Data Processing Agreement
Last updated: 7 October 2026.
This agreement is part of the Terms of Service between the customer ("controller") and Megametrics ("processor"), for business customers whose use of Megametrics involves personal data under the GDPR, the UK GDPR or similar laws.
Subject and duration
The processor processes personal data only to provide Megametrics to the controller, for as long as the controller's account exists and for up to 30 days after it is deleted.
Nature and purpose
Loading data from the platforms the controller connects, storing it, calculating reports, checks and exports, delivering emails the service needs and answering the controller's questions with the AI analyst.
Data subjects and categories of data
- Data subjects: the controller's users and team members, and people whose email addresses the controller enters as invitees or export recipients.
- Personal data: email addresses, names, roles, sign-in records, and the contents of the controller's projects. Marketing data loaded from the platforms is requested as totals by campaign and channel, not as data about individual website visitors.
Processor obligations
The processor will:
- Process personal data only on the controller's documented instructions, which are the Terms of Service, this agreement and the controller's use of the service.
- Make sure that people authorized to process the data are bound by confidentiality.
- Keep appropriate security measures in place, including encrypted connections, encryption of platform tokens at rest, separation of each workspace's data, role-based access and regular backups.
- Help the controller respond to requests from data subjects. Most requests can be handled directly in the service: correcting the profile, downloading data and deleting the account.
- Notify the controller without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting the controller's data.
- Delete the controller's personal data within 30 days after the account or workspace is deleted, except for backups, which are deleted within 30 days of being made, and records the law requires us to keep.
- Make available the information needed to show compliance with this agreement, on request to aslansakov@gmail.com.
Sub-processors
The controller authorizes the following sub-processors:
- Hetzner Online GmbH, a server in Falkenstein, Germany — hosting, the database and its backups.
- Stripe — payments and subscriptions.
- Resend — email delivery.
- Anthropic — answers of the AI analyst; receives the question and the query results for that question.
The processor will give at least 30 days' notice by email before adding or replacing a sub-processor. The controller may object; if we can't resolve the objection, the controller can cancel and receive a refund for the unused part of a prepaid period.
International transfers
The database is stored in Germany. Stripe, Resend and Anthropic are based in the USA; transfers to them rely on the European Commission's Standard Contractual Clauses, with the UK Addendum for data from the UK.
Liability and order of precedence
The liability terms of the Terms of Service apply. Where this agreement and the Terms of Service conflict on the processing of personal data, this agreement prevails.