Server operations
Publish instance governance
The supported release generates deployment-specific pages from facts stored on your own Server. It sends no governance configuration to the software maintainer and does not decide whether your legal assessment is correct.
Complete this workflow at /admin/governance. Do not use placeholder provider, contact or legal-basis text, and do not describe the instance as certified or automatically compliant.
1. Identify the controller
Record the real controller identity, postal address, privacy contact, authority and any applicable representative or DPO contact.
2. Record deployment facts
Record purposes and your selected basis or Swiss justification, data categories, providers, countries, retention periods, optional features, rights route and incident contact.
3. Save a private draft
Saving does not change public pages. Draft content remains root-only until publication.
4. Preview and resolve preflight
Review every generated page and the path-level diff. Resolve Missing, Requires controller decision and Contradiction results. Externally unverifiable items remain your responsibility.
5. Acknowledge and publish
Confirm your authority and review, reauthenticate with the root passkey and publish one immutable version.
6. Retain evidence and repeat after changes
Export the non-secret policy bundle. Material controller, purpose, processor, country, feature or retention changes require a new version and relevant organiser acknowledgement.
Public and evidential results
- Public pages:
/privacy,/legal,/terms,/data-policy,/retention,/rightsand/processors. - Each publication has a numbered immutable snapshot, SHA-256, timestamp, publisher and change classification.
- Activation email and Desktop organiser notices link the applicable policy identity.
- Processor contract references and internal notes are never included in public output.
Still outside automatic verification
The application cannot verify your controller status, legal basis, provider agreement, transfer assessment, national notice duties or physical deletion of off-server copies. Treat these as controller decisions or external evidence.