Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE
Apps / GOpenCDR / GOpenCDR data processing annex

GOpenCDR data processing annex

The Art. 28(3) specifics for GOpenCDR's enterprise services: what is processed on the customer's behalf, about whom, who else touches it, and for how long.

Last updated 27 September 2026 Auf Deutsch lesen →

On this page

  1. What this annex is
  2. Nature and purpose of the processing
  3. Categories of data subjects
  4. Categories of personal data
  5. Processing operations
  6. Sub-processors
  7. Security measures particular to this service
  8. Retention
  9. On termination

This applies alongside the general terms of service and privacy policy. Where they differ on a point about GOpenCDR specifically, this page wins.

What this annex is

The data processing agreement is the Art. 28 GDPR agreement for every hosted service. This annex names what is particular to GOpenCDR's enterprise services, the private mirrors, private namespaces and organisation management described in the enterprise terms. Where the annex and the agreement differ on a point about GOpenCDR, the annex wins.

It does not cover registration data in hosted TLDs, for which Gelhaus Solutions and the TLD operator are joint controllers under the joint controller arrangement, nor anything we process as a controller under the GOpenCDR privacy notice.

Nature and purpose of the processing

Operating the enterprise services the customer has ordered: resolving queries from the customer's networks on its private mirrors; serving the customer's private zones on those mirrors; managing the customer's members, roles, service accounts and single sign-on; and streaming audit events to the customer. Nothing else.

Categories of data subjects

  • The customer's staff and the other members it admits.
  • People and devices whose DNS queries reach the customer's private mirrors.
  • People or devices named in the customer's private zones, where the customer names any.

Categories of personal data

  • Member data: the name and email address the customer's identity provider delivers, the single sign-on subject identifier, group memberships provisioned over SCIM, roles, sessions and passkeys.
  • Resolver data: the client address, the name and type queried, the time and the response code, and only where the customer's configuration switches query logging on. By default a private mirror keeps no log that links a query to a client address for longer than 24 hours, and then only for debugging.
  • Zone data the customer enters. Host names can identify a person or a device.
  • Audit events about the customer's organisation.

The service is not built for special categories of personal data, and the customer does not put them into zones or names.

Processing operations

Storing, resolving, publishing zones to the customer's mirrors, controlling access, streaming audit events, backing up and deleting.

Sub-processors

  • IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany: server hosting in Germany.
  • Sentry (Functional Software, Inc.), on its EU data region: error reports. It is configured to receive no user identifier, cookie, header, request body, query string or value of a local variable. An error report carries the exception, its stack trace, the route that failed and the request identifier.

A private mirror runs either on our servers at IONOS in Germany or on infrastructure the customer provides, as the order states. On the customer's own infrastructure, we reach it only through the mirror agent.

Security measures particular to this service

  • The customer's data is kept apart from every other customer's in data stores, caches, logs, backups and support tooling.
  • Query logging is off unless the customer switches it on. Rate limiting keeps its per-address counters in memory only.
  • Members sign in through the customer's single sign-on, for domains whose ownership has been verified; administrative roles need a passkey.
  • Mirror agents sign every request with their own key. Keys are held in our key store and never leave it.
  • Audit records are append-only, and every change in the customer's organisation writes one.

Retention

  • Resolver query logs: as the customer configures them, at most as long as the order allows. None by default, and debugging logs are deleted within 24 hours.
  • Member data and zone data: for the term of the order, then returned or deleted as the data processing agreement provides.
  • Audit events: for the term of the order. The customer keeps its own copy through the audit stream.
  • Backups expire on their own cycle and are restored only to recover the service.

On termination

The customer can export its data at any time. After an order ends, the data stays available for 30 days for export and is then deleted, as the data processing agreement provides.

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform Billing
  • GOpenCDR

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany