Archived version
GAnalytics data processing annex
The Art. 28(3) specifics for a hosted analysis instance, and why most of what GAnalytics does is not processing on anybody's behalf.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
What this annex is
The Art. 28(3) specifics for hosted GAnalytics. It is part of the data processing agreement, which carries the obligations.
Most of GAnalytics is not processing on anybody's behalf: it ingests public records and publishes analysis, and for that we are the controller in our own right — see the privacy notice. This annex covers the part where you have an instance and we run it for you.
Nature and purpose
Operating an analysis instance for you: running your connectors and pipelines, holding the resulting datasets, and serving your dashboards, posts and API.
Categories of data subjects
Your people who hold accounts in the instance, and any individual named inside a public record your connectors ingest — a credited researcher, a listed contact.
Categories of personal data
Accounts: identity and sign-in details, roles, module settings.
API keys: name, scopes and a hash of the secret. Never the secret.
Content you create: dashboards, widgets, posts.
Audit log: who did what and when.
Ingested records: whatever the public source contains, including any individual named in it.
Special categories
Not sought. A public vulnerability record is not a place they ordinarily appear, but the content of an ingested record is not something either of us authors.
Sub-processors
Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and for this service:
- Sentry (Functional Software, Inc.), EU data region — error and performance reporting.
Security measures particular to this service
- API key secrets are stored as hashes; keys carry scopes and are issued per instance.
- Pipeline provenance is recorded — stages, walk cursors, connector state, and a hash identifying the transform code — so a datum can be traced to the run that produced it, which is what makes a correction possible rather than a guess.
- The audit log records actions in the instance.
Retention
Account and key records last as long as the account. Datasets last as long as you keep them; they are the product of the tool and there is no automatic expiry.
On termination
As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle.
Version identifier
ganalytics-dpa-2026-09-06
Content hash, SHA-256
6e513f6e427562e579f0df5a864329ad4e55754bd2f1a2a2e8ce6e5ee2263036