while those technologies are disabled.

Strictly necessary

Name/keyTypeHost/domainProviderExact sole purposeTriggerInformationDurationPECR routeUK GDPR basis if applicableRecipients/transfers
__Host-vl_preFirst-party Secure, HttpOnly, SameSite=Lax host cookieCurrent Vivat Lex Web hostVivat LexKeep one short-lived sign-in attempt bound to its server-side anti-forgery and security state.A visitor starts a protected sign-in flow.Opaque random handle only; it does not contain an email address, provider token or entitlement.15 minutesStrictly necessary to provide the secure sign-in requested by the visitor.Legitimate interests: authentication security and abuse prevention.Vivat Lex and its standalone-web Google Cloud hosting and database services; provider safeguards apply to any international transfer.
__Host-vl_sidFirst-party Secure, HttpOnly, SameSite=Lax host cookieCurrent Vivat Lex Web hostVivat LexMaintain the authenticated web session that the visitor requested and enforce server-side revocation.A sign-in succeeds.Opaque random session handle only; identity and entitlement evidence remain server-side.12 hours, or earlier logout or revocationStrictly necessary to provide the signed-in service requested by the visitor.Contract steps and performance; legitimate interests in session security.Vivat Lex and its standalone-web Google Cloud hosting and database services; provider safeguards apply to any international transfer.
Firebase Authentication temporary user stateApplication-requested browser-memory persistence; the Firebase SDK may also probe first-party IndexedDB, localStorage or sessionStorage during initialisationCurrent Vivat Lex Web origin and its standalone Firebase authentication handlerGoogle Firebase Authentication, for Vivat LexComplete a Google sign-in, or Apple sign-in if offered, and exchange the temporary provider credential for the Vivat Lex server session.The visitor chooses an available Google sign-in, or Apple if offered, after the anti-bot check; the email one-time-code flow does not use browser Firebase Authentication.Temporary Firebase user and provider response. The SDK may also maintain auxiliary operational storage, as described in the Firebase entries below.Vivat Lex requests memory persistence and signs the temporary Firebase user out after server exchange; auxiliary SDK storage is provider-controlledStrictly necessary to provide the available sign-in method selected by the visitor.Contract steps; legitimate interests in authentication security.Google Cloud acts under the applicable data-processing terms; provider safeguards apply to any international transfer.
firebase-app-check-database / firebase-app-check-storeFirst-party origin-scoped IndexedDB token cacheCurrent Vivat Lex Web originGoogle Firebase App Check, for Vivat LexCache the application-attestation token needed to protect authentication and private-learning requests.Opening enabled sign-in or entitled Learning requests App Check; automatic token refresh is enabled.Attestation token with provider-returned issue and expiry times; no course answer or payment-card data.Until the expiry time supplied by Google, with automatic refresh while the protected feature is in use. Expiry is determined by the token returned by the provider.Strictly necessary to protect the requested authenticated or private-learning service.Legitimate interests: application integrity, fraud and abuse prevention.Google Cloud processes the attestation for Vivat Lex under Google Cloud terms; provider safeguards apply to any international transfer.
_GRECAPTCHAGoogle-documented necessary third-party cookie when reCAPTCHA risk analysis executes; its domain, path and expiry are controlled by GoogleGoogle reCAPTCHA domains used by the deployed App Check integrationGoogle Cloud reCAPTCHA Enterprise, for Vivat LexAssess application and automated-abuse risk so Firebase App Check can attest protected requests.Firebase App Check executes reCAPTCHA Enterprise for a new or refreshed attestation.Browser, device and interaction signals used for security, fraud and abuse prevention.Provider-controlled; Google publishes no fixed cookie lifetime in its reCAPTCHA service FAQ at the verification dateGoogle documents this cookie as necessary for the requested risk analysis and security service.Legitimate interests: application integrity, fraud and abuse prevention.Google Cloud processes reCAPTCHA customer data for Vivat Lex under Google Cloud terms; provider safeguards apply to any international transfer.
firebase-heartbeat-database / firebase-heartbeat-storeFirst-party origin-scoped IndexedDB operational storeCurrent Vivat Lex Web originGoogle Firebase core SDK, for Vivat LexRetain dated Firebase SDK/version heartbeat metadata so required Firebase requests carry a compatible X-Firebase-Client header.The application accesses Firebase Authentication or App Check.UTC date and Firebase SDK/platform version string; not course progress, identity content or advertising data.Sent entries are cleared; at most 30 dated entries are retained; the database and last-sent date may remain until site data is clearedTreated as technically inherent operational metadata for the requested Firebase-backed sign-in and application-integrity service, not optional audience analytics.Legitimate interests: provider compatibility, security and fault diagnosis.Google Firebase receives the heartbeat header under Google Cloud terms; provider safeguards apply to any international transfer.
Cloudflare Turnstile challenge tokenShort-lived single-use third-party widget token; the tested widget has no pre-clearance and therefore does not issue cf_clearance through that featurechallenges.cloudflare.com and the current Vivat Lex Web pageCloudflare Turnstile, for Vivat LexCheck that a sign-in bootstrap is not automated before the server accepts it.Opening enabled sign-in renders the security widgets; requesting an email code or selecting an available Google sign-in, or Apple if offered, sends the returned token to server-side Siteverify.Challenge result and browser/network signals used for security and bot detection; Vivat Lex sends the token to Cloudflare Siteverify.5 minutes; single useStrictly necessary to protect the visitor's requested sign-in flow from automated abuse.Legitimate interests: service security and abuse prevention.Cloudflare processes the validation request under its applicable data-processing terms; provider safeguards apply to any international transfer.
vivatLexCheckoutIntentIdFirst-party sessionStorage key; conditional and set only after the server accepts checkout creationCurrent Vivat Lex Web originVivat LexReconnect the checkout processing/status page to the server-owned checkout intent; this browser value is not payment or entitlement authority.Only after Vivat Lex accepts the checkout request and returns a valid checkout reference.Opaque Vivat Lex checkout-intent identifier.Current browser-tab session. The application removes an invalid reference; removes it after a failed, payment-resolved-without-contract, expired, suspended or revoked outcome; or removes it after paid active or scheduled status, receipt and reconciliation are all confirmed. A refund-pending or otherwise unresolved status reference remains until the tab or window closes or site data is cleared.Strictly necessary to provide the checkout status flow requested by the visitor once checkout is enabled.Contract steps and performance; legitimate interests in reliable payment-status handling.Vivat Lex and its standalone-web Google Cloud hosting and database services; the identifier is resolved only against server-side Commerce records under the provider safeguards described in the Privacy Policy.
vivatLexLearningAttemptRequest:v1:*First-party sessionStorage key family; conditional and set only for an answerable private-learning itemCurrent Vivat Lex Web originVivat LexRestore the same unanswered learning item after a page reload, without counting it twice or duplicating progress.Only after the server successfully serves an answerable private-learning item with an attempt identifier.A random, pseudonymous opaque request identifier. The storage-key suffix contains a protected learning-format family identifier (a separate axis from the twelve FLK1 and FLK2 course subjects) and either an opaque navigation cursor or the word ‘first’. The value and key contain no course body, question, answer, explanation, name, email, contact detail, payment value, entitlement identifier, release content or progress count; the opaque handle may be linkable to protected server records.Current browser-tab session. The application removes the relevant handle after a successful answer, invalid or conflicting-request recovery, or successful logout; otherwise the browser clears it when the tab or window closes or site data is cleared.Strictly necessary for the visitor-requested function of restoring an unanswered private-learning item after reload, idempotent item opening and accurate progress. Course access authority does not rely on this browser value.Contract performance; legitimate interests in reliable private-learning delivery and progress integrity.Vivat Lex and its standalone-web Google Cloud hosting and database services; the reference is matched only to protected learning records and is accepted only while the signed-in account, device, course access, current course item and active learning session are valid.

