GOpenCSR terms
What one G Open account gives you across GOpenCDR, GOpenCNR and GOpenCSR, who may hold one, how changes are signed, how accounts and posts are restricted and challenged, and what stays on record for good.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GOpenCSR specifically, this page wins.
What GOpenCSR is
GOpenCSR, the Gelhaus Open Community Services Registry at csr.gplatform.org, holds what the G Open registries share. GOpenCDR registers names and GOpenCNR allocates addresses and runs a network; GOpenCSR signs people in for both and keeps accounts, organisations and roles, four-eyes approvals, councils and motions, the policy system, abuse cases, audiences, notifications and mail, consent records, the API front door, and the one transparency log for all three services at csr.gplatform.org/tlog.
These terms cover your account and what you do in GOpenCSR itself. They sit under the general terms of service, which carry the liability limits, the governing law and everything else that is not particular to GOpenCSR, and they are read together with the acceptable use policy, which you accept with them. The organisation verification terms are part of these terms. What we process about you is in the privacy notice. The provider is Gelhaus Solutions, whose details are in the legal notice. Tier 0 is the root operator role across all three services, and Gelhaus Solutions holds it.
One account for three services
One G Open account signs you in to GOpenCDR, GOpenCNR and GOpenCSR. Sign-in happens only on csr.gplatform.org: every page that asks for your password or your passkey shows that address and names the product that sent you there. When you sign in to GOpenCDR or GOpenCNR, that product receives your account identifier, your email address, your display name and your roles from GOpenCSR. Mail about your account comes from csr@gplatform.org, and a reply reaches us.
At sign-up you accept these terms, the acceptable use policy and the general terms. The privacy notice is there for you to read; it is not something you agree to. Further documents apply as you take on more:
- Names. When you register or manage a name: the GOpenCDR terms and the GOpenCDR acceptable use policy, and GOpenCDR's documents for any role you take on there.
- Addresses and the network. When you become a GOpenCNR member: the GOpenCNR terms and the GOpenCNR acceptable use policy, and the network participation agreement for each router you connect.
- The API. When you create an API key: the API terms.
- Councils. When you take a council seat: the council conduct code.
These terms govern the account; a registry's terms govern what you hold in that registry. Where two documents speak to the same point, the one written for the role in question wins on that point, and an agreement signed by both sides wins over anything published here. For the account itself these terms apply, and GOpenCDR's terms govern names.
Who may hold an account
Accounts are for people aged 16 or over, one account to a person. If you are under 18, you confirm at sign-up that a parent or guardian agrees, and we may ask for proof. Without that consent, the contract is not valid (Sections 107 and 108 BGB).
Organisations take part through their people. Any account may create an organisation, and whoever creates it becomes its owner. Once it is verified under the organisation verification terms, the organisation can hold resources in both registries. The holders of resources are people and verified organisations: companies, associations, public bodies and registered groups.
Sanctions screening
An account needs only a verified email address. When you first become a holder of resources, as a GOpenCNR member or a GOpenCDR registrant, you give your legal name and your country. Only Tier 0 sees them; they are never public and never in RDAP, and they are kept while you are a holder and for 12 months after. An organisation is screened by its verified name and country.
Every holder is screened against the EU's consolidated list of financial sanctions when it first becomes a holder and every day at 03:00 UTC, because EU sanctions law forbids making resources available to anybody on it. The screening compares those names and countries with the list, and it finds near matches as well as exact ones.
A possible match places holds at once, automatically:
- no new names and no new addresses;
- no transfers out;
- what already exists keeps working.
A person at Tier 0 then reviews the match. If it is not the same party, Tier 0 clears it and records why. The holds are lifted, and that holder is not flagged again for that list entry unless the entry changes. If it is the same party, Tier 0 confirms the match under four-eyes, with a second Tier 0 person approving it; while Tier 0 is one person, an approval made alone is flagged as decided alone. A confirmed match blocks the holder's names and addresses together and becomes a case under the abuse and sanctions policy.
A match when someone first becomes a holder places the same holds: the account exists, but it can obtain nothing until the match is cleared. If the list cannot be downloaded, the previous day's copy is used and the download is tried again.
The holds are automated decisions within the meaning of Art. 22 GDPR. They are permitted because they are necessary to perform the contract and required by Union law, the EU sanctions regulations (Art. 22(2)(a) and (b) GDPR). A person at Tier 0 reviews every match, and you have the right to obtain a person's intervention, to put your point of view and to contest the decision (Art. 22(3) GDPR).
Only the holder and Tier 0 know that a review exists. Anybody else sees only that the holder cannot be added right now. No screening outcome tied to a holder is written to the public transparency log, and the transparency report gives counts only. How to challenge a confirmed match is set out under "What may be restricted, and how it is decided" below.
