Draft for review – text in development

This Cookie Policy is currently being reviewed and may be updated before final approval. The final cookie inventory will be confirmed through a technical scan of the live website after the cookie-consent and anti-spam tools have been fully configured.

Cookie Policy

Organisation: Society for Magnetic Resonance Angiography (SMRA)
Website: society4mra.org
Contact: contact@society4mra.org
Draft version: 2026-08-25-draft
Last updated: 25 August 2026

1. About This Cookie Policy

This Cookie Policy explains how the Society for Magnetic Resonance Angiography (“SMRA”, “we”, “us” or “our”) uses cookies and similar technologies on the SMRA website.

It explains:

  • what cookies and similar technologies are;
  • why the Website uses them;
  • which types of cookies may be used;
  • which cookies are necessary for the Website to function;
  • how Google Analytics is used;
  • when visitor consent is required;
  • how visitors can change or withdraw their choices; and
  • how to contact SMRA with questions.

This Policy should be read together with the:

2. Who Is Responsible?

2.1 Data Controller

The Society for Magnetic Resonance Angiography is responsible for deciding why cookies and similar technologies are used on the Website.

Questions about this Cookie Policy should be sent to:

contact@society4mra.org

2.2 Technical Service Provider and Data Processor

Empirical Cultures Ltd provides website development, technical administration, maintenance and member-system support on behalf of SMRA.

Empirical Cultures Ltd may configure, maintain and review cookies, analytics and consent-management tools on SMRA’s instructions. Where personal information is processed while providing these technical services, Empirical Cultures Ltd acts as a Data Processor for SMRA.

SMRA remains responsible for deciding which technologies are used and for ensuring that visitors receive appropriate information and choices.

3. What Are Cookies?

A cookie is a small text file placed on a computer, telephone, tablet or other device when a person visits a website.

Cookies can enable a website to:

  • recognise a browser or device;
  • keep a user signed in;
  • maintain a secure session;
  • remember preferences;
  • protect forms and accounts;
  • understand how the Website is used; and
  • provide embedded or third-party functions.

This Policy also applies, where relevant, to similar technologies such as:

  • local storage;
  • session storage;
  • pixels and web beacons;
  • software-development identifiers;
  • device identifiers;
  • tags; and
  • other technologies that store information on, or access information from, a user’s device.

4. First-Party and Third-Party Cookies

4.1 First-Party Cookies

First-party cookies are set by the SMRA Website itself. They may support functions such as:

  • WordPress login and authentication;
  • Member Area access;
  • account security;
  • user-interface preferences;
  • forms and submissions;
  • voting protections;
  • download access; and
  • remembering cookie preferences.

4.2 Third-Party Cookies

Third-party cookies are set by another organisation whose service is used or embedded on the Website.

Depending on the final Website configuration, these may include services such as:

  • Google Analytics;
  • CAPTCHA or anti-spam providers;
  • YouTube or other embedded video services;
  • social-media platforms;
  • newsletter and subscription services;
  • external surveys or forms;
  • conference-registration providers; and
  • other embedded external resources.

Third-party providers may process information under their own terms and privacy notices.

5. Session and Persistent Cookies

5.1 Session Cookies

Session cookies normally remain only while a browser session is open and are removed when the browser is closed.

They may be used to:

  • test whether a browser accepts cookies;
  • maintain a login session;
  • protect forms;
  • maintain navigation state; and
  • support temporary security controls.

5.2 Persistent Cookies

Persistent cookies remain on a device for a defined period or until the user removes them.

They may be used to:

  • remember login choices;
  • remember Website preferences;
  • remember cookie-consent choices;
  • support security and fraud prevention; and
  • measure Website use over time.

6. Legal Basis and Cookie Consent

6.1 Strictly Necessary Cookies

Some cookies are required for the Website or a service requested by the user to operate.

These cookies may be used without optional consent where permitted by applicable law. They may include cookies needed for:

  • secure login;
  • authentication;
  • Member Area access;
  • account security;
  • password reset;
  • form security;
  • voting integrity;
  • load balancing;
  • remembering cookie choices; and
  • other essential Website functions.

Strictly necessary cookies cannot normally be disabled through the Website’s cookie settings because doing so may prevent the requested service from working.

6.2 Non-Essential Cookies

Non-essential cookies may include:

  • analytics cookies;
  • optional functionality cookies;
  • embedded-media cookies;
  • social-media cookies;
  • advertising or remarketing cookies; and
  • other cookies that are not required to provide the requested service.

Where required, these cookies will be used only after the visitor has made an informed and affirmative choice.

Rejecting optional cookies must not prevent visitors from accessing ordinary public information. However, certain optional embedded functions may remain unavailable.

6.3 Withdrawing Consent

Visitors may change or withdraw their consent at any time through the Website’s Cookie Settings control once the final consent-management tool has been configured.

Withdrawing consent does not affect the lawfulness of processing that occurred before consent was withdrawn.

Implementation point: A permanent “Cookie Settings” control should be added to the Website before this draft is approved, allowing visitors to revisit their choices without searching for this page.

7. Categories of Cookies Used by the Website

7.1 Strictly Necessary and Security Cookies

These cookies enable core Website functions such as:

  • testing whether cookies can be stored;
  • logging users into WordPress;
  • maintaining authenticated sessions;
  • protecting administrator and member accounts;
  • providing password-reset functionality;
  • enforcing Member Area access;
  • protecting forms from misuse;
  • preventing duplicate voting;
  • maintaining secure downloads; and
  • protecting the Website from malicious activity.

7.2 Functionality and Preference Cookies

These cookies may remember choices such as:

  • Website or account-display settings;
  • administrative-interface preferences;
  • language preferences;
  • cookie-consent choices; and
  • other optional Website settings.

Some preference cookies may be essential to provide a setting requested by the user. Others may require consent depending on their purpose and duration.

7.3 Analytics Cookies

Analytics cookies help SMRA understand how visitors use the Website.

They may provide aggregate information such as:

  • how many people visit the Website;
  • which pages are viewed;
  • how visitors arrive at the Website;
  • approximate geographic region;
  • device and browser category;
  • how long users interact with pages;
  • navigation and engagement patterns; and
  • technical errors or usability problems.

Analytics cookies are not required for the basic operation of the Website and should be activated only after appropriate consent.

7.4 Embedded Content and External-Service Cookies

Some pages may contain content or functionality provided by external services, such as:

  • videos;
  • social-media content;
  • surveys;
  • registration services;
  • subscription forms;
  • maps;
  • CAPTCHA services; and
  • other embedded resources.

Embedded content may behave as if the visitor had visited the third-party website directly and may allow the provider to set cookies or use similar technologies.

Where required, optional embedded services should remain blocked until the visitor gives the relevant consent.

8. Current and Expected Cookie Inventory

The table below describes the principal cookies expected from the current WordPress and Google Analytics configuration.

Cookie names may include a unique hash or identifier. Exact cookies can also change when WordPress, plugins, security services or third-party providers are updated.

Cookie or pattern Provider Purpose Category Typical duration
wordpress_test_cookie SMRA / WordPress Tests whether the visitor’s browser can accept cookies, particularly for login. Strictly necessary Session
wordpress_[hash]
wordpress_sec_[hash]
SMRA / WordPress Authenticates users and protects secure login sessions. Strictly necessary Normally session or approximately 2 days; up to approximately 14 days where “Remember Me” is selected, subject to configuration.
wordpress_logged_in_[hash] SMRA / WordPress Recognises a signed-in user on the public-facing Website and Member Area. Strictly necessary Normally session or approximately 2 days; up to approximately 14 days where “Remember Me” is selected, subject to configuration.
wp-settings-{user_id}
wp-settings-time-{user_id}
SMRA / WordPress Stores interface and account-display preferences for signed-in WordPress users. Functionality / necessary for saved user settings Approximately 1 year
_ga Google Analytics Helps distinguish visitors for aggregate Website-usage measurement. Analytics – optional Default: 2 years
_ga_<measurement-id> Google Analytics Maintains Google Analytics session state for the relevant Analytics property. Analytics – optional Default: 2 years
Cookie-consent preference cookie SMRA / final consent-management provider Remembers whether the visitor accepted or rejected the available cookie categories. Strictly necessary Name and duration to be confirmed after the consent tool is configured.
Security, firewall and anti-abuse cookies SMRA / WordPress security tools Helps protect accounts, forms, voting, downloads and the Website against unauthorised or malicious activity. Strictly necessary Varies according to security function and configuration.
CAPTCHA or anti-bot technologies Provider to be confirmed Protects public forms, including nomination forms, from automated spam and attacks. Security or optional third-party functionality, depending on implementation To be confirmed after the provider is selected and scanned.

