Legal
Switching providers
Data export, formats, periods and infrastructure location under the Data Act.
Switching Providers and Data Portability
As of: 14 September 2026
This English version is provided for convenience. Only the German version is legally binding.
This page describes how you transfer your data to another provider or to your own infrastructure, which data this includes and where our infrastructure is located. It implements the information obligations under Art. 25, 26, 28 and 29 of Regulation (EU) 2023/2854 (Data Act) and forms part of our contracts for gh0stcloud Self-Service and Managed Packages (clause 12 of the GTC).
1. Requesting a switch
- Write to us in text form at info@gh0stservice.com stating that you wish to switch, to transfer your data to your own infrastructure or to have your data deleted. You can combine the request with your termination.
- The notice period is one month in Self-Service and, for Managed Packages, one month to the end of a month after the minimum term has expired. It is therefore shorter than the statutory maximum period of two months.
- After the notice period expires, a transition period of 30 calendar days begins. During this time, we continue to provide the services, support you with the switch and inform you of known risks to continuity. You can extend the transition period once.
- If a transition period of 30 days is technically unfeasible in an individual case, we notify you of this within 14 working days of your request, stating the reasons, and specify an alternative period of no more than seven months.
- After the transition period, you can retrieve your data for at least a further 30 calendar days. Thereafter, we delete it completely, unless a statutory retention obligation applies.
2. Transferable data and formats
The following list is exhaustive. It also serves as our register of data structures, data formats and standards under Art. 26(b) Data Act.
| Data category | Where it is stored | Format and method |
|---|---|---|
| Description of your applications (desired state) | in your own Git repository; for Managed Packages, in a repository that we maintain for you | Kubernetes manifests and Helm charts (YAML); for Managed Packages, handover as a complete Git repository |
| Container images that we provide for you | our container registry | OCI image format |
| Persistent data of your applications | storage volumes | file archive (tar) |
| Databases | database instances operated by us | PostgreSQL: pg_dump (SQL or custom format); MariaDB and MySQL: SQL dump |
| Secrets (credentials, keys) | secrets management | JSON with key-value pairs, handed over in encrypted form |
| Reachability, network rules, projects and namespaces | platform configuration | YAML or JSON |
| Logs and metrics of your applications, within the respective retention period | monitoring systems | logs as JSON Lines, metrics in OpenMetrics text format |
| Account, usage and billing data | customer portal | invoices as PDF/A-3 with embedded ZUGFeRD XML, usage data as CSV |
The platform uses open standards (Kubernetes API, Helm, OCI, Git, SQL). We provide interfaces for the transfer free of charge.
3. Excluded internal data
Internal data whose disclosure would jeopardise security or trade secrets is not transferred (Art. 25(2)(f) Data Act):
- configuration and credentials of the shared platform infrastructure
- security and audit logs of the platform, to the extent that they concern other customers or the platform itself
- internal cost, calculation and pricing models
These exclusions do not impede the switch, because they contain no data of your applications.
4. Costs
We charge no switching charges for a switch, a transfer to your own infrastructure or a deletion. We do not charge for data transfer incurred in transferring your data as part of a switch. Ongoing charges until the end of the contract and, for Managed Packages, remuneration until the end of the minimum term remain unaffected.
Parallel use of multiple providers (Art. 34 Data Act): The first 1024 GiB of outbound data transfer per month are included. Beyond that, we charge for data transfer in accordance with the price list, at most at the costs incurred for it.
5. Location and jurisdiction of the infrastructure (Art. 28 Data Act)
- All IT infrastructure on which we process our customers' data is located in data centres of Hetzner Online GmbH in Germany and is subject to German law.
- The platform is operated exclusively by gh0stservice GmbH, a company with its registered office in Cologne. Neither gh0stservice GmbH nor the data centre operator is part of a group of companies headquartered outside the European Union.
- We do not use service providers outside the European Union for our customers' data. For the issuance of TLS certificates, we transmit only hostnames to Let's Encrypt (USA); this involves no access to content.
6. Protection against unlawful access by third-country authorities
- We disclose data to authorities only on the basis of applicable law of the European Union or of Germany.
- We review every request for its legal basis and scope. We comply with requests from authorities outside the European Union only on the basis of an international agreement that is binding on us, and only to the minimum extent necessary.
- We challenge unlawful or overly broad requests.
- We inform the affected customer before any disclosure, to the extent that this is legally permissible.
- Access to customer data is technically restricted to a small number of people and is possible only with multi-factor authentication. Public connections are encrypted throughout with TLS.
7. Limitations
Data that you keep in your own external services, for example in your own Git hosting or your own container registry, is located outside our platform and does not need to be transferred. It remains unaffected by a switch.