GPlatform Control data processing annex
The Art. 28(3) specifics for the hosted control plane, and the narrow set of personal data it can ever hold on your behalf.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GPlatform Control specifically, this page wins.
When this applies
This annex supplements the data processing agreement and applies where we process personal data on your behalf through GPlatform Control.
For most of what this service does we are not a processor at all: an instance identifier, a module version and a usage aggregate are not personal data, and for the small stream that touches people we are the controller and the privacy notice says so. This annex covers the parts where we act on your instructions.
Subject matter and duration
Operating the control plane your instances enrol into, for as long as the arrangement runs.
Nature and purpose
Licence issuance and lifecycle, catalogue and artifact delivery, instance management, key escrow, support, audit anchoring, and — where we host an application for you — running that deployment.
Categories of data subject
Your administrators and the people you add to your organisation. Where we host an application for you, that application's own users and whatever the application's own annex describes.
Categories of personal data
Your account: name, email address, role, sign-in and session records, and support correspondence.
From audit.tail, if you leave it on: the display name of an administrator and the action they took. Not their IP address and not their user id, which the verb does not return.
From diagnostics, if you turn them on: stack-trace fingerprints, which are hashes and contain no paths, arguments or data.
Nothing else. End-user data from an application on your instance does not reach this service — not in the heartbeat, not in a command result, and not in an audit anchor, which carries head hashes rather than entries.
Processing operations
Receipt, storage, licence resolution, delivery of leases and artefacts, support access under the consent rules in the terms, export, restriction and deletion.
Sub-processors
Hosting on servers rented from IONOS SE (Germany) and Contabo GmbH (Germany, being wound down), and our own hardware in Germany. All within the EU. You will be told before a new sub-processor is engaged and may object.
Technical and organisational measures
Every connection is initiated by your instance; there are no inbound connections into your network. Write verbs are off until you turn them on, and privileged verbs require a local person to consent at the time of use, with an expiry your side enforces. The escrowed lockdown key is held in Vault, one per instance, with the database holding only the public half and a path. Access on our side is role-separated and written to an audit log.
Assistance
We will help you meet a data subject's request and your obligations under Art. 32 to 36, and will tell you without undue delay about a personal data breach affecting your data.
Deletion
On the end of the arrangement, your instance, licence and account records are deleted or returned at your choice, except where the law requires them to be kept. Audit anchors are retained for the integrity of the chains they anchor; they contain head hashes and no entries, and so contain no personal data of yours.