Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE

Archived version

GControl terms

How GControl is licensed, what your instance will and will not do when we ask, and the two containment actions you cannot switch off.

Version 2026-09-06 Published 6 September 2026

This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.

On this page

  1. What this covers
  2. Licence
  3. Standalone operation
  4. What it sends us, and what it never does
  5. What we can ask your instance to do
  6. Containment, which you cannot switch off
  7. Support
  8. Your keys
  9. Updates
  10. Availability and support scope
  11. If it ends
  12. No warranty, no service level, and limited liability

What this covers

GControl runs applications on infrastructure you control: installing them, updating them, holding their licences, taking their backups and keeping an audit trail of what happened. It talks to GPlatform for licensing, catalogue and support, and that conversation is the part of it these terms spend most of their words on.

The service it enrols into is a separate product with separate terms: see GPlatform Control. This page is about the software you run.

These sit alongside the general terms of service.

Licence

GControl is licensed under the Elastic License 2.0, plus one additional restriction from us: commercial use requires a business licence.

That addition is stated separately because ELv2 does not contain it. ELv2's own limitations are three — you may not provide the software to others as a hosted or managed service, may not circumvent the licence-key functionality, and may not remove or alter the licensing, copyright or other notices — and it otherwise permits a company to run the software commercially for its own internal purposes. Our additional term removes that permission.

Non-commercial use on your own infrastructure is free of charge. Commercial use of any kind, including internal use inside a business, needs a business licence from us.

Applications installed through GControl carry their own licences and their own entitlements. A licence covers named applications, a tier, and caps; what you hold is what the signed lease says you hold.

Entitlements are enforced by a signed lease, refreshed continuously. A revoked licence is not a command we send you — it simply drops out of the next lease, and the software acts on that by itself. This matters in one direction worth stating: an instance that never speaks to us again still loses a revoked entitlement when the lease it holds expires. It is not a remote kill switch for the software; it is the licence ending on its own terms.

Standalone operation

GControl runs with no upstream at all. Everything except licence-dependent features works standalone, and an instance can run for months before it ever enrols. When it does enrol, it hands over the ledger it accumulated in that window, because a fact that only exists once we hear about it does not exist when it matters.

What it sends us, and what it never does

Set out in full in the privacy notice. In summary: every call is initiated by your instance and there are no inbound connections into your network, ever. The heartbeat carries versions, module lists, health, counts and daily usage aggregates. It does not carry your end users' data, the readings behind the aggregates, your backup contents, or any credential.

What we can ask your instance to do

The vendor can issue commands. Your instance decides whether to carry them out, and you configure that.

Read verbs — describe the instance, list apps and modules, report health, tail the audit log, report backup status — are on by default and you can switch any of them off.

Write verbs — apply a licence, restart or start an app, change settings, install or upgrade or remove a module, run a backup — are off by default. You turn on what you want us to be able to do.

Privileged verbs — open a support session, unseal, open a shell, restore a backup, pin a release — always require a local person to consent at the time of use, and that consent expires. Consent that never expires is an approval somebody gave once and a vendor holds forever.

Every command is recorded with who asked, why, what your side decided and what happened.

Containment, which you cannot switch off

Two verbs are not yours to disable, because a containment action you can veto is not containment.

Freeze stops deployments and signs out app sessions. Your data stays readable and starting things again is yours to do from your own screen.

Seal does all of that and additionally discards the key that makes wrapped data readable, which takes an instant regardless of how much data there is. It is undone only by an unseal, which needs somebody here to verify you out of band and an admin on your side to approve the result. A seal is refused outright unless the key can be escrowed first, because a discard nobody can undo is not containment.

These are the only grounds. Containment is used where use of a licence is unlawful, where an instance is causing damage to others or to the service, or where a court or authority requires it. There are no others, and this list is exhaustive.

Freeze first. Where a Freeze is enough to deal with the situation, a Freeze is what happens. A Seal is used only where the ground cannot be met by stopping deployments alone, and the reason it could not is recorded with it.

A lapsed subscription is never a ground. Not paying is a commercial matter, and its consequences are commercial: a subscription lapses, a tier drops, an entitlement leaves the next lease. We will not Freeze or Seal an instance because a subscription lapsed, a payment failed, or an invoice is disputed, and nothing in the GPlatform Control terms or the GPlatform Billing terms about suspension changes that. Suspension there stops a service we run. It does not reach containment on your instance.

You are told. Before it happens where that is possible, and immediately afterwards where it is not, with the ground and the reasoning. Both halves of any containment go into your audit chain.

It is reversed as soon as the ground falls away. We will unseal without undue delay once the situation that justified it has ended, and it is not held open to obtain anything from you.

If you disagree, say so to the address in the legal notice and it will be looked at by a person. Where containment turns out to have been wrong, it is reversed and the audit chain records that too.

Support

A support session is something you approve. We ask, naming the scope, the reason and who is asking; one of your admins approves or denies it; and the expiry is enforced on your side so that a compromised upstream cannot extend it.

A shell is a separate decision. Approving a support session does not approve a shell, and a shell grant is considerably shorter, because a shell is granted for the thing somebody is doing now. Where one is opened it is recorded to a transcript on your instance, and both the approval and the fact that somebody actually used it are kept.

Your keys

Each instance gets a lockdown keypair. The public half lives with you; the private half is generated and held by us, in Vault, per instance and never per org, so one exposure cannot unlock every customer. It moves only during an unseal, after a human has verified the requester out of band.

We hold it so that a sealed instance can be recovered. That is the whole purpose, and it is the reason a seal is refused when escrow is not possible.

Updates

Release offers ride the heartbeat response and your own channel policy decides what to do with them. Security updates apply under your policy, bounded by your deferral window. Pushing a specific release outside that is a privileged verb and needs your consent at the time.

Availability and support scope

Standalone operation is not a degraded mode and no uptime of ours is required for it. Where we are unreachable, licence-dependent features continue on the grace period in the lease you hold and then stop.

No service level is promised unless a separate signed agreement states one.

If it ends

The software keeps running. What ends is the licence: entitlements drop out of the lease, and features behind them stop. Your applications, their data and their volumes are on your infrastructure throughout, and nothing here gives us the ability to remove them.

No warranty, no service level, and limited liability

This product is provided as it is and as it happens to be available, without warranty of any kind, and is used at your own risk. No uptime, response time or restoration time is owed unless a separate signed agreement states one. Where it is provided free of charge, liability is limited to intent and gross negligence (Section 521 BGB).

To the fullest extent the law permits, we are not liable for damage arising from its use, its unavailability, or any loss of data — and keeping your own backups is your responsibility. The limits that mandatory law requires, the exclusions that apply within them, and the additional cap that applies to business customers are set out in full in the general terms of service, which govern this product and are not restated here.

Version identifier

gcontrol-terms-2026-09-06

Content hash, SHA-256

7beb414ea609b1e685decf34dc60450625e95a867fd531177de12713407ceced

All documents →

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany