Data Processing Agreement
Last updated: August 31, 2026
1. Parties and scope
This Agreement is between you (the Controller) and perfbit, a sole proprietorship based in Bengaluru, India (the Processor).
It governs our processing of personal data contained in the performance telemetry your application sends to perfbit, and it forms part of our Terms of Service. By using perfbit you accept this Agreement; no signature is required. If your organisation needs a countersigned copy, email privacy@perfbit.app.
2. Subject matter and nature of processing
We process telemetry solely to provide performance monitoring: receiving events from your application, aggregating them into per-build metrics, and displaying those metrics to you in the dashboard.
Categories of data: timing measurements, frame statistics, screen names, network request origins and paths, crash messages and stack traces, application and OS version, platform, and a randomly generated session identifier.
Data subjects: end users of your application. perfbit does not assign persistent identifiers to individuals and does not receive names, email addresses, contacts, location, or advertising identifiers from the SDK.
Duration: for as long as your subscription is active, subject to the retention windows in our Privacy Policy.
3. Our obligations
We will:
- Process personal data only on your documented instructions, which include your use of the service and this Agreement
- Ensure anyone authorised to process the data is bound by confidentiality
- Implement the technical and organisational measures described in section 5
- Not engage a new sub-processor without updating the list in section 6 and giving you advance notice
- Assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations under Articles 32 to 36 GDPR
- Delete or return all personal data at the end of the service, as described in section 7
- Make available the information reasonably necessary to demonstrate compliance with Article 28
4. Personal data breaches
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notice will describe the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.
We will not require you to wait on our own investigation before you can meet your 72-hour notification deadline under Article 33.
5. Security measures
- Encryption in transit (TLS 1.2 or above) and at rest
- Tenant isolation enforced at the database level through row-level security, so one customer's queries cannot reach another customer's data
- Access to production data limited to personnel who require it to operate the service
- Rate limiting and per-application credentials on the ingestion API
- Redaction of common sensitive patterns in crash data before it leaves your application
- Automated backups of the production database
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed on our sub-processors page.
We will give at least 30 days' notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds within that period, you may terminate your subscription and receive a pro-rata refund of any prepaid, unused fees.
7. Deletion and return
You can export your data at any time, and deleting your account deletes the underlying telemetry. On termination we delete your data in accordance with the retention schedule in our Privacy Policy, except where we are required by law to keep records - for example billing records for tax purposes.
8. International transfers
Where personal data is transferred out of the European Economic Area or the United Kingdom, that transfer is made under the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this Agreement by reference. The sub-processors page records where each provider stores data.
9. Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide the information necessary to demonstrate compliance with this Agreement and cooperate with an audit conducted by you or an independent auditor you appoint, subject to reasonable confidentiality terms.
10. Liability and precedence
Liability under this Agreement is subject to the limitations in our Terms of Service. Where this Agreement conflicts with the Terms of Service on the subject of data protection, this Agreement prevails.
11. Contact
Questions, countersignature requests, or data protection enquiries: privacy@perfbit.app