Data Processing Agreement
The processing terms that apply when AppMetricsKit handles mobile analytics data for a customer.
Last updated: July 29, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between AppSurge in Belgium, operating AppMetricsKit ("Processor"), and the customer using the Service ("Controller"). It applies when the Processor handles personal data in mobile analytics events on the Controller's behalf. It becomes effective when the Controller accepts the Terms of Service or starts using the Service.
1. Scope, roles, and duration
The Controller determines the purposes and essential means of processing and is responsible for the lawfulness of its instructions. The Processor handles analytics data only to provide, secure, support, and maintain the Service. Processing continues for the term of the Controller's use of the Service and until data is deleted according to the configured retention period, a valid deletion instruction, or an applicable legal requirement.
2. Processing details
- Subject matter: mobile product, subscription, purchase, and diagnostic analytics.
- Nature and purpose: receive, validate, filter, store, aggregate, display, export, retain, and delete analytics data so the Controller can understand use of its mobile applications.
- Data subjects:users of the Controller's mobile applications.
- Personal data: hashed account identifiers when configured, session and event identifiers, timestamps, app and operating system versions, device model, locale, timezone, permitted event payload values, purchase and subscription events, diagnostic events, and privacy findings containing short redacted samples.
- Frequency:continuously or intermittently, as determined by the Controller's SDK and integration configuration.
The Service is not intended for special category data, raw account identifiers, advertising identifiers, precise location, payment card data, or free form text that may identify a person. The Controller must not intentionally submit such data.
3. Controller instructions and obligations
The Terms, this DPA, settings selected in the Service, API requests, and written support requests are the Controller's documented instructions. The Controller must provide all required notices, establish a lawful basis, configure access and retention appropriately, and review the event payloads sent by its apps. If an instruction would infringe applicable data protection law, the Processor will inform the Controller unless prohibited by law.
4. Processor obligations
- Process personal data only on documented instructions.
- Ensure that people authorized to process the data are bound by confidentiality obligations.
- Maintain technical and organizational measures appropriate to the processing risk.
- Assist the Controller with data subject requests, security obligations, impact assessments, and regulator consultations where required and reasonably possible.
- Notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
- Make information reasonably necessary to demonstrate compliance with this DPA available to the Controller.
5. Subprocessors
The Controller gives general authorization for the Processor to use subprocessors needed for database hosting, application hosting, authentication, payments, email delivery, monitoring, support, and optional revenue integrations. The Processor will impose data protection obligations appropriate to each subprocessor's work and remains responsible for its processing obligations. A current list is published on the subprocessor page. Where required by law, the Processor will provide notice of a material new subprocessor and allow the Controller to object on reasonable data protection grounds.
6. Security measures
- Transport encryption using TLS.
- Infrastructure encryption at rest.
- Role-based access control scoped to each organization.
- Tenant-scoped authorization in server functions.
- Ingest keys and API keys stored as hashes rather than plaintext.
- Audit records for sensitive administrative actions.
- SDK and ingest guardrails that remove configured keys and detected risky payload values before event storage.
7. Data subject requests
If the Processor receives a request relating to Controller data, it will direct the requester to the Controller unless law requires a different response. Taking into account the nature of processing, the Processor will provide reasonable assistance through retention, export, and telemetry deletion controls or through support.
8. Return and deletion
During the subscription term, the Controller may export available data using the Service. On instruction or termination, the Processor will delete Controller analytics data according to the product's deletion workflow and operational retention schedule, unless law requires continued storage. Deletion runs in batches and may not be immediate. Legal and security records may be retained only for the period required by law or reasonably needed to establish or defend legal claims.
9. International transfers
When personal data is transferred outside the European Economic Area, the Processor will use an adequacy decision, Standard Contractual Clauses, or another lawful transfer safeguard where required. The parties will complete any required transfer annexes or additional safeguards on request.
10. Audits
The Controller may request available security and privacy documentation no more than once per year, unless a personal data breach or regulator requires additional review. If that information is insufficient, the parties will agree on a proportionate audit that protects other customers, confidential information, and service security. The Controller is responsible for audit costs unless the audit identifies a material breach of this DPA by the Processor.
11. Order of precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA controls. Other terms, including liability limits, remain governed by the Terms unless applicable law requires otherwise.
12. Contact
Send DPA, subprocessor, transfer, or privacy requests to support@appmetricskit.com. Contact support if you require a countersigned copy or completed transfer annexes.