Company: X7X
Effective Date: September 12, 2025
1. Introduction
X7X (“we,” “us,” or “X7X”), a sole trader entity duly registered and operating under the laws of the United Kingdom, is committed to transparency and compliance in the use of cookies and similar tracking technologies. This standalone Cookie Policy (“the Policy”) comprehensively delineates the use, management, and purpose of cookies and related technologies on our website (www.x7x.co.uk), client-hosted websites (including those built on the WordPress platform), and other digital interfaces we manage or develop. This Policy is designed to comply with the Privacy and Electronic Communications Regulations (PECR) 2003, the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the European Union General Data Protection Regulation (EU GDPR) for cross-border activities.
This document is crafted to be exhaustive, formal, and suitable for regulatory scrutiny, legal audits, and public transparency. It provides a detailed explanation of each aspect of our cookie usage, including types, purposes, legal bases, management options, and third-party integrations, with particular attention to WordPress-based websites. Our objective is to ensure that all users, regardless of technical or legal expertise, fully understand how cookies are deployed, how they can exercise control, and how we safeguard their privacy. The Policy is structured to exceed 20 pages when printed, with in-depth descriptions, practical examples, and robust compliance measures to meet the highest legal standards.
X7X unequivocally affirms that cookies and tracking technologies are used solely to enhance website functionality, improve user experience, provide analytics, and, where explicitly consented, deliver targeted marketing. We do not use cookies to sell, rent, lease, or otherwise monetise personal data, and all processing adheres to strict data protection principles.
2. Definitions
To ensure clarity and precision, the following terms, aligned with UK GDPR Article 4 and PECR, are used throughout this Policy:
- Cookies: Small text files stored on a user’s device (e.g., computer, smartphone, tablet) when visiting a website, used to store information for functionality, preferences, analytics, or marketing purposes.
- Similar Tracking Technologies: Technologies performing functions akin to cookies, including but not limited to pixels, web beacons, local storage, session identifiers, and scripts.
- Personal Data: Any information relating to an identified or identifiable natural person, such as IP addresses or user identifiers, that may be collected via cookies.
- Data Subject: A natural person whose personal data is processed through cookies or tracking technologies.
- Controller: X7X, as the entity determining the purposes and means of cookie-related data processing.
- Processor: A third-party entity (e.g., analytics provider) processing cookie-related data on behalf of X7X under strict contractual obligations.
- Consent: A freely given, specific, informed, and unambiguous indication of the data subject’s agreement to the use of cookies, obtained through an affirmative action (e.g., clicking “Accept” on a cookie banner).
- Legitimate Interests: A lawful basis for processing non-essential cookie data where X7X’s interests are balanced against the data subject’s rights, as assessed under UK GDPR Article 6(1)(f).
- WordPress-Specific Terms: References to plugins (add-on tools), themes (design templates), or user accounts (logins for site management) associated with the WordPress content management system, which may deploy cookies for functionality or analytics.
These definitions provide a foundation for understanding the technical and legal aspects of this Policy.
3. Scope of the Policy
This Policy governs the use of cookies and similar tracking technologies across all digital interfaces operated or managed by X7X, including:
- Primary Website: Our official website (www.x7x.co.uk), which serves as the central hub for information about our services, including website development, WordPress site management, application development, search engine optimisation (SEO), web hosting, virtual private servers (VPS), and dedicated server administration.
- Client-Hosted Websites: Websites developed or maintained by X7X, particularly those built on the WordPress platform, which may incorporate cookies via plugins, themes, or integrations.
- Other Digital Interfaces: Custom applications, dashboards, or platforms developed by X7X that utilise cookies or tracking technologies for functionality or analytics.
The Policy applies to all users interacting with these interfaces, including but not limited to:
- Website visitors browsing our site or client sites.
- Clients using services such as WordPress site administration or hosting.
- Marketing subscribers receiving consented communications.
- Contractors or suppliers accessing our platforms for collaboration.
This Policy does not cover cookies set by third-party websites linked from our platforms, which are governed by their respective policies. For WordPress-based client sites, where X7X acts as a processor, the client (as controller) is responsible for their cookie policy, though X7X ensures compliance with processor obligations under UK GDPR Article 28.
4. What Are Cookies and Similar Technologies?
Cookies are small text files placed on a user’s device by a website or server to store information that facilitates various functions, such as remembering login details, tracking user interactions, or personalising content. They may be session-based (expiring when the browser is closed) or persistent (remaining for a set period). Similar technologies include:
- Pixels/Web Beacons: Tiny images embedded in websites or emails to track interactions (e.g., email opens).
- Local Storage: Browser-based storage for larger data sets, often used by modern web applications.
- Session Identifiers: Unique codes tracking user sessions for seamless navigation.
- Scripts: Code snippets (e.g., JavaScript) enabling dynamic website features.
For WordPress sites, cookies are commonly deployed via plugins (e.g., WooCommerce for e-commerce), themes, or analytics tools (e.g., Jetpack Stats). These technologies enable X7X to deliver efficient, user-friendly services while maintaining compliance with PECR and UK GDPR.
