Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GBoarse / GBoarse data processing annex

GBoarse data processing annex

The shortest annex in the set, which is a fact about the product rather than an omission.

Last updated 1 September 2026 Auf Deutsch lesen →

On this page

  1. What this annex is
  2. Nature and purpose
  3. Categories of data subjects
  4. Categories of personal data
  5. Sub-processors
  6. Security measures particular to this service
  7. Retention
  8. On termination

This applies alongside the general terms of service and privacy policy. Where they differ on a point about GBoarse specifically, this page wins.

What this annex is

The Art. 28(3) specifics for hosted GBoarse. It is part of the data processing agreement, which carries the obligations.

This is the shortest annex in the set, and that is a fact about the product rather than an omission.

Nature and purpose

Operating a simulated market for you: running the matching engine, holding the simulation state, and serving the web interface and bot API.

Categories of data subjects

Your users — a handful of people — and the operators of any bot accounts they create.

Categories of personal data

Email address, display name, role, bot flag and interface preferences; the identity link to our self-hosted Stack Auth; account ownership and configuration; API key metadata with the secret as a hash; and admin audit entries naming the acting user.

Orders, positions, trades and balances are simulation state. They are attributable to an account and therefore to a person, but they are not information about a person in the world — nothing here corresponds to any real holding.

Special categories

None, and none can arise: the system has no free-text field a person writes about themselves in.

Sub-processors

Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others. Identity runs on our own self-hosted Stack Auth. No error reporting service, no analytics, no AI provider.

Security measures particular to this service

  • API key secrets are stored as hashes; keys carry scopes, an instrument allowlist, a rate limit and an expiry, and can be revoked.
  • Administrative actions are recorded with their parameters and the decision taken.
  • Instrument mode is a declared property, so a manipulable instrument is distinguishable from one that is not.

Retention

Account and key records last as long as the account. Simulation state persists as the simulation; engine snapshots exist for restore.

On termination

As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany