Legal
Privacy Policy
Your privacy is important to us. Here you can learn how we protect and use your data.
Privacy Policy
As of: 14 September 2026
In this privacy policy, we inform you in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR) which personal data we process when you visit our website, create an account, use our services or contact us.
1. Controller
gh0stservice GmbH
Else-Lang-Str. 10
50858 Köln, Germany
Phone: +49 152 59647188
Email for data protection enquiries: datenschutz@gh0stservice.com
We are not obliged to appoint a data protection officer (§ 38 BDSG (German Federal Data Protection Act), Art. 37 GDPR) and have not appointed one. Your enquiries are handled by the management.
2. Our roles
As controller, we process data for our website, your customer account, billing, support, the security of our systems and compliance with legal obligations. This privacy policy relates to that processing.
As processor, we process the data that our customers process in their applications, databases and storage on our platform. The respective customer is responsible for this processing. It is based on our Data Processing Agreement (DPA). If you use an application that a customer operates with us, please direct any questions to that customer.
3. Hosting and infrastructure
We operate our website, the customer portal, sign-in (Keycloak), our email server, our DNS servers, our code management, monitoring, and our support and customer management systems ourselves. All systems run in data centres of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, at locations in Germany. Hetzner processes data as our processor; a data processing agreement is in place with Hetzner.
4. Accessing the website and the portal
When you access our website and our portal, our servers process technically necessary connection data and store it in logs:
- IP address
- date and time of the request
- requested address, method and status code
- amount of data transferred
- referrer URL
- browser and operating system identifier (user agent)
From the IP address, we derive the country from which the request originates. For this purpose, we use a locally stored geolocation database; no data is transmitted to third parties in the process.
Purpose: delivery of content, stability, error analysis, detection and defence against attacks and misuse.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable operation of our services.
Retention period: 14 days. We retain log entries relating to a specific security incident until the incident has been resolved.
5. Cookies and storage on your device
We store information on your device or access information stored there only if this is strictly necessary for a service you have requested (§ 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act)) or if you have given your consent (§ 25(1) TDDDG).
Strictly necessary (no consent required):
| Name | Purpose | Retention period |
|---|---|---|
ghc_operating_mode (cookie) | remembers whether you have selected the pages for Self-Service or for operation by us | 180 days |
i18n_redirected (cookie) | remembers the selected language | 1 year |
| Keycloak session cookies (on kc.mgmt.gh0stcloud.de) | sign-in and session security | until the end of the session, at most 48 hours |
gh0stportal.keycloak.session (session storage) | keeps you signed in to the portal | until the browser window is closed |
gh0st-privacy-consent (local storage) | stores your consent decisions, without an identifier | until you change it |
| Settings in local storage (e.g. selected operating system, AI assistant, saved cost estimates, sidebar, organisation context) | convenience features that you trigger yourself | until you delete them |
Legal basis for further processing: Art. 6(1)(b) and (f) GDPR.
Only with consent: audience measurement and session recording (clause 6).
You can change your decision at any time via "Privacy settings" in the page footer.
6. Audience measurement and error analysis with Rybbit (only with consent)
If you have given your consent with "Allow all", we use a self-operated instance of the open-source software Rybbit. No data is transmitted to the manufacturer or to third parties.
Statistics: pages viewed and navigation paths, referrer and campaign parameters from the requested address, browser, operating system, device type, screen size and language, approximate location (country and region, derived from the IP address), loading times (Web Vitals), JavaScript errors and clicks on outbound links. Rybbit generates a pseudonymous identifier from the IP address and browser identifier; the full IP address is not stored.
Session recording: recording of page rendering, mouse movements, clicks and scrolling during your visit in order to understand usability problems and errors. Input in form fields is not recorded.
Purpose: improvement of content, usability, stability and loading times.
Legal basis: your consent, § 25(1) TDDDG and Art. 6(1)(a) GDPR.
Retention period: statistical data for at most 13 months, session recordings for at most 30 days.
Withdrawal: You can withdraw your consent at any time with effect for the future via "Privacy settings" in the page footer.
7. Registration and customer account
When you register, we process: account type (private individual or organisation), name of the organisation, first name, last name, email address, username, country and billing country, your consent to the GTC and the privacy notices and, for consumers, your request for performance to begin immediately, in each case with version and time. To protect against automated registrations, your browser computes a small task; we store only a verification value from it. We then send you an email with a confirmation link that is valid for 24 hours.
In the account, we additionally process billing and contact details (for example salutation, address, telephone number and, for companies, the VAT identification number) as well as voluntary information about your experience and role, which we use to tailor guidance in the portal.
Purpose: conclusion and performance of the contract, proof of consents given.
Legal basis: Art. 6(1)(b) GDPR; for proof, Art. 6(1)(c) and (f) GDPR.
Retention period: We delete unconfirmed registrations after 30 days. We store account data for the duration of the contract, and proof of consents until three years after the end of the contract. Statutory retention obligations (clause 12) remain unaffected.
8. Sign-in
For signing in to the portal and gh0stcli, we use the self-operated software Keycloak. We process the user identifier, email address, name, organisation membership, roles and sign-in events (time, IP address, result).
Purpose: secure sign-in, protection against unauthorised access.
Legal basis: Art. 6(1)(b) and (f) GDPR.
Retention period: sign-in events 90 days; account data for the duration of the contract. Inactive sessions end after 60 minutes, and sessions end after 48 hours at the latest.
gh0stcli: Sign-in takes place via your browser. gh0stcli stores access tokens in your operating system's keychain. gh0stcli does not transmit usage statistics or crash reports to us.
