What this document governs
This is the governance charter for Goable's consent-based research programme: a programme built from de-identified operational outcomes contributed by participating tenants. It sets out who decides if, how and when operational data becomes a research release, and the controls every release must pass first.
It is a framework of commitments, not a record of audited fact. The roles and processes below are the programme's stated policy. Where something does not exist yet, this page says so plainly rather than implying a maturity the programme has not reached.
Nothing becomes a research release until consent, minimisation, disclosure control and committee approval have each been met.
Controller, processor, and the research dataset
The role split depends on the data context. For operational and analytics data the tenant is the controller and Goable is its processor. For a research release, the position is stated as policy, not asserted as a settled legal conclusion.
| Context | Controller | Processor | Position |
|---|---|---|---|
| Operational data | Tenant (controller) | Goable (processor) | Bookings, score calls and session outcomes. Goable processes them only to deliver the service, under the data processing agreement. |
| Tenant analytics | Tenant (controller) | Goable (processor) | The tenant's own operational records, surfaced back to that tenant. Never leaves the tenant boundary. |
| De-identified research dataset | Goable (stated position) | Not applicable | For a research release the programme's stated position is that Goable acts as controller of the de-identified dataset, potentially under a joint controller arrangement with contributing tenants. This is the programme's policy position, not a settled legal determination. |
Four distinct purposes, one release path
Service delivery, model calibration, tenant analytics and research are distinct purposes with distinct legal bases. Operational audit records stay tenant-scoped; only eligible, consented and de-identified derivatives can ever enter a research release.
| Purpose | What data | Legal basis | Can feed a public release? |
|---|---|---|---|
| Service delivery | Score calls, session records, audit logs | Contract, Art. 6(1)(b) | No. Stays tenant-scoped. |
| Model calibration | Aggregated forecast and outcome pairs | Legitimate interest, Art. 6(1)(f), assessed by a documented balancing test | No. Internal to model quality. |
| Tenant analytics | The tenant's own operational records | Contract, Art. 6(1)(b) | No. Visible only to that tenant. |
| Research release | Consented, de-identified eligible outcomes | Consent, tenant opt-in | Yes, only when consent and disclosure-control thresholds are met. |
Opt-in by default off, and revocable
Default off
research_consent defaults false on every tenant. By default, no operational record is a research candidate.
Tenant opts in
Only the tenant, as controller of its operational data, can set research_consent to true. Goable does not set it on a tenant's behalf.
Eligible rows become candidates
From opt-in onward, consented and de-identified eligible outcomes become candidates for a future release, subject to every downstream control.
Revocation
The tenant can revoke at any time. Revocation stops future candidacy and removes rows not yet released. It cannot always recall an anonymous aggregate already published in a versioned release, and we say so plainly.
The honest limit sits in the last step: revocation reaches future candidacy and unreleased rows, but an anonymous aggregate already published in a versioned release cannot always be recalled.
What an eligible outcome is, and is not
An eligible outcome is a consented, de-identified session outcome. The minimisation schema strips identifying and commercial detail at the tenant boundary, so only a generalised derivative can leave it.
- Exact coordinates, generalised to a grid cell
- Precise timestamps, reduced to a coarse period
- Operator and business identity
- Customer identity and any personal data
- Free-text notes and attachments
- Exact prices and commercial demand
- Raw provider payloads
- Generalised grid cell
- Activity family
- Coarse time bucket
- Forecast summary that preceded the decision
- Ran or cancelled outcome
- Declared equipment category, where supplied
Illustrative shape only. Values are placeholders to show the structure, not a real record.
Documented controls, assessed per release
The measures below are disclosure-control controls applied before a release, not a claim that released data is unconditionally anonymous. Each release is assessed on its own residual re-identification risk; the programme does not treat any dataset as automatically out of scope.
Coordinates are generalised to a grid before release; no exact spot is disclosed.
Minimum distinct contributors behind any released cell; cells below threshold are suppressed.
Releases trail real time so no live commercial signal is exposed.
Each release carries a documented residual re-identification risk assessment before publication.
These controls reduce re-identification risk; they do not guarantee anonymity by default. The residual risk assessment is documented per release and reviewed before publication.
Retention, DSAR and the standing commitments
The commitments below are stated as policy and documented in detail in the data processing agreement. Where a precise figure would depend on the data category, this page points to that document rather than asserting a single number.
Who decides what may be released
The programme's data access committee reviews and approves what may be released. It is a governance body defined by this charter; its membership is not published on this page. Its remit is fixed below.
No dataset is published until the committee has reviewed and approved it against the consent and disclosure-control thresholds.
The committee reviews each per-release residual risk assessment and can require additional generalisation, higher thresholds or suppression.
Members declare interests; anyone conflicted on a given release recuses from that decision.
Papers and derived analyses built on a release are reviewed before submission.
The committee manages corrections, errata and, where necessary, retraction of a release or a finding.
When a release is permitted, and its status today
A public release is permitted only when consent, sample-size and disclosure-control thresholds are met and the data access committee has approved it. Each release is versioned and carries a DOI so it can be cited and corrected.
The first release has not been published. When it is, each release will carry a version and a DOI.
Until the first dataset meets the stated consent, sample-size and disclosure-control thresholds and is approved for release, there is no dataset to cite, and this page carries no DOI to link. We say so plainly rather than imply otherwise.