GOpenCDR privacy notice
What GOpenCDR processes about registrants, operators and the people who use its resolver, for how long, who else touches it, and what the public log keeps for good.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GOpenCDR specifically, this page wins.
Who is responsible
The controller is Gelhaus Solutions, a sole proprietorship of Enno Gelhaus, Eichenwald 3, 49624 Löningen, Germany, reachable at egelhaus@ennogelhaus.de.
For names in a TLD that we host for a TLD operator, that operator is a joint controller with us for the registration data. The essence of that arrangement is published as the joint controller arrangement. You may exercise your rights against either of us, and we are the point of contact for both.
This notice covers GOpenCDR. The website around it is covered by the site's privacy policy.
The short version
- Your account holds an email address, a password hash and your passkeys. No name, no postal address, no phone number.
- The audit log keeps your IP address for 90 days, and after that only a keyed hash that cannot be turned back into the address.
- Registrant data is kept for 12 months after an account or a domain ends, then deleted.
- RDAP shows your domain, not you. Everything about you in it is redacted.
- The public transparency log is permanent. It names domain names, TLD strings and account identifiers, never an email address, a name or an IP address, and what it names cannot be erased.
- One cookie, set when you sign in, and strictly necessary, so there is no consent banner.
- No trackers, no analytics, no advertising anywhere in GOpenCDR.
- The servers are in Germany. Error reports go to Sentry's EU data region with every category of personal data switched off.
Your account
When you create an account we store:
- your email address and when it was verified;
- a hash of your password (argon2id), never the password itself;
- your passkeys: the credential identifier, its public key, its signature counter, its transports, the authenticator model identifier (AAGUID), whether it is backed up, the label you give it, and when it was created and last used. The private key never leaves your device;
- the state of the account: active or locked, failed sign-ins and how long a lock lasts;
- the roles you hold and who granted them;
- your sessions: a hash of the session token, when each began, was last used and ends, the last time you confirmed with a passkey, and whether it was ended early;
- your API keys: the name you give each, its public prefix, a keyed hash of its secret, its permissions, its expiry (at most 400 days) and when it was last used;
- the invitations you redeemed;
- one-time tokens for the links and codes we mail you, stored only as hashes. A verification link works for 24 hours, a password reset link for one hour, and a code for 15 minutes.
Why. To provide the account and the registry you signed up for (Art. 6(1)(b) GDPR), and to keep them secure (Art. 6(1)(f) GDPR, the legitimate interest being the security of the service and of your account).
Mail from GOpenCDR is plain text, sent from noreply@cdr.gplatform.org by our own mail server. It contains no tracking pixels and no links that identify who opened it.
Your names
For each name you register we store the name and its TLD, its state and statuses, its nameservers and any glue addresses, its DS records, when it was created and last changed, and which account holds it. A TLD with a stricter registration policy may collect more, and its policy is where it tells you what and why.
Why. Registering and publishing a name is the service (Art. 6(1)(b) GDPR).
What becomes public. The name, its nameservers and its DS records are published in the TLD zone, because that is what makes a name resolve. RDAP answers for the name with its status, dates, nameservers and DNSSEC data, and marks everything about you as redacted, following RFC 9537. Who may see the redacted parts, and on what grounds, is set out in the registration data disclosure policy.
The audit log
Every change and every sign-in attempt writes an audit record: who acted (an account, an API key, a mirror or the system), what was done, to which object, whether it succeeded, a request identifier, and a keyed hash of the IP address it came from. The hash is an HMAC-SHA256 under a secret held in our key store. It can show that two events came from the same address, and it cannot be turned back into the address.
The raw IP address is kept apart and deleted after 90 days by a scheduled job that records what it deletes. After that, only the hash remains.
Audit records are never changed or deleted. They are the evidence of what happened to every name and every root change, and they are kept for as long as the registry exists. Once an account is erased, the records about it name only its identifier.
Attempts at signing in, signing up and requesting reset links are counted per address and per account in short fixed windows, keyed by the same hash and never by the address itself. Expired windows are deleted.
Why. Security, defence against abuse, and accountability for every change (Art. 6(1)(f) GDPR).
Request logs
The web server and the API write one line for each request: the IP address, the time, the method and path, the status, how long it took, the user agent and a request identifier. Cookies and authorization headers are removed before anything is written, and application logs are built never to contain an email address or registrant data. Request logs are deleted after 14 days.
Why. Operating the service, finding faults and defending it against attacks (Art. 6(1)(f) GDPR).
The public transparency log
GOpenCDR publishes an append-only log of root changes, key events, policy changes, vetoes, abuse actions and role grants at the root, as a Merkle tree with signed checkpoints. Anyone can check that we never showed different histories to different people.
An entry holds identifiers only: the account identifiers of whoever holds a root role and of whoever proposed or decided a change the log records, and the domain names and TLD strings an entry concerns. It never holds an email address, a name or an IP address.