Signing up: invitations and vouching
Sign-up is by invitation, and whoever invites you vouches for you. An existing account holder or Tier 0 can invite.
- An invitation is for one email address, works once and is valid for 30 days. It carries a code such as
GR-7Q4M-2KXD, who invited you, who vouched for you, and an optional note. It can be withdrawn until it is used. - The voucher is named on any case against the invited holder for 12 months after they join. Being named does not make the voucher liable for what the other person does. It puts on record who brought them in.
- Each account can vouch a limited number of times. The limit is shown in the account.
After creating your account, you confirm your email address with a code, valid for 15 minutes, or a link, valid for 24 hours, and then add a passkey.
Signing in and keeping your account safe
- Passwords have at least 15 characters and are stored only as an argon2id hash. Five wrong passwords in a row lock the account for 15 minutes.
- Passkeys are bound to
csr.gplatform.organd work nowhere else, and the private key never leaves your device. Keep a second passkey: with only one, losing it leaves you only your recovery codes, each of which works once. - Root roles sign in with a passkey every time. A password alone is not enough for them.
- Step-up. A sensitive action, in any of the three products, asks you to confirm with your passkey on
csr.gplatform.org. A confirmation counts for 5 minutes. - Sessions end after 7 days without use and after 30 days at most; for root roles, after 30 minutes without use and after 12 hours at most. Signing out everywhere or resetting your password ends your sessions in all three products, and a product you were signed in to stops accepting that sign-in within 10 minutes.
Keep your password, passkeys, recovery codes and keys to yourself. You are responsible for keeping them safe and for what is done with your account. If you suspect that somebody else has access, sign out everywhere and tell us at once at contact@gplatform.org.
Signing changes
Every change you make to a registry object is signed by you. In the browser, the change is shown to you in a signing step on csr.gplatform.org, and your passkey signs its hash. For automation, an Ed25519 key that you register under a passkey signs instead. Both are logged.
Signing a change declares that you want exactly the change shown, for the holder you act for. Check it in the signing step, not on the page behind it. If the change moves after you open it, its hash no longer matches and nothing is signed. A change that needs your signature applies only once it is signed.
The receipt of a signed change is its entry in the transparency log, with a proof that the entry is included in the log. Anyone can check the signature against the holder's keys, and witnesses cosign the log's checkpoints, so a change cannot appear in one history and be missing from another.
An automation key signs only what you registered it for. Revoke it, or replace it with a new key, when it is no longer needed or may be exposed. The signatures it has already made stay valid.
Organisations, roles and acting for a holder
People act for a holder through roles:
- Owner: everything, including who the other owners are. An organisation always has at least one owner.
- Admin: runs the organisation, its people, their roles and its resources.
- Tech: makes technical changes to the resources the role covers.
- Abuse: receives the holder's abuse cases and answers them.
- Read-only: sees what the role covers and changes nothing.
A role on the holder covers everything it holds; a role on one resource covers what sits under that resource. Every grant and every revocation is logged, and a role grant is never deleted: a revoked grant stays in the history.
When you act in a role, you act for the holder, and the holder is bound by what you do within that role. An organisation answers for whom it admits and for the roles it gives. When your authority to act for an organisation ends, an owner or admin revokes your role.
Every holder has a public abuse relay address, abuse+<handle>@relay.csr.gplatform.org, through which anyone can reach it about abuse. It is mandatory, and the holder answers what arrives through it. A holder's admin and tech contacts are seen only by Tier 0 and are redacted in RDAP.
What is public about a holder. For a verified organisation: its name, its handle, its verified domain with the method and date of verification, what it holds, its council seats with their representatives, and its abuse relay address. For a person: only a handle and the relay address; a person's legal name and country are seen only by Tier 0. Your display name appears on no public page and in no log entry, unless you hold a public seat.
API keys and automation
Scripts reach the registries through the API front door at csr.gplatform.org/api/{cdr,cnr,csr}/v1 with API keys, under the API terms. Every key expires, after 400 days at most, and no key ever carries Tier 0 permissions. A key does not sign: a change that needs your signature is signed in the signing step or with an automation key.
What you accepted, and when
The account records which version of each document you accepted, and when, by its identifier in the document archive. The account lists the documents you accepted, and each opens as it read when you accepted it, not as it reads today.
Accounts that came from GOpenCDR
Sign-in moved from cdr.gplatform.org to GOpenCSR. Every account that moved is bound by these terms and the acceptable use policy from the move, without a separate acceptance step. Accounts, passkey records, sessions, roles, invitations, API keys, approval history, councils, seats, motions, elections, policies, abuse cases and consent records moved with their identifiers unchanged. The controller is the same: Gelhaus Solutions.
