Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE

Archived version

Data processing agreement

The Art. 28 GDPR terms for every hosted service. What a particular service processes is named in its own annex.

Version 2026-09-06 Published 6 September 2026

This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.

On this page

  1. When this applies
  2. Who is who
  3. What is processed, and for what
  4. Instructions
  5. Confidentiality
  6. Security
  7. Sub-processors
  8. Helping you meet your own obligations
  9. When something goes wrong
  10. Deletion and return
  11. Audits
  12. Liability, and everything else
  13. Changes

When this applies

This agreement applies where you use a hosted service operated by Gelhaus Solutions and, in doing so, place personal data concerning other people into it — your members, your employees, your users, the people who report vulnerabilities to you. In the language of Art. 28 GDPR you are the controller and we are the processor.

It does not apply to software you run on your own infrastructure. There we have no access to your systems and no part in your processing, and you are the controller alone. Each product's own terms say which of the two you are in.

It applies from the moment the service is made available to you until the service ends and the deletion described below has been carried out.

Who is who

The processor is Gelhaus Solutions, a sole proprietorship of Enno Gelhaus, Eichenwald 3, 49624 Löningen, Germany. Contact for anything in this agreement: egelhaus@ennogelhaus.de.

The controller is you, the account holder.

What is processed, and for what

The subject matter is the operation of the hosted service you have signed up for. The purpose is providing that service to you and nothing else.

The nature of the processing, the categories of personal data and the categories of data subject depend entirely on which service it is, and are named in that service's own annex:

  • GAdvisory
  • GControl
  • GPlatform Control
  • GPlatform Billing
  • GeGroups
  • DAnalytics
  • GAnalytics
  • GBoarse
  • Contribution Checker
  • Discord Tickets

The last two are hosted by us without being part of GHub or running on GPlatform. That changes their licence, not our obligations: where we hold personal data on your behalf, this agreement applies the same way.

Each annex is part of this agreement for the service it names.

Instructions

We process personal data only on your documented instructions, including on transfers to a third country. Your instructions are this agreement, the settings you choose in the service, and anything else you tell us in writing.

Where an instruction appears to us to breach the GDPR or another data protection provision, we will say so and may suspend that instruction until it is confirmed or withdrawn. We are not obliged to carry out an instruction we believe to be unlawful.

Where we are required by Union or Member State law to process beyond your instructions, we will inform you of that requirement before processing, unless the law forbids telling you.

Confidentiality

Everyone we authorise to process personal data under this agreement is bound to confidentiality, either by contract or by a statutory duty. That obligation survives the end of their engagement.

Access to production systems is limited to those who need it to run the service, and is logged.

Security

We take the measures required by Art. 32 GDPR. Each service's annex describes the ones specific to it, because a list of general assurances is worth very little; what follows applies across all of them.

Transport is encrypted. Passwords, API tokens and comparable secrets are stored as hashes rather than as values, and integration secrets are encrypted at rest. Access is role-based and logged in an audit trail. Backups are encrypted and their restoration is tested rather than assumed. Systems are patched on a schedule and out of it where a vulnerability requires.

We may change a measure for one at least as protective. We will not weaken the overall level of protection.

Sub-processors

You give general authorisation for us to engage sub-processors. The ones engaged for every hosted service are:

  • IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany — server hosting.
  • Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany — server hosting, being wound down.

Both are in Germany. Some services run on hardware we own, also in Germany. Mail runs on our own servers and file storage on our own MinIO; the rule we work to is that anything which can reasonably be self-hosted is.

No sub-processor engaged for a hosted service is outside the EU. Where a service engages any further sub-processor, it is named in that service's annex — GPlatform Advisory engages one, and it is on an EU data region.

That is a statement about sub-processors, and it is deliberately not the broader claim that nothing ever crosses a border. Two things can, and both are named in the annex of the service they belong to: a browser push is delivered by the push service the reader's own browser nominates, and publishing a document sends it to whoever you publish to. Neither is processing on your behalf, and both happen because somebody asked for them.

Each sub-processor is bound by a contract imposing the same obligations as this one. Where a sub-processor fails to meet them, we remain fully liable to you for its performance.

We will inform you before adding or replacing a sub-processor, giving you a reasonable period to object. Where you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected service and be refunded the unused part of any prepaid fee.

Helping you meet your own obligations

Taking into account the nature of the processing, we will assist you:

With requests from data subjects (Arts. 12–23). Where somebody exercises a right against you and the data is in our systems, we help you find it, correct it, export it or delete it. Where the service has a feature that does this, we will point you at it rather than doing it by hand. Where a data subject approaches us directly about data you control, we will not answer them on the substance; we will refer them to you and tell you it happened.

With your obligations under Arts. 32 to 36: securing the processing, notifying breaches, communicating them to data subjects, carrying out an impact assessment, and consulting your supervisory authority. Our assistance is limited to what we know and what is in our control, which for most of these is information about how the service works.

Ordinary assistance is included. Where a request is disproportionate — repeated, or an exercise requiring substantial engineering — we may charge for the effort, and will say so before starting.

When something goes wrong

We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, in any event in time for you to meet your own 72-hour deadline under Art. 33.

The notification will describe what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we do not have all of it at once, we will send what we have and follow up rather than wait until the picture is complete.

We will not notify your supervisory authority or your data subjects on your behalf unless you ask us to in writing. That notification is yours to make.

Deletion and return

At the end of the service you choose: we return your personal data, or we delete it.

Unless you tell us otherwise, we keep it available for 30 days after the service ends so you can export it, and delete it after that. Say the word and we delete it sooner. Where the service has an export feature, that is the fastest route and it is yours to run at any time.

Backups are not deleted individually. They expire on their own retention cycle, and data in a backup is restored only to recover the service, never to bring back something you deleted. This is the ordinary limit of erasure in any backed-up system and it is stated rather than left to be discovered.

We delete nothing that Union or Member State law requires us to keep, and will tell you what and why if that ever applies.

Audits

We will make available to you the information needed to demonstrate compliance with Art. 28, and allow and contribute to audits and inspections carried out by you or an auditor you appoint.

In practice, ask, and you get: a description of the technical and organisational measures, the sub-processor list, and answers about how the service handles data. That covers almost every audit anybody actually needs.

Where that is not enough, an on-site inspection can be arranged with reasonable notice, during business hours, in a way that does not disrupt operations, and by someone under an obligation of confidentiality who is not a competitor of ours. Where an inspection goes beyond what Art. 28(3)(h) requires, we may charge for the time.

Liability, and everything else

Liability, governing law and jurisdiction are as stated in the general terms of service. Nothing in this agreement limits liability under Art. 82 GDPR.

Where this agreement and any other agreement between us differ on a point about processing personal data on your behalf, this one wins. Where a service's own annex differs from this document on a point about that service, the annex wins.

Changes

We may amend this agreement where the law, a supervisory authority or a change to the service requires it. Where an amendment is material, customers under an ongoing arrangement will be told in advance.

Version identifier

gs-dpa-2026-09-06

Content hash, SHA-256

fe0749903d23228b5033159b1460fa6e5aa4bc1d257d4c87499d96100142ec74

All documents →

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany