Skip to content
Legal

Data Processing Agreement

When you connect an ad network or a revenue source, ROASSensor processes data on your behalf. This agreement sets out what we do with it, what we don't, and the commitments we make as your processor.

Last updated: September 9, 2026

01

Overview

This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Controller”) and ROASSensor (the “Processor”) for use of the Service. It applies wherever we process personal data on your behalf, and it takes effect automatically when you connect a data source, so there is nothing to sign.

Terms not defined here carry the meaning given in our Terms of Service and Privacy Policy. Where this DPA conflicts with those documents on a question of data processing, this DPA governs.

02

Roles of the Parties

You are the Controller: you decide which ad networks and revenue sources to connect and for what purpose. We are the Processor: we act only on your documented instructions, and connecting a source in your workspace is such an instruction.

For our own business records (your account, billing, and support history), we act as a Controller in our own right, and that processing is described in the Privacy Policy rather than here.

03

Subject Matter and Duration

We process personal data in order to provide the Service: syncing spend and revenue from the platforms you authorize, reconciling the two, attributing revenue to campaigns and creatives, and presenting the result in your dashboard.

Processing lasts as long as your account is active. When you disconnect a source, delete your account, or the agreement ends, the retention and deletion terms below apply.

04

Categories of Data and Data Subjects

The personal data we process on your behalf is limited to what the Service needs to compute attribution. Depending on the sources you connect, it may include:

  • Pseudonymous identifiers: visitor ids, click ids, session ids, and device or app identifiers collected by the tracking snippet or SDK.
  • Hashed contact identifiers: email addresses and phone numbers are normalized and hashed before they enter our tracking tables; we do not store them in the clear.
  • Technical data: IP address, user agent, referrer, and page or screen viewed.
  • Transaction data: order identifiers, amounts, currency, and refund status received from your payment processor or reported by your server.

The data subjects are the visitors, app users, and customers of the Controller. We do not knowingly process special categories of personal data, and the Service should not be used to send us any.

05

Our Obligations as Processor

We process personal data only on your documented instructions, including for international transfers, unless required otherwise by law, in which case we will tell you before processing, unless that law forbids it.

We ensure that personnel authorized to process personal data are bound by confidentiality, and we limit access to those who need it to operate or support the Service.

We do not sell personal data, and we do not use the data we process on your behalf to build or improve products for anyone else. Aggregated, de-identified statistics that cannot reasonably be linked back to you or any data subject are the only exception.

06

Security Measures

We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest for sensitive fields, scoped and revocable access tokens for connected platforms, role-based access control within a workspace, and least-privilege access internally.

Access tokens for connected sources are stored encrypted and are used read-only: we do not post to, or modify anything in, your connected accounts.

07

Sub-processors

You give general authorization for us to engage sub-processors to provide the Service, for example cloud hosting, email delivery, error monitoring, and payment processing.

Every sub-processor is bound by written terms imposing data-protection obligations no less protective than those in this DPA, and we remain responsible to you for their performance. We will give you notice of any intended addition or replacement of a sub-processor, and you may object on reasonable data-protection grounds.

08

International Transfers

We may process and store personal data in countries other than your own. Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the Standard Contractual Clauses, together with any additional measures the transfer requires.

09

Assisting with Data Subject Requests

Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures in responding to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, or objection.

Where a data subject contacts us directly about data we process on your behalf, we will not respond substantively; we will refer them to you, and tell you promptly.

Erasure for an individual can be requested at any time and is described on our Data Deletion page.

10

Personal Data Breach

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and will provide the information you reasonably need to meet your own notification obligations.

Notification is not an acknowledgement of fault or liability.

11

Audits and Information

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by you or an auditor you mandate.

To keep audits proportionate, we may satisfy a request by providing existing documentation or third-party reports where these reasonably answer it. Audits are at your expense, during business hours, subject to confidentiality, and no more than once a year unless required by a supervisory authority or following a breach.

12

Return and Deletion

Disconnecting a source deletes that source's stored access token, stops further syncing, and removes the metrics synced from it. Deleting your account removes your profile, every connected source and its tokens, and your synced metrics.

On termination we delete or return personal data processed on your behalf, except where storage is required by law. Residual copies may persist briefly in encrypted backups and are overwritten on our normal backup rotation.

13

Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

14

Contact Us

Questions about this DPA, or a request to execute a countersigned copy for your records? Email us at [email protected] and we'll be glad to help.