Data Processing Agreement (DPA)

pursuant to Article 28 of Regulation (EU) 2016/679 – Version 2026.10-P – Last updated: 1 October 2026

This is a translation provided for convenience. In case of discrepancy, the Italian version prevails.

This Agreement forms an integral part of the Terms and Conditions of Service (the “Contract”) between the Customer, acting as controller (the “Controller”), and Goose S.r.l., Via dei Metalmeccanici 15, 12038 Savigliano (CN), Italy, VAT No. IT03483570044, acting as processor (“Goose” or the “Processor”). It is deemed accepted upon conclusion of the Contract. Terms not defined herein have the meaning given to them in the GDPR or in the Contract.

1. Subject matter and instructions

1.1. Goose processes the personal data contained in the Customer Data solely on behalf of the Controller and on its documented instructions. The Contract, this Agreement and the configuration and use of the Service by the Controller and its Users constitute the Controller’s complete instructions.

1.2. Goose shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

1.3. Where Union or Member State law requires Goose to carry out further processing, Goose shall inform the Controller before such processing, unless the law prohibits it from doing so.

2. Description of the processing

Nature and purposeProvision of the CRM and order-taking Service on a SaaS basis: hosting, storage, synchronisation with mobile/desktop apps, processing, generation of documents (quotations, orders, delivery notes, invoices), sending of e-mails and documents at Users’ request, geocoding of addresses, integrations activated by the Controller, backup, technical support, security and abuse prevention.
Categories of data subjectsThe Controller’s Users (employees, sales agents, collaborators); the Controller’s customers, prospective customers, suppliers and principals and their contact persons; other persons whose data the Controller decides to enter.
Categories of dataIdentification and contact data; professional and business data; commercial and accounting data (quotations, orders, invoices, payments, commissions); notes and activities; geolocation data of addresses and, if the function is activated by the Controller, location of Users’ devices; Users’ credentials and access logs; uploaded attachments. The Service is not intended for the processing of special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR): the Controller undertakes not to enter such data.
DurationFor the term of the Contract and until the data are deleted in accordance with section 9 of this Agreement.

3. Obligations of the Processor

Goose undertakes to:

  1. ensure that persons authorised to process the data are bound by confidentiality and have received appropriate training, and that access to Customer Data by Goose personnel takes place only to the extent necessary for the provision of the Service, for support requested by the Controller or for security purposes, in accordance with the principle of least privilege;
  2. implement the technical and organisational measures set out in Annex A;
  3. assist the Controller, taking into account the nature of the processing, by appropriate measures in responding to requests for the exercise of data subjects’ rights (Arts. 15-22 GDPR), including through the consultation, modification, export and deletion functions available in the Service; requests received directly by Goose shall be forwarded to the Controller without delay;
  4. assist the Controller in ensuring compliance with the obligations under Articles 32-36 GDPR (security, breach notification, data protection impact assessment, prior consultation), by providing the information available to it;
  5. maintain a record of the processing activities carried out on behalf of the Controller (Art. 30(2) GDPR);
  6. make available to the Controller the information necessary to demonstrate compliance with this Agreement and allow for and contribute to the audits referred to in section 7.

4. Sub-processors

4.1. The Controller grants Goose a general written authorisation to engage the sub-processors listed in Annex B. Goose shall impose on each sub-processor, by contract, data protection obligations no less stringent than those of this Agreement and shall remain fully liable for their performance.

4.2. Goose shall inform the Controller of any addition or replacement of sub-processors with at least 30 days’ prior notice, by e-mail to the Administrator and by updating this page. The Controller may object on reasonable grounds relating to data protection within that period; failing an agreed solution, the Controller may withdraw from the Contract and obtain a refund of the unused portion of the fees.

5. Transfers outside the EU

Customer Data are hosted in data centres located in the European Union. Any transfers to third countries, including as a result of access by sub-processors, take place only on the basis of an adequacy decision (including the EU-US Data Privacy Framework for certified providers) or of appropriate safeguards pursuant to Article 46 GDPR (Standard Contractual Clauses), supplemented, where necessary, by supplementary measures.

