GOAT labs
StudiesPolymarketBenchNEWModelsDomainsMethodologyFAQAboutContributorsCareers
Log inContactBecome a contributor
Legal

GOAT Labs — Data Processing Addendum

Effective Date: July 1, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between GOAT Labs ("GOAT") and Contributor (the "Agreement", i.e., the Terms of Service) and applies where GOAT processes personal data contained in Contributor Trace Data on Contributor's behalf.

Terms of ServicePrivacy PolicyDPA
Contents · 16 sections
  1. 1Roles and Scope
  2. 2Definitions
  3. 3Documented Instructions
  4. 4Contributor Obligations
  5. 5Confidentiality and Personnel Access
  6. 6Security Measures
  7. 7Subprocessors
  8. 8Data-Subject and Consumer Requests
  9. 9Security Incidents
  10. 10Audits and Compliance Information
  11. 11International Transfers
  12. 12Deletion and Return
  13. 13Deidentified Data Carve-Out and Downstream Reidentification Ban
  14. 14CCPA Service-Provider Terms for the Raw-Trace Stage
  15. 15Processing Details Annex
  16. 16Precedence and Liability
On this page
  1. 1Roles and Scope
  2. 2Definitions
  3. 3Documented Instructions
  4. 4Contributor Obligations
  5. 5Confidentiality and Personnel Access
  6. 6Security Measures
  7. 7Subprocessors
  8. 8Data-Subject and Consumer Requests
  9. 9Security Incidents
  10. 10Audits and Compliance Information
  11. 11International Transfers
  12. 12Deletion and Return
  13. 13Deidentified Data Carve-Out and Downstream Reidentification Ban
  14. 14CCPA Service-Provider Terms for the Raw-Trace Stage
  15. 15Processing Details Annex
  16. 16Precedence and Liability

1. Roles and Scope

For Raw Trace Data containing personal data that GOAT receives from an identified Contributor that has accepted the Agreement, GOAT acts as processor or service provider for the limited core purposes of ingesting, storing, securing, and supporting that data and, where enabled, redacting, validating, and deidentifying it. GOAT acts as an independent controller or business — not as Contributor's processor — for: fraud and abuse prevention; contributor attribution and the maintenance of attribution and identity mappings; structural and economic metadata and fingerprints; program-metric and Cashback calculation and verification; deduplication; security; audit; provenance; product integrity; and re-processing. The parties agree that GOAT's processing for these purposes constitutes processing for GOAT's permitted business purposes under the Agreement and this DPA and does not, by itself, render GOAT a controller of Contributor Personal Data for other purposes.

GOAT also acts as controller or business for: (a) GOAT account, contact, billing, payout, website, fraud-prevention, security, and compliance data; and (b) De-Identified Data that GOAT designates as no longer constituting personal data or personal information under applicable law.

Where Trace Data is submitted through a public project slug or anonymous ingestion (which is enabled by default), the Contributor that owns or controls the project is the controller for, and is deemed to have instructed GOAT to process, all such Trace Data, regardless of which person or machine transmitted it. GOAT does not verify the identity or authority of any sender and processes such traffic in reliance on the project owner's instruction and warranties.

2. Definitions

"Contributor Personal Data" — personal data within Raw Trace Data submitted by, for, or through Contributor (including via repository-level, organization-level, anonymous, or slug-based capture, or connected observability Sources).

"Security Incident" — a breach of GOAT's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Contributor Personal Data. A Security Incident does not include (i) unsuccessful or attempted security events that do not result in unauthorized access to or disclosure of Contributor Personal Data (such as pings, port scans, or denied access attempts), (ii) incidents affecting only De-Identified Data, or (iii) incidents affecting only data for which GOAT acts as controller (addressed under the Privacy Policy).

"Subprocessor" — a processor engaged by GOAT to process Contributor Personal Data on GOAT's behalf.

"De-Identified Data" — data GOAT derives from Raw Trace Data and designates for use in Corpus Products. Data that GOAT can, by reasonably available means — including GOAT's own retained attribution mappings, fingerprints, repository/source labels, session identifiers, provider response identifiers, or un-pseudonymized observability end-user identifiers — link or relate to a natural person, Contributor, customer, or account does not qualify as De-Identified Data and remains personal data subject to this DPA. Designation alone does not make data De-Identified.

