Data processing by Nextcloud GmbH for Nextcloud Enterprise customers

We differentiate fundamentally from cloud service providers: we develop and deliver the Nextcloud Enterprise software to our customers, who operate it themselves or through a hosting provider of their choice. We have no access to any data customers process within their Nextcloud installations. We do not provide hosting services and consequently do not act as data controller for personal data processed on customer-operated or third-party hosted Nextcloud instances.

The following only applies to Nextcloud Enterprise customers:

In certain defined situations, we may collect limited personal data from and about these customers. Such collection occurs only where customers actively interact with us, for example when requesting support or sharing diagnostic information.

There are ten specific circumstances in which we may collect personal data, outlined below.

No. Processing activity Personal data Retention period
1 When admins provide their names and email addresses to subscribe to the Nextcloud security update newsletter, including log.
  1. Name, email address (can be pseudonymous)
  2. Email log that includes the content and metadata Message ID, Status (Delivered, Processed, Undeliverable), Email address, Subject, Tag (always empty), Date and Time, Bounce reason (if undelivered).
  1. Until consent is withdrawn
  2. 45 days.
2 When procurement officials contact us with pre-contractual questions, sign-up for licenses and communicate about procurement and legal issues, including log.
  1. Name, email address, name of company/organisation + contents of the communication
  2. Email log that includes the content and metadata Message ID, Status (Delivered, Processed, Undeliverable), Email address, Subject, Tag (always empty), Date and Time, Bounce reason (if undelivered).
  1. 7-10 years statutory retention periods under the German Fiscal Code (AO) and German Commercial Code (HGB) for relevant business correspondence.
  2. 45 days.
3 When admins ask for third level support from us and share data about themselves and possibly other colleagues in the support ticket and/or attachment. This processing includes the registration of metadata about the filing of support tickets. Contents of support request + attachments, plus technical data.
  • Support tickets 3 years after contract termination. Admins can request Nextcloud to delete all support tickets older than 13-15 months.
  • Support metadata: retained as long as the ticket exists. Plus: Nextcloud’s sub-processor Zammad retains the Zammad Production Log with technical data relating to the use of the Support portal for 42 days.
  • In incidental cases Nextcloud has to retain a specific support ticket for 7-10 years, for compliance with statutory retention periods under the German Fiscal Code (AO) and German Commercial Code (HGB). This is only the case if a support ticket documents a contractual dispute, where a customer asks for reimbursement or damages via a support ticket, and engages in legal procedures against Nextcloud.
4 When admins voluntarily share Diagnostic Data with us, in one of three ways:

  • When they install the Support App;
  • When they share the System Information Report;
  • When they share the Usage Survey data.
IP-address + Subscription key + Instance ID. The Support app and Usage Survey app collect the number of users (pseudonymous data) together with configuration data such as version and installed apps. The System Information Report can contain customer identifiers (Talk URLs). Nextcloud additionally technically always collects the IP address when a customer uses the Support app and shares Usage Survey data or when a customer files a support request and shares a System Information Report. As long as the contract exists. IP addresses collected by the Support Portal are stored for 7 days.
5 When admins and legal employees of organisations visit Nextcloud.com to look up legal and technical information. This includes processing of personal data via functional cookies, and registration of visitor data in a webserver access log. (Nextcloud.com) IP address, browser, OS, timestamp, visited page. 7 days in webserver access log, only processed in RAM memory before aggregation for analytics
Maximum expiry date for cookies in visitor’s browser: 30 days. Nextcloud does not store the cookie information in any other log.
6 When admins visit the admin and support portal to file support tickets. This includes processing of personal data via functional cookies, and registration of visitor data in a web server access log. (Support portal) IP address, browser, OS, timestamp, visited page. 7 days in webserver access log, only processed in RAM memory before aggregation for analytics
Maximum expiry date for cookies in visitor’s browser: 30 days. Nextcloud does not store the cookie information in any other log.
7 When admins and end users update the software (software update and release download logs). (Software update) IP address, query string containing the Subscription Key (for Enterprise instances) and configuration information such as the current Nextcloud and PHP versions, installation date, and the chosen release channel. 14 days.
8 When admins and end users enable push notifications from Nextcloud on their mobile devices. Device ID and the date on which the device was registered as well as the public key used for push notification delivery. Until the app is deinstalled or the account removed from the device.
9 If a customer chooses to engage one of our (sub-) processors (e.g. technology partners). (Commercial Contact Data – depends on the technology partner), number of licenses, duration of the contract. As long as necessary to fullfil the contract.
10 If admins and end users file a Data Subject Rights’ request (log of privacy and access requests). Reply to a DSAR can contain any of the above mentioned data. 2 years after the request.

