UTC --:--:--

Goable — Data Processing Agreement (DPA)

Version: 2026-06-26.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Fabio Carucci, an Italian sole proprietor trading as "Goable" ("Processor", "Goable"), and the Customer ("Controller") identified in the tenant record. It applies whenever Goable processes Personal Data on the Controller's behalf in connection with the Service.

By accepting the Terms of Service at signup or by continuing to use the Service, the Controller accepts this DPA. Where the Controller requires a counter-signed version on the Controller's paper, contact privacy@goable.io to open the redline workflow.

1. Definitions

Terms with initial capitals in this DPA have the meaning given in the GDPR (Regulation (EU) 2016/679) and in the Terms of Service. In particular:

  • Personal Data, Data Subject, Processing, Controller, Processor, Sub-processor, Personal Data Breach, Supervisory Authority have the meanings in GDPR Articles 4 and 33.
  • Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 as set out in EU Commission Implementing Decision 2021/914 of 4 June 2021.
  • Annex I, Annex II, Annex III refer to the annexes at the end of this DPA.

2. Subject matter, scope, and roles

2.1 Subject matter: Goable processes Personal Data on the Controller's behalf as set out in Annex I, solely to provide the Service per the Terms of Service.

2.2 Roles:

  • For per-request payloads (geographic + temporal + activity + pseudonymised user reference + outcomes), Goable acts as the Controller's Processor.
  • For the Controller's own tenant account data (display name, contact email, billing identifiers, authentication credentials, legal-acceptance ledger), Goable acts as an independent Controller. This DPA does not govern that processing: the Privacy Policy does.
  • For the published research dataset (aggregated data released under CC BY 4.0), Goable acts as an independent Controller. Aggregates are released only after a documented disclosure-control review and are treated as no longer Personal Data where that determination is documented; withdrawal of the Controller's consent stops future research processing.

2.3 Duration: This DPA applies for as long as Goable processes Personal Data on the Controller's behalf, that is, for the term of the Terms of Service, plus any post-termination period during which Goable retains data per clause 9.

3. Processor obligations

Goable, acting as Processor, undertakes to:

3.1 Process only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required by Union or Member State law to which Goable is subject (in which case Goable will inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest). The Controller's documented instructions are: (a) the API requests the Controller submits and the configuration set in the console, and (b) any additional written instruction the Controller sends to privacy@goable.io.

3.2 Ensure persons authorised to process the Personal Data are under a contractual obligation of confidentiality or are bound by an appropriate statutory obligation of confidentiality.

3.3 Implement technical and organisational measures (TOMs) appropriate to the risk, as described in Annex II.

3.4 Not engage another Processor (Sub-processor) without the Controller's general written authorisation. The Controller hereby grants such general authorisation. Goable maintains the current list of Sub-processors in Annex III and at https://goable.io/legal/data-processing-agreement. Goable notifies the Controller at least 30 days before any addition or replacement, giving the Controller the right to object. If the Controller objects on reasonable grounds (e.g. inability to satisfy specific data-protection obligations in the Controller's industry), the parties will work in good faith to find a resolution; failing that, the Controller may terminate the Terms of Service per clause 10.2 of the Terms.

3.5 Impose on Sub-processors the same data-protection obligations as set out in this DPA, by way of a written contract.

3.6 Assist the Controller, by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests for exercising Data Subjects' rights (GDPR Chapter III). In particular, Goable provides:

  • The programmatic GDPR Article 17 cascade DELETE /v1/decision/user-data/:pseudonym (described in Privacy Policy clause 8.1).
  • Audit-log export on request via privacy@goable.io.
  • Within one month of the Controller's authenticated request, the Personal Data Goable holds about a Data Subject identified by pseudonym, in a structured, commonly-used, machine-readable format.

3.7 Assist the Controller in ensuring compliance with GDPR Articles 32 to 36, taking into account the nature of processing and the information available to Goable.

3.8 At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data. Aggregated contributions to the research dataset made under the Controller's prior consent are not subject to this clause, to the extent Goable has determined, following the disclosure-control review, that they are no longer Personal Data.

3.9 Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Controller agrees to give Goable reasonable notice (no less than 30 days, except where required earlier by a Supervisory Authority), bear the cost of the audit, and conduct the audit under reasonable confidentiality obligations. For lightweight verification, Goable will provide the most recent audit reports it holds (e.g. when SOC2 is obtained), penetration-test summaries, and a written response to the Controller's reasonable security questionnaire.

