At a glance
We use strictly necessary technologies to operate, secure and remember choices on Lazomis QI. Optional analytics, preference or marketing technologies remain off until the visitor gives valid consent. Visitors can refuse non-essential technologies and later change their choice through Cookie settings.
Document control
| Organisation | Flux Medical Limited, trading as Lazomis QI |
|---|---|
| Company number | 16158150 |
| Registered office | Unit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG |
| Privacy contact | privacy@lazomis.co.uk |
| Version | 2.0 |
| Effective date | 15 August 2026 |
| Review cycle | At least every six months and after material technology or legal changes |
1. About this policy
This Cookie Policy explains how Flux Medical Limited (Flux Medical, Lazomis, we, us or our) uses cookies, local storage, pixels, tags, software development kits and comparable technologies on the Lazomis QI website and platform. It explains their purposes, durations, providers and the choices available to visitors and users.
It should be read with the Lazomis QI Privacy Policy, which explains how personal information is collected, used, shared, retained and protected. This policy does not override contractual controls that apply to organisation workspaces or project data.
2. What cookies and similar technologies are
A cookie is a small text file stored on a browser or device when a website is visited. Session cookies normally expire when the browser session ends; persistent cookies remain until their stated expiry or deletion. First-party cookies are set by the visited website, while third-party cookies are set or read by another provider whose service is used on the website.
Similar technologies may store identifiers or preferences in browser storage, detect events through pixels or tags, or allow an integrated service to operate. In this policy, ‘cookies’ includes these similar technologies unless the context requires otherwise.
3. Legal basis and consent
The Privacy and Electronic Communications Regulations generally require clear information and consent before information is stored on, or accessed from, a user's device. An exception applies where the storage or access is strictly necessary to provide a service the user has requested, or solely to transmit a communication.
Where consent is required, it must be freely given, specific, informed and indicated by a clear positive action. Non-essential technologies must not be activated before consent. Rejecting them must be as easy as accepting them, and consent may be withdrawn at any time.
Where information generated by a cookie is personal data, the UK GDPR also applies. Our corresponding lawful basis is normally consent for optional analytics, preference and marketing technologies, and contract or legitimate interests for related strictly necessary processing where appropriate. The precise basis is explained in the Privacy Policy.
No consent by silence
Continuing to browse, closing the banner, pre-ticked controls or inactivity are not treated as valid consent to non-essential cookies.
4. Categories we may use
| Category | Purpose | Consent position |
|---|---|---|
| Strictly necessary | Authentication, security, session continuity, load management, requested preferences and recording cookie choices. | Used without optional consent only where the legal exemption applies. |
| Analytics and performance | Understand visits, navigation, errors, speed and feature use so the service can be improved. | Off until consent unless a specific lawful exemption applies and has been documented. |
| Preferences and functionality | Remember optional choices or provide enhanced functions beyond what is necessary for the requested service. | Off until consent where not strictly necessary. |
| Marketing and communications | Measure campaigns, referrals or advertising and recognise engagement across services. | Off until consent. |
| Embedded or integration technologies | Enable content or services supplied by another provider. | Depends on purpose; optional components remain blocked until required consent. |
5. Current cookie and technology register
The live Cookie settings panel displays the current register and allows category-level choices. The table below sets out the register structure. It is completed from a technical scan of the production website and verified after each material release; names, providers and durations are not guessed.
| Name / technology | Provider | Category | Purpose | Duration |
|---|---|---|---|---|
| Consent record | Lazomis QI / consent-management provider | Strictly necessary | Stores the visitor's cookie choices and consent version. | Shown in Cookie settings |
| Authentication and session technologies | Lazomis QI / authentication provider | Strictly necessary | Signs users in, maintains authorised sessions and protects accounts. | Session or provider-defined period |
| Security and load-management technologies | Lazomis QI / infrastructure provider | Strictly necessary | Helps protect, route and reliably deliver the service. | Provider-defined period |
| Analytics technologies | Provider shown in Cookie settings | Analytics | Measures agreed website and feature usage. | Only if enabled; period shown in Cookie settings |
| Campaign or marketing technologies | Provider shown in Cookie settings | Marketing | Measures agreed campaign or advertising activity. | Only if enabled; period shown in Cookie settings |
| Embedded-service technologies | Relevant embedded provider | Relevant category | Operates an embedded video, form, payment or other integration. | Provider-defined period |
Register accuracy
The Cookie settings panel is the authoritative live record. Where an entry here differs from the panel, the panel prevails and this policy is updated at the next review.
6. Strictly necessary technologies
Strictly necessary technologies support functions a user has explicitly requested or that are essential to transmit the service. Depending on the route used, these may support sign-in, session continuity, account security, fraud prevention, load balancing, checkout continuity, saved privacy choices or access to protected areas.
The strictly necessary label is applied narrowly. A technology is not necessary merely because it is convenient, improves analytics, supports general business goals or is included by default in a third-party product. These technologies cannot normally be disabled through our consent panel, but users may block them in the browser; doing so may prevent the Service from working.
7. Analytics and performance
With consent, analytics may help us understand page visits, referral source, approximate region, device and browser type, navigation, feature use, errors and performance. We use this information to improve usability, reliability and content, preferably in aggregated or privacy-protective form.
