Archived version
GPlatform Billing data processing annex
Why we are mostly a controller here rather than your processor, and the narrow case where we are not.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
Read this part first
For almost everything GPlatform Billing does, we are not your processor. Taking your money, invoicing you, keeping the accounting records and meeting our tax obligations are things we do as controller, in our own right and under our own legal duties. You cannot instruct us to stop keeping an invoice, and an annex that implied otherwise would be misleading.
The privacy notice is therefore the document that governs most of this relationship.
This annex supplements the data processing agreement and applies to the narrow part where we do act on your instructions: the contact and membership data you enter about your own people so that they can use the billing console.
Subject matter and duration
Maintaining the accounts of the people you add to your organisation, for as long as the arrangement runs.
Nature and purpose
Providing access to the billing console for the people you nominate, and recording what they did with it.
Categories of data subject
The people you add to your organisation, and the people you invite to it.
Categories of personal data
Name, email address, role, sign-in and session records including IP address and user agent, invitation records, and the commercial actions taken by each person.
Not payment instruments, which we never hold. Not the end users of any application you run, whose data does not reach this service at all.
Processing operations
Receipt, storage, display in the console, sending invitation and notification email, export, restriction and deletion.
Sub-processors
Stripe Payments Europe, Limited (Ireland) as payment service provider — noting that for the payment itself Stripe acts as its own controller rather than as our sub-processor.
IONOS SE (Germany) for outgoing email, and hosting on servers rented from IONOS and Contabo GmbH (Germany) and our own hardware in Germany.
You will be told before a new sub-processor is engaged and may object.
Technical and organisational measures
Passwords are hashed with Argon2. Session and invitation tokens are stored as digests, never in a usable form. Roles are enforced per organisation. GPlatform Control is reached over mutually authenticated TLS on the local network and never through the public proxy, with a credential scoped to automated licences that cannot touch a staff-issued one. The commercial trail is append-only and no code updates a row in it.
Assistance
We will help you meet a data subject's request and your obligations under Art. 32 to 36, and will tell you without undue delay about a personal data breach affecting your data.
Deletion
On the end of the arrangement, the account and membership records of your people are deleted or returned at your choice.
This does not reach the invoices. Accounting records must be kept for ten years under Sec. 147 AO and Sec. 14b UStG, and they contain the billing identity of your organisation. That retention is a legal obligation on us as controller and is outside the scope of any instruction you can give.
Version identifier
gplatform-billing-dpa-2026-09-06
Content hash, SHA-256
1550ab271c22f98bdf49d73d65415d715067ba5f13b1673ace00283bb10fd4d2