Important: This table is a working inventory. The final version must be checked against a live cookie scan covering public pages, login, onboarding, My Account, Member Directory, voting, nomination forms, downloads and embedded content.

9. Google Analytics

9.1 Purpose

The Website uses Google Analytics 4 to help SMRA understand Website use and improve content, navigation, accessibility and performance.

Google Analytics may collect information such as:

  • pages viewed;
  • approximate visit time and duration;
  • navigation and engagement events;
  • referring website or campaign;
  • browser and device category;
  • operating system;
  • screen resolution;
  • approximate geographic region; and
  • technical and diagnostic information.

9.2 Consent

Google Analytics is not required for the Website to function.

The final Website configuration must ensure that Analytics cookies are not stored before the visitor has consented to analytics, unless SMRA has documented that a specific legal exception applies to the exact configuration.

If a visitor rejects analytics cookies, the Website should remain usable, although SMRA will receive less information about how the Website performs.

9.3 Information SMRA Does Not Intend to Send to Google Analytics

SMRA does not intend to send the following information to Google Analytics:

  • member names;
  • email addresses;
  • passwords;
  • complete membership records;
  • uploaded biographies or documents;
  • form contents;
  • nomination details;
  • individual voting selections;
  • private Member Directory profile content; or
  • other direct personal identifiers.

Analytics configuration should be reviewed to prevent personal information from appearing in page URLs, event names, query strings or custom parameters.

9.4 Advertising Features

SMRA does not intend to use Google Analytics for personalised advertising, remarketing or cross-service advertising unless:

  • the proposed use has been separately assessed;
  • this Policy and the Privacy Notice have been updated;
  • appropriate consent has been obtained; and
  • visitors have been given a clear way to reject or withdraw consent.

9.5 Google Information and Opt-Out

Further information about Google’s privacy practices is available at:

Google also provides a browser add-on designed to prevent Website activity from being made available to Google Analytics:

The browser add-on is an additional option and does not replace the choices that should be available through the SMRA Website’s Cookie Settings.

10. Login, Member Area and Account Cookies

Cookies are essential for secure access to:

  • the login page;
  • password reset;
  • member onboarding;
  • My Account;
  • member profiles;
  • Member Directory;
  • voting;
  • member-only resources; and
  • administrative functions.

Without authentication cookies, the Website cannot reliably recognise that a member has signed in.

Blocking or deleting login cookies may:

  • log the user out;
  • prevent login;
  • interrupt onboarding;
  • prevent access to My Account;
  • interrupt a form or voting session; or
  • require the user to sign in again.

11. Forms, Nominations and Voting

Public and member-only forms may use cookies or similar technologies to:

  • protect against spam and automated attacks;
  • maintain temporary form state;
  • validate secure submissions;
  • prevent duplicate submissions;
  • confirm member eligibility;
  • prevent duplicate voting; and
  • support secure file uploads.

Where a CAPTCHA or third-party anti-bot service is introduced, its cookies and technologies will be reviewed and added to the final inventory.

Information submitted through forms is governed primarily by the SMRA Privacy Policy and the specific information shown with the relevant form.