- Analytics remains disabled until the relevant consent is recorded.
- The collection is configured to minimise identifiers and unnecessary detail.
- Sensitive project content and patient information must not be deliberately placed in analytics event names, URLs, properties or recordings.
- IP handling, user identifiers, retention, advertising features and cross-service sharing are reviewed before deployment.
- Session replay or comparable monitoring is not enabled without a separate risk assessment, transparency and valid consent.
8. Preferences and functionality
Preference technologies may remember optional display, language or feature choices. A preference essential to deliver a function the user has just requested may be strictly necessary; broader personalisation normally requires consent. The Cookie settings panel identifies the category applied to each live technology.
9. Marketing and communications
Marketing technologies may measure campaign links, newsletter engagement, referrals or advertising effectiveness. They may allow a provider to recognise a browser across pages or services. Such technologies remain off until consent and are not required to create or use a Lazomis account.
Lazomis does not infer consent to marketing cookies from newsletter subscription, account creation or acceptance of the Terms of Use. Email tracking, pixels and link measurement are also assessed under PECR and the UK GDPR and are explained at the point of collection where appropriate.
10. Authentication, payments and embedded services
10.1 Authentication
Authentication providers may use essential session, anti-abuse and security technologies to sign users in and protect accounts. The Cookie settings register identifies the provider-facing technologies visible on the Lazomis domain where technically possible.
10.2 Payments
A payment provider may use essential security, fraud-prevention and checkout technologies when a user chooses to buy Project Credits or another service. Its own website or embedded checkout may also apply its privacy and cookie information. Optional payment-provider analytics or marketing must not be treated as automatically necessary.
10.3 Embedded content and forms
Videos, forms, maps, support tools or other embedded services may place or read technologies. Optional content is blocked or replaced with a consent prompt until the relevant choice is made where required. Following a link to another website means that provider's own policy applies there.
11. Managing and withdrawing consent
Visitors can choose categories through the initial banner and reopen Cookie settings from the website footer. The interface provides equally prominent ‘Accept all’ and ‘Reject non-essential’ options, alongside a clear route to customise choices. Necessary technologies are identified separately.
- Withdrawing consent stops future optional storage or access as soon as reasonably possible.
- Changing a choice does not automatically delete information already lawfully collected, but applicable retention and deletion controls continue to apply.
- Where technically feasible, consent withdrawal also removes relevant first-party optional cookies from the browser.
- Third-party cookies may need to be deleted using the provider, browser or device controls.
- A minimal consent record may be retained to demonstrate and respect the choice.
12. Browser and device controls
Most browsers allow users to view, block or delete cookies, restrict third-party cookies, clear site data and control tracking features. Device and privacy settings may provide additional controls. Browser settings vary and may change; users should consult the help information for their browser or device.
Blocking all cookies may prevent sign-in, saved choices, security checks, checkout or other requested features. Browser signals such as Global Privacy Control or Do Not Track are assessed against applicable legal requirements and technical capability; this policy does not promise support for a signal unless the Service confirms it.
13. Retention and renewal of consent
Each technology is retained only for the period shown in the current Cookie settings register or until the user deletes it. Durations are chosen according to purpose and minimised where possible. Session technologies expire with the session unless security or continuity requires a documented persistent period.
Consent is refreshed at appropriate intervals and sooner where purposes, categories, providers or technologies materially change. Consent records include the choice, time, notice or policy version and enough context to demonstrate the choice without retaining unnecessary device data.
14. Information generated by these technologies
Depending on the technology and choice, information may include a consent status, random identifier, session or authentication token, IP address, approximate location inferred from IP, device and browser information, referral information, timestamps, viewed pages, interactions, error and performance data, and purchase or campaign status.
Complete payment-card details are handled by the payment provider and are not intended to be stored in Lazomis cookies. Cookies and analytics must not intentionally capture patient-identifiable information, project free text, passwords or other sensitive content.
15. Third parties and international transfers
Some technologies are supplied by hosting, authentication, payment, analytics, communications, support or embedded-service providers. The live register names each provider and links or signposts its relevant privacy information. We assess contracts, data use, retention, security, subprocessors and locations before deployment.
If personal data is transferred outside the United Kingdom, we use an applicable safeguard described in the Privacy Policy, such as UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum or another lawful mechanism. Consent to a cookie is not used as a substitute for required international-transfer safeguards.
16. Changes to this policy
We update this policy and the live register when technologies, purposes, providers or legal requirements materially change. The effective date identifies the current version. Where a change affects an existing consent, we request a new choice before activating the changed non-essential use.
17. Contact and complaints
| Purpose | Contact |
|---|---|
| Cookie or privacy enquiry | privacy@lazomis.co.uk |
| Postal contact | Flux Medical Limited, Unit 7 Wheatcroft Business Park, Landmere Lane, Edwalton, Nottingham, England, NG12 4DG |
| Service complaint | https://lazomis-qi.co.uk/complaints |
| ICO complaint | https://ico.org.uk/make-a-complaint/data-protection-complaints/ |
Please do not send patient-identifiable or other sensitive information through ordinary email unless a secure, authorised route has been agreed.