- Cookie policy →
Thanex Cookie Policy
Last Updated: 21 July 2026
1. Purpose and Scope
1.1 The Cookie Policy, referred to as the “Policy,” explains how Thanex Ltd uses cookies, local storage, software development kits, pixels, tags, web beacons, device identifiers, and comparable storage or access technologies across its website, web application, mobile applications, and associated digital services.
1.2 Thanex Ltd, referred to as “Thanex,” “we,” “us,” or “our,” is a private limited company incorporated in England and Wales under company number 16426957. Its registered office is at Flat 11, Mill Pond Place, 1 Mill Lane, Maidstone, England, ME14 1GL, United Kingdom.
1.3 The Policy applies to:
(a) https://thanex.uk;
(b) the Thanex web application and cloud portal;
(C) Thanex mobile applications made available for compatible devices;
(d) Account-registration and authentication pages;
(e) subscription and billing interfaces controlled by Thanex;
(f) Business Workspaces, Organisations, and Projects; and
(g) landing pages, contact forms, early-access forms, newsletters, and support interfaces operated by or for Thanex.
1.4 Third-party websites, application marketplaces, authentication pages, and payment portals may place their own cookies under their respective policies. Thanex does not control technologies placed independently by Apple, Google, Microsoft, Stripe, Mailchimp, Amazon Web Services, or another external operator on that operator’s own website.
2. Contact Details
2.1 Questions concerning cookies, consent settings, analytics, or related personal-data processing may be sent to:
Thanex Ltd
Flat 11, Mill Pond Place
1 Mill Lane
Maidstone
England
ME14 1GL
United Kingdom
Email: support@thanex.uk
Website: https://thanex.uk
Company number: 16426957.
3. Applicable Legislation
3.1 Thanex’s use of cookies and related technologies is governed principally by:
(a) regulation 6 and Schedule A1 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, referred to as “PECR”;
(b) the United Kingdom General Data Protection Regulation, referred to as the “UK GDPR”;
(C) the Data Protection Act 2018;
(d) the Data (Use and Access) Act 2025; and
(e) Regulation (EU) 2016/679 and applicable national electronic-communications legislation where the Service is offered to persons in the European Economic Area.
3.2 PECR applies when information is stored on, or accessed from, a User’s computer, telephone, tablet, browser, mobile application, or other terminal equipment. The rules apply whether or not the information constitutes personal data.
3.3 Where cookie-derived information identifies or can reasonably be connected to an individual, the UK GDPR or EU GDPR also applies.
4. Meaning of Cookies and Similar Technologies
4.1 A cookie is a small text file placed on a browser or device when a person accesses a website or online service. Cookies may store an identifier, preference, authentication status, session information, consent choice, or other technical information.
4.2 The term “cookies” in the Policy includes comparable technologies unless the context requires otherwise.
First-Party Cookies: Technologies set by Thanex or through the Thanex domain.
Third-Party Cookies: Technologies set by an external provider whose service is incorporated into or accessed through the Thanex website or application.
Session Cookies: Temporary files that ordinarily expire when the browser or application session ends.
Persistent Cookies: Files that remain for a specified period or until deleted through browser, device, or application settings.
Local Storage: Browser or application storage used to retain preferences, identifiers, or functional information on a device.
Software Development Kits: Components included within a mobile application that may support authentication, analytics, crash reporting, payments, or notifications.
Pixels and Web Beacons: Small files or code elements that may record when a page or email is viewed or when a link is selected.
Device Identifiers: Technical identifiers associated with a browser, application installation, notification service, or device.
5. General Rules for Use
5.1 Thanex must provide clear information about the purpose of a cookie or related technology.
5.2 Non-essential cookies requiring consent will not be activated before the User has made an affirmative choice.
5.3 Consent must be freely given, specific, informed, and capable of withdrawal. Closing a banner, continuing to browse, or failing to alter a pre-selected setting will not, by itself, constitute valid consent where consent is legally required.
5.4 Strictly necessary technologies may be used without consent where they are required to provide a service expressly requested by the User, carry a communication, maintain security, prevent fraud, authenticate a User, preserve a selected setting, or perform another function permitted by Schedule A1 to PECR.
5.5 Schedule A1 also contains conditional exceptions for certain statistical and website-appearance technologies. Such exceptions apply only where their statutory requirements are met, including clear information and a simple, free method of objection.
5.6 Thanex may continue to request consent for analytics where doing so provides clearer control or where a provider’s processing does not fall wholly within the applicable statistical exception.
6. Categories of Technologies Used
6.1 Strictly Necessary Technologies
6.1.1 Strictly necessary technologies support functions without which the requested website, application, or Account service cannot operate properly.
