GAnalytics privacy notice
What an account holds, what the connectors ingest, and why a person named in a public vulnerability record is processed as part of that record rather than sought out.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GAnalytics specifically, this page wins.
Who is responsible
Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, egelhaus@ennogelhaus.de.
For an instance you run yourself, you are the controller and we process nothing.
What is stored about you, if you have an account
Your account and sign-in details, the API keys you create — held as hashes, never as values — the dashboards and widgets you build, the posts you write, your module settings, and an audit log of what you did in the instance.
That is the whole of it. This is an analysis tool, not a product with an audience.
What it ingests
Public records: the CVE Program and comparable sources, walked through connectors. Those records are about vulnerabilities and about the organisations that publish them.
They sometimes name people — a researcher credited in an advisory, a contact on a record. Where they do, that data is already public, was published by whoever published the record, and is processed here as part of the record rather than sought out. We do not build profiles of individuals, do not enrich records with anything about a person from elsewhere, and do not publish analysis about a named individual's performance.
The legal basis for processing it is legitimate interest, Art. 6(1)(f): the interest is in the public understanding how a vulnerability disclosure ecosystem actually performs. If you are named in a public record and would rather not appear in our copy of it, write to us and say so.
Provenance
Every pipeline run keeps its stages, walk cursors and connector state, and a transform is identified by the hash of its code. That exists so a published figure can be traced back to what produced it — which is a data quality property, and also what lets us tell you where a mention of you came from.
Who else touches it
Hosting is IONOS SE (Germany), Contabo GmbH (Germany, being wound down), and our own hardware in Germany. All in the EU.
Errors are reported to Sentry, on its EU data region: exceptions, stack traces, the failing request, and a signed-in user's identifier.
No analytics service, no advertising network, no AI provider.
How long
Account and API key records last as long as the account. Audit entries are kept as the record of what was done. Ingested public records are kept as the dataset — that is what the tool is.
Your rights
Access, rectification, erasure, restriction, portability and objection, including objection to processing based on legitimate interests. An informal email is enough.
You may complain to a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.