12. Embedded Videos, Social Media and External Links

The Website includes links to services such as:

  • YouTube;
  • LinkedIn;
  • Facebook;
  • Instagram;
  • X or other social-media services;
  • newsletter services;
  • conference and registration providers; and
  • other external resources.

A normal external link does not necessarily place a third-party cookie on the SMRA Website. However, after following the link, the external provider may use cookies under its own policies.

Where videos, social feeds, maps, surveys or other services are embedded directly into an SMRA page, the provider may set cookies or collect technical information without the user leaving the Website.

Optional embedded content should be blocked until the visitor has made the relevant cookie choice where required.

13. Managing Cookie Choices

13.1 Website Cookie Settings

The final Website will provide a cookie banner and Cookie Settings control allowing visitors to:

  • accept all optional cookies;
  • reject all optional cookies;
  • choose cookies by purpose or category; and
  • change or withdraw their choice later.

Strictly necessary cookies will remain active because they are required for the requested Website function.

13.2 Browser Settings

Most browsers allow users to:

  • view stored cookies;
  • delete cookies;
  • block all cookies;
  • block third-party cookies;
  • allow cookies only for selected websites; and
  • clear cookies when the browser closes.

Browser instructions vary. Users should consult their browser’s help or privacy settings.

13.3 Effect of Blocking Cookies

Blocking all cookies may affect the Website. In particular:

  • members may be unable to log in;
  • password reset may not work correctly;
  • Member Area access may fail;
  • account preferences may not be retained;
  • forms may not submit correctly;
  • voting or duplicate-submission protections may fail;
  • downloads may become unavailable; and
  • embedded content may not display.

14. Cookie Retention

Cookies are retained only for the period reasonably necessary for their purpose.

Retention depends on:

  • whether the cookie is a session or persistent cookie;
  • the security or authentication requirement;
  • the visitor’s cookie choice;
  • the configuration of WordPress or the relevant plugin;
  • the settings of a third-party service; and
  • applicable legal and operational requirements.

Cookie expiry is different from the retention of information held in an analytics account, Website log or database. Those retention arrangements are addressed separately in the Privacy Policy and the relevant service configuration.

SMRA and Empirical Cultures Ltd will periodically review cookie durations and remove cookies or technologies that are no longer needed.

15. International Processing

Some third-party technology providers may process information outside the United Kingdom or European Economic Area.

Where cookie or analytics information is transferred internationally, SMRA will seek to ensure that an appropriate legal mechanism is available, as described in the Privacy Policy and Data Protection Notice.

Visitors should also review the privacy information of the relevant third-party provider.

16. Security

SMRA and its authorised service providers use reasonable technical and organisational measures intended to protect information associated with cookies and similar technologies.

Measures may include:

  • HTTPS-encrypted Website connections;
  • secure authentication;
  • restricted administrative access;
  • firewall and security monitoring;
  • security updates;
  • anti-spam controls;
  • session expiry;
  • access logging; and
  • data minimisation.

Users should keep their browser and device up to date and protect access to devices used for member accounts.

17. Changes to This Cookie Policy

SMRA may update this Cookie Policy when:

  • new Website features are introduced;
  • plugins or technical providers change;
  • Google Analytics settings change;
  • a new CAPTCHA or consent-management service is introduced;
  • cookie names or durations change;
  • legal or regulatory requirements change; or
  • a cookie scan identifies additional technologies.

The current version and last-updated date will be shown at the top of this page.

Where a change materially affects optional cookie use, visitors may be asked to make a new choice.

18. Related Documents

19. Contact Us

Questions or concerns about cookies and similar technologies should be sent to:

Society for Magnetic Resonance Angiography (SMRA)
Email: contact@society4mra.org

Document status: Draft for review

This text is in development. Before final approval, SMRA should complete a live cookie scan, configure a consent banner and permanent Cookie Settings control, confirm the CAPTCHA provider, verify the Google Analytics configuration, and replace the provisional inventory with the exact cookies and retention periods detected on the Website.