HackXium

Legal

Cookie Policy

Effective 24 July 2026Version 1.0Xium Labs Ltd

1. Introduction

This Cookie Policy explains how HackXium uses cookies and similar technologies when you visit or use our platform at hack.xiumlabs.com (the Service). It describes what these technologies are, which ones we set, why we set them, and the choices available to you. It applies to every visitor to the Service, whether or not you hold an account.

The Service is operated by Xium Labs Ltd, a company registered in England and Wales under company number 16702035 (we, us, our). We provide cohort-based executive training in AI and cybersecurity for senior professionals, and the cookies we set exist solely to make that service work securely and reliably.

This policy sits alongside our Privacy Policy, which explains more broadly how we collect and use personal data, and our Terms of Service, which govern your use of the Service. Where a cookie or similar technology involves the processing of personal data, the Privacy Policy applies to that processing. If anything in this policy is unclear, we encourage you to contact us using the details in section 10 before continuing to use the Service.

2. What cookies are

A cookie is a small text file that a website places on your device (computer, tablet or phone) when you visit it. The file is stored by your browser and sent back to the website on later visits or as you move between pages. Cookies allow a website to recognise your device, remember that you have signed in, and distinguish your session from everyone else’s. They are a standard, long-established part of how the web works.

Alongside cookies, websites can use similar technologies that serve comparable purposes. The most relevant for the Service is local storage, a feature of modern browsers that lets a website store small amounts of information on your device. Unlike cookies, information in local storage is not automatically sent to our servers with each request; it stays in your browser until it is cleared. Where this policy refers to cookies, it includes local storage and similar technologies unless we say otherwise.

Two distinctions are useful when reading the rest of this policy:

  • First-party and third-party cookies. First-party cookies are set by the website you are visiting, in this case by us. Third-party cookies are set by a different organisation whose content or services appear on, or are linked from, the page you are viewing. As explained in section 6, we do not currently allow third parties to set advertising or analytics cookies through the Service.
  • Session and persistent cookies. Session cookies last only as long as your browsing session and are deleted when you close your browser. Persistent cookies remain on your device for a fixed period, or until you delete them, so that the website can recognise you when you return.

3. How we use cookies

Our approach is deliberately minimal. Today, the Service sets only essential cookies: those that are strictly necessary for the Service to function and to keep it secure. We do not set advertising cookies, we do not set third-party analytics cookies, and we do not use cookies to track you across other websites or to build profiles of your interests.

The essential cookies we set do three things:

  • Authentication. When you sign in through our sign-in page or create an account via sign up, cookies keep you signed in as you move around the Service, so you do not have to re-enter your credentials on every page. Without them, enrolment, learning materials, deliverable submission and your certificates would be inaccessible.
  • Security. Cookies help us protect sign-in and payment flows against common attacks, such as requests forged from other sites, and help us detect and limit abusive or automated activity. These protections operate in the background and exist to keep your account and our platform safe.
  • Preferences. We use local storage to remember a small number of choices you make, such as whether you have acknowledged our cookie notice, so that we do not show you the same message repeatedly.

If we ever decide to introduce cookies that are not strictly necessary, for example analytics cookies to help us understand how our programmes are used, we will update this policy first and ask for your consent before setting them, as described in section 5. Nothing in our current design assumes or depends on non-essential cookies.

4. The cookies we set

The table below describes the cookies and local storage entries the Service sets, grouped by what they do. We have described them generically rather than by internal technical name, because technical names can change with routine engineering work while the purpose and duration remain stable. Every entry in this table falls within the strictly necessary category.

NameCategoryPurposeDuration
Authentication (session)Strictly necessaryIdentifies your signed-in session so you stay logged in as you navigate between pages, access learning materials and submit deliverables.Session
Authentication (persistent sign-in)Strictly necessaryAllows the Service to recognise your device and keep you signed in between visits, so you do not have to sign in again every time you return.Up to 12 months
SecurityStrictly necessaryProtects sign-in and payment flows against forged requests and other common attacks, and helps us detect and limit abusive or automated activity.Session
Preferences (local storage)Strictly necessaryRemembers choices you have made on this device, such as whether you have acknowledged our cookie notice.Up to 12 months

Exact lifetimes may be shorter than the maximum shown, and session entries are removed when you close your browser or sign out. If we add a cookie that does not fit within these categories, we will update this table before it is deployed.

