Black & White Group is not a website operator or data controller. Each website identifies the Participating Business responsible for that site and publishes a site-specific technology schedule.
Our approach
We use the minimum technology reasonably necessary to provide secure, accessible and effective websites. We do not deploy optional analytics, advertising, personalisation or embedded-content technology before the required choice has been made. Refusing optional technology does not prevent access to the core website.
Categories
Strictly necessary
Technology essential to transmit communications, provide a service expressly requested by the user, maintain security, balance traffic, retain a shopping or form session, remember a privacy choice or provide another applicable statutory function may operate without consent. It is not used for unrelated profiling or advertising.
Functional
Functional technology remembers optional choices or enables non-essential features. It is used only with consent unless a specific legal exception applies and the use remains within that exception.
Analytics
Analytics helps measure use and improve the service. Consent is obtained where required. Any statutory exception for limited statistical purposes is used only after a documented assessment confirming the purpose, safeguards, information and opt-out requirements.
Advertising and cross-service tracking
Advertising, behavioural profiling, cross-site tracking and similar technology is disabled by default and requires valid consent. The businesses do not treat legitimate interests alone as permission to access or store information on a user's device where PECR requires consent.
Consent standard
Where consent is required, it is freely given, specific, informed and demonstrated by clear positive action. The first layer provides equally prominent options to accept all and reject all optional categories, with a route to granular settings. Categories are off by default. Continuing to browse is not consent.
Users can reopen settings and withdraw consent as easily as they gave it. Withdrawal prevents future optional use and, where technically supported, removes related first-party technology. Third-party deletion instructions are provided where removal cannot be completed directly.
Consent evidence is retained only as long as reasonably required to demonstrate the choice and is refreshed when purposes or providers materially change or when the existing choice is no longer reliable.
Information we provide
The site-specific schedule identifies, as applicable:
- technology name or identifier;
- provider and whether it is first or third party;
- purpose and category;
- information accessed or stored;
- duration or expiry;
- consent or applicable exception;
- whether information is shared or transferred internationally; and
- how the user changes the choice.
The schedule is based on a production scan and configuration review. It is updated before a new technology is enabled, not retrospectively.
Third parties and embedded content
Maps, videos, chat, booking, review, social-media and payment content may allow another organisation to set or read technology. Optional embeds are blocked behind consent or replaced with a simple external link unless an exception clearly applies. Providers receive privacy, security, transfer, retention and contract review before approval.
Controls and assurance
Every site is scanned before launch, after material releases and at least annually. The review covers response headers, scripts, tag managers, iframes, network requests, cookies, browser storage and consent behaviour. Findings, owner and correction date are recorded. Unknown technology is blocked or removed while investigated.
Consent controls are tested for keyboard access, visible focus, screen-reader labels, responsive presentation and equivalent reject and accept journeys. Dark patterns, obstructive withdrawal and misleading button hierarchy are prohibited.
Current position
At the review date, the public holding pages for Black & White Facilities and Black & White Property Services returned no Set-Cookie header and contained no script, iframe, analytics, pixel, local-storage or session-storage implementation. Their current site-specific schedules therefore record no cookies or optional storage and access technologies. This position must be rescanned when the full websites are deployed.
Contact and rights
Questions and privacy rights are directed to the operator named on the relevant website and in its privacy notice. A user may also complain to the Information Commissioner's Office.
Approved by David Swaddle, Founder, on 30 August 2026.