goff
Legal NoticeDPATerms
EN/DE

ARTICLE 28 GDPR

DPA

Last updated: September 19, 2026

← Back to home
Draft – complete before publication.The company, contact, and infrastructure details marked “[COMPLETE]” must be reviewed and replaced. This text is not a substitute for legal review.

Parties

This Data Processing Agreement (“DPA”) is entered into between the customer as controller (“Controller”) and the provider of the goff API identified in the Legal Noticeas processor (“Processor”). It forms part of the main agreement. Terms have the meanings assigned to them in the General Data Protection Regulation (“GDPR”).

1. Subject matter and duration

The subject matter is the processing of personal data submitted by the Controller through the API for evaluation by AI-supported decision models. Processing continues for the term of the main agreement and thereafter for as long as the Processor processes data for the Controller in accordance with the agreement or statutory retention obligations apply.

2. Nature and purpose of processing

Processing includes receiving, transmitting, holding in memory, analysing, and returning API content in order to produce typed choice, score, and yes/no results. Content data is not used to train or improve models and is not intentionally retained after the response. Infrastructure providers process it only as necessary to host and transmit the request. Billing and security metadata is processed separately from API content.

Under the current product design, API request and response content is not exported to Moesif or Stripe; credentials and response fields are masked. The Controller must nevertheless submit only data necessary for the relevant purpose.

3. Types of data and categories of data subjects

CategoryExamples
API contentText, structured states, criteria, model responses
Identification and contact dataNames, business contact details, internal identifiers
Usage data and metadataTime, model, token count, status, technical request identifier
Other dataContent determined by the Controller, including special categories under Article 9 GDPR where expressly agreed

Data subjects may include, in particular, the Controller’s employees, customers, prospects, suppliers, communication partners, and users. The Controller determines the content and categories through its use of the service.

4. Instructions

The Processor processes personal data solely on documented instructions from the Controller, unless processing is required by Union or Member State law. The main agreement, this DPA, API configuration, and documented support requests constitute instructions. If the Processor considers an instruction unlawful, it will inform the Controller without undue delay and may suspend execution until the matter is clarified.

5. Processor obligations

The Processor undertakes in particular to:

  • use only authorised persons who are bound by confidentiality;
  • maintain appropriate technical and organisational measures under Article 32 GDPR;
  • reasonably assist the Controller with data-subject requests, data protection impact assessments, and consultations;
  • report personal data breaches without undue delay after becoming aware of them, using the information available;
  • maintain required records and cooperate with supervisory authorities;
  • delete or return data, at the Controller’s choice, after the agreement ends unless statutory retention is required.

6. Controller obligations

The Controller is responsible for the lawfulness, transparency, data minimisation, and accuracy of processing and for satisfying data-subject rights. It will not submit special categories of personal data under Article 9 GDPR or data concerning criminal convictions under Article 10 GDPR until the parties have documented the specific use and additional safeguards.

7. Sub-processors

The Controller grants general authorisation for the sub-processors listed below. The Processor will give at least 30 days’ notice of an intended addition or replacement. The Controller may object on substantiated data-protection grounds. If no reasonable alternative is available, either party may terminate the affected service for cause.

Sub-processorServiceLocation
Microsoft Ireland Operations Limited / Microsoft AzureHosting, networking, and managed databaseEU – Sweden (Azure region “Sweden Central”); [COMPLETE transfer mechanism]
Moesif, Inc.Technical usage metadata, metering, and credit management; no API content[COMPLETE processing location and transfer mechanism]
[COMPLETE additional production providers][COMPLETE service][COMPLETE location]

Depending on the function, Stripe also processes payment and billing data as an independent controller. Before publication, the allocation of roles must be reviewed and Stripe must be listed here to the extent it acts as a sub-processor.

8. International transfers

Processing outside the European Economic Area takes place only on documented instructions and in compliance with Chapter V GDPR. Where no adequacy decision exists, the European Commission’s Standard Contractual Clauses and, where required, additional safeguards will be agreed. The mechanisms actually used must be identified in the sub-processor list.

9. Evidence and audits

The Processor will provide all information necessary to demonstrate compliance with Article 28 GDPR. Following reasonable notice and generally once per year, the Controller may conduct audits itself or through an auditor bound by confidentiality. Current certificates, audit reports, and questionnaires will be used first. Additional effort may be charged at customary market rates unless the audit was prompted by a breach attributable to the Processor.

Annex 1 – Technical and organisational measures

  • Encrypted transmission using TLS and separation of public and internal services;
  • API keys, role-based access, and separate database accounts;
  • Masking of authorisation data, cookies, and request and response content in usage analytics;
  • Retention of technical and security application logs for no more than 30 days without prompts, request content, answers, API keys, authorisation headers, or cookies;
  • Minimisation of technical metadata and disabled product telemetry in the model router;
  • Hardened containers with restricted privileges, internal services, and secret-protected configuration;
  • Backups, recovery procedures, monitoring, security updates, and documented security-incident handling;
  • Regular effectiveness reviews and access restrictions based on the need-to-know principle.

[COMPLETE specific backup periods, other deletion periods, encryption of data at rest, recovery objectives, and the contact channel for security incidents.]

Annex 2 – Deletion and retention policy

DataStandard period
API request and response contentProcessed for the duration of the request and not intentionally retained in application or error logs. Technical and security logs without this content are deleted after no more than 30 days.
Technical usage metadata[COMPLETE period]
API keys and account mappingUntil deletion by the customer or end of the agreement, plus [COMPLETE period]
Backups[COMPLETE rotation and deletion period]

10. Order of precedence and final provisions

If this DPA conflicts with another agreement, this DPA prevails for matters within its scope. Otherwise, the Terms and the main agreement apply. Amendments to this DPA must be made in text form. If a provision is invalid, the remaining provisions remain unaffected.

goff

Legal information for the API.

Legal NoticeDPATerms