pursuant to Article 28 of Regulation (EU) 2016/679 – Version 2026.10-P – Last updated: 1 October 2026
This is a translation provided for convenience. In case of discrepancy, the Italian version prevails.
This Agreement forms an integral part of the Terms and Conditions of Service (the “Contract”) between the Customer, acting as controller (the “Controller”), and Goose S.r.l., Via dei Metalmeccanici 15, 12038 Savigliano (CN), Italy, VAT No. IT03483570044, acting as processor (“Goose” or the “Processor”). It is deemed accepted upon conclusion of the Contract. Terms not defined herein have the meaning given to them in the GDPR or in the Contract.
1.1. Goose processes the personal data contained in the Customer Data solely on behalf of the Controller and on its documented instructions. The Contract, this Agreement and the configuration and use of the Service by the Controller and its Users constitute the Controller’s complete instructions.
1.2. Goose shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
1.3. Where Union or Member State law requires Goose to carry out further processing, Goose shall inform the Controller before such processing, unless the law prohibits it from doing so.
| Nature and purpose | Provision of the CRM and order-taking Service on a SaaS basis: hosting, storage, synchronisation with mobile/desktop apps, processing, generation of documents (quotations, orders, delivery notes, invoices), sending of e-mails and documents at Users’ request, geocoding of addresses, integrations activated by the Controller, backup, technical support, security and abuse prevention. |
| Categories of data subjects | The Controller’s Users (employees, sales agents, collaborators); the Controller’s customers, prospective customers, suppliers and principals and their contact persons; other persons whose data the Controller decides to enter. |
| Categories of data | Identification and contact data; professional and business data; commercial and accounting data (quotations, orders, invoices, payments, commissions); notes and activities; geolocation data of addresses and, if the function is activated by the Controller, location of Users’ devices; Users’ credentials and access logs; uploaded attachments. The Service is not intended for the processing of special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR): the Controller undertakes not to enter such data. |
| Duration | For the term of the Contract and until the data are deleted in accordance with section 9 of this Agreement. |
Goose undertakes to:
4.1. The Controller grants Goose a general written authorisation to engage the sub-processors listed in Annex B. Goose shall impose on each sub-processor, by contract, data protection obligations no less stringent than those of this Agreement and shall remain fully liable for their performance.
4.2. Goose shall inform the Controller of any addition or replacement of sub-processors with at least 30 days’ prior notice, by e-mail to the Administrator and by updating this page. The Controller may object on reasonable grounds relating to data protection within that period; failing an agreed solution, the Controller may withdraw from the Contract and obtain a refund of the unused portion of the fees.
Customer Data are hosted in data centres located in the European Union. Any transfers to third countries, including as a result of access by sub-processors, take place only on the basis of an adequacy decision (including the EU-US Data Privacy Framework for certified providers) or of appropriate safeguards pursuant to Article 46 GDPR (Standard Contractual Clauses), supplemented, where necessary, by supplementary measures.
6.1. Goose shall notify the Controller, at the Administrator’s e-mail address and using the contact details indicated in the control panel, of any personal data breach affecting Customer Data without undue delay and in any event within 24 hours of becoming aware of it.
6.2. The notification shall contain, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the point of contact at Goose, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects. Information not available at the time shall be provided in phases without further undue delay.
6.3. Goose shall cooperate with the Controller to enable it to fulfil its obligations to notify the Italian Data Protection Authority (Garante per la protezione dei dati personali) (72 hours) and, where the Controller is subject to the NIS2 legislation (Legislative Decree 138/2024), to submit the early warning and incident notification to CSIRT Italia (24 hours / 72 hours), as well as to communicate the breach to data subjects.
7.1. Upon request, once a year or following a breach, Goose shall provide documentation on the security measures (updated Annex A and answers to the Controller’s security questionnaires).
7.2. Where such documentation is not sufficient or the audit is required by a supervisory authority, the Controller may carry out an audit, directly or through an auditor bound by confidentiality who is not a competitor of Goose, with at least 30 days’ prior notice, during business hours and in a manner that does not compromise the security and data of other customers. The costs of the audit shall be borne by the Controller, unless material breaches attributable to Goose are identified.
The Controller warrants that it has a legal basis for processing the data entered into the Service, that it has provided the required information notices to data subjects (including Users, in particular with regard to any geolocation function, in compliance with Article 4 of Italian Law 300/1970 (Workers’ Statute) where applicable), that it will correctly configure permissions and user accounts, and that it will activate two-factor authentication, where available.
Upon termination of the Contract, Goose shall make the Customer Data available for export for 90 days and shall delete them from production systems within 180 days of termination and from backups at the end of the relevant rotation cycle, save for retention obligations imposed by law. Upon request, Goose shall confirm the deletion in writing.
The liability of the parties is governed by Article 82 GDPR and, as between the parties, by the Contract. In the event of conflict between this Agreement and the Contract in matters of data protection, this Agreement shall prevail. At the Controller’s request, Goose shall sign a bilateral copy of this Agreement.
Goose has launched a plan to strengthen its security measures; this Annex will be updated upon completion of the related work.
| Provider | Service | Data location / safeguards |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, databases, storage, backup | EU (Ireland) |
| SparkPost / MessageBird (Bird B.V.) | Sending of transactional e-mails and documents (including 2FA codes) | USA – DPF/SCC |
| Google Ireland Ltd | Address geocoding (Google Maps Platform); support e-mail (Google Workspace) | EU/US – DPF/SCC |
| Crisp IM SAS | Support chat | EU (France) |
Optional integrations activated by the Controller (e.g. Google Calendar, Mailchimp, Freshdesk, ERP systems) are not sub-processors of Goose: the relevant providers are selected and contracted directly by the Controller.