Last updated
23 July 2026
Current conclusion
The public calculator uses necessary first-party security cookies and, when analytics is effective, Google Analytics cookies. Visitors in the EEA, United Kingdom, and Switzerland are asked before Google loads. Visitors elsewhere receive analytics by default after regional classification and can opt out at any time. Unknown regions and Global Privacy Control signals remain denied.
Strictly necessary cookies
- abk_session_id: first-party anonymous session cookie used to protect calculator requests from cross-site forgery. It does not contain financial inputs or results.
- abk_admin: admin-only signed session cookie used after protected backoffice login.
- CSRF token: generated by the backend and sent through the API proxy for write requests. It is tied to the session and protects forms from cross-site request forgery.
- abk_analytics_consent: signed first-party choice stored for up to 12 months so the service can apply an analytics grant or rejection.
Internal analytics
Every calculation contributes one aggregate event containing only the ruleset, applicant count, and supported or unsupported outcome. When analytics is effective, the backend may also retain broad financial and result bands for 730 days. Exact income, debt, DUO, age, property, savings, VvE, erfpacht, mortgage, cash, or result values are never written to analytics storage.
Google Analytics cookies
- _ga: distinguishes an analytics browser for up to two years, subject to the visitor’s consent and browser controls.
- _ga_<measurement-id>: preserves GA4 session state for up to two years, subject to the same controls.
Google Analytics receives allowlisted page, navigation, calculator-step, guide, engagement, approximate-country, device, and campaign events. It never receives exact financial values, form text, contact details, full query URLs, ABK session identifiers, or raw error messages. Google Signals, advertising personalization, remarketing, Google Ads linking, session replay, and heatmaps are disabled.
Retention and withdrawal
GA4 user and event data is retained for 14 months with reset on new activity. Restricted EU Google Cloud and local banded analytics use a rolling 730-day retention period. Identifier-free daily totals may be kept longer. Use Cookie settings in the footer to reject or withdraw; withdrawal stops future tracking and removes accessible Google Analytics and attribution cookies from this browser.
Source attribution
UTM campaign and referrer attribution is preserved only while analytics is effective. The all-user aggregate mortgage-completion event never includes attribution.
Non-essential tracking
Advertising cookies, cross-site advertising pixels, Google Signals, marketing audiences, and replay tools are not used. Any future marketing category must be disclosed and separately controlled before it loads.
Questions
Use the contact page for privacy or cookie questions.