Optional analytics

Name/keyTypeHost/domainProviderExact purposeTriggerInformationDurationConsent categoryRecipients/transfersLast verified

No optional analytics entry is active unless listed here and valid choice controls are operating.

Optional personalisation

Name/keyTypeHost/domainProviderExact purposeTriggerInformationDurationConsent categoryRecipients/transfersLast verified

No optional personalisation entry is active unless listed here and valid choice controls are operating.

Optional advertising

Name/keyTypeHost/domainProviderExact purposeTriggerInformationDurationConsent categoryRecipients/transfersLast verified

No optional advertising entry is active unless listed here and valid choice controls are operating.

Approved UK statistical-purpose exception

Name/keyTypeHost/domainProviderSole aggregate-improvement purposeAggregation/deletion pointObjection controlDurationProvider roleTransfersAssessment referenceLast verified

No UK statistical-purpose exception is relied on unless an approved entry appears here.

Approved UK appearance or functionality exception

Name/keyTypeHost/domainProviderSole appearance/function purposeInformationObjection controlDurationSecondary-use controlsTransfersAssessment referenceLast verified

No UK appearance or functionality exception is relied on unless an approved entry appears here.

Version and effective date

Document version
2026-09-12.5
Effective and last reviewed
12 September 2026

The version accepted at checkout is recorded with the order and forms part of the customer's durable confirmation. A later publication does not retrospectively replace that accepted version or reduce any mandatory consumer right.