Data Processing Agreement

The terms under which Measura processes personal data on your behalf, including our sub-processors and the security measures actually in place.

1. Parties and scope

This Data Processing Agreement (“DPA”) applies between Safli Technologies Ltd (“Processor”, “Measura”) and the customer entity that has accepted the Measura Terms of Service (“Controller”, “you”).

It governs the processing of personal data that Measura carries out on your behalf when you use the Service, and forms part of the Terms of Service. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.

It is written to satisfy Article 28 of the GDPR and the corresponding obligations under Nigeria Data Protection Act 2023 (NDPA).

2. Definitions

Personal data, processing, controller, processor, data subject and supervisory authority carry the meanings given in the GDPR and Nigeria Data Protection Act 2023 (NDPA).

Customer Personal Data means personal data contained in data submitted to the Service by you or collected by the Measura SDK embedded in your applications.

Sub-processor means a third party engaged by Measura to process Customer Personal Data.

3. Roles of the parties

For Customer Personal Data, you are the controller and Measura is the processor. You determine the purposes and means of processing, and you are responsible for the lawfulness of the collection you instruct.

Measura acts as a controller in two limited respects: for account, billing and support data relating to your personnel, and for platform level security and fraud prevention signals evaluated across our customer base. Processing in the controller capacity is described in our Privacy Policy and falls outside this DPA.

4. Processing instructions

Measura processes Customer Personal Data only on your documented instructions. Your instructions comprise this DPA, the Terms of Service, and the configuration choices you make in the Service, including which events you send, which attribution windows you set, and which advertising network postbacks you enable.

Measura will inform you if, in its opinion, an instruction infringes applicable data protection law, and may suspend performance of that instruction until it is amended or confirmed.

Measura will not process Customer Personal Data for its own purposes, will not sell it, and will not use it to build advertising profiles across customers.

5. Confidentiality

Measura ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, and that access is limited to those who require it to deliver or support the Service. Administrative access to customer records is recorded in an append only audit log capturing the actor, the action and the values changed.

6. Security measures

Measura implements the technical and organisational measures set out below. These are the measures actually in place, not aspirations.

MeasureImplementation
Data minimisation at ingestionIP addresses are truncated to a /24 network (IPv4) or /48 block (IPv6) before any database write. No unmasked end user IP address is stored.
Tenant isolationRow level security is enforced by the database on every tenant table, scoped by a server controlled identity claim rather than by application code.
Credential storageAPI keys are stored as SHA-256 hashes. Plaintext keys are displayed once at creation and cannot be recovered.
Request authenticityEvery event carries an HMAC-SHA256 signature computed with a per customer secret. Requests outside a ten minute replay window are rejected.
Secret managementAdvertising network credentials are held in a managed secret vault, referenced by identifier rather than stored in application tables.
Transport securityAll traffic to the Service is over TLS.
Encryption at restProvided by the underlying managed database platform.
Application hardeningContent Security Policy, frame denial, MIME type enforcement, referrer policy, permissions policy and HTTP Strict Transport Security on both dashboards.
Access loggingAppend only audit log of administrative changes, recording prior and new values.
Opt out handlingThe all zero advertising identifier signalling limited ad tracking is discarded rather than stored.

7. Sub-processors

You give general authorisation for Measura to engage the sub-processors listed below. Each is bound by data protection terms no less protective than this DPA.

Sub-processorPurposeData handledLocation
SupabasePrimary platform: Postgres database, authentication, edge functions, object storage and secret vault.All event, device, attribution and account data. This is the principal store.United States (us-west-2, Oregon).
CloudflareHosting, DNS and content delivery for the marketing site and both dashboards. Every page is served from Cloudflare Workers.HTTP request metadata including IP address and user agent at the edge. No event, device or attribution data is stored here.Global edge network.
Google (OAuth)Optional single sign-on for dashboard accounts.Authentication assertion containing email address and profile name.Global.
GitHub (OAuth)Optional single sign-on for dashboard accounts.Authentication assertion containing email address and profile name.United States.
ResendTransactional email delivery for team invitations sent from the dashboard.The invited person’s email address, the inviting team name, the assigned role and the single-use invitation link. No event, device or attribution data.United States.
Google (Play Integrity)Device and app attestation, only for customers who enable integrity checking.The Play Integrity token issued on the device, exchanged for a verdict covering app and device recognition and licensing. No advertising identifier.Global.
Google (Firebase Cloud Messaging)Uninstall detection, only for customers who enable it. Token liveness is checked; no message is delivered to the end user.The FCM registration token for the device.Global.

Changes to the list

Measura will give at least thirty days’ notice before adding or replacing a sub-processor. If you have a reasonable objection on data protection grounds, raise it within that period and we will work in good faith to find an alternative. If none is available you may terminate the affected part of the Service without penalty.

Advertising networks are not sub-processors

Where you enable a postback, the receiving advertising network acts as an independent controller of what it receives, not as our sub-processor. That transfer is made on your instruction and you are responsible for having a lawful basis for it.

8. International transfers

Customer Personal Data is stored in a managed database in the us-west-2 region (Oregon, United States), and may be transferred to and processed in other countries where our sub-processors operate.

Where a transfer involves personal data subject to the GDPR or UK GDPR and the destination is not covered by an adequacy decision, Measura will enter into an approved transfer mechanism with the customer before such data is processed. This means the European Commission’s standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another mechanism approved under the applicable regime, executed as part of this agreement.

9. Assisting with data subject requests

Taking into account the nature of the processing, Measura will assist you in responding to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability and objection.

If a data subject contacts Measura directly about Customer Personal Data, we will refer them to you and will not respond substantively except on your instruction or where legally required.

The developer dashboard provides a form for logging requests. A request must identify the data subject by advertising identifier or device identifier.

10. Personal data breach

Measura will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

Where information is not available at the time of the initial notification, it will be provided in phases as it becomes available.

Notifying a supervisory authority or affected data subjects, where required, remains your responsibility as controller. Measura will provide reasonable assistance.

Report a suspected breach or security issue to privacy@measura.dev.

11. Audits and information rights

Measura will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you appoint.

Audits must be requested with at least thirty days’ notice, occur no more than once per year unless required by a supervisory authority or following a breach, take place during business hours, and not unreasonably disrupt the Service. The auditor must be bound by confidentiality and must not be a competitor of Measura.

As we hold no third party certification to offer in place of an audit, we will respond to reasonable written security questionnaires instead where that meets your requirement.

12. Retention, return and deletion

The Service applies the following automated retention windows.

DataRetentionMechanism
Raw events7 to 90 days, configurableRetention is set per account, defaulting to 14 days on Free and 90 days on paid plans. A job at 04:00 UTC drops whole monthly partitions past the 90 day maximum, and a second job at 04:30 UTC removes rows for accounts on a shorter window. Only events that have completed attribution are removed, so an unprocessed backlog is never discarded.
Derived records (devices, clicks, installs, attributions, fraud flags)90 days minimum, or your raw window if longerA job at 05:00 UTC removes derived records once we have held them past the window. Retention is measured from when we received a record, not when the event occurred, so imported historical attribution is not purged on import. A device is only removed once it has no remaining events or installs.
Operational metrics30 daysA scheduled job deletes older rows daily at 03:00 UTC.
Rate limiting counters1 hourA scheduled job clears expired windows every 15 minutes.
Data subject request exports7 days from generationThe export document assembled for a data subject request is the most concentrated copy of one person’s data we hold, so it is not kept once it has served its purpose. A job at 03:40 UTC deletes any export older than seven days and clears the download reference. Re-submitting the request regenerates it from live data within five minutes.
Closed accounts30 days, then permanent deletionClosing an account stops event collection immediately and starts a 30 day window in which it can be cancelled and fully restored. A job at 02:00 UTC permanently deletes accounts past that window, including apps, devices, events, attribution and your end users’ payment records.
Accounting records after closure6 yearsA minimal record of which plan an account held and over which periods survives closure, because section 375(2) of the Companies and Allied Matters Act 2020 requires accounting records to be preserved for six years. It carries no end user data and no contact details, is not readable by any customer account, and is deleted automatically once the six years elapse.

On termination of the Service, Measura will delete Customer Personal Data within a reasonable period, except where retention is required by law. If you require the return of data in a usable format, request it before terminating, since we do not currently provide a self service bulk export and deletion is not reversible.

13. Liability

The limitations and exclusions of liability in the Terms of Service apply to this DPA, except that nothing limits either party’s liability to a data subject or a supervisory authority under applicable data protection law.

14. Annex: details of processing

Subject matter

Provision of mobile attribution measurement, deep linking, fraud signalling and analytics.

Duration

For the term of the Terms of Service, plus the retention periods set out above.

Nature and purpose

Collection, recording, structuring, storage, matching, scoring, aggregation, transmission to configured advertising networks, and erasure, for the purpose of attributing app installs and events to marketing activity and detecting fraudulent activity.

Categories of data subjects

  • End users of applications operated by the Controller.
  • Personnel of the Controller who hold dashboard accounts.

Categories of personal data

CategoryFields
Device identifiersGoogle Advertising ID (gaid) and Android ID, where a customer chooses to send them. The Measura SDK does not collect either.
Device characteristicsDevice model, operating system name and version, application version, screen resolution, SDK constructed user agent string
Network dataIP address truncated to a /24 or /48 network, HTTP user agent header
Derived identifiersOne way device fingerprint hash and its entropy measure
Behavioural dataEvent type and timestamps, session start and end, purchase value and currency, developer supplied event properties, install referrer string
Attribution dataClick identifier, campaign identifier, channel, confidence score and its derivation, fraud score and flags
Account dataName, business email address and authentication provider identifiers for dashboard users

Special category data. None is requested and none should be sent. Developer supplied event properties are free form and are not inspected by Measura, so the Controller is responsible for ensuring no special category data, financial account numbers, government identifiers or health data is placed in them.

15. Contact and execution

To execute this DPA as a signed agreement, or to raise a question about it, contact privacy@measura.dev.

Safli Technologies Ltd
RC 9615785
Plot 2 Hunkuyi Close, Garki
Abuja, Nigeria

Was this page useful?

AI tools