Archived version
GPlatform Control privacy notice
What we hold once your instance has enrolled, how long we keep it, and the one place your administrators can appear.
This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.
Which half this is about
GControl runs on your infrastructure, and its privacy notice sets out exactly what leaves your instance, field by field, taken from the wire protocol. This notice is about what happens to it once it arrives, and about the account you hold with us.
For this, the controller is Gelhaus Solutions, Eichenwald 3, 49624 Löningen, Germany, egelhaus@ennogelhaus.de.
Where we host an application for you, we are the processor for what is inside it, and the data processing agreement with the annex for this service applies to that.
Your account with us
The organisation, the people you add to it, the roles you assign them, and their sign-in. Recovery codes exist; keep them somewhere that is not the account they recover.
Support conversations, and who took part in them.
What we hold about your instances
The instance identifier, the label you chose for it, its version and the protocol features its build understands, the catalogue and allowlist versions it holds, the public half of the key it signs app leases with, and its current emergency state.
Per application: its id, version, manifest reference, installed module ids and versions, condition, health report, at-rest mode, and whether it holds a licence seat.
Counts, never identities. A number of end users an application can see, with an opaque fingerprint of the datastore it counted them in so replicas can be de-duplicated. No end-user data reaches us, from any application, ever.
Usage aggregates the broker already folded, as the billing and usage record.
Chain heads — the head hash of your audit chain and of your stamp ledger. Head hashes, not entries: anchoring proves a chain has not been rewritten without telling us what is in it.
Command results, which are small, structured, and never contain application user data.
Health values, filtered against what the application declared in its manifest before they ever leave your side, kept for 90 days.
The one place your people can appear
audit.tail is a read verb and read verbs are on by default. It returns recent rows of your audit log: the sequence number, the time, the action, the display name of whoever did it, the subject, and the row hash.
It deliberately does not return the IP address or the user id, both of which your local entry does store. So what can reach us is an administrator's display name and what they did — not where they were, and never your application end users.
If you would rather that did not leave, switch audit.tail off. It is your allowlist and we will not turn it back on.
Diagnostics, which are off
Opt-in and off by default, recorded per instance with who turned them on, and revocable. The absence of a consent record means off, so a failed write can never quietly enable sharing.
When on they carry an error rate, a slow-request rate, and fingerprints of stack traces — hashes, not traces. No paths, no arguments, no data.
The key we hold
The private half of each instance's lockdown key, in Vault, one per instance. The database holds the public half and a path, never the material. It moves only during an unseal, after a person has verified the requester out of band.
Why we may do this
Providing the licensed software and the services attached to it is performance of a contract, Art. 6(1)(b) GDPR.
Licence enforcement, counting seats and usage, the integrity of the audit anchors and the security of the service are legitimate interests under Art. 6(1)(f): the interest is in the software being used as licensed, and in an incident being reconstructible afterwards.
Diagnostics are consent, Art. 6(1)(a), given per instance and withdrawable.
How long
Instance, licence and entitlement records for as long as the licence and afterwards as the record of it. Health samples 90 days. Meter aggregates as the billing and usage record. Audit anchors for the integrity of the chains they anchor. Diagnostics stop arriving the moment consent is withdrawn.
Who else touches it
Hosting on servers rented from IONOS SE (Germany) and Contabo GmbH (Germany, being wound down), and on our own hardware in Germany. All in the EU, no transfer to a third country. No analytics service and no advertising network.
Your rights
Access, rectification, erasure, restriction, portability and objection, as in the general privacy policy. An informal email is enough.
You may complain to a supervisory authority; the competent one here is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
Version identifier
gplatform-control-privacy-2026-09-06
Content hash, SHA-256
d2f0e5a6baad4aff0a00b46968d2304e62a391812ff81f789db405ac96baab5b