CUNNTAS
Cookie Policy
This Cookie Policy explains how CUNNTAS, a bookkeeping, accounting, payroll and financial administration platform operated by Mayside Partners Limited, a company registered in Scotland under company number SC642690, uses cookies and similar browser technologies.
The name CUNNTAS is pronounced “KOON-tas”. It comes from the Scottish Gaelic word cunntas, meaning “account”, “accounts”, “accounting” or “reckoning” — a name that reflects both the purpose of the platform and its Scottish identity.
CUNNTAS uses cookies primarily to operate the platform securely, maintain authenticated User sessions and provide security functions such as trusted-browser authentication.
This Policy should be read together with the CUNNTAS Privacy Policy.
1. What Is a Cookie?
A cookie is a small piece of information stored by a website in a User's browser.
Cookies allow a website or application to recognise information associated with a browser between individual page requests and, where appropriate, between separate visits.
Different cookies have different purposes and lifetimes. Some exist only during a browser session, while others remain until a specified expiry date or until they are removed.
2. How CUNNTAS Uses Cookies
CUNNTAS uses cookies and related browser technologies where they are necessary for the operation, authentication and security of the platform.
They are used to perform functions including:
- Maintaining authenticated User sessions
- Protecting forms and requests against unauthorised actions
- Supporting mandatory Two-Factor Authentication
- Remembering a browser that a User has chosen to trust for 30 days
- Restoring an authorised session where appropriate
- Maintaining security and platform integrity
CUNNTAS does not use cookies merely because they are available. A cookie or similar technology should have an identifiable purpose within the operation of the platform.
3. Strictly Necessary Cookies
The principal cookies used by CUNNTAS are Strictly Necessary Cookies.
These are required for the platform to operate securely and correctly.
Without them, functions such as signing in, maintaining an authenticated session, submitting protected forms and recognising a trusted browser would not operate as intended.
Because these technologies are necessary to provide a service expressly requested by the User or to maintain essential platform security, they cannot simply be disabled through CUNNTAS while continuing to use all authenticated functions of the platform.
Users can prevent or remove cookies using their browser, but doing so may prevent CUNNTAS from operating correctly.
4. Authentication and Session Cookies
When a User signs in, CUNNTAS establishes an authenticated session.
A session cookie allows the browser and CUNNTAS to associate subsequent requests with that authenticated session so that the User does not need to enter their credentials every time they move from one page to another.
The ordinary CUNNTAS session cookie is designed for the authenticated browser session.
It does not contain the User's password.
If the session ends, expires or becomes unavailable, the User may be required to sign in again unless an appropriate trusted-browser credential allows the authorised session to be restored.
5. Two-Factor Authentication
Two-Factor Authentication is mandatory for CUNNTAS Users.
The authentication process may use browser cookies or related session information to maintain the secure authentication sequence between entering the User's email address and password and completing the required Authenticator verification.
These technologies form part of the security process and are not used for advertising or behavioural tracking.
6. Trust This Browser for 30 Days
After successfully completing Two-Factor Authentication, a User may choose:
Trust this browser for 30 days
When selected, CUNNTAS places a secure browser credential on that browser.
This allows CUNNTAS to recognise that the User has previously completed the required Two-Factor Authentication on that browser and ordinarily avoids requiring another Authenticator code for the following 30 days.
The trusted-browser credential is separate from the User's ordinary authenticated session.
This means a User may sign out and subsequently sign in again with their email address and password while the browser remains trusted, without normally having to repeat the Authenticator challenge.
7. Separate Trusted Credentials for Different Users
More than one CUNNTAS User Account may be used through the same browser.
CUNNTAS maintains trusted-browser authorisation separately for each User so that trusting one CUNNTAS account does not replace the trusted-browser authorisation belonging to another account.
Each User's trusted status remains subject to its own validity and expiry.
8. Trusted-Browser Expiry
A trusted-browser credential is valid for a maximum period of 30 days from the time it is established.
Using the trusted browser does not indefinitely extend that period.
Once the trusted-browser period expires, CUNNTAS will require the User to complete Two-Factor Authentication again before a new trusted-browser period can be established.
This ensures that trusted status does not become permanent merely because a browser is used regularly.
9. When Trusted-Browser Access May Be Revoked
CUNNTAS may invalidate a trusted-browser credential before its normal expiry where appropriate for security.
This may occur following circumstances including a security reset, changes to authentication credentials, replacement or resetting of Two-Factor Authentication, removal of a trusted browser by the User or Administrator, account suspension, or other activity requiring existing trusted credentials to be invalidated.
Users can therefore be required to authenticate again even where 30 days have not elapsed.
10. Signing Out
Selecting Sign Out ends the current authenticated CUNNTAS session.
Signing out does not necessarily remove an otherwise valid trusted-browser authorisation.
If the browser remains trusted, the User can subsequently sign in again using their normal credentials without ordinarily being required to provide another Authenticator code until the trusted period expires or is revoked.
