Data processing agreement
This agreement will describe how Apsio processes the telemetry your app sends, on your behalf and on your instructions.
This text has not been reviewed by a lawyer yet and is not in force. It describes how Apsio is designed to work, so the final version can be written from it. Placeholders in square brackets are still open.
Roles
Your organization is the controller of the telemetry your apps send. Apsio, operated by [Legal name of the operating company, CNPJ and address], is the processor.
What is processed
Sessions, spans, logs, metrics, crash reports and wireframe replay from your apps, as configured in the SDKs. Users are identified only by a hash your app provides; IP addresses are not stored.
Location
During early access, data is stored in US East. [Transfer mechanism for customers in the EU and Brazil, such as standard contractual clauses.]
Subprocessors
Cloudflare (edge, ingest and object storage), Railway (application servers and databases), Stripe (payments), WorkOS (sign-in), Resend (email) and PostHog (product analytics of the console). [Confirm the list and each one's region before launch.]
Deletion
Data is deleted when its retention ends, when you ask for one user's data to be erased, and after an account closes. [Time limits.]
Security measures
As described on the security page.