Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Cookie Policy

Version 1.0 · Effective 2026-05-22

Version: 1.0 Effective date: 2026-05-22

This Cookie Policy explains how Penaxtra (the "Provider") uses cookies and similar technologies when you visit penaxtra.com or use the Service. It complements the Privacy Policy at /legal/privacy and is governed by the same legal framework (GDPR + ePrivacy Directive + KVKK).

1. What are cookies

Cookies are small text files stored on your device when you visit a website. We use them to maintain your session, prevent cross-site request forgery, remember your theme preference, and gather aggregate analytics. We do not use cross-site tracking cookies or third-party advertising tags.

2. Cookies we set

CookiePurposeTypeRetention
__Host-penaxtra_sessSession identifier after sign-in. Required for authenticated access to the console.Strictly necessary12 hours absolute, 30 minutes idle
csrf_cookieCross-site request forgery defence on form submissions.Strictly necessarySession
pnx_themeStores the user's selected theme (default-light, aurora, default-dark).Functional12 months
pnx_consentRecords cookie consent state (if shown in the future).Strictly necessary12 months

All cookies are set with Secure; HttpOnly; SameSite=Strict (session cookie) or Secure; SameSite=Lax (theme cookie). The session cookie uses the __Host- prefix to bind it to the origin and require the Secure attribute.

3. Third-party cookies

We do not embed third-party advertising cookies. The hCaptcha widget on the contact and trial forms (provided by an independent operator) sets its own cookies for bot-detection purposes only, scoped to the hCaptcha domain. Refer to the hCaptcha privacy policy for details.

4. Analytics

We use a privacy-respecting first-party analytics implementation hosted in the European Union. It does not set cookies, does not fingerprint visitors, and aggregates page-view counts without storing any cross-site identifier. You may opt out by enabling Do Not Track in your browser; we honour the signal.

5. Consent management

The cookies in section 2 marked "Strictly necessary" are exempt from prior consent under the ePrivacy Directive because they are required for the requested service. Functional cookies (theme) require your action to be set; choosing a theme in the settings page constitutes consent. Non-essential analytics are not used.

If we introduce any non-essential cookie in the future, a consent banner will appear on first visit, defaulting to opt-out, and you will be able to manage preferences at any time.

6. Browser controls

You can configure your browser to refuse cookies. Doing so will break the sign-in flow for the Service because the session cookie is strictly necessary. Browser-specific guidance is published by the major browsers (Chrome, Firefox, Safari, Edge, Brave).

7. Updates

We may update this Cookie Policy from time to time. Material changes will be communicated alongside the Privacy Policy.

8. Contact

Questions about cookies: [email protected].