Data collected for the 10 circumstances above comes from these 7 sources:

1. Data collection via outbound mail (admins)

2. Data collection via outbound mail (commercial contact data)

The logs contain Message ID, Status (Delivered, Processed, Undeliverable), Email address, Subject, Tag (always empty), Date and Time, Bounce reason (if undelivered).

3. Data collection via support portal log

  • User actions (ticket creation, updates, login events)
  • Internal application processes
  • Errors and warnings
  • API requests
  • Database interactions
  • Permission problems
  • Email processing results
  • Incoming mail fetch results
  • IMAP/POP3 connection status
  • Mail parsing errors
  • Ticket creation from emails
  • Successful logins
  • Failed login attempts
  • Session creation
  • Logout events
  • API authentication
  • OAuth / LDAP authentication (if used)

4. Diagnostic Data collection

 

  • via Usage Survey data
    If admins share Usage Survey data with us, they share the unique ID of the Nextcloud instance (for example: ocee3ii9ih59). The Usage Survey gathers broad insights into how Nextcloud is used. It collects high-level diagnostic data, such as installed apps, PHP versions, and Nextcloud release versions. It is much more comprehensive than the Support app and is primarily used for ecosystem statistics. Admins can choose to share some or all of the following categories of data via the Usage Survey Data:

    • Server instance details (version, memcache used, status of locking/previews/avatars)
    • PHP environment (version, memory limit, max execution time, max file size)
    • Database environment (type, version, database size)
    • App list (for each app: name, version, enabled status)
    • Statistics (number of files, users, storages per type, comments and tags)
    • Number of shares (per type and permission seting)
    • Encryption information (is it enabled, what is the default module)
  • via Support App
    The Support App collects strictly functional and targeted data that are directly relevant for troubleshooting support cases, alongside the user count required for account and license management.

    • subscription key
    • instance id
    • user count
    • version
    • active user count
    • app list
  • Data collection via System Information Report
    The report includes very detailed configuration and status information. We have taken steps to remove identifying data from the report, as marked with the words: „***REMOVED SENSITIVE VALUE***“. System Information reports do not collect the ID of the Nextcloud instance, or passwords/secrets/tokens and hostnames. However, the report can include some data that can help identify the specific customer, via URLs that include the organisation name of the customer. Since we have the contact data for the admin and the commercial contact person, this data is identifiable for us. As mentioned in the table, we also collect the IP address with which the (identifiable) admin connects to the support portal. We only retain these IP addresses for 7 days.

5. Data collection via webserver access log

Example:

127.0.0.1 - max [10/Oct/2000:13:55:36 -0700] "GET /apache_pb.gif HTTP/1.0" 200 2326 "http://www.example.com/start.html" "Mozilla/4.08 [en] (Win98; I ;Nav)

6. Update and download logs

Example of update check by self-hosted Nextcloud server

<ip> - - [26/Feb/2026:00:00:21 +0000] "GET /customers/<subscriptionKey>/?version=27x1x11x3x1677622860.9738x1772064018xstablexx2024-06-25T10:28:34+00:00%20883b016f74f1f65a55c42c75fe04c1262936a190x8x2x30x3x1 HTTP/1.1" 200 5360 "-" "Nextcloud Server Crawler" 9401

Whenever an admin downloads a new version of the software from Nextcloud’s hosted repository (not from the GitHub repository), the download request is logged. This log contains the IP address, the timestamp, and the specific file requested (e.g., a .zip archive).

<ip> - - [26/Feb/2026:03:02:18 +0000] "GET /server/releases/nextcloud-29.0.16.zip HTTP/1.1" 200 24386311 "-" "Nextcloud Updater" 247256452

7. Push proxy log

The push proxy (running on servers managed by Nextcloud) operates with deliberately limited knowledge: it holds the user public key, device identifier, push token, and the Google/Apple developer certificate, but not the device private key. It therefore cannot decrypt the content of push notifications. The proxy verifies the notification signature, re-signs it with the appropriate developer certificate, and forwards it to Google (Firebase Cloud Messaging) or Apple (APNs). No notification content is logged or stored in persistent form.