3. Documented Instructions

GOAT will process Contributor Personal Data only on Contributor's documented instructions, as set out in the Agreement, this DPA, the product configuration Contributor selects, and any documented support request or written instruction, unless applicable law requires otherwise.

Contributor instructs GOAT through the configuration, credentials, connections, and settings associated with Contributor's account and projects as recorded in GOAT's systems (the connection, credential, and connector records GOAT maintains constitute the documented-instruction artifact). Those instructions include permission to receive Raw Trace Data, perform redaction and deidentification (where enabled), calculate program metrics, provide dashboards and support, and delete or return data as described here. Where Contributor enables repository-, organization-, or multi-user capture (including via a public slug or committed credential), Contributor represents it is authorized to instruct GOAT on behalf of, and to submit the Trace Data of, all individuals captured through that configuration; Contributor's instruction is deemed to cover all such submissions, whether or not the individual submitter separately accepted this DPA, and GOAT is not required to obtain separate instructions or acceptance from any such individual. If GOAT believes an instruction violates applicable data-protection law, GOAT may notify Contributor and suspend the relevant processing.

4. Contributor Obligations

Contributor is the controller for, and makes all obligations and acknowledgments in this DPA with respect to, ALL Trace Data submitted to any project, slug, DSN, key, or capture configuration Contributor controls or enables — including data submitted anonymously, via a public slug, via a committed credential, or by any user, teammate, contractor, agent, or process Contributor enables, whether or not that submitter has a GOAT account or accepted any GOAT terms. Contributor is responsible for: ensuring it has lawful grounds; giving all required notices to, and obtaining all required consents and authorizations from, every data subject whose personal data may be captured — including Contributor's employees, teammates, contractors, customers, and the end users of Contributor's own products whose identifiers or data appear in connected observability Sources; configuring Sources and filters responsibly; not submitting special-category, criminal-offense, health/PHI, payment-card, government-ID, precise-geolocation, biometric, or children's data unless GOAT expressly agrees in writing; and, as controller, receiving, validating, and responding to data-subject and consumer requests relating to Contributor Personal Data.

Contributor is solely responsible for, and assumes all risk arising from, any prohibited-category data it or its connected Sources submit, whether or not knowingly. GOAT does not detect, classify, screen, or block such data and is not liable for its capture, storage, retention, or any downstream processing. Submission of prohibited-category data (without GOAT's prior written agreement, or in breach of any agreed controls) is a material breach permitting GOAT to suspend processing, exclude affected data, and withhold or reverse Cashback. Contributor acknowledges that GOAT does not and cannot verify the submitter's identity, authority, or the existence of any required consent, and agrees GOAT is not liable for Contributor's failure to obtain them.

5. Confidentiality and Personnel Access

GOAT will ensure that persons authorized to process Contributor Personal Data are subject to confidentiality obligations and access Contributor Personal Data only on a need-to-know basis. A limited number of authorized GOAT personnel may access decrypted Raw Trace Data only where necessary and only to the minimum extent necessary for incident response, fraud investigation, legally required processing, or a Contributor-initiated support request, in each case on a logged, audited, need-to-know basis subject to least-privilege role controls. GOAT does not use decrypted Raw Trace Data for routine operations, analytics, or any commercial purpose.

6. Security Measures

GOAT maintains technical and organizational measures designed to protect Contributor Personal Data, including: application-layer authenticated encryption (XChaCha20-Poly1305, per-project, purpose-separated key derivation) of raw trace content fields in a segregated raw store; TLS encryption in transit; segregation of raw content into an isolated store with least-privilege, role-based access controls that prevent dashboard and analytics systems from reading raw content; hashing of stored credentials; environment segregation; access controls and need-to-know restrictions; and append-only audit logging of sensitive access and actions.