9. Use of the platform
When you use the platform via the portal, gh0stcli or Git, we process logs of requests and changes, for example user and organisation identifiers, the action triggered, time, result and technical metadata. For every request to the application programming interfaces of our Kubernetes clusters, we write audit logs containing metadata (who, when, which action, on which resource), without request contents.
Purpose: operation, error analysis, traceability of changes, detection of attacks and misuse.
Legal basis: Art. 6(1)(b) and (f) GDPR. Our legitimate interest lies in the security of the platform and in investigating incidents, which often only become apparent long after they began.
Retention period: platform application logs 30 days, security logs 90 days, audit logs 12 months.
We process logs and data of your own applications on your behalf under the Data Processing Agreement (DPA).
10. Payments via Mollie
We process payments (top-ups, payment methods, direct debit mandates, refunds) via Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. We transmit to Mollie your name, your email address, the amount and internal references to the customer, organisation and payment type. You enter your payment details (for example bank account or card details) directly with Mollie; we receive only the status and a reference of the payment.
Mollie processes the data as an independent controller, including for the fulfilment of its own legal obligations (for example the prevention of money laundering). Further information can be found in Mollie's privacy policy.
Legal basis: Art. 6(1)(b) GDPR.
11. Emails
We send transactional emails (for example confirmation links, invoices, account status notices, acknowledgements of receipt) via our self-operated email server. We do not send advertising emails.
Legal basis: Art. 6(1)(b) and (c) GDPR.
Retention period: sending logs 30 days; contents of invoices and legally relevant confirmations in accordance with clauses 12 and 13.
12. Invoices, accounting and taxes
For invoicing, accounting and tax returns, we process invoice, contract and payment data.
- Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany (Lexware Office): accounting software, as processor
- Bontax GmbH Steuerberatungsgesellschaft, Alfter, Germany: tax advice and bookkeeping, as independent controller under the rules of professional law
- DATEV eG, Paumgartnerstr. 6-14, 90429 Nürnberg, Germany: data centre and software of our tax advisors
Legal basis: Art. 6(1)(b) and (c) GDPR in conjunction with § 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code) and § 14b UStG (German VAT Act).
Retention period: invoices and accounting vouchers 8 years, books and annual financial statements 10 years, commercial and business letters 6 years, in each case from the end of the calendar year. During these periods, we restrict processing to the fulfilment of the retention obligations.
13. Contact, support and customer relationship
If you contact us by email, telephone or via our support system, we process your details and the history of the communication. For support and customer relationships, we use self-operated systems (Zammad, Twenty).
Purpose: handling your request, initiation and performance of contracts.
Legal basis: Art. 6(1)(b) GDPR; for enquiries unrelated to a contract, Art. 6(1)(f) GDPR.
Retention period: three years after the last contact or the end of the business relationship, unless a statutory retention obligation applies.
14. Online termination and online withdrawal
Via the pages "Verträge hier kündigen" (Terminate contracts here) and "Vertrag widerrufen" (Withdraw from contract), we process the information you provide there (for termination: contract reference, name, address, email address, type of and reason for termination, requested date; for withdrawal: name, contract designation and email address), the wording of your declaration and the time of receipt. You receive an acknowledgement of receipt by email; our team receives an internal notification.
Purpose: receipt, acknowledgement and implementation of your declaration.
Legal basis: Art. 6(1)(c) GDPR in conjunction with § 312k and § 356a BGB (German Civil Code), and Art. 6(1)(b) GDPR.
Retention period: three years from the end of the year in which the declaration was received.
15. Notices of content and security vulnerabilities
If you notify us of illegal content or security vulnerabilities, we process your contact details, the content of the notice and our communication about it.
Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065 and Art. 14 of Regulation (EU) 2024/2847; otherwise Art. 6(1)(f) GDPR.
Retention period: three years after the case has been closed.
16. TLS certificates
To make our services and our customers' applications accessible via encrypted connections, we obtain TLS certificates from Let's Encrypt (Internet Security Research Group, San Francisco, USA). Only the hostnames of the addresses to be secured are transmitted. As with all publicly trusted certificates, issued certificates, and thus these hostnames, are published in public Certificate Transparency logs. If a hostname chosen by a customer contains personal data, this data thereby becomes public.
Legal basis: Art. 6(1)(b) and (f) GDPR. Where hostnames constitute personal data, the transfer to the USA is based on Art. 49(1)(b) GDPR, because it is necessary for the performance of the contract at your request.
17. Recipients and transfers to third countries
Within our company, personal data is accessible only to those persons who need it for their tasks. External recipients are the bodies named in this policy: Hetzner Online GmbH, Mollie B.V., Haufe-Lexware GmbH & Co. KG, Bontax GmbH Steuerberatungsgesellschaft, DATEV eG and, limited to hostnames, Let's Encrypt. We transmit data to authorities and courts only if we are legally obliged to do so.
Apart from the hostnames under clause 16, we do not transfer any personal data to countries outside the European Union or the European Economic Area.
18. Automated decisions
The status of your account (for example pausing applications when the starting credit has been used up, or suspension due to unpaid invoices) is determined automatically by our systems on the basis of credit, payment status and deadlines. These decisions are necessary for the performance of the contract (Art. 22(2)(a) GDPR). You may at any time request that a person review the decision, express your point of view and contest the decision. No profiling for advertising purposes takes place.
19. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR). You may withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data, unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
A message to datenschutz@gh0stservice.com is sufficient to exercise your rights.
20. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority. The authority competent for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2-4, 40213 Düsseldorf
www.ldi.nrw.de
21. Obligation to provide data
The information provided during registration, in the customer account and for billing is required for the conclusion and performance of the contract. Without it, we cannot conclude the contract. Voluntary information is marked as such.
22. Changes
We update this privacy policy when our processing or the legal situation changes. The version published here at any given time applies.