A passkey made for cdr.gplatform.org cannot sign in on csr.gplatform.org, so every such passkey is enrolled again once, by 31 October 2026. Until then the old passkey keeps working. After that it is refused, and the account is recovered through a one-time link to its verified email address, valid for 30 minutes, or with a recovery code; a new passkey is then enrolled and the old one removed. An account without a verified email address asks Tier 0. Password sign-in keeps working for accounts without root roles.
Taking part in governance
Each registry has its own councils: a Registry Council, a Community Council and an Operators Council. GOpenCSR has no councils of its own. It runs what they share: seats, elections, motions, sponsor votes, public comment and the community pools.
Standing is earned in each product and never crosses products. Nothing earned in one product counts toward another product's seats, votes, candidacies, support or petitions. A GOpenCNR member's free name under .gnet, for example, counts toward nothing in GOpenCDR.
Anyone signed in may suggest a motion to a council's community pool, and may comment wherever public comment is open. Suggestions are always public. Support for a community motion counts only from accounts with standing in that council's product; the number of supporters is public, their names are not.
How the councils work together across products is set out in the governance charter, shared part, which binds all three products, with a rider for each: GOpenCDR's governance charter is GOpenCDR's rider, and the GOpenCNR charter rider is GOpenCNR's. Whoever holds a seat, and Tier 0, keeps the council conduct code: interests are declared, confirmed every year and published, and an elected seat holder recuses on matters about their own resources or organisation. Once a majority of a council's seats is elected, Tier 0's block seats abstain on matters about Gelhaus Solutions' own resources; until then, Tier 0 does not recuse.
Governance records are public for good: seats held, recorded votes, tabled motions, sponsors once they are published, and public comments. A comment removed under these terms stays removed, and votes sealed under a motion with confidential votes stay sealed.
What may be restricted, and how it is decided
This section is also the information Art. 14 of the Digital Services Act requires, for accounts and for what is posted in GOpenCSR. It applies with the general terms of service, which set out in full how we restrict, suspend and end, and adds what is particular to GOpenCSR. Restrictions on names and addresses are set out in each registry's terms and in the abuse and sanctions policy.
What can be restricted.
- An account can be locked against sign-in, suspended, or closed. Its sessions can be ended, and its API keys and automation keys revoked.
- A holder can be placed under the holds described under sanctions screening above.
- A public comment, a suggestion in a community pool or the text of a motion can be removed from public view, in whole or in part. What is removed stays removed.
On what grounds. Unlawful content, a breach of these terms or of the acceptable use policy, a match on the EU sanctions list, abuse as the abuse and sanctions policy defines it, a binding order of a court or a competent authority, and a risk to the security of the account, such as a sign that somebody else has its credentials. Disagreement and criticism are not grounds, including criticism of us, of Tier 0 or of a council, and neither is any lawful opinion.
Who decides, and how. A person at Tier 0 takes every decision to restrict an account or a post on the grounds above. Reports and automated checks find candidates and never decide on their own. Three things run automatically because they follow from rules rather than from a judgement: the 15-minute lock after five wrong passwords, rate limits, and the holds a possible sanctions match places until a person has reviewed it, which are automated decisions under Art. 22 GDPR with the safeguards set out above.
What you are told. You get a statement of reasons no later than when a restriction takes effect: what was done, on which ground, under which rule and on which facts, whether it followed a report, our own findings or an automated check, how long it lasts, and how to challenge it. Before your account is suspended or closed, you are told what is intended and why, you can respond, and we decide again in the light of your response. Only in the cases the general terms name do we act before hearing you, and hear you afterwards: child sexual abuse material, a threat to life or limb, malware or phishing, a compromised account, an attack on our systems or on others, a match on a sanctions list, and a binding order of a court or an authority; even then, the statement of reasons reaches you no later than when the measure takes effect. Where the law forbids telling you, you are told as soon as it no longer does.
How to challenge it. Within six months, reply to the notice or write to contact@gplatform.org. The appeal is heard by the Registry Council of the product where it happened: the product whose council the post was in, or the product where the conduct took place. The statement of reasons names it. The person who took the decision does not vote on the appeal. While a council's seats are still held by Tier 0, before people are elected to them, Tier 0 reviews the appeal and says so in its answer. A restriction stays in place while the appeal is heard. The courts remain open to you whatever the outcome.
Points of contact. For authorities, and for anyone using GOpenCSR, the single point of contact under Arts. 11 and 12 DSA is contact@gplatform.org, in English or German. Reports of abuse and of unlawful content go to abuse@gplatform.org.
Every restriction is counted in the joint transparency report, published every six months for all three services under the transparency report policy.
When an account ends
You may close your account at any time. Closing it ends what the account holds as a person in each registry, as that registry's terms describe; under GOpenCDR's terms, for example, every registration it holds ends. What an organisation holds does not end when one of its people leaves, and because an organisation always has an owner, its last owner names another before leaving. We may close an account on the grounds and in the way set out in the section above. We may also end the contract for an account without giving reasons, with at least four weeks' notice by email, as the general terms allow for a free service. If we stop offering GOpenCSR altogether, we tell you at least 60 days ahead, as they set out.