6.1.2 Their purposes may include:
(a) establishing and maintaining a secure session;
(b) authenticating a registered User;
(C) preserving an Account sign-in state;
(d) detecting fraud, abuse, or technical faults;
(e) protecting forms and application interfaces;
(f) distributing network traffic;
(g) maintaining billing or checkout continuity;
(h) recording privacy and cookie choices;
(i) preserving information entered during a multi-stage process; and
(j) enabling access to a Business Workspace or Project.
6.1.3 Blocking these technologies through browser or device settings may prevent login, Account access, form submission, payment processing, or other core functions.
6.1.4 The legal permission for storage or access ordinarily arises under paragraphs 3 or 4 of Schedule A1 to PECR. Where personal data is processed, Thanex may rely on contractual necessity, legal obligations, or legitimate interests in operating and protecting the Service.
6.2 Preference and Functionality Technologies
6.2.1 Preference technologies remember choices that alter the appearance or operation of the website or application.
6.2.2 Their purposes may include remembering:
(a) light or dark display settings;
(b) language or regional preferences;
(C) previously selected interface options;
(d) notification settings;
(e) consent choices; and
(f) accessibility or layout settings.
6.2.3 Thanex’s website may use local storage to retain a selected display theme. The browser may preserve that preference until the User clears local storage or changes the setting.
6.2.4 Where the website-appearance exception under paragraph 6 of Schedule A1 applies, Thanex will provide clear information and a simple method of objection. Consent will be requested where the statutory exception does not apply.
6.3 Analytics and Performance Technologies
6.3.1 Analytics technologies assist Thanex in understanding how the website and Service are used.
6.3.2 Information may include:
(a) pages viewed;
(b) date and time of access;
(C) approximate session duration;
(d) referral source;
(e) browser and device type;
(f) operating system;
(g) application version;
(h) general geographic area derived from network information;
(i) selected links or buttons;
(j) errors, crashes, and performance events; and
(k) aggregated use of website or application functions.
6.3.3 Analytics data may be used to measure demand, identify technical faults, assess navigation, understand feature use, and make improvements.
6.3.4 Google Analytics may be used where enabled. Google Analytics commonly uses first-party cookies including:
Cookie or Technology | Provider | Purpose | Typical Duration |
_ga | Google Analytics | Distinguishes website Users for statistical measurement. | Up to two years. |
_ga_<container-id> | Google Analytics | Maintains session-state information for the relevant analytics property. | Up to two years. |
6.3.5 Google states that the default expiration period for _ga and _ga_<container-id> is two years, although Thanex may configure a shorter period. Google’s technical information is available at https://developers.google.com/analytics/devguides/collection/ga4/tag-options.
6.3.6 Google Analytics will be configured through the applicable consent mechanism where consent is required. Refusing analytics cookies will not prevent access to the principal Thanex Service.
6.3.7 Thanex may use consent mode or comparable controls to communicate a User’s consent status to Google. Limited technical signals may still be transmitted in a restricted form according to the configuration and applicable law.
6.4 Marketing and Campaign-Measurement Technologies
6.4.1 Marketing technologies may measure newsletter registration, campaign performance, advertisement attribution, or engagement with Thanex communications.
6.4.2 Such technologies may record:
(a) whether an email was delivered;
(b) whether an email was opened;
(C) whether a link was selected;
(d) the date and time of an interaction;
(e) the associated campaign;
(f) IP address and device information; and
(g) conversion or registration activity.
6.4.3 Thanex may use Mailchimp to administer newsletters, early-access registrations, announcements, and authorised marketing communications.
6.4.4 Mailchimp emails may contain single-pixel images or web beacons capable of recording email opens and link interactions. Mailchimp’s own explanation is available at https://mailchimp.com/legal/cookies/.
6.4.5 Marketing cookies, pixels, or comparable tracking technologies will be used only with the consent required by PECR, the UK GDPR, the EU GDPR, or other applicable legislation.
6.4.6 Withdrawing cookie consent does not automatically unsubscribe a person from an email list. Marketing emails can be stopped by selecting the unsubscribe link in the relevant message or contacting support@thanex.uk.
6.5 Authentication Technologies
6.5.1 Thanex may permit Users to sign in with Apple, Google, or Microsoft.
6.5.2 Selecting a third-party sign-in option may direct the User to the provider’s domain or activate the provider’s authentication interface. The provider may use cookies to:
(a) confirm an existing provider session;
(b) authenticate the User;
(C) prevent fraud;
(d) record authorisation choices; and
(e) return an authentication token to Thanex.
6.5.3 Technologies used independently on the provider’s domain are governed by that provider’s policy. Thanex receives only the information authorised through the authentication process, subject to the provider’s settings and the Thanex Privacy Policy.
