Gobelino Gobelino

Data Processing Agreement (DPA)

Last updated: October 11, 2026

1. Parties and purpose of this agreement

This Data Processing Agreement ("DPA") supplements Gobelino's Terms of Service and applies automatically, with no separate signature required, to every organization that creates a Gobelino account (the "administrator" or "controller"). It implements the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR") for the relationship between data controller and data processor.

Acceptance of this DPA happens at the same time as account creation and is recorded with a date and time.

2. Roles

For the technical data collected from devices enrolled under the administrator's account (see section 4 of the Privacy Policy), the administrator is the data controller: they decide which devices to enroll, which restrictions to apply, whether and when to request location, and which apps to install. Gobelino acts as the data processor, processing data solely on the administrator's instructions as expressed through use of the panel and agent app.

3. Subject matter, nature, and duration of processing

Subject matter: provision of the Gobelino mobile device management service. Nature of the operations: collection, storage, consultation, and deletion of the technical data listed in the Privacy Policy. Duration: for the lifetime of the administrator's account, until the service ends or data is deleted as described in section 6 of the Privacy Policy.

4. Data types and categories of data subjects

Data types: technical device information (model, operating system, battery, network, installed apps, hardware identifiers), geographic location only on request or at configured intervals, Wi-Fi credentials set by the administrator. Remote screen-view/control sessions (see section 5 of the Privacy Policy) stream video in real time directly between the device and the administrator's browser, without Gobelino processing or storing its content. No special category data under GDPR Art. 9 is processed. Categories of data subjects: the administrator's employees/collaborators using the enrolled devices.

5. Gobelino's obligations as processor

Gobelino agrees to:

  • process data solely on the administrator's documented instructions, as expressed through use of the service;
  • ensure personnel authorized to process the data are bound by confidentiality obligations;
  • implement appropriate technical and organizational measures (HTTPS encryption in transit, two-factor authentication for panel access, data minimization — see sections 6 and 7 of the Privacy Policy);
  • reasonably assist the administrator in responding to data subject rights requests;
  • notify the administrator without undue delay of any personal data breach it becomes aware of;
  • not engage sub-processors beyond those listed in section 7 of the Privacy Policy without notice;
  • delete or render data inaccessible as described in section 6 of the Privacy Policy upon device removal or account termination.

6. Sub-processors

Gobelino relies on the following sub-processors to provide the service: Railway (infrastructure and database hosting), Cloudflare (storage for the daily database backup, via its R2 service), Sentry (error tracking for the panel and the agent app — receives stack traces and technical software data, not personal data belonging to the people using the devices), Resend (transactional email, e.g. team invitations), Google's Firebase Cloud Messaging (push notifications for immediate device wake-up, processes device identifiers), and Aptoide (the app search engine used by the panel's "Install app" feature, receives the search terms typed by the administrator). The administrator generally authorizes the use of these sub-processors. Material changes to this list will be communicated.

7. Administrator's obligations as controller

The administrator warrants that it has an appropriate legal basis for processing its employees'/collaborators' data through Gobelino, and that it has informed them accordingly — see section 5 of the Terms of Service.

8. Liability

Limitations and allocation of liability between the parties are governed by section 8 (Limitation of liability) and section 9 (Indemnification) of the Terms of Service, which also apply to this DPA. Nothing here affects each party's own direct liability toward data subjects under GDPR Art. 82 for its own GDPR violations not resulting from the other party's instructions.

9. Changes

This DPA may be updated over time, particularly during the product's beta phase. The most recent version is always available at this same address.

10. Contact

For questions about this agreement, contact legal@gobelino.net.