It cannot be erased. Every checkpoint is signed over the whole log, so removing a single entry would invalidate every checkpoint after it and destroy the one thing the log exists to prove. We rely on Art. 6(1)(f) GDPR, the legitimate interest being a root anyone can verify, and we regard the integrity of an append-only public record as a compelling legitimate ground in the sense of Art. 21(1) GDPR. What we can do, and do when an account is erased, is delete the email address and credentials behind an identifier, so that nothing we hold connects it to a person any more.
Abuse reports and requests from authorities
When you report abuse, we process what you send, including your email address, to handle the report (Art. 6(1)(f) GDPR). We do not pass your identity to the registrant unless you agree or the law requires it. Abuse cases are kept for 12 months after they are closed.
Requests from courts and authorities are recorded with their legal basis and with what we disclosed (Art. 6(1)(c) GDPR), and counted in the transparency report every six months.
The public resolver
GOpenCDR runs a public resolver at dns.cdr.gplatform.org, over DNS over TLS and DNS over HTTPS.
- No query log by default. The resolver writes no log that links a query to the address it came from.
- Debugging is the only exception. When a fault has to be investigated, such logging can be switched on for as long as that takes, and anything it records is deleted within 24 hours.
- Statistics are aggregates. Query counts by TLD and response code and cache figures are kept, with minimum counts so that no single client stands out, and with no addresses in them.
- Rate limiting happens in memory. Counters per address protect against floods. They are never written to disk and are gone within minutes.
- Your address stays with us. The resolver sends no EDNS Client Subnet, so no other server learns your address or your network, and it minimises what it asks each server (QNAME minimisation), so each sees only the part of the name it needs. Encrypted queries and answers are padded, so their size says less about them.
- Names outside GOpenCDR are resolved through the IANA root, as any resolver does. The servers asked see the resolver's address, not yours.
Why. Providing the resolver you chose to use and keeping it working and safe (Art. 6(1)(f) GDPR).
Mirrors in GOpenCDR's default pool are bound to the same rule: no log that links queries to client addresses for longer than 24 hours, and then only for debugging. A mirror outside the default pool is run by its own operator, who is responsible for what it logs. Our authoritative nameservers answer resolvers rather than people and keep no per-query log, only aggregate counts.
Mirror operators
If you run a mirror, we also store its public addresses and host names, the public key of its agent, a hash of its enrolment token, and the results of every conformance check and probe of its public service, for as long as it is enrolled and 12 months after (Art. 6(1)(b) GDPR).
Councils
If you hold or represent a seat on a GOpenCDR council, your name, the seat and the capacity you act in are published, and so are your votes, because recorded votes are how the councils are held to account (Art. 6(1)(f) GDPR). Ballots in elections are secret. The governance charter sets this out.
Your device
GOpenCDR sets one cookie, __Host-gocdr_session, and only when you sign in. It carries a random token and nothing else. Script cannot read it, the browser sends it only over HTTPS and never with a request started by another site, and it ends with your session: after 7 days without use or 30 days at most, or for root and TLD roles after 30 minutes without use or 12 hours at most.
That cookie is strictly necessary to provide the service you asked for, so no consent is needed for it (Section 25(2) No. 2 TDDDG) and there is no banner. Nothing else is stored on or read from your device, and no GOpenCDR site or client carries analytics, trackers, advertising or fingerprinting.
Who else processes it
- IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany, provides the server in Germany on which the portal, the API, the databases, the DNS servers and the mail server run.
- Sentry (Functional Software, Inc.), on its EU data region, receives error reports. It is configured to receive no user identifier, cookie, header, request body, query string or value of a local variable: an error report carries the exception, its stack trace, the route that failed and the request identifier. The data is stored in the EU. The company is based in the United States, so access from there cannot be ruled out, and it is covered by the EU standard contractual clauses in Sentry's data processing agreement.
Our signing keys and encrypted backups are kept on our own hardware in Germany. Beyond that, registration data goes to the operator of the TLD it belongs to, and to courts and authorities only under the registration data disclosure policy. What is public is listed above.
How long
- Account data: while the account exists, and 12 months after it is closed. Then the email address and every credential are deleted.
- Registration data: while the registration exists, and 12 months after it ends.
- Raw IP addresses in the audit log: 90 days.
- Audit records: for as long as the registry exists, naming only an identifier once an account is erased.
- Request logs: 14 days.
- Idempotency records, which let a retried request return its first answer: 24 hours.
- Abuse cases: 12 months after they are closed.
- The transparency log: permanently.
- Resolver query logs: none by default, and debugging logs deleted within 24 hours.
- Backups are not edited. They expire on their own cycle and are restored only to recover the service.
The 12 months cover abuse, transfer and dispute follow-up. Where a statutory retention period applies, such as for invoices, it applies instead.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR). Write to the address above; an informal email is enough, and we answer within 30 days.
You have the right to lodge a complaint with a supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
An email address is required to hold an account; without one, we cannot provide it. There is no automated decision-making within the meaning of Art. 22 GDPR. Locking an account for 15 minutes after five wrong passwords in a row is a security measure, not a decision about you.
Changes
This notice changes when GOpenCDR does. Every version is kept in the document archive.