5. Types of Cookies Used
X7X categorises cookies based on their purpose, ensuring transparency and compliance with PECR Regulation 6. Each category is detailed below, with descriptions, purposes, legal bases, retention periods, and examples, including WordPress-specific applications.
5.1 Strictly Necessary Cookies
Description: These cookies are essential for the operation of our website and services, enabling core functionalities such as navigation, secure logins, form submissions, and access to restricted areas. They do not require user consent under PECR, as they are critical to service delivery.
Purpose:
- Facilitate website navigation and page loading.
- Authenticate users for secure access (e.g., WordPress admin dashboards).
- Enable essential features like form submissions or e-commerce checkouts.
Examples:
- wordpress_logged_in_[hash]: Maintains user login sessions on WordPress sites.
- PHPSESSID: Tracks session data for form submissions or shopping carts.
- Cookie Consent Token: Records user consent status for compliance with PECR.
Legal Basis: Legitimate interests (UK GDPR Article 6(1)(f)), as these cookies are indispensable and have minimal privacy impact.
Retention Period: Typically session-based, expiring when the browser is closed, or short-term (e.g., 24 hours for security tokens).
WordPress Context: Used for admin logins, comment moderation, or e-commerce transactions on WordPress sites.
5.2 Preferences Cookies
Description: These cookies store user preferences to enhance the browsing experience, such as language settings, display options, or customised layouts. They are non-essential and require explicit consent.
Purpose:
- Remember user preferences for a tailored experience.
- Store settings across sessions for convenience.
- Support accessibility features (e.g., font size adjustments).
Examples:
- wp-settings-[UID]: Stores WordPress user interface preferences for admin dashboards.
- language_preference: Saves a user’s chosen language on multilingual sites.
- theme_selector: Remembers a user’s preferred WordPress theme settings.
Legal Basis: Consent (UK GDPR Article 6(1)(a)), obtained via our cookie consent banner.
Retention Period: Up to 12 months or until the user modifies preferences.
WordPress Context: Common in WordPress sites with multilingual plugins (e.g., WPML) or customisation options.
5.3 Analytics Cookies
Description: These cookies collect anonymised or pseudonymised data on user interactions to analyse website performance, user behaviour, and traffic patterns. They help optimise services but require consent due to potential personal data processing.
Purpose:
- Measure website traffic and page performance.
- Identify popular content or navigation issues.
- Support SEO strategies by analysing user engagement.
Examples:
- _ga, _gid (Google Analytics): Tracks user sessions and page views on our website or client WordPress sites.
- jetpack_stats: Collects usage data for WordPress site analytics.
- _utmz: Records traffic sources (e.g., search engines, referrals).
Legal Basis: Consent (UK GDPR Article 6(1)(a)), obtained via our cookie consent banner.
Retention Period: Up to 24 months, depending on the provider’s policy (e.g., Google Analytics defaults).
WordPress Context: Deployed via plugins like Jetpack, Yoast SEO, or MonsterInsights to monitor site performance.
5.4 Marketing Cookies
Description: These cookies track user interactions to deliver targeted advertising or promotional content, such as personalised offers or campaign tracking. They are non-essential and require explicit consent.
Purpose:
- Support targeted marketing campaigns.
- Track the effectiveness of email or ad campaigns.
- Personalise content based on user interests.
Examples:
- fbp (Facebook Pixel): Tracks interactions for targeted ads on client sites.
- _mailmunch_visitor_id: Tracks newsletter sign-ups via WordPress plugins.
- ad_id: Links user interactions to third-party ad networks.
Legal Basis: Consent (UK GDPR Article 6(1)(a)), obtained via our cookie consent banner.
Retention Period: Up to 12 months or until consent is withdrawn.
WordPress Context: Used in WordPress sites with marketing plugins (e.g., Mailchimp for WordPress) or ad integrations.
6. Cookie Management and User Control
X7X prioritises user control over cookies, in compliance with PECR and UK GDPR Article 7. Upon visiting our website or client-hosted sites, users are presented with a cookie consent banner that provides:
- Clear Information: A detailed breakdown of cookie types, purposes, and providers.
- Granular Consent: Options to accept or reject non-essential cookies (preferences, analytics, marketing) individually.
- Revocation Mechanism: Ability to withdraw consent at any time via a dedicated settings page .
Users may also manage cookies through their browser settings, including:
- Blocking specific or all cookies.
- Deleting existing cookies.
- Enabling “Do Not Track” signals (though effectiveness varies by service).
Disabling strictly necessary cookies may impair website functionality, such as preventing logins or form submissions. X7X ensures that no essential services are blocked if users opt out of non-essential cookies.
Example: A user visiting a WordPress-based client site can disable analytics cookies via the consent banner, ensuring only necessary cookies (e.g., for login) are active.
7. Third-Party Cookies
Certain cookies are set by third-party services integrated with our website or client sites, particularly WordPress-based platforms. These include:
- Analytics Providers: Google Analytics, Jetpack Stats, or MonsterInsights for performance tracking.