What survives erasure. After the contract ends, you can have your data exported for 30 days, as the general terms set out, by writing to contact@gplatform.org. An account's email address and credentials are kept while the account exists and for 12 months after it ends, and then erased: the email address is replaced by a placeholder, and the credentials and the display name are deleted. The account identifier stays, because audit records are never changed or deleted and an entry in the transparency log cannot be removed; after erasure, they name only that identifier. The transparency log never holds an email address, a name or an IP address. Cases are kept for 12 months after they close. Governance records, including declarations of interest, stay public for good, with the record they belong to. What else we keep after an account ends, and for how long, is set out in the privacy notice.
When GOpenCSR is unavailable
When GOpenCSR or the transparency log is down:
- registry changes that were already accepted wait, and are logged when it returns;
- sign-in and four-eyes approvals wait;
- routers and mirrors keep running on their last signed bundle.
When sign-in moves to GPlatform SSO
When GPlatform SSO, the sign-in service Gelhaus Solutions runs for its products, takes over sign-in from GOpenCSR, the sign-in transition terms apply. It is a move between our own sign-in services, which the general terms allow. The transition terms are part of these terms and set out what moves and what stays in GOpenCSR, the one further passkey enrolment, the notice at least six weeks ahead, and the acceptance asked at your next sign-in.
Your content, your account and these clauses
The general terms of service set out in full the licence you give us to your content, how we may move your account between our own sign-in services, how new terms come into force, and how we restrict, suspend and end. This section adds only what is particular to GOpenCSR.
Your content. You keep all rights in what you submit. In GOpenCSR, the licence covers what you post and send here: public comments, suggestions to a community pool, the text of motions, declarations of interest, abuse reports with their evidence, and what you submit to verify or describe an organisation, including a register extract. It is used only to run GOpenCSR and the councils, cases and records it keeps for GOpenCDR and GOpenCNR. For that purpose only, we may sublicense it to:
- IONOS SE, which hosts GOpenCSR and our mail server for us;
- GOpenCDR and GOpenCNR, our own products, where a motion, a case or a record concerns them;
- the witnesses that cosign the transparency log, and anyone mirroring the log, to serve and verify it;
- a successor of the business and companies affiliated with Gelhaus Solutions, as the general terms set out.
Showing your content where GOpenCSR shows it (a comment to the public, a report to the holder it concerns, what an appeal needs to the council that hears it) is part of running the service and gives nobody a licence. Nobody receives a licence to your content for their own purposes.
What is permanent. These are permanent records, and this is your notice of it before you submit them: the councils' records (seats held, recorded votes, tabled motions, sponsors once they are published, and public comments), declarations of interest, and every entry in the transparency log. For them the licence has no time limit: you allow us, and anyone mirroring or verifying the record, to copy and publish them as part of it, as the general terms set out. A comment removed under these terms stays removed, and votes sealed under a motion with confidential votes stay sealed. Nothing else you submit in GOpenCSR is a permanent record.
Your account. It is the one G Open account, kept by GOpenCSR. The move between our own sign-in services that the general terms allow is, here, the move of sign-in to GPlatform SSO, set out in the sign-in transition terms.
GOpenCSR is free of charge. So when new terms come, the general terms' rule for free services applies: if you have not accepted the new version when the six weeks' notice is over, your account is restricted until you accept. You can still sign in, read, export your data, exercise your rights under data protection law, close the account and accept, and nothing else. For an export or a request under data protection law, write to contact@gplatform.org. The restriction does not itself end anything you hold: names stay registered, and allocations and routes stay in place. While it lasts, though, you cannot reconfirm names or address space, so a yearly reconfirmation that falls due goes through grace and redemption as usual, as the GOpenCDR terms and the GOpenCNR terms describe. If you, or an organisation you act for, have a paid order with us, such as under GOpenCNR's enterprise terms, your account is never restricted this way: you stay on the version you accepted until we end the paid contract at its next ordinary end date, as the general terms set out.
Changes to these terms
These terms change only as the general terms set out under "New versions of these terms". A material change is emailed to your address at least six weeks before it takes effect, and at your next sign-in you are asked to accept the new version, which is shown to you in full and linked in the document archive. A new version applies to you only once you accept it. What applies if you have not accepted it when the six weeks are over is set out under "Your content, your account and these clauses" above. Every version stays in the document archive, so the version you accepted stays readable.
Everything else
Warranty, service levels and the limits of our liability are as set out in the general terms of service, which govern GOpenCSR and are not restated here; German law applies, as they set out. GOpenCSR is provided free of charge, and for what is given away, liability is limited to intent and gross negligence (Section 521 BGB).