6.6 Payment and Subscription Technologies
6.6.1 Stripe processes Thanex Subscriptions purchased through the website or web application. Apple, Google, and Microsoft may support authentication but do not process Thanex Subscription payments.
6.6.2 Payment technologies may support:
(a) checkout sessions;
(b) payment authentication;
(C) fraud detection;
(d) billing-portal access;
(e) subscription renewal;
(f) refund administration; and
(g) transaction security.
6.6.3 Cookies placed on a payment provider’s own checkout page are controlled by that provider. Refusing essential payment technologies may prevent completion of a purchase.
6.7 Mobile-Application Technologies
6.7.1 Mobile applications may use device storage, application identifiers, notification tokens, authentication tokens, cached data, and software development kits rather than conventional browser cookies.
6.7.2 Such technologies may support:
(a) Account authentication;
(b) secure session maintenance;
(c) application preferences;
(d) push notifications;
(e) error detection;
(f) application performance; and
(g) prevention of unauthorised access.
6.7.3 Camera permission permits capture through the application. Location permission permits the application to receive GPS coordinates for a Project capture. Notification permission permits delivery of authorised push notifications.
6.7.4 Device permissions are not cookies, but they are addressed in the Policy because they involve access to device functions and may generate or store technical identifiers.
6.7.5 Permissions may be changed through the device’s operating-system settings. Disabling a permission may cause the associated feature to stop operating.
7. Cookie and Technology Register
7.1 The following register describes the principal technologies that may be used. The precise name and duration of a technical cookie may vary according to domain configuration, provider updates, application version, and consent settings.
Category | Provider | Purpose | Duration | Consent Position |
Session and authentication | Thanex | Maintains authorised Account access and secures sessions. | Session-based or for the limited authentication period. | Strictly necessary. |
Security and fraud prevention | Thanex or infrastructure provider | Detects malicious activity, protects forms, and secures Accounts. | Session-based or for a limited security period. | Strictly necessary where the PECR exception applies. |
Cookie-preference record | Thanex or consent provider | Records the User’s consent, refusal, or selected categories. | Persistent for the stated preference period. | Strictly necessary to honour privacy choices. |
Display-theme storage | Thanex | Remembers light, dark, or another selected display setting. | Until changed or cleared. | Appearance exception or consent, according to configuration. |
_ga | Google Analytics | Distinguishes Users for statistical analysis. | Up to two years. | Consent unless a lawful exception fully applies. |
_ga_<container-id> | Google Analytics | Maintains analytics-session state. | Up to two years. | Consent unless a lawful exception fully applies. |
Email pixel | Mailchimp | Measures email opens and campaign engagement. | Activated when the email is opened, with associated records retained under the marketing-retention schedule. | Consent or another applicable electronic-marketing permission. |
Link-tracking identifier | Mailchimp | Measures selections made within a marketing email. | Associated with the relevant campaign record. | Consent or another applicable electronic-marketing permission. |
Social sign-in technologies | Apple, Google, or Microsoft | Authenticates the User and records authorisation. | Set by the selected provider. | Necessary for the sign-in method selected by the User. |
Payment technologies | Stripe | Processes website and web-application payments, prevents fraud, and administers Subscriptions. | Set by Stripe. | Strictly necessary for the requested transaction. |
Push-notification token | Apple, Google, Thanex, or a notification provider | Routes authorised application notifications to a device. | Until revoked, refreshed, disabled, or no longer required. | Subject to device permission and Service settings. |
7.2 A consent-management interface may display more current technical details where a provider changes a cookie name or duration. The live interface should be read together with the Policy.
7.3 Thanex does not presently state that it uses Meta Pixel, cross-site behavioural advertising cookies, or unrelated third-party advertising networks. Any future introduction of such technology will require an updated disclosure and any legally required consent before activation.
8. Cookie Consent and Preference Management
8.1 When legally required, a cookie banner or preference interface will permit Users to:
(a) accept all optional categories;
(b) reject all optional categories;
(C) make category-level selections;
(d) review information about each purpose; and
(e) change or withdraw consent later.
8.2 Rejecting optional cookies must be no more difficult than accepting them.
8.3 Strictly necessary technologies cannot ordinarily be disabled through the Thanex consent interface because they support the service requested by the User. They may nevertheless be blocked through browser settings, subject to the functional consequences.
8.4 Consent withdrawal will apply prospectively. Processing undertaken lawfully before withdrawal remains lawful.
8.5 Previously placed cookies may remain on the device until deleted or expired. Following withdrawal, Thanex will cease reading or using them for the withdrawn purpose where technically and legally required.
8.6 Cookie choices may not follow a User across every browser, device, or Account. Preferences may need to be repeated after changing devices, clearing browser data, using private-browsing mode, or accessing a different Thanex domain.