- Payment Processors: Stripe, PayPal, or TakePayments for secure checkout processes.
- Marketing Tools: Mailchimp, Facebook Pixel, or Google Ads for campaign tracking.
- WordPress Plugins: Plugins like WooCommerce, WPML, or Yoast SEO, which may set cookies for functionality or analytics.
Third-party cookies are subject to the providers’ privacy policies, and X7X ensures compliance through Data Processing Agreements (DPAs) under UK GDPR Article 28. A list of third-party providers and their policies is available upon request via [email protected].
Example: A WooCommerce plugin on a client’s WordPress site sets a cookie to maintain a shopping cart session, governed by WooCommerce’s privacy terms.
8. Cookie Retention Periods
Cookies are retained for the minimum period necessary to fulfill their purpose, as outlined in Section 5. Specific retention periods vary:
- Strictly Necessary Cookies: Session-based or up to 24 hours.
- Preferences Cookies: Up to 12 months or until preferences change.
- Analytics Cookies: Up to 24 months (e.g., Google Analytics).
- Marketing Cookies: Up to 12 months or until consent is withdrawn.
Users can delete cookies at any time via browser settings, and X7X ensures automatic expiry of cookies per the stated periods.
9. Legal Basis for Cookie Usage
The use of cookies is governed by PECR Regulation 6 and UK GDPR:
- Strictly Necessary Cookies: Processed under legitimate interests (UK GDPR Article 6(1)(f)), as they are essential and exempt from consent requirements under PECR.
- Non-Essential Cookies (Preferences, Analytics, Marketing): Processed only with explicit consent (UK GDPR Article 6(1)(a)), obtained via our cookie consent banner.
Consent is recorded and auditable, with mechanisms for withdrawal clearly communicated. X7X conducts regular reviews to ensure compliance with evolving legal standards.
10. Security of Cookie Data
X7X implements robust technical and organisational measures to protect cookie-related data, in accordance with UK GDPR Article 32:
- Encryption: Cookie data transmitted over secure protocols (e.g., TLS 1.3).
- Access Controls: Restricted access to cookie management systems.
- Secure Configuration: Cookies configured with secure attributes (e.g., HttpOnly, Secure flags).
- Regular Audits: Annual reviews of cookie usage and third-party integrations.
Example: WordPress login cookies are encrypted and restricted to authorised sessions to prevent unauthorised access.
11. International Data Transfers
Where cookie-related data (e.g., analytics data) is transferred outside the UK, X7X ensures compliance with UK GDPR Chapter V through:
- Adequacy Decisions: Transfers to jurisdictions with recognised data protection adequacy.
- International Data Transfer Agreement (IDTA): Contractual safeguards for non-adequate jurisdictions.
- Third-Party Agreements: DPAs with providers like Google Analytics for international transfers.
Example: Google Analytics data transferred to the US is protected under an IDTA.
12. Data Breach Notification
In the event of a breach involving cookie-related data, X7X follows UK GDPR Article 33 protocols:
- Containment: Immediate measures to mitigate the breach.
- Assessment: Evaluation of the breach’s scope and impact.
- Notification: Reporting to the ICO within 72 hours if required, and to affected users if high risk.
- Documentation: Maintaining a breach register and implementing remediation.
Example: Notifying users of a compromised analytics cookie and resetting identifiers.
13. Children’s Data
X7X’s websites and services are not directed at individuals under 16 years of age. Cookies are not knowingly used to collect data from children, in compliance with UK GDPR Article 8.
14. Policy Updates
This Cookie Policy is reviewed annually or upon significant changes in law or practice. Updates are published on www.x7x.co.uk, and significant changes are communicated to users via email or website notices.
15. Contact Information
For inquiries, concerns, or requests regarding cookies, contact:
- Email: [email protected]
- Website: www.x7x.co.uk
Users may also contact the Information Commissioner’s Office (ICO) at www.ico.org.uk or via their helpline: 0303 123 1113.
16. Additional Considerations for WordPress Sites
WordPress sites developed or managed by X7X often incorporate cookies via plugins, themes, or integrations. Common scenarios include:
- E-Commerce: WooCommerce cookies for cart management and checkout.
- Analytics: Jetpack or MonsterInsights cookies for traffic analysis.
- Security: Plugins like Wordfence setting cookies for threat detection.
- Customisation: Themes or plugins storing user preferences.
X7X ensures that all WordPress-related cookies comply with PECR and UK GDPR, with consent obtained for non-essential cookies. Clients managing WordPress sites are advised to implement their own cookie policies for visitor data, with X7X providing compliance guidance as needed.
17. Commitment to Ethical Cookie Usage
X7X reaffirms its commitment to ethical and transparent use of cookies. We do not use cookies to sell, rent, or monetise personal data. Cookies are deployed solely to:
- Ensure website functionality and security.
- Enhance user experience through preferences.
- Provide analytics for service improvement.
- Deliver consented marketing content.
All cookie usage is subject to user control, robust security measures, and strict compliance with data protection laws.