6. Personal data breaches and security incidents

6.1. Goose shall notify the Controller, at the Administrator’s e-mail address and using the contact details indicated in the control panel, of any personal data breach affecting Customer Data without undue delay and in any event within 24 hours of becoming aware of it.

6.2. The notification shall contain, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the point of contact at Goose, the likely consequences and the measures taken or proposed to address the breach and mitigate its effects. Information not available at the time shall be provided in phases without further undue delay.

6.3. Goose shall cooperate with the Controller to enable it to fulfil its obligations to notify the Italian Data Protection Authority (Garante per la protezione dei dati personali) (72 hours) and, where the Controller is subject to the NIS2 legislation (Legislative Decree 138/2024), to submit the early warning and incident notification to CSIRT Italia (24 hours / 72 hours), as well as to communicate the breach to data subjects.

7. Audits

7.1. Upon request, once a year or following a breach, Goose shall provide documentation on the security measures (updated Annex A and answers to the Controller’s security questionnaires).

7.2. Where such documentation is not sufficient or the audit is required by a supervisory authority, the Controller may carry out an audit, directly or through an auditor bound by confidentiality who is not a competitor of Goose, with at least 30 days’ prior notice, during business hours and in a manner that does not compromise the security and data of other customers. The costs of the audit shall be borne by the Controller, unless material breaches attributable to Goose are identified.

8. Obligations of the Controller

The Controller warrants that it has a legal basis for processing the data entered into the Service, that it has provided the required information notices to data subjects (including Users, in particular with regard to any geolocation function, in compliance with Article 4 of Italian Law 300/1970 (Workers’ Statute) where applicable), that it will correctly configure permissions and user accounts, and that it will activate two-factor authentication, where available.

9. Return and deletion of data

Upon termination of the Contract, Goose shall make the Customer Data available for export for 90 days and shall delete them from production systems within 180 days of termination and from backups at the end of the relevant rotation cycle, save for retention obligations imposed by law. Upon request, Goose shall confirm the deletion in writing.

10. Liability and final provisions

The liability of the parties is governed by Article 82 GDPR and, as between the parties, by the Contract. In the event of conflict between this Agreement and the Contract in matters of data protection, this Agreement shall prevail. At the Controller’s request, Goose shall sign a bilateral copy of this Agreement.

Annex A – Technical and organisational measures (summary)

  • Infrastructure: hosting on Amazon Web Services, EU region (Ireland), in data centres certified to ISO/IEC 27001 and SOC 1/2/3; a separate database for each customer (tenant).
  • Encryption in transit: communications encrypted via HTTPS/TLS 1.2 or higher, with HSTS.
  • Authentication and access: personal credentials for each User; two-factor authentication by means of a code sent by e-mail, which can be enabled by the Controller for the application; role- and group-based permissions configurable by the Controller; limit on concurrent sessions per user and expiry of inactive sessions.
  • Traceability: logging of Users’ access to and sessions in the application.
  • Continuity: periodic database backups; offline operation of the apps for core functions.
  • Organisation: access to data limited to authorised personnel bound by confidentiality; notification of incidents to the customer within 24 hours.

Goose has launched a plan to strengthen its security measures; this Annex will be updated upon completion of the related work.

Annex B – Authorised sub-processors

ProviderServiceData location / safeguards
Amazon Web Services EMEA SARLHosting, databases, storage, backupEU (Ireland)
SparkPost / MessageBird (Bird B.V.)Sending of transactional e-mails and documents (including 2FA codes)USA – DPF/SCC
Google Ireland LtdAddress geocoding (Google Maps Platform); support e-mail (Google Workspace)EU/US – DPF/SCC
Crisp IM SASSupport chatEU (France)

Optional integrations activated by the Controller (e.g. Google Calendar, Mailchimp, Freshdesk, ERP systems) are not sub-processors of Goose: the relevant providers are selected and contracted directly by the Controller.

Start your trial now!

30 days free. No credit card required.

Start Goose for Free
Trial
Administration
User Area
To login, simply fill out the fields below.

We use cookies to assure the website’s functionality and to take into account your browsing choices in order to offer you the best experience on our website. In addition we reserve the right to use third-party cookies. To learn more please see our Privacy Policy and Cookie Policy. By continuing to browse the website, the user agrees to use cookies.
OK