Skip to content
Legal

Data Processing Agreement

Revenue Sensor reads business reporting data on your behalf. This agreement sets out what we do with it, what we will not do with it, and what you can hold us to.

Last updated: August 27, 2026

01

Scope & Roles

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Controller”) and Revenue Sensor (the “Processor”) and applies wherever we process personal data on your behalf in providing the Service.

You determine the purposes and means of that processing: you choose which ad accounts, apps and revenue sources to connect, and who on your team may see the results. We process that data only to provide the Service to you.

02

Nature of Processing

Categories of data

The Service is built around aggregated business reporting: daily spend, revenue, installs and related counts, broken down by app, country and account. It does not use an SDK, and it does not receive device identifiers, advertising IDs, or event-level data about your end users.

Data subjects

In practice the personal data we process is about your own personnel: the names, email addresses and role assignments of the people you invite into your workspace, together with authentication and audit records for those accounts.

Duration

Processing continues for as long as your account is active. Daily reporting detail is retained for the history window included in your plan; account records are retained until you delete the account.

03

Your Instructions

We process personal data only on your documented instructions, which include the configuration choices you make in the product and the terms of this DPA, unless required otherwise by law. If we believe an instruction infringes applicable data protection law, we will tell you rather than act on it silently.

We do not sell personal data, and we do not use your connected data to build advertising profiles or to train models for other customers.

04

Confidentiality

Access to your data is limited to personnel who need it to operate or support the Service. Those individuals are bound by confidentiality obligations that survive the end of their engagement.

05

Security Measures

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit and of stored credentials at rest.
  • Read-only scopes on every platform connector, so the Service cannot modify campaigns, listings or payouts.
  • Passwordless authentication with device-bound sessions and inactivity expiry.
  • Role-based access control within each workspace.
  • Logical separation of each customer’s data.
  • Regular patching of infrastructure and dependencies.
06

Sub-processors

We use a small number of sub-processors to run the Service — cloud hosting and infrastructure, transactional email delivery, and payment processing. Payment card details are handled entirely by our payment provider and never reach our servers.

You may request the current sub-processor list at any time, and we will give you notice of a new sub-processor before it begins processing your data so that you have the opportunity to object.

07

Data Subject Rights

Taking into account the nature of the processing, we will assist you with your obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability or objection.

Most of these can be satisfied directly in the product: workspace owners can view, change and remove team member records themselves. Where they cannot, contact us and we will help.

08

Incident Notification

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it. The notification will describe what we know, the likely consequences, and the measures taken or proposed.

09

International Transfers

Our infrastructure and sub-processors may process data outside your country of establishment. Where personal data is transferred out of the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) together with supplementary measures appropriate to the transfer.

10

Return & Deletion

On termination of the Service, or on your written request, we will delete the personal data we process on your behalf, except where retention is required by law. Reporting data can be exported to CSV at any time before you close the account.

Our Data Deletion page explains how to make a deletion request and what the timeline looks like.

11

Audits & Evidence

We will make available the information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits conducted by you or an auditor you mandate, on reasonable notice and subject to confidentiality.

12

Requesting a Signed Copy

If your organisation requires a countersigned DPA, or has its own template it needs us to review, email [email protected] with the details. We aim to respond within 5 business days.

This document supplements our Privacy Policy and Terms of Service; where it conflicts with either on the subject of processing personal data on your behalf, this DPA controls.