Category
Always activeStrictly necessary
Site operation: load balancing, secure logins, session continuity, CSRF protection, consent storage.
| Cookie / token | Type | Duration | Purpose |
|---|---|---|---|
| gaaslaw_session | First-party · HttpOnly · Secure | 7 days | Authenticated session for /app and /admin routes. |
| gaas_consent_v1 | First-party | 12 months | Records your cookie preferences. |
| gaaslaw_demo_mode | First-party | Session | Tracks Demo Mode state on the protected app shell. |
Legal basis: Legitimate interest · PECR Regulation 6(4) (strictly necessary exemption)