3.10 Inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection provisions.

4. Personal Data Breach

4.1 Notification. Goable notifies the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provides information in phases as it becomes available. As an operational commitment, Goable aims to send an initial notice within 24 hours of confirming that the Controller's data is impacted. The notification includes, to the extent then known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and the contact point at Goable. The 72-hour deadline in GDPR Article 33 is the Controller's obligation to notify its Supervisory Authority, not a Processor deadline; Goable's role is to support the Controller in meeting it.

4.2 Cooperation. Goable cooperates with the Controller in fulfilling the Controller's notification obligations to the Supervisory Authority (GDPR Article 33) and to Data Subjects (GDPR Article 34).

4.3 Channel. Initial notification is by email to the tenant contactEmail on record, with a follow-up call where the impact severity warrants. Goable maintains a security@goable.io channel for the Controller to escalate breach-related queries.

5. International transfers

5.1 Within EEA. Personal Data processed on the Controller's behalf is primarily processed within the European Economic Area, as described in Annex III.

5.2 Outside EEA. Where Personal Data is transferred to a Sub-processor outside the EEA, Goable relies on the EU Commission's Standard Contractual Clauses (Module 3, Processor-to-Processor, where Goable transfers to its Sub-processor as a Processor of the same Personal Data). The SCCs are incorporated into this DPA by reference; where any term of this DPA conflicts with the SCCs, the SCCs prevail.

5.3 Supplementary measures. Goable assesses each transfer per the EDPB recommendations on supplementary measures (Recommendations 01/2020) and applies appropriate technical (encryption in transit + at rest), contractual (SCCs + addendum), and organisational measures.

6. Aggregate liability and indemnification

6.1 Liability under this DPA is subject to the limitation of liability and indemnification provisions of the Terms of Service.

6.2 Nothing in this DPA limits liability for violations of mandatory data-protection law, where such limitation is prohibited.

7. Governing law and forum

This DPA is governed by the same law and forum as the Terms of Service (the laws of Italy; the competent courts of Italy), except where mandatory data-protection law of another jurisdiction applies to a Data Subject's claim.

8. Order of precedence

In case of conflict between the documents that govern the relationship, the following order of precedence applies (the Terms of Service state the same order):

  1. Any signed order form or master agreement between the parties.
  2. The Standard Contractual Clauses, for questions of international data transfer.
  3. This DPA, for data-processing matters.
  4. The Terms of Service.
  5. The other referenced policies (Privacy Policy, AUP, SLA, Liability Framework).

9. Term and survival

This DPA enters into force on the Controller's acceptance and remains in force for as long as Goable processes Personal Data on the Controller's behalf. Clauses 3.8 (deletion / return), 3.9 (audit cooperation), 4 (breach notification post-incident cooperation), 5 (international transfer obligations for transfers that occurred during the term), 6 (liability), and 7 (governing law) survive termination.


Annex I — Details of processing

Categories of Data Subjects: The Controller's end users (e.g. booking customers, app users), represented to Goable only as pseudonyms (HMAC-SHA256 over the Controller's internal user-id, keyed by a salt the Controller holds; cleartext never reaches Goable).

Categories of Personal Data: Geographic coordinates, sub-spot slug, time windows, activity slug, pseudonymised user reference, optional non-identifying attributes (skill level, equipment type), session outcomes (captured as structured reason codes, with an optional free-text comment that the Controller must not populate with special-category or direct-identifier data), audit-log entries (raw weather samples, provider chain, forecast horizon, calibrated response).

Special categories of personal data: None permitted. The Controller warrants under the AUP not to submit special-category data (GDPR Article 9).

Nature and purpose of processing: Compute 0–100 suitability scores per activity / place / time; surface recommendations, explanations, counterfactuals, and personalised decisions; close the calibration loop via outcome reports; (where opted in by the Controller) contribute aggregated research contributions to the open research dataset.

Frequency of processing: Continuous, on-demand on each API call.

Duration of processing: For the term of the Terms of Service plus the audit-log retention period (one year by default, extendable per signed addendum). End-user pseudonyms erased on the Controller's GDPR Article 17 request via the programmatic cascade.

Recipients: Goable's authorised personnel under confidentiality obligations; the Sub-processors listed in Annex III. No further disclosure except as required by law.

Annex II — Technical and organisational measures (TOMs)

Pseudonymisation and encryption (GDPR Article 32(1)(a)):

  • End-user identifiers received as pseudonyms only (HMAC-SHA256 keyed by a Controller-held salt).
  • TLS 1.2+ for all data in transit; HSTS preload; TLS 1.0/1.1 disabled.
  • AES-256 at rest via AWS-managed KMS for Postgres + S3 + DynamoDB.
  • API keys stored as SHA-256 hashes; ops user passwords scrypt-hashed; magic-link tokens stored as SHA-256 hashes.

Confidentiality, integrity, availability, and resilience of processing systems (Article 32(1)(b)):

  • Tenant-scoped row-level access controls at the API layer; cross-tenant access is a CVE-class bug actively defended against with end-to-end tests.
  • API/compute runs in AWS eu-west-1 (Ireland); the primary database is Neon Postgres in eu-central-1 (Frankfurt).
  • Tamper-evident, versioned audit trail; per-request id correlatable across surfaces.

Restoration of availability (Article 32(1)(c)):

  • Neon Postgres point-in-time recovery and regular logical backups; backups stored encrypted with separate IAM access. Recovery targets are documented internally and reviewed periodically.

Regular testing, assessing, and evaluating (Article 32(1)(d)):

  • Automated CI test suite across the engine + API + admin layers.
  • pnpm-lock pinned + Dependabot watching; critical CVE alerts gate prod deploys.
  • Periodic internal security review.
  • Penetration test scheduled on first signed enterprise engagement.

Access management:

  • AWS Identity Center SSO with TOTP-mandatory for all production access.
  • Principle of least privilege for service IAM roles.
  • Console session JWTs are short-lived; API keys are scope-gated and per-tenant, with a logout denylist in place.

Incident response and breach notification:

  • Triage channel for incidents; public status strip updated promptly on detection.
  • Post-mortems published for any incident affecting tenant traffic.
  • Breach notification to the Controller per clause 4.

Disposal and erasure:

  • Programmatic GDPR Article 17 cascade (DELETE /v1/decision/user-data/:pseudonym) hard-deletes per-user models and decision-runs; anonymises audit-log rows.
  • On tenant termination, account data is deleted per the Privacy Policy retention schedule.

Annex III — Authorised Sub-processors

The current Sub-processor list. Goable updates this list with at least 30 days' notice as required by clause 3.4.

Sub-processorRoleCountry of processingSafeguard
Amazon Web Services EMEA SARLAPI/compute hosting (Lambda, API Gateway, S3) and CloudFront CDN for the public API ingress (api.goable.io)EU (Ireland, eu-west-1)EU data region
Neon Inc.Primary Postgres databaseEU (Germany, Frankfurt, eu-central-1)EU data region; SCCs for any processing outside the EEA
Vercel Inc.Website and console front-end hostingEU (Frankfurt, fra1)SCCs for any processing outside the EEA
Upstash Inc.Redis (rate-limit counters, ephemeral sessions)EUEU data region
Stripe Payments Europe Ltd.Payment processing, subscription management, usage meteringEU (Ireland) with sub-processors in USSCCs
Cloudflare Inc.DNS and the console/marketing edge; Turnstile CAPTCHA on signupEU edge; global edge locationsNo tenant API payloads cached at the edge; SCCs where applicable
Anthropic Ireland Ltd.LLM inference for the AI explainer + decision-agent natural-language layer. Sub-processor when the Goable-provided fallback key is used; where a tenant uses its own key (BYOK), Goable does not hold that keyEU (Ireland) with possible US fallbackSCCs
Resend Inc.Transactional email (magic links, billing receipts, drift alerts)EU edge with US data planeSCCs
PostHog Inc.First-party product analytics on the console (self-hosted EU instance)EUEU data region

Contact

Privacy: privacy@goable.io Security disclosures: security@goable.io Legal / contractual notices: contact@fabio-carucci.com

Operator: Fabio Carucci (trading as Goable), Magliano Alfieri, 12050 (CN), Italy. P.IVA IT04133450041.


Last updated: 2026-06-26. This document is published at https://goable.io/legal/data-processing-agreement. The version stored in legal_documents and accepted at signup is the canonical version for the Controller; on request, the Controller can obtain a downloadable copy of the full text, version, content hash, and acceptance timestamp of the version they accepted.