Legal
Switching to another provider
How a switch works, what each hosted service lets you take, in which formats, and every limit we know of. The register the EU Data Act asks for, kept current.
This page belongs to "Switching to another provider" in the general terms. What you can take from each service is listed, exhaustively, in that service's terms; this page says how it reaches you.
How a switch works
- You ask. Write to contact@gplatform.org from the address on the account: which service, which account or organisation, and whether we move your data to another provider, to your own infrastructure, or erase it. Name a date if you want a later one.
- One month's notice starts with your request.
- The switch follows without undue delay once the notice period ends, within 30 days at most. Your contract runs on its terms meanwhile, and we help with the switch and tell you of every risk to it we know of. If 30 days are not technically feasible, we say so within 14 working days of your request, with reasons, and name a period of at most seven months. You may extend the transitional period once, by a period you consider more appropriate.
- Handover. We send a download link to the address on the account, for an archive of your data in the formats below. Where the new provider takes the data directly and that is technically feasible, we send it there instead, and say so in our reply.
- Retrieval. After the transitional period you can still retrieve your data for at least 30 days. Then we erase it, except what the law requires us to keep, permanent records, and what the service's privacy notice or terms say it keeps.
Nothing in a switch costs anything: not the switch, not moving the data, not the transitional period. A switch ends a paid contract early, and we refund the unused time pro rata.
Service by service
GAdvisory. Each person downloads their own data under Settings › Account › Data export. Each advisory downloads as a CVE record and a GCVE record. Git sync keeps advisories, submissions, comments and audit entries in your own repository. An organisation's data as a whole comes as JSON on request. Published advisories and CVE records stay published.
Contribution Checker. Each person downloads their own data from the account menu. A project's administrators download its CLA record as JSON or CSV. A project's data as a whole comes as JSON on request.
GeGroups. Owners and administrators download a group as JSON, its member list as CSV and its calendar as iCalendar; each person downloads their own data. A group download carries up to 20,000 messages. File contents, photos, chat, polls, databases, revisions and further messages come as JSON on request, with the files.
GOpenCDR. All data comes as JSON on request. Registration data is public through RDAP, and a mirror's traffic downloads as CSV. A domain name stays in GOpenCDR's namespace: its records move, the name does not.
GOpenCSR. All data comes as JSON on request.
GOpenCNR. All data comes as JSON on request, with reverse zones as zone files and transparency-log receipts as the log issues them. Address space and ASNs are allocated, never owned, and do not move.
GPlatform SSO. You download your own account as JSON at sso.gplatform.org/v1/account/export while signed in. Organisations, teams, applications and the rest come as JSON on request.
GPlatform Billing. Invoices download as PDF in the console; everything else comes as JSON on request. Card details are held by Stripe, never by us, and you give them to the new provider yourself.
GPlatform Control. Licence files download from the portal; everything else comes as JSON on request. The escrowed private half of an instance's lockdown key stays in Vault.
YAGPDB. All data comes as JSON on request, with uploaded sounds in their original format. A server's data is deleted 30 days after the bot leaves it, so ask before you remove the bot.
Discord Tickets. A server's administrators download a ZIP from the dashboard's settings with the settings, tickets and transcripts. Panels and automations come as JSON on request. Transcripts are deleted 24 months after their ticket closed.
What stays behind everywhere
Password, token and key hashes, private and secret keys, one-time tokens, the secrets of sessions, applications, webhooks and integrations, the instructions we send to AI models, and our internal database identifiers. Each service's terms name them exhaustively. Leaving them behind never delays or prevents a switch.
Data on request
Unless a service's section above names another format, data we hand over on request is one JSON file per kind of record, in a ZIP archive. Each file is an array of objects whose fields carry the names the service uses; times are in ISO 8601, in UTC. Files and attachments come in the format they were uploaded in. We prepare it within the transitional period, and the download link stays valid for the whole retrieval period.
Register of formats and standards
- JSON (RFC 8259): all services.
- Dates and times (ISO 8601): all services.
- JSON Lines, NDJSON (jsonlines.org, ndjson.org): GAdvisory, Discord Tickets.
- CSV (RFC 4180): Contribution Checker, GeGroups, GOpenCDR.
- ZIP (PKWARE APPNOTE): Discord Tickets, data on request.
- iCalendar (RFC 5545): GeGroups.
- CVE JSON 5 (CVE Record Format 5, cve.org): GAdvisory.
- GCVE JSON (GCVE BCP-05, gcve.eu): GAdvisory.
- RDAP (RFC 9083): GOpenCDR.
- DNS zone files (RFC 1035): GOpenCDR, GOpenCNR.
- DNSSEC trust anchors (RFC 9718): GOpenCDR.
- OpenID Connect Discovery, JSON Web Key Sets (OpenID Connect Discovery 1.0, RFC 7517): GPlatform SSO.
- HTML (WHATWG HTML): Discord Tickets.
- PDF (ISO 32000): GPlatform Billing.
- PNG (ISO/IEC 15948): Discord Tickets.
- Licence file (
.gclicence, described in the GControl documentation): GPlatform Control.
Data structures
GAdvisory personal download: one JSON document, gadvisory-user-export/v1, with a section per kind of record: account, memberships, sessions, consents, subscriptions, notifications, tokens, audit entries and authored content.
Contribution Checker personal download: one JSON document, contribution-checker-account-export/1. CLA record: JSON with the ledger's integrity result, events, signatures, corporate agreements, rosters and waivers, or CSV with one row per ledger entry.
GeGroups group download: one JSON document with the group, lists, members, topics, messages, files, events and wiki pages. Member list: CSV with list, name, email, role, status, delivery mode and joined date.
GPlatform SSO account download: one JSON document, gplatform-account.json, with profile, emails, linked providers, sessions, consents and audit entries.
Discord Tickets server download: a ZIP holding settings.json, tickets.jsonl with one ticket per line, an HTML transcript per ticket and the server's icon.
Everything else follows "Data on request" above.