Data Processing Agreement
The terms under which Measura processes personal data on your behalf, including our sub-processors and the security measures actually in place.
1. Parties and scope
This Data Processing Agreement (“DPA”) applies between Safli Technologies Ltd (“Processor”, “Measura”) and the customer entity that has accepted the Measura Terms of Service (“Controller”, “you”).
It governs the processing of personal data that Measura carries out on your behalf when you use the Service, and forms part of the Terms of Service. Where this DPA conflicts with the Terms of Service on a data protection matter, this DPA prevails.
It is written to satisfy Article 28 of the GDPR and the corresponding obligations under Nigeria Data Protection Act 2023 (NDPA).
2. Definitions
Personal data, processing, controller, processor, data subject and supervisory authority carry the meanings given in the GDPR and Nigeria Data Protection Act 2023 (NDPA).
Customer Personal Data means personal data contained in data submitted to the Service by you or collected by the Measura SDK embedded in your applications.
Sub-processor means a third party engaged by Measura to process Customer Personal Data.
3. Roles of the parties
For Customer Personal Data, you are the controller and Measura is the processor. You determine the purposes and means of processing, and you are responsible for the lawfulness of the collection you instruct.
Measura acts as a controller in two limited respects: for account, billing and support data relating to your personnel, and for platform level security and fraud prevention signals evaluated across our customer base. Processing in the controller capacity is described in our Privacy Policy and falls outside this DPA.
4. Processing instructions
Measura processes Customer Personal Data only on your documented instructions. Your instructions comprise this DPA, the Terms of Service, and the configuration choices you make in the Service, including which events you send, which attribution windows you set, and which advertising network postbacks you enable.
Measura will inform you if, in its opinion, an instruction infringes applicable data protection law, and may suspend performance of that instruction until it is amended or confirmed.
Measura will not process Customer Personal Data for its own purposes, will not sell it, and will not use it to build advertising profiles across customers.
5. Confidentiality
Measura ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, and that access is limited to those who require it to deliver or support the Service. Administrative access to customer records is recorded in an append only audit log capturing the actor, the action and the values changed.
6. Security measures
Measura implements the technical and organisational measures set out below. These are the measures actually in place, not aspirations.
| Measure | Implementation |
|---|---|
| Data minimisation at ingestion | IP addresses are truncated to a /24 network (IPv4) or /48 block (IPv6) before any database write. No unmasked end user IP address is stored. |
| Tenant isolation | Row level security is enforced by the database on every tenant table, scoped by a server controlled identity claim rather than by application code. |
| Credential storage | API keys are stored as SHA-256 hashes. Plaintext keys are displayed once at creation and cannot be recovered. |
| Request authenticity | Every event carries an HMAC-SHA256 signature computed with a per customer secret. Requests outside a ten minute replay window are rejected. |
| Secret management | Advertising network credentials are held in a managed secret vault, referenced by identifier rather than stored in application tables. |
| Transport security | All traffic to the Service is over TLS. |
| Encryption at rest | Provided by the underlying managed database platform. |
| Application hardening | Content Security Policy, frame denial, MIME type enforcement, referrer policy, permissions policy and HTTP Strict Transport Security on both dashboards. |
| Access logging | Append only audit log of administrative changes, recording prior and new values. |
| Opt out handling | The all zero advertising identifier signalling limited ad tracking is discarded rather than stored. |
7. Sub-processors
You give general authorisation for Measura to engage the sub-processors listed below. Each is bound by data protection terms no less protective than this DPA.
| Sub-processor | Purpose | Data handled | Location |
|---|---|---|---|
| Supabase | Primary platform: Postgres database, authentication, edge functions, object storage and secret vault. | All event, device, attribution and account data. This is the principal store. | United States (us-west-2, Oregon). |
| Cloudflare | Hosting, DNS and content delivery for the marketing site and both dashboards. Every page is served from Cloudflare Workers. | HTTP request metadata including IP address and user agent at the edge. No event, device or attribution data is stored here. | Global edge network. |
| Google (OAuth) | Optional single sign-on for dashboard accounts. | Authentication assertion containing email address and profile name. | Global. |
| GitHub (OAuth) | Optional single sign-on for dashboard accounts. | Authentication assertion containing email address and profile name. | United States. |
| Resend | Transactional email delivery for team invitations sent from the dashboard. | The invited person’s email address, the inviting team name, the assigned role and the single-use invitation link. No event, device or attribution data. | United States. |
| Google (Play Integrity) | Device and app attestation, only for customers who enable integrity checking. | The Play Integrity token issued on the device, exchanged for a verdict covering app and device recognition and licensing. No advertising identifier. | Global. |
| Google (Firebase Cloud Messaging) | Uninstall detection, only for customers who enable it. Token liveness is checked; no message is delivered to the end user. | The FCM registration token for the device. | Global. |
Changes to the list
Measura will give at least thirty days’ notice before adding or replacing a sub-processor. If you have a reasonable objection on data protection grounds, raise it within that period and we will work in good faith to find an alternative. If none is available you may terminate the affected part of the Service without penalty.
Advertising networks are not sub-processors
Where you enable a postback, the receiving advertising network acts as an independent controller of what it receives, not as our sub-processor. That transfer is made on your instruction and you are responsible for having a lawful basis for it.
8. International transfers
Customer Personal Data is stored in a managed database in the us-west-2 region (Oregon, United States), and may be transferred to and processed in other countries where our sub-processors operate.
Where a transfer involves personal data subject to the GDPR or UK GDPR and the destination is not covered by an adequacy decision, Measura will enter into an approved transfer mechanism with the customer before such data is processed. This means the European Commission’s standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another mechanism approved under the applicable regime, executed as part of this agreement.
9. Assisting with data subject requests
Taking into account the nature of the processing, Measura will assist you in responding to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability and objection.
If a data subject contacts Measura directly about Customer Personal Data, we will refer them to you and will not respond substantively except on your instruction or where legally required.
The developer dashboard provides a form for logging requests. A request must identify the data subject by advertising identifier or device identifier.
10. Personal data breach
Measura will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
Where information is not available at the time of the initial notification, it will be provided in phases as it becomes available.
Notifying a supervisory authority or affected data subjects, where required, remains your responsibility as controller. Measura will provide reasonable assistance.
Report a suspected breach or security issue to privacy@measura.dev.
11. Audits and information rights
Measura will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you appoint.
Audits must be requested with at least thirty days’ notice, occur no more than once per year unless required by a supervisory authority or following a breach, take place during business hours, and not unreasonably disrupt the Service. The auditor must be bound by confidentiality and must not be a competitor of Measura.
As we hold no third party certification to offer in place of an audit, we will respond to reasonable written security questionnaires instead where that meets your requirement.
12. Retention, return and deletion
The Service applies the following automated retention windows.
| Data | Retention | Mechanism |
|---|---|---|
| Raw events | 7 to 90 days, configurable | Retention is set per account, defaulting to 14 days on Free and 90 days on paid plans. A job at 04:00 UTC drops whole monthly partitions past the 90 day maximum, and a second job at 04:30 UTC removes rows for accounts on a shorter window. Only events that have completed attribution are removed, so an unprocessed backlog is never discarded. |
| Derived records (devices, clicks, installs, attributions, fraud flags) | 90 days minimum, or your raw window if longer | A job at 05:00 UTC removes derived records once we have held them past the window. Retention is measured from when we received a record, not when the event occurred, so imported historical attribution is not purged on import. A device is only removed once it has no remaining events or installs. |
| Operational metrics | 30 days | A scheduled job deletes older rows daily at 03:00 UTC. |
| Rate limiting counters | 1 hour | A scheduled job clears expired windows every 15 minutes. |
| Data subject request exports | 7 days from generation | The export document assembled for a data subject request is the most concentrated copy of one person’s data we hold, so it is not kept once it has served its purpose. A job at 03:40 UTC deletes any export older than seven days and clears the download reference. Re-submitting the request regenerates it from live data within five minutes. |
| Closed accounts | 30 days, then permanent deletion | Closing an account stops event collection immediately and starts a 30 day window in which it can be cancelled and fully restored. A job at 02:00 UTC permanently deletes accounts past that window, including apps, devices, events, attribution and your end users’ payment records. |
| Accounting records after closure | 6 years | A minimal record of which plan an account held and over which periods survives closure, because section 375(2) of the Companies and Allied Matters Act 2020 requires accounting records to be preserved for six years. It carries no end user data and no contact details, is not readable by any customer account, and is deleted automatically once the six years elapse. |
On termination of the Service, Measura will delete Customer Personal Data within a reasonable period, except where retention is required by law. If you require the return of data in a usable format, request it before terminating, since we do not currently provide a self service bulk export and deletion is not reversible.
13. Liability
The limitations and exclusions of liability in the Terms of Service apply to this DPA, except that nothing limits either party’s liability to a data subject or a supervisory authority under applicable data protection law.
14. Annex: details of processing
Subject matter
Provision of mobile attribution measurement, deep linking, fraud signalling and analytics.
Duration
For the term of the Terms of Service, plus the retention periods set out above.
Nature and purpose
Collection, recording, structuring, storage, matching, scoring, aggregation, transmission to configured advertising networks, and erasure, for the purpose of attributing app installs and events to marketing activity and detecting fraudulent activity.
Categories of data subjects
- End users of applications operated by the Controller.
- Personnel of the Controller who hold dashboard accounts.
Categories of personal data
| Category | Fields |
|---|---|
| Device identifiers | Google Advertising ID (gaid) and Android ID, where a customer chooses to send them. The Measura SDK does not collect either. |
| Device characteristics | Device model, operating system name and version, application version, screen resolution, SDK constructed user agent string |
| Network data | IP address truncated to a /24 or /48 network, HTTP user agent header |
| Derived identifiers | One way device fingerprint hash and its entropy measure |
| Behavioural data | Event type and timestamps, session start and end, purchase value and currency, developer supplied event properties, install referrer string |
| Attribution data | Click identifier, campaign identifier, channel, confidence score and its derivation, fraud score and flags |
| Account data | Name, business email address and authentication provider identifiers for dashboard users |
Special category data. None is requested and none should be sent. Developer supplied event properties are free form and are not inspected by Measura, so the Controller is responsible for ensuring no special category data, financial account numbers, government identifiers or health data is placed in them.
15. Contact and execution
To execute this DPA as a signed agreement, or to raise a question about it, contact privacy@measura.dev.
Safli Technologies Ltd
RC 9615785
Plot 2 Hunkuyi Close, Garki
Abuja, Nigeria
AI tools
