BrekkyMetrics data processing addendum
A processor addendum in plain language. It matches the privacy policy. This is a public HTML page, not a PDF.
This addendum sits with the Terms of service for the contracting entity named in those terms. The privacy policy is the source of truth for what we collect.
Roles
If you use BrekkyMetrics on a site or app you control, you are the controller for visitor events. We (BrekkyMetrics) are the processor. We process that data to provide the dashboard, prevent abuse, and bill plans.
Instructions
You instruct us by creating a project, installing the tracker or an SDK, sending events, inviting teammates, and using the dashboard. We only process visitor events as needed to run that service.
Confidentiality
We treat visitor events and account data as confidential. Access is limited to people who need it to operate the product or to respond to you.
Subprocessors
We use subprocessors listed on /subprocessors. Today that includes Supabase (database, auth, infra), Stripe (billing for paid plans), and Resend (transactional email).
Security
Traffic uses HTTPS. Hosting is described on /security. We do not sell visitor data. We do not run ads against it.
Deletion
Event history follows your plan retention. If you close the account, we delete or anonymize project data on a reasonable schedule unless law requires we keep it. Email hello@brekkymetrics.com to request deletion.