Legal

Data Processing Agreement

Draft version. This agreement is being finalized and is under legal review. It is published for transparency and may change before it takes effect. Questions? Email hello@measurebase.com.

This Data Processing Agreement ("DPA") is entered into between the customer identified in the applicable Order Form or account registration ("Controller") and:

Dash Forward, trading as Measurebase
Zwanenbloem 57, 6661 LZ Elst (GLD), The Netherlands
Chamber of Commerce (KVK) number: 91017408
("Processor", "Measurebase", "we", "us")

(each a "Party", together the "Parties")

This DPA forms part of, and is incorporated by reference into, the Terms of Service or master subscription agreement between the Parties (the "Principal Agreement"). It applies whenever Measurebase processes Personal Data on the Controller's behalf in the course of providing the Measurebase server-side tagging service (the "Service"). Terms not defined in this DPA have the meaning given in the Principal Agreement.

1. Definitions

1.1. "GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation), as may be amended, extended, or re-enacted.

1.2. "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Article 4 GDPR.

1.3. "Customer Data" means the Personal Data that the Controller (or its own end users, via the Controller's website or app) submits to, or that passes through, the Service — i.e., the tracking events, request metadata, and derived signals described in Annex 1.

1.4. "Sub-processor" means any Processor engaged by Measurebase to carry out specific processing activities on behalf of the Controller as part of the Service.

1.5. "Security Incident" means a Personal Data Breach affecting Customer Data processed by Measurebase as Processor.

2. Subject Matter and Duration

2.1. This DPA governs the Processing of Personal Data by Measurebase as Processor on behalf of the Controller in connection with the Service, as further described in Annex 1.

2.2. This DPA takes effect on the date the Controller first accepts the Principal Agreement or creates a Measurebase account, and remains in effect for as long as Measurebase processes Customer Data on the Controller's behalf, notwithstanding any expiry or termination of the Principal Agreement, until all such Processing has ceased and Customer Data has been returned or deleted in accordance with Section 10.

3. Nature and Purpose of Processing

3.1. Measurebase provides server-side Google Tag Manager hosting: the Controller routes tracking events from its own website or app (pageviews, conversions, and other custom events the Controller's own tag configuration defines) through a tagging server that Measurebase operates on the Controller's behalf, on infrastructure Measurebase hosts and administers.

3.2. Measurebase Processes Customer Data solely to provide, secure, support, and improve the Service, including: receiving and forwarding tracking requests to the destinations the Controller's own Google Tag Manager container configures (e.g. Google Analytics, Google Ads, or other third-party tag endpoints the Controller selects); the optional data-processing features described in Section 3.3 that the Controller may enable or disable at its own discretion; storing request logs for the retention period the Controller's plan provides (Section 8); and monitoring, security, and abuse prevention for the underlying infrastructure.

3.3. Optional processing features. The Service includes several features that change what Measurebase does with the data flowing through it, each independently controllable by the Controller from its own account:

None of these features send Customer Data to a new third-party recipient beyond what the Controller's own Google Tag Manager and Google Analytics/Ads configuration already directs it to — they change what Measurebase's own infrastructure does with the data in transit.

3.4. Measurebase does not sell Customer Data, does not use Customer Data for its own advertising or profiling purposes, and does not process Customer Data for any purpose other than providing the Service, except as required by applicable law.

4. Categories of Data Subjects and Personal Data

4.1. Data Subjects: visitors to, and users of, the Controller's own website(s) or application(s).

4.2. Categories of Personal Data: IP addresses (processed transiently to operate the transport; stored by Measurebase only in anonymized form, and additionally masked before reaching the Controller's tagging container when IP Anonymization is enabled); device, browser, and operating system identifiers; approximate geolocation derived from IP address; first-party cookie identifiers and click identifiers described in Section 3.3; and any other data the Controller's own Google Tag Manager and Google Analytics/Ads configuration chooses to send through the Service. The Controller alone determines what data its own tag configuration collects and transmits — Measurebase's role is limited to hosting the transport layer and the optional processing features described in Section 3.3, and Measurebase has no visibility into, or control over, the Controller's tag configuration decisions.