Scope and limitations (Contributor acknowledges): application-layer encryption applies to Raw Trace Data and pre-redaction spill blobs; account-level data, the cleaned/queryable projection, dataset exports, and Subprocessor-stored data rely on the encryption and access controls of GOAT's Subprocessors (for example, Cloudflare R2 at-rest encryption) rather than this application-layer scheme. Encryption keys are held as environment-level secrets within GOAT's deployment environment; GOAT does not currently use a hardware security module or managed key-management service, and key rotation is performed manually. GOAT does not currently operate its own backup, point-in-time-recovery, breach-detection, intrusion-detection, or security-monitoring systems; disaster recovery and infrastructure-level monitoring rely entirely on the managed infrastructure and default capabilities of GOAT's Subprocessors. Redaction and deidentification are automated, best-effort processes that are probabilistic, include no human-review step, and may be partial, incomplete, or — in a given deployment — disabled; Raw Trace Data is stored encrypted prior to and independently of any such processing. GOAT may update these measures provided the overall level of security is not materially reduced; GOAT does not warrant any specific recovery-point or recovery-time objective or any particular monitoring, detection, or recovery capability.

7. Subprocessors

Contributor generally authorizes GOAT to engage Subprocessors. GOAT's current Subprocessors include: Supabase (managed Postgres, authentication, and authentication-email delivery; AWS-hosted), ClickHouse Cloud (trace/span store; AWS-hosted), Cloudflare (R2 encrypted object storage and dataset exports, and edge/CDN; storage region "auto"), Upstash (Redis queues/cache/rate-limiting), Resend (transactional email), Google (OAuth identity provider), GOAT's compute host (currently Hetzner; an EU-based provider, specific region not contractually pinned), and Coinbase (used by GOAT to make manual, off-platform Cashback payments to a Contributor-provided wallet address or Coinbase email — GOAT performs no automated integration and no sanctions, KYC, or AML screening). GOAT will make its current Subprocessor list available to Contributor on written request and will use commercially reasonable efforts to notify Contributor (including by posting an updated list) before a new Subprocessor begins processing Contributor Personal Data, generally at least 30 days in advance where practicable. Contributor may object on reasonable data-protection grounds during that period; if the parties cannot resolve the objection in good faith, Contributor may terminate the affected Service or program participation as its sole remedy. GOAT will enter a written agreement with each Subprocessor imposing data-protection obligations that are, in substance, no less protective than those in this DPA (including as required by Article 28(4) GDPR), and, solely to the extent required by Article 28(4) GDPR or equivalent applicable law and subject to the limitations of liability in the Agreement, remains responsible for a Subprocessor's compliance with such obligations.

8. Data-Subject and Consumer Requests

As controller, Contributor is solely responsible for receiving, validating, and responding to data-subject and consumer requests relating to Contributor Personal Data in Trace Data. If GOAT receives such a request directly, GOAT may direct the requester to Contributor and will notify Contributor where required and reasonably possible. Taking into account the nature of processing and the information available to GOAT, GOAT will provide reasonable assistance by appropriate technical and organizational measures insofar as possible — including providing available information, locating data associated with a Contributor or project, and, where feasible, deleting or restricting it — for requests Contributor cannot fulfill through the Service alone. For data subjects who are not Contributor's own users (including teammates, end users, or other individuals whose data appears in connected Sources), GOAT will, where it can reasonably identify the responsible Contributor and the relevant data, route the request to that Contributor; GOAT is not obligated to identify, locate, segregate, produce, or delete the data of any individual data subject within encrypted, aggregated, append-only, or partition-based stores, and does not warrant that any individual item can be located, accessed, or deleted. GOAT may charge a reasonable fee for assistance that exceeds its baseline obligations under applicable data-protection law and may decline assistance the Service does not technically support. Contributor will defend and indemnify GOAT against any claim, request, or proceeding by a data subject, consumer, employee, teammate, end user, or other person arising from Trace Data Contributor submitted, including any request GOAT cannot fulfill due to the design of the Service.

9. Security Incidents

GOAT will notify Contributor without undue delay after GOAT becomes aware of a Security Incident affecting Contributor Personal Data, and will provide information in phases as it becomes available if not all details are known at the time of the initial notice. The notice will include then-available details about the nature of the incident, affected categories of data, mitigation taken or proposed, and information Contributor reasonably needs for its own legal or regulatory response. Contributor acknowledges that GOAT relies substantially on its Subprocessors' managed-infrastructure monitoring, does not independently operate continuous intrusion-detection, alerting, or on-call security monitoring, and that GOAT's ability to detect, confirm, and characterize an incident depends on those Subprocessors and on information actually available to GOAT; GOAT does not warrant detection of any particular incident. Contributor, as controller, is solely responsible for determining and meeting any statutory or regulatory notification timelines applicable to it. GOAT's notice does not, by itself, constitute an admission of liability or fault.

10. Audits and Compliance Information

Upon reasonable request and subject to confidentiality protections, GOAT will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of relevant security measures and any audit reports or certifications GOAT then maintains. Where that information is insufficient for Contributor to demonstrate compliance, or where required by a supervisory authority or following a Security Incident, Contributor (or its mandated independent auditor) may, on at least 30 days' notice and no more than once per 12 months (or as required by a supervisory authority), conduct an audit subject to reasonable scope, security, confidentiality, and cost controls.

11. International Transfers

To the extent a cross-border transfer of Contributor Personal Data requires a transfer mechanism, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference and deemed executed as of the Effective Date — Module Two (controller-to-processor) applying where GOAT acts as processor and Module One (controller-to-controller) applying where GOAT acts as an independent controller under Section 1 — and the UK International Data Transfer Addendum is likewise incorporated. Their Annexes are populated by Sections 6, 7, and 15; GOAT is the data importer and Contributor the data exporter. GOAT and its Subprocessors may process Contributor Personal Data in the European Union, the United States, and other countries, as determined by GOAT's hosting and Subprocessor configuration (data residency is set at the infrastructure and Subprocessor level and is not individually configurable by Contributor). Contributor, as controller, is responsible for determining whether a transfer mechanism is required for its own transfers to GOAT and for any transfer-impact assessment for those transfers. The parties may execute further annexes reasonably required.

12. Deletion and Return

Contributor acknowledges that GOAT retains Raw Trace Data in encrypted, access-segregated storage on a long-term and potentially indefinite basis for re-processing, provenance, security, audit, and fraud-prevention, that GOAT does not currently operate automated or self-service deletion tooling, and that project deletion is a soft-delete (archival) that stops future ingestion but retains previously captured data. During the term and after termination, GOAT will, at Contributor's election and using commercially reasonable efforts, delete, de-identify, or return Contributor Personal Data that remains reasonably accessible to GOAT in its operational systems within a commercially reasonable period after the wind-down or export period, and will at minimum cease active processing and access-restrict (quarantine) any Contributor Personal Data it cannot then technically delete, pending deletion as soon as feasible. The following are excepted: data retained as required by law or reasonably necessary for legal defense, auditability, fraud investigation, or secure backup restoration; append-only legal, consent, rights, provenance, and audit records that are immutable by design; and De-Identified Data and Corpus Products already derived, and datasets already exported or licensed, which are excluded from deletion and return obligations (to the extent they remain outside personal-data scope). Disconnecting a Source stops future collection and deletes stored Source credentials but does not delete Trace Data already ingested. Contributor bears the reasonable costs of any deletion or return. Archived or backup copies retained for the above purposes remain protected under this DPA until deleted in the ordinary course.

13. Deidentified Data Carve-Out and Downstream Reidentification Ban

To the extent data has in fact been de-identified to the standard in Section 2 and no longer constitutes personal data or personal information under applicable law, that data falls outside this DPA, and GOAT may use, combine, analyze, license, distribute, and commercialize it and resulting Corpus Products in its own independent capacity, under the Agreement and Privacy Policy. GOAT does not represent that it operates an automated per-record gate that verifies De-Identified status before commercialization; GOAT applies such manual or automated controls as it elects, which may be limited, partial, or absent, and Contributor acknowledges and assumes the risk that data not meeting the De-Identified Data standard may be processed, licensed, or included in Corpus Products.

GOAT shall, by binding contract, prohibit each recipient of De-Identified Data and Corpus Products from attempting to reidentify any natural person, Contributor, customer, or account, require recipients to flow that prohibition to onward recipients, and itself maintain reasonable technical and organizational measures intended to prevent reidentification. GOAT does not warrant that any recipient will comply and is not responsible for a recipient's breach. Contributor will not, and will not direct or enable any third party to, attempt to reidentify, re-link, or re-associate any De-Identified Data or Corpus Product with any natural person, Contributor, customer, or account, except as strictly necessary to exercise a legal right with respect to Contributor's own personal data. GOAT determines, in its reasonable discretion, whether data constitutes De-Identified Data; Contributor assumes the risk of, and will not hold GOAT liable for, any reidentification arising from metadata Contributor authorized GOAT to process or retain.

Contributor acknowledges that GOAT retains, for attribution, payout, provenance, and fraud-prevention, internal mappings between pseudonymous references and account identities, plaintext repository/source labels, and identifiers contained in connected observability data (including third-party end-user identifiers), some of which are stored without pseudonymization; to the extent such data remains reasonably linkable, it is personal data and is not De-Identified Data.

14. CCPA Service-Provider Terms for the Raw-Trace Stage

For Contributor Personal Data governed by the CCPA during the raw-trace processor stage, GOAT will not sell or share that data, and will not retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement and this DPA (including the operational purposes in Section 1) or as otherwise permitted by applicable law, and will provide the level of privacy protection required by law for that stage. GOAT will not combine that Contributor Personal Data with personal information from any other source except as permitted by Cal. Civ. Code §1798.140(e)(6), and GOAT certifies that it understands the restrictions in this Section and will comply with them. This Section's exclusion applies only to data that has in fact been de-identified to the standard in Section 2; the service-provider commitments here apply to all Contributor Personal Data that has not in fact met that standard, for so long as it has not. For all other data described in Section 1(a)–(b), GOAT acts as a business/controller and the service-provider restrictions in this Section do not apply.

15. Processing Details Annex

Subject matter: ingestion, storage, support, and redaction, validation, and deidentification (which are automated, best-effort, probabilistic, and include no human review) of Raw Trace Data; analytics; program-metric and Cashback calculation; fraud and abuse review; and deletion, de-identification, or return of Contributor Personal Data where and to the extent technically feasible.

Duration: the term of the Agreement plus any limited post-termination period needed for export, deletion (where feasible), legal compliance, or secure backup retirement. Encrypted, access-segregated Raw Trace Data is retained for as long as necessary for re-processing, provenance, security, audit, and fraud-prevention, and is deleted on a verified request where technically feasible; append-only legal/audit records are retained for the limitation and record-keeping period required by law.

Categories of data subjects: Contributor's users, employees, contractors, end users, customers, and other natural persons whose personal data may appear in Trace Data submitted by, for, or through Contributor — including persons captured via repository-level, organization-level, anonymous, or observability-Source ingestion who take no GOAT-specific action.

Categories of personal data: names, email addresses, usernames, and identifiers; pseudonymous contributor and machine identifiers; prompts, completions, and reasoning; tool-call content and results (including file contents, code, diffs, command output, and pasted artifacts); tool/MCP definitions and system prompts; log and span metadata; session, conversation, and provider response identifiers; repository and file context (including repository origin/remote, branch, commit, and working-directory paths); observability end-user identifiers and user-supplied metadata (which GOAT does not pseudonymize); internal attribution mappings linking pseudonymous contributor references to GOAT account identities, and retained source/repository labels, used for attribution, payout, provenance, and fraud-prevention; payout instruments (wallet address or Coinbase email); IP addresses recorded only on specific audited security and account events; and other personal data embedded in submitted Trace Data.

Sensitive data: not intended and not permitted unless expressly agreed in writing with appropriate controls; the Service does not screen, classify, or block data by category before capture, and Contributor is solely responsible for and assumes all risk for any such data it submits.

16. Precedence and Liability

This DPA forms part of, and is governed by, the Agreement. Except where this DPA expressly states a data-protection-specific term that applicable law requires to control, the Agreement governs; in case of conflict on commercial terms, the Agreement controls. The Agreement's governing-law, venue, dispute-resolution (including any arbitration and class-action waiver), limitation-of-liability, and disclaimer provisions apply in full to this DPA and to any claim arising under it, and each party's aggregate liability arising out of or related to this DPA is subject to, and counts toward, the limitations and exclusions of liability in the Agreement. This DPA does not, and shall not be construed to, expand either party's liability beyond what the Agreement provides.

GOAT labs

Get paid for your production LLM traces. Research built in the open.

Research
StudiesPolymarketBenchMethodologyFAQ
Contribute
Become a contributorModels & ratesGet started
Company
AboutCareersContact
Legal
Terms of ServicePrivacy PolicyDPA
© 2026 GOAT labs · San Francisco