This allows the User to end an active session without unnecessarily removing a deliberate security preference for a device under their control.
11. Session Restoration
A browser session can sometimes end because of browser behaviour, server session management or other technical circumstances.
Where a valid trusted-browser credential exists, CUNNTAS may use it to restore an authorised authenticated session rather than unnecessarily requiring the User to repeat the complete authentication process.
This facility is intended to provide continuity for legitimate Users while retaining the security requirements associated with the trusted-browser credential.
An explicit Sign Out is treated differently from an unintended loss of the underlying session.
12. Security of CUNNTAS Cookies
Security-related CUNNTAS cookies are configured with protections appropriate to their purpose.
Where applicable, these include restricting cookies to encrypted HTTPS connections and preventing normal client-side scripts from reading authentication credentials stored in protected cookies.
CUNNTAS also uses browser cookie controls intended to reduce the risk of cookies being sent in inappropriate cross-site requests.
The sensitive value used to recognise a trusted browser is not intended to be stored in the CUNNTAS database as an ordinary readable authentication token.
13. Form and Request Security
CUNNTAS uses security mechanisms to help establish that protected requests originate from the authenticated CUNNTAS session.
These protections are important for actions that create, alter or submit information.
Associated session information may therefore be used to validate protected requests and reduce the risk of another website causing an authenticated browser to perform an unintended action.
14. Public Pages
Public CUNNTAS pages may be viewed without signing into an Organisation.
Where a public page does not require a cookie to provide its functionality, CUNNTAS does not need to establish an authenticated session merely because somebody reads that page.
Some essential technical or security functionality may nevertheless operate where necessary to deliver or protect the service.
15. Analytics and Advertising Cookies
CUNNTAS does not currently rely upon non-essential advertising or behavioural-tracking cookies as part of the core platform service.
If CUNNTAS introduces analytics, advertising or other non-essential cookie technologies that require User consent in the future, appropriate information and consent controls will be provided before those technologies are used where required by law.
We will not describe a non-essential tracking technology as “necessary” merely to avoid providing an appropriate choice.
16. Third-Party Services
CUNNTAS integrates with external services where necessary to provide functions including payments, banking, Open Banking and other platform services.
When a User is transferred to or interacts directly with a third-party service, that provider may use its own cookies or browser technologies.
Those technologies are controlled by the relevant provider and are subject to its own privacy and cookie information.
The use of a third-party service does not mean that CUNNTAS permits that provider to place unrelated advertising or behavioural-tracking cookies throughout the CUNNTAS platform.
17. Payment Providers
Where a User interacts with a supported payment provider to establish or make a payment, the payment provider may use cookies necessary to authenticate, secure or process the transaction.
Those cookies are governed by the relevant payment provider.
CUNNTAS retains the billing and accounting information required to administer the resulting subscription, Invoice, Credit Note or payment without requiring the payment provider's cookies to become general CUNNTAS tracking technologies.
18. Banking and Open Banking Providers
Connecting a bank account may require a User to interact with a bank, financial institution or authorised Open Banking provider.
Those services may use their own cookies for authentication, security, consent or session management.
Such cookies operate within the relevant external banking or authorisation process and are governed by the provider responsible for that service.
19. Managing Cookies Through Your Browser
Users can inspect, block or remove cookies using the controls provided by their web browser.
The precise procedure depends upon the browser being used.
Removing CUNNTAS cookies may sign the User out, remove trusted-browser status or require the User to complete Two-Factor Authentication again.
Blocking Strictly Necessary Cookies may prevent authenticated CUNNTAS functions from operating.
20. Public and Shared Computers
Users should not select Trust this browser for 30 days on a public computer, shared workstation or another device they do not control.
Where CUNNTAS has been accessed from such a device, the User should sign out when finished.
Users should also consider clearing browser information where appropriate if they have used a device that is not under their exclusive control.
21. Cookies Do Not Replace Account Security
A trusted-browser credential is one part of the CUNNTAS authentication system.
Users remain responsible for protecting their passwords, Authenticator credentials and Recovery Codes and for maintaining the security of devices through which CUNNTAS is accessed.
A User who believes that a device or account may have been compromised should take appropriate security action and should not rely merely upon deleting browser cookies.
22. Changes to This Cookie Policy
CUNNTAS may introduce new functions or change the technologies used to operate existing functions.
This Cookie Policy may therefore be updated when the platform, applicable law or our use of browser technologies changes.
If a future change introduces non-essential cookies requiring consent, the appropriate consent mechanism will be introduced as part of that change.
The current version of this Policy will be identified by its Last Updated date.
23. Contact
Questions concerning the use of cookies or similar technologies by CUNNTAS may be directed to: Mayside Partners Limited. Enquiries may be submitted using the contact details provided through the CUNNTAS platform.
Last Updated: 10 August 2026