4.3. Measurebase does not intentionally process special categories of Personal Data (Article 9 GDPR) and instructs the Controller not to configure its tags to transmit such data through the Service.

5. Controller's Instructions

5.1. Measurebase will Process Customer Data only on the Controller's documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by Union or Member State law to which Measurebase is subject — in which case Measurebase will inform the Controller of that legal requirement before Processing, unless the law prohibits this on important grounds of public interest.

5.2. The Principal Agreement, this DPA, and the Controller's own configuration of the Service (including which optional features it enables and which destinations its Google Tag Manager container sends data to) together constitute the Controller's complete instructions to Measurebase for the purposes of Article 28(3)(a) GDPR. Any additional instruction must be agreed in writing and may be subject to additional fees if it requires material additional effort.

5.3. Measurebase will immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

6. Confidentiality

6.1. Measurebase ensures that any person it authorizes to Process Customer Data (including employees, contractors, and Sub-processors) is subject to a binding written obligation of confidentiality, whether contractual or statutory, and Processes Customer Data only on Measurebase's instructions unless required to do otherwise by law.

7. Sub-processors

7.1. The Controller provides general written authorization for Measurebase to engage Sub-processors to support the Service, subject to the conditions in this Section 7.

7.2. Measurebase's current Sub-processors are listed in Annex 2. Each Sub-processor is bound by a written agreement imposing data protection obligations equivalent to those in this DPA.

7.3. Measurebase will give the Controller at least 30 days' notice before adding or replacing a Sub-processor, by email to the Controller's registered account contact. The Controller may object on reasonable data-protection grounds within that notice period; if the Parties cannot resolve the objection, the Controller may terminate the affected part of the Service without penalty.

7.4. Measurebase remains fully liable to the Controller for the performance of a Sub-processor's obligations, to the same extent Measurebase would be liable for its own acts and omissions.

8. Data Retention and Deletion

8.1. Customer Data is retained in three tiers, each shorter-lived than the last. (a) Infrastructure access logs at the ingestion edge are retained for at most 72 hours, and visitor IP addresses in them are anonymized at the point of capture (IPv4 truncated to a /24 network, IPv6 to /56) before being written to disk. (b) Request logs in the Service's database — the tier the dashboard's request-log views read — are retained for the period the Controller's plan provides: 3 days (Free), 7 days (Solo), 14 days (Growth), 21 days (Scale), or 30 days (Business) from the date of the request, or a longer period the Controller has separately arranged, after which they are automatically and permanently deleted. These stored request logs likewise contain only anonymized IP addresses and no request payloads. (c) Beyond those windows, only aggregate daily statistics remain (counts per day by request type, referring site, browser and device class, and bot category), which contain no Personal Data and are retained for the life of the Controller's account.

8.2. The Controller may delete a domain or its account at any time from its own dashboard, subject to the eligibility checks the Service applies (e.g. outstanding invoices). Deletion removes the associated Customer Data from Measurebase's production systems, subject to Section 10 (residual copies in encrypted backups are rotated out and permanently overwritten within seven days for the nightly tier, and on the next release cycle for the off-site copy).

9. Assistance with Data Subject Rights and Compliance Obligations

9.1. Taking into account the nature of the Processing, Measurebase will assist the Controller, insofar as this is possible, by appropriate technical and organizational measures, for the fulfilment of the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR. Because Measurebase has no direct relationship with, and generally cannot independently identify, the Controller's own website visitors, Measurebase expects the Controller to handle Data Subject requests directly using the export, deletion, and configuration tools the Service provides, and will provide reasonable additional assistance on request.

9.2. Measurebase will assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of Processing and the information available to Measurebase.

10. Return or Deletion of Customer Data

10.1. On termination or expiry of the Principal Agreement, and at the Controller's choice, