Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE

Archived version

GControl data processing annex

The Art. 28(3) specifics for hosted GPlatform Control, and why a self-hosted instance is a different relationship entirely.

Version 2026-09-06 Published 6 September 2026

This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.

On this page

  1. What this annex is
  2. Nature and purpose of the processing
  3. Categories of data subjects
  4. Categories of personal data
  5. Processing operations
  6. Sub-processors
  7. Security measures particular to this service
  8. Retention
  9. The limit on erasure
  10. On termination

What this annex is

The Art. 28(3) specifics for hosted GPlatform Control. It is part of the data processing agreement, which carries the obligations.

Where you run GControl on your own infrastructure you are the controller and there is no processing on your behalf to agree — but we do receive the small upstream payload described in the privacy notice, for which we are the controller in our own right. The two are different relationships and it is worth keeping them apart.

Nature and purpose of the processing

Operating the control plane for your applications: holding their licences and entitlements, carrying their catalogue and releases, recording their health and usage, taking and tracking their backups, and keeping the audit trail of what was done to them.

Categories of data subjects

  • Your administrators and operators — the people who hold accounts in the control plane and act in it.
  • The end users of applications you run, only as counts. No end-user identity is processed here.
  • People named in an audit entry as the actor of an action.

Categories of personal data

Account data for your people in the control plane: name, email address, role, session and recovery records.

Audit entries: who did what, when, the subject of the action, the reason given, and the hash chaining the row to the one before it.

Command records: which verb was asked for, by whom, with what reason, what your side decided, who consented, and the outcome.

Support session records: the scope and reason of a session, who requested and who approved it, when it expired, and whether a shell was approved and opened.

Operational measurements: health samples, meter buckets, seat and user counts, instance and application versions. These describe systems rather than people, with the exception of the counts, which are numbers and not identities.

What is not processed

The end users of your applications, their content, their identities. The readings behind a usage aggregate. Your backup contents. Any credential of yours.

Processing operations

Collection, storage, retrieval, use, restriction, erasure within the limits below, and backup. Containment actions — freeze, seal — where the terms allow, each recorded on both sides.

Sub-processors

Those named in the general agreement — IONOS SE and Contabo GmbH, both in Germany, plus our own hardware in Germany — and no others for this service.

Security measures particular to this service

  • Instance authentication is a per-instance identifier plus a rotating bearer secret over TLS.
  • The audit chain is hash-linked and anchored, so a rewrite is detectable.
  • Lockdown keys are held per instance and never per org, so one exposure cannot unlock every customer, and the private material lives in Vault with only a path in the database.
  • Key custody is registered, and the rule that the two halves of a dual signature never share custody is recorded so that it can be checked rather than assumed.
  • Health values are filtered against the application's declared manifest keys before they are stored at all.
  • Support access requires approval on your side, a shell requires a second and shorter approval, and expiry is enforced on your side so that a compromised control plane cannot extend it.

Retention

Health samples: 90 days. Meter buckets: kept as the usage and billing record. Instance, licence and entitlement records: for the term and afterwards as the record of it. Audit entries: for the integrity of the chain — see the limit below.

The limit on erasure

The audit chain is hash-linked, which is what makes it evidence, and individual rows are therefore not deletable in the ordinary way. Where erasure of an audit entry is required, we will discuss what is achievable — ordinarily redaction of a field rather than removal of a row.

On termination

As set out in the general agreement: return or deletion at your choice, 30 days of export availability by default, backups expiring on their own cycle.

Version identifier

gcontrol-dpa-2026-09-06

Content hash, SHA-256

4d7dc7fda2af43f2515d654ff141230bb5f6e1af5188358464d8cf6d1b340e60

All documents →

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany