gShare

Privacy Policy

Controller

See legal notice. Contact for all matters: kontakt@gshare.jenpa.de


What data we process

  • Server logs: IP address, timestamp, requested URL, browser/OS – 14 days, then deleted.
  • Upload/download: file name, size, type, timestamp, IP address, link status – kept as long as the link is active. Deleted irrevocably after expiry or use.
  • User account (optional): email, password (hashed), registration/login timestamp – until the account is deleted.
  • Security/abuse: IP address, access patterns, block reason – 14 days; blocks on hosting/data-centre address ranges may remain in place permanently but are reviewed annually.
  • Reports (abuse@gshare.jenpa.de): report content, reporter's contact details, affected link – up to 6 months.

Purpose and legal basis

Provision of the service (Art. 6(1)(b) GDPR) as well as security, abuse prevention, and enforcement of legal claims (Art. 6(1)(f) GDPR, in conjunction with Art. 16 DSA for reports). Uploaded files are not reviewed for their content.


Who sees the data

  • Hosting provider with servers located in Germany
  • Cloud storage provider for files, servers located in the EU
  • Authorities, where legally required

No selling, no tracking, no disclosure for advertising purposes. Data processing agreements (Art. 28 GDPR) are in place with all providers.


Third countries

The storage provider used belongs to a corporate group headquartered outside the EU. Access by the parent company under the laws of that country cannot be fully excluded. The same applies to Google Analytics, see below. Basis for any such transfer: Standard Contractual Clauses (Art. 46(2)(c) GDPR), supplemented by the adequacy decision on the EU-US Data Privacy Framework where applicable.


Cookies and analytics

Strictly necessary cookies (session, login) are used without consent, legal basis Section 25(2) No. 2 TDDDG.

We additionally use Google Analytics (Google Ireland Limited) for traffic analysis, but only after your consent via the consent manager on first visit. This processes IP address (truncated), device, and usage data; access by the US parent company is not excluded (Standard Contractual Clauses, Art. 46(2)(c) GDPR). Legal basis: your consent (Art. 6(1)(a) GDPR), revocable at any time with future effect via the consent manager or by email. Without consent, no analytics takes place.

For technical error analysis, we use the service Sentry, split into server-side and browser-side collection:

Server-side, we automatically capture technical errors in our application (e.g. error messages, affected function). IP addresses and cookies are removed before transmission; this only concerns data from our own server environment, not your device. Legal basis: legitimate interest in stable, error-free operation (Art. 6(1)(f) GDPR).

In your browser, we only use Sentry if you have consented to the "Statistics/Analytics" category in the consent manager. This transmits anonymised technical error data from your browser (e.g. error messages, browser/system information); IP addresses, cookie contents, and form data are removed before transmission. Legal basis: your consent (Art. 6(1)(a) GDPR), revocable at any time via the consent manager or by email. Without consent, this client-side collection is not loaded.


Your rights

Access, rectification, erasure, restriction, data portability, objection (Art. 15–18, 20, 21 GDPR), and withdrawal of consent given. Requests to kontakt@gshare.jenpa.de. Complaints may be lodged with [competent state data protection authority] or any other supervisory authority.


Automated decisions

Do not take place. Automated security blocks (see above) are not a decision within the meaning of Art. 22 GDPR; deletions and account suspensions are always decided by a human.


Changes

This policy may be amended as needed. The version published on this page at any given time applies.

Last updated: 11.08.2026