GeGroups data processing annex
The Art. 28(3) specifics for hosted GeGroups, including the one category of data only you can enumerate and why delivery is not sub-processing.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GeGroups specifically, this page wins.
What this annex is
The Art. 28(3) specifics for hosted GeGroups. It is part of the data processing agreement, which carries the obligations.
Nature and purpose of the processing
Operating mailing lists and group workspaces on your behalf: accepting and distributing messages, archiving them, delivering to your members, and running the files, wiki, calendar, polls and chat attached to a group.
Categories of data subjects
- Your members — everyone subscribed to a list, and everyone who posts to one.
- Non-members who write to a list, whose address and message are processed whether or not the message is accepted.
- Your moderators and group owners, who appear as actors in the activity log.
- People on a ban list, held by address or by domain.
- Operators of third-party mail servers, whose source IP addresses appear in DMARC reports sent to your domains.
Categories of personal data
Accounts: email addresses including additional verified aliases, display name, avatar, biography, signature, locale, timezone, preferences.
Subscriptions: list, role, delivery mode, posting privilege, moderation state, moderator notes, labels, join source, approver, last delivery.
Message content: HTML and plain bodies, a sanitised copy, snippet, headers, the original raw RFC822 message, sender name and address, attachments, edit history, reactions, and moderation state with reasons.
Group content: files, photos and captions, wiki pages and all revisions with authorship, calendar events and RSVPs, polls and individual votes, chat messages, user-defined tables, drafts.
Custom member fields — defined by you. This is the one category we cannot enumerate: whatever fields you create and whatever your members answer into them become personal data in your instance, and their necessity and lawfulness are yours.
Delivery and reputation: recipient addresses, delivery outcomes, remote SMTP responses, attempt counts, VERP tokens, and per-subscription bounce state.
Activity log: actor, action, target, timestamp, IP address and user agent.
DMARC reports: reporting organisation, domain, disposition, and the source IP addresses of servers sending mail as your domain.
Special categories
Not sought by the software. Two routes bring them in anyway: a message body is free text, and a custom member field is whatever you decided to ask. Both are yours to govern.
Processing operations
Receipt, distribution, delivery by email to third-party mail providers, archiving, display according to each list's privacy settings, moderation, storage, export, restriction and deletion.
Sub-processors
Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others.
Mail is handled by our own Stalwart servers, file storage is our own MinIO, and identity runs on Hexclave, our own self-hosted fork of Stack Auth. None of those is a third party. This service uses no error reporting service, no analytics and no AI provider.
Delivery is not sub-processing
Sending a message to a member delivers it to whatever provider hosts that member's address, which may be anywhere in the world. That provider is chosen by your member and instructed by nobody. It is what email is, it cannot be configured away, and it is named here so that it is not mistaken for an undisclosed sub-processor.
Security measures particular to this service
- Your domains are authenticated with SPF, DKIM and DMARC, so mail from them is deliverable and harder to forge. DKIM private keys are held per domain.
- List privacy defaults are the cautious ones: a new list is private, joining is restricted, and only members may post.
mask_email_in_archivedefaults to off. Where an archive is public and masking is off, member addresses are public. This is a default worth changing and we will tell you so.- Archive download is off by default.
- Deletions are soft, so a moderation error is recoverable.
- Bounce handling stops delivery to repeatedly failing addresses.
Retention
Account data lasts as long as the account. Message archives last as long as the group keeps them; there is no automatic expiry, and setting a policy for your own archives is yours.
A delivered message cannot be recalled. Removing it from the archive removes our copy, not the copies in your members' mailboxes. Neither of us can reach those.
On termination
As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle.