Skip to content

How your data is processed.

The data processing agreement (DPA) for Good Either Way, plus every subprocessor we use — the whole list, no hidden vendors.

Last updated 8 August 2026.

The parties

Controller: you, or the organisation you represent (member, donor, charity, or creator). Processor: Skiwo AS (org 916636660), Pilestredet 17, 0164 Oslo, Norway — the company behind Good Either Way. This DPA applies whenever we process personal data on your behalf and forms part of our Terms.

What we process, and why

Account email addresses and names; commitment and session records (self-reported); private proof photos (visible only to their owner unless the owner shares one with their exercise buddies; never reviewed); payment tokens (we never hold card numbers — Stripe does); support correspondence; and the aggregate statistics described in our Privacy page. Purpose: running the service you signed up for. Nothing here is ever sold or rented, and nothing you do inside the app feeds an advertising profile. The one place advertising touches us at all is the public marketing pages, where — only if you consent — Google's tag tells us that an ad we paid for brought someone here. Your sessions, your photos and your stake never leave for that purpose.

Our promises as processor

We process personal data only to provide the service; we apply the safeguards described on the Privacy page (encryption in transit, private storage with expiring links, least-access); we tell you without undue delay if we learn of a personal data breach affecting your data; we help with access and deletion requests (self-serve deletion is built in); and when you delete your account we delete your data for real.

Subprocessors — the full list

Salesforce/Heroku (application hosting, EU region) · Amazon Web Services (file storage on S3 and email via SES, eu-west-1 Ireland) · Stripe (payments, card storage, charity payouts — Stripe is an independent controller for its own KYC) · Cloudflare (DNS and network security in front of the site, plus cookieless visit counting on the public marketing pages — no cookies, no cross-site tracking, and never inside the app once you're signed in) · Google (advertising measurement on the public marketing pages only, and only after you consent — never in the signed-in app) · Skiwo AS (ConsentKit, our own consent tool, which records your cookie choice). Our fonts are served from our own servers, so no font CDN sees you at all. Dormant unless switched on: Twilio (WhatsApp notifications — currently off). We'll update this list before adding anyone new.

International transfers

Hosting and storage sit in the EU (Heroku EU, AWS eu-west-1). Stripe, Cloudflare, and Google operate globally under standard contractual clauses. We operate from Norway (EEA) and serve members worldwide, so GDPR-grade handling is the default for everyone, not a regional favour.

Sub-DPAs and audits

Each subprocessor is bound by its own data processing terms at least as protective as these. Want a signed copy of this DPA or have an audit question? Email hello@goodeitherway.com — a human answers.

Questions?

Email hello@goodeitherway.com. A human reads every one.