Version 2026.10-P – Last updated: 1 October 2026
This is a translation provided for convenience. In case of discrepancy, the Italian version prevails.
1.1. This policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Italian Privacy Code (Legislative Decree 196/2003) (the “Privacy Code”) by Goose S.r.l., Via dei Metalmeccanici 15, 12038 Savigliano (CN), Italy, VAT No. IT03483570044 (“Goose” or the “Controller”), and describes how we process the personal data of:
1.2. Data entered by customers into the application. The data that customers enter into the Goose service (for example, their customers’ records, orders, activities and sales agents’ locations) are processed by Goose as a processor on behalf of the customer, who is the controller, in accordance with the Data Processing Agreement (DPA). For information on such processing, data subjects should contact the customer company that uses Goose.
For any matter relating to data protection and to exercise your rights, you may write to privacy@gooseapp.com or by certified e-mail (PEC) to gooseapp@pec.it. To report security issues: security@gooseapp.com. Goose has not designated a Data Protection Officer (DPO), since the conditions set out in Article 37 GDPR are not met.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| a) Website browsing and system security | IP address, date and time, pages requested, browser and operating system, technical cookies | Legitimate interest in the secure operation of the website (Art. 6(1)(f)) | For as long as strictly necessary for security purposes, unless required for the investigation of unlawful acts |
| b) Contact requests, commercial information, support via e-mail, chat or forms | First name, surname, company, e-mail address, telephone number, content of the request; for chat, the messages exchanged | Pre-contractual measures requested by the data subject or performance of the contract (Art. 6(1)(b)); legitimate interest in responding (Art. 6(1)(f)) | 24 months from the last contact, unless a contractual relationship is established |
| c) Account registration and management, free trial, provision of the service, support | First name, surname, e-mail address, company, telephone number, login credentials, preferences | Performance of the contract (Art. 6(1)(b)) | For the duration of the relationship; after termination, until deletion as provided in the Terms and Conditions |
| d) Access security and prevention of abuse and fraud | Access logs (user, date and time, IP address, device), two-factor authentication codes, failed attempts, anti-bot verification (reCAPTCHA) | Legitimate interest in the security of the service and legal obligation to adopt security measures (Arts. 6(1)(f), 6(1)(c) and 32 GDPR; Legislative Decree 138/2024) | For as long as strictly necessary for security purposes; longer only if necessary for handling an incident |
| e) Purchases, invoicing and tax compliance | Billing data (company name, address, VAT number, tax code, PEC address or recipient code), plan, amounts, payment identifiers. Card data are processed exclusively by Stripe | Performance of the contract and legal obligation (Art. 6(1)(b) and (c)) | 10 years (Art. 2220 of the Italian Civil Code) |
| f) Service communications (expiry dates, renewals, updates to the Terms, security alerts, incident notifications) | E-mail address and name of the contact person | Performance of the contract and legal obligation (Art. 6(1)(b) and (c)) | For the duration of the relationship |
| g) Newsletter and promotional communications about Goose services | E-mail address, name, company; total number of clicks on the links of each newsletter, not linked to the individual recipient | For those who voluntarily subscribe to the newsletter: consent (Art. 6(1)(a)), which may be withdrawn at any time. For those who have registered an account or purchased the service, with regard to similar services: legitimate interest pursuant to Article 130(4) of the Privacy Code, with the right to object at any time using the link included in every e-mail | Until consent is withdrawn or an objection is made. We do not record opens or clicks of individual recipients |
| h) Website usage statistics (Google Analytics 4) | Cookie identifiers, pages visited, events (e.g. completed registration), technical device data | Consent given through the cookie banner (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code), which may be withdrawn at any time | According to the cookie durations set out in the Cookie Policy; data in Google Analytics: up to 14 months |
| i) Protection of rights in judicial or out-of-court proceedings | Data relevant to the dispute | Legitimate interest (Art. 6(1)(f)) | For the duration of the dispute and until the relevant rights become time-barred |
The provision of the data referred to in letters c) and e) is necessary to enter into and perform the contract; the provision of data for purposes g) and h) is optional and refusal has no consequence on the use of the service. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on data subjects, nor do we transfer or sell personal data to third parties for their own marketing purposes.
The website does not use any profiling or advertising measurement tools. Should such tools be introduced, they will be activated only with prior consent, and this policy and the Cookie Policy will be updated.
Data are processed by authorised Goose personnel, who are bound by confidentiality, and by service providers acting as processors under contracts compliant with Article 28 GDPR:
| Provider | Service | Location / safeguards |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting of website, application, databases and backups | EU (Ireland) |
| SparkPost (Bird B.V.) | Sending of transactional e-mails, access codes and newsletters | USA – EU-US Data Privacy Framework and SCC |
| Google Ireland Ltd | Corporate e-mail (Workspace), Analytics (only with consent), reCAPTCHA, Maps Platform | EU/USA – EU-US Data Privacy Framework and SCC |
| Crisp IM SAS | Support chat on the website and in the app | EU (France) |
| Freshworks (Freshdesk) | Support ticket management and knowledge base | EU/USA – EU-US Data Privacy Framework and SCC |
| Stripe Payments Europe Ltd | Card payments and recurring charges (independent controller for anti-money laundering and anti-fraud obligations) | EU/USA – DPF and SCC |
| Consultants and professional firms | Accounting, tax compliance, legal advice | Italy |
Data may also be disclosed to public authorities, judicial authorities, the Italian Data Protection Authority (Garante per la protezione dei dati personali) and the National Cybersecurity Agency (ACN)/CSIRT Italia where required by law. The up-to-date list of service providers is available on request.
Data are hosted in the European Union. Certain providers (e.g. Google, SparkPost, Stripe) may process data in the United States: in such cases, the transfer takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 (EU-US Data Privacy Framework) for certified companies, or of the Standard Contractual Clauses approved by the Commission (Art. 46 GDPR). A copy of the safeguards may be requested using the contact details given in section 2.
We adopt technical and organisational measures to protect data, including: HTTPS/TLS encrypted connections with HSTS, two-factor authentication by means of a code sent by e-mail, which can be enabled for the application, role-based permissions, logging of access to the application, periodic backups and separation of each customer’s database. The measures are subject to an ongoing strengthening plan. In the event of a personal data breach likely to result in a high risk to your rights, we will inform you without undue delay, as required by Article 34 GDPR.
The website uses technical cookies, which are necessary for its operation and for the services requested (reserved area, registration, payments, support chat opened by the user) and, only with prior consent given through the banner and separately for each category, Google Analytics cookies (statistics) and cookies from embedded YouTube videos. You can change your choice at any time from the “Cookie preferences” link at the bottom of every page. Full details are set out in the Cookie Policy.
Pursuant to Articles 15-22 GDPR, you may at any time: access your data and obtain a copy; request rectification or erasure; request restriction of processing; receive the data you have provided in a structured format and transmit them to another controller (portability); object to processing based on legitimate interest and, at any time and without giving reasons, to processing for marketing purposes; withdraw your consent, without affecting the lawfulness of processing carried out prior to withdrawal. You may also unsubscribe from the newsletter using the link included in every e-mail.
Requests should be sent to privacy@gooseapp.com; we will respond within one month, which may be extended by two further months in more complex cases. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) (www.garanteprivacy.it) or with the supervisory authority of the EU Member State in which you reside or work.
The website and the service are intended for businesses and professionals and are not directed at persons under 18 years of age.
We may update this policy to reflect regulatory, technical or service changes. The date of the latest update is shown at the top of the page; material changes will be communicated to customers by e-mail or by means of a notice within the application. Previous versions are available on request.