9. Statistical Cookies Under the United Kingdom Exception
9.1 Paragraph 5 of Schedule A1 to PECR permits certain statistical storage or access without consent where all statutory conditions are satisfied.
9.2 The exception requires, among other matters:
(a) collection solely for statistical purposes concerning use of the service or website;
(b) use of the statistics with a view to improving the service or website;
(C) no sharing except with a person assisting with those improvements;
(d) clear and comprehensive information; and
(e) a simple, free method of objection.
9.3 Analytics used for advertising, cross-service profiling, unrelated commercial purposes, or wider provider purposes may fall outside the exception. Thanex will use a consent-based configuration where the full conditions cannot be established.
10. Browser and Device Controls
10.1 Cookies may be deleted or blocked through browser settings. The method depends on the browser and device.
10.2 Common browser guidance is available at:
(a) Google Chrome: https://support.google.com/chrome/answer/95647;
(b) Apple Safari: https://support.apple.com/guide/safari/manage-cookies-sfri11471/mac;
(C) Mozilla Firefox: https://support.mozilla.org/kb/cookies-information-websites-store-on-your-computer; and
(d) Microsoft Edge: https://support.microsoft.com/en-us/edge/manage-cookies-in-microsoft-edge-view-allow-block-delete-and-use.
10.3 Mobile Users may also alter privacy, analytics, advertising, location, camera, and notification permissions through Apple iOS or Android settings.
10.4 Blocking all cookies may prevent Account login, payment processing, preference storage, and operation of secure areas of the Service.
11. Google Analytics Controls
11.1 Where Google Analytics is used, Users may refuse the analytics category through the Thanex cookie interface.
11.2 Google also provides a browser add-on intended to prevent Google Analytics from using data collected through supported browser activity. Information is available at https://tools.google.com/dlpage/gaoptout.
11.3 Google’s own privacy information is available at https://policies.google.com/privacy.
12. Mailchimp and Email Controls
12.1 A recipient may unsubscribe from Thanex marketing by selecting the unsubscribe link in an email.
12.2 Blocking images in an email client may prevent certain open-tracking pixels from loading, although link selections may still be recorded where tracked links are used.
12.3 Mailchimp’s Cookie Statement is available at https://mailchimp.com/legal/cookies/, and its privacy information is available at https://www.intuit.com/privacy/statement/.
13. Personal Data and Lawful Bases
13.1 Cookie-derived personal data may include an IP address, device identifier, session identifier, browser type, pages viewed, referral source, interaction information, approximate location, consent status, and Account association.
13.2 Depending on the purpose, Thanex may rely on:
(a) consent for optional analytics and marketing technologies;
(b) contractual necessity for requested Account functions;
(C) compliance with legal obligations; or
(d) legitimate interests in security, fraud prevention, fault diagnosis, and operation of the Service.
13.3 A PECR exception does not remove the need for a lawful basis where the information is personal data.
13.4 Further information about personal-data rights, disclosures, retention, security, and complaints appears in the Thanex Privacy Policy.
14. International Processing
14.1 Google, Mailchimp, Microsoft, Apple, Stripe, Amazon Web Services, and other providers may process technical information outside the United Kingdom.
14.2 Restricted transfers will be managed through an applicable adequacy regulation, the United Kingdom International Data Transfer Agreement, the United Kingdom Addendum to the European Commission’s Standard Contractual Clauses, the Standard Contractual Clauses, the UK Extension to the EU-US Data Privacy Framework for eligible recipients, or another lawful mechanism.
14.3 Provider locations and safeguards are addressed more fully in the Thanex Privacy Policy and Data Protection and Data Management Policy.
15. Retention
15.1 Each cookie remains for the session or persistent period assigned to it, unless deleted earlier by the User or withdrawn through an applicable consent control.
15.2 Analytics records may be retained separately from the cookie itself according to the configured analytics-retention period.
15.3 Consent records may be retained for as long as reasonably required to demonstrate the User’s choice, apply that choice, and meet legal-accountability requirements.
15.4 Security and authentication records may be retained separately where necessary to investigate unauthorised access, protect Accounts, or comply with law.
16. Changes to the Policy
16.1 Thanex may update the Policy when it introduces or removes a technology, changes a provider, modifies a retention period, alters a consent method, or responds to legal or regulatory developments.
16.2 Material changes will be communicated through the website, application, consent interface, or another appropriate method.
16.3 Consent will be requested again where a new purpose requires consent that has not previously been obtained.
17. Complaints and Rights
17.1 Questions, objections, consent concerns, and rights requests may be sent to support@thanex.uk.
17.2 A person may also complain to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Website: https://ico.org.uk/make-a-complaint/
Telephone: 0303 123 1113.
17.3 Persons in the European Economic Area may complain to the supervisory authority in the Member State of their habitual residence, place of work, or the alleged infringement.