Privacy

Privacy Statement

This page explains what information is and is not collected by this website, and how information supplied through linked services is used.

CSF collection scheduler

CSF scheduler inputs stay in your browser. The planning tool runs locally on your device and is provided as a convenience to help draft and export suggested collection schedules.

This website does not receive study IDs, participant IDs, timepoints, collection schedules, exported files, or other information entered into the scheduler.

Booking calendar

Booking calendar submissions are handled by Google Calendar appointment scheduling. The details you enter there are sent through the Google Calendar booking workflow so the requested session can be reviewed and responded to.

A booking request is not automatically confirmed. Booking details are used to assess availability, identify possible clashes, and arrange follow-up through the rooms.

General enquiry form

General enquiry form submissions are used only to respond to the enquiry. They are not intended for booking requests, urgent clinical matters, or transfer of confidential study schedules.

If the form is connected, the reply email address is first used to send a short-lived verification code. The enquiry is not accepted until that email verification step succeeds. This helps confirm that the supplied address can receive replies and reduces spam.

Submitted details are processed by a Firebase Cloud Function and Google Workspace Gmail so the enquiry can be delivered without exposing a direct email address on the public page. Unverified attempts do not become completed enquiries.

The contact form uses Firebase App Check with a Google reCAPTCHA provider as an anti-abuse measure. The site stores short-lived server-side verification and rate-limit records in Firestore, including hashed email identifiers, hashed verification codes, expiry times, failed-attempt counts, and counters used to temporarily throttle repeated requests.

Request-source metadata available to Firebase or Google Cloud may be hashed and used to rate-limit repeated verification-code requests, verification attempts, or accepted enquiries. Raw verification codes are not stored, and rate-limit records are intended to expire automatically.

Diagnostic logs may be created to monitor whether contact form verification and submission steps succeed or fail. These logs do not include submitted names, organisations, phone numbers, message bodies, raw email addresses, raw IP addresses, or verification codes.

Technical hosting data

Firebase Hosting, Firebase App Check, Cloud Functions, Firestore, and Google Workspace may process standard technical logs needed to serve and secure the website, such as request timing, IP-derived network information, user agent details, abuse-prevention signals, and error information.

The website does not add its own analytics tracking, advertising pixels, or marketing cookies.

Theme preference

Theme preference is stored only in your browser so the site can remember whether you chose Auto, Light, or Dark mode. The Auto setting follows your device or browser colour-scheme preference.

This site does not set cookies for theme selection. The stored theme preference is not sent to the website server and can be cleared through your browser site data settings.

Third-party services

This site embeds or links to Google services, including Google Calendar appointment scheduling, Firebase, Google Cloud, Google reCAPTCHA, and Google Workspace Gmail. A separate Apps Script contact script is retained only for manual emergency use and is not used by the public site contact form. Those services handle information according to their own Google account, Workspace, and service policies.

Use and disclosure

Information provided through the booking calendar or contact form is used for booking administration, enquiry follow-up, and related professional correspondence.

This website does not sell personal information. Information is not used for advertising profiling or unrelated marketing.