6. Cookies set by others

At present, no third party sets advertising or analytics cookies through the Service. We do not embed advertising networks, social media tracking pixels or third-party analytics tools in our pages, and we have no commercial arrangements under which other organisations may read or write cookies on our domain for those purposes.

There are two situations in which a third party may nonetheless set its own cookies in connection with your use of the Service:

  • Payment pages.Payments for our programmes are handled by external accredited payment processors. When you proceed to payment, you may interact with pages or components operated by the payment processor, which may set its own cookies for fraud prevention, security and the operation of the payment itself. Those cookies are set by the processor, not by us, and are governed by the processor’s own privacy and cookie policies.
  • Embedded or linked third-party content. If we embed content hosted by a third party, or link you to an external site (for example supplementary reading connected to a programme on our coursespages), that third party may set cookies when you interact with its content or visit its site. Again, those cookies are governed by the third party’s own policies, and we encourage you to review them.

We choose our service providers with care and we do not permit any provider to use cookies set in connection with the Service for its own advertising or profiling purposes. Our Privacy Policy explains more about the categories of trusted service providers we work with and the safeguards that apply to them.

7. How to manage cookies

You are always in control of the cookies stored on your device. Every major browser lets you view the cookies a site has set, delete some or all of them, and block cookies from particular sites or from all sites. These controls are usually found in the browser’s settings under headings such as privacy, security, or site data, and each browser publisher provides current instructions in its help documentation. Because menu layouts change frequently, we recommend consulting your browser’s own help pages for up-to-date steps rather than relying on third-party guides.

In general, you can:

  • delete cookies already stored on your device, individually or for all sites at once;
  • block all cookies, or block only third-party cookies while allowing first-party cookies;
  • configure your browser to clear cookies automatically each time you close it;
  • use private or incognito browsing modes, in which cookies are discarded when the window is closed; and
  • clear local storage for a specific site, usually through the same site data controls that manage cookies.

You should be aware of the consequences of blocking essential cookies for this Service. Because everything we set is strictly necessary, blocking cookies for hack.xiumlabs.com will prevent you from signing in and staying signed in, will break enrolment and payment flows, and will make your learning materials, deliverable submissions and certificates inaccessible. Public pages, such as programme listings on our discover page and certificate verification pages, will generally remain viewable, but any feature that depends on knowing who you are will not work. If you delete cookies, you will be signed out and will need to sign in again.

8. Similar technologies

As noted in section 2, we use browser local storage alongside cookies. Our use of local storage is narrow: we store small preference values on your device, such as a record that you have acknowledged our cookie notice, and limited state that helps the interface behave consistently between visits on the same device.

Information held in local storage stays in your browser. It is not transmitted to our servers with each request in the way a cookie is, it is not shared with third parties, and it is not used to track your activity on other websites. It persists until you clear it through your browser’s site data controls or until we replace it as part of an update to the Service.

We do not use device fingerprinting, tracking pixels, web beacons or similar covert identification techniques anywhere on the Service. If our use of similar technologies ever expands beyond what is described here, we will update this policy before making the change.

9. Changes to this policy

We keep this policy under review and will update it when our use of cookies or similar technologies changes, when the law or regulatory guidance changes, or when we can make the policy clearer. The effective date at the top of this page tells you when the current version took effect.

For minor changes, such as clarifications of wording or updates to the table in section 4 that do not introduce a new category of cookie, the updated policy published on this page is the authoritative version. For material changes, in particular the introduction of any cookie that is not strictly necessary, we will take reasonable steps to bring the change to your attention before it takes effect, for example through a notice on the Service or an email to account holders, and where the law requires it we will obtain your consent first.

We recommend revisiting this page from time to time, particularly before enrolling in a new programme, so that you remain aware of how we use these technologies.

10. Contact us

If you have any questions about this Cookie Policy, our use of cookies and similar technologies, or your choices, please contact us:

  • By email: [email protected]
  • In writing: Xium Labs Ltd, registered in England and Wales, Company No. 16702035

For questions about how we handle personal data more generally, including the rights available to you under UK data protection law, please see our Privacy Policy. If you are not satisfied with our response to a concern about cookies or personal data, you have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection and PECR.