Data Processing Agreement
The data-processing terms for customers using AppMetricsKit as a privacy-first mobile analytics processor.
Last updated: June 20, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between AppSurge, Belgium, operating AppMetricsKit ("Processor"), and the Customer ("Controller") and governs the processing of analytics data on the Controller's behalf.
1. Roles
The Controller determines the purposes and means of processing. The Processor processes data only on documented instructions from the Controller, as configured in the product.
2. Nature of processing
The Processor collects pseudonymous mobile analytics events. The platform is designed to avoid personal data: identifiers are hashed on device, IP addresses are discarded after coarse geo derivation, and ingest-time guardrails detect and redact PII.
3. Subprocessors
The Processor uses a limited set of subprocessors required to operate the service, such as hosting, authentication, payments, email delivery, monitoring, and optional revenue integrations. A current list is available on request and material changes are notified in advance where required.
4. Security
- Encryption in transit (TLS) and at rest.
- Role-based access control scoped to each organization.
- Ingest keys and API keys stored only as salted hashes.
- Tenant isolation enforced in every server function.
5. Data subject rights & deletion
Because data is pseudonymous, the Controller can satisfy access and deletion requests using the in-product retention settings and the delete-app / delete-organization data flows. Data is purged on the configured retention schedule.
6. International transfers
Where data is transferred across regions, the Processor relies on appropriate safeguards (e.g. Standard Contractual Clauses).
7. Audit
The Controller may request available security documentation and may download privacy audit reports generated from the product where those reports are available.
Contact
DPA and privacy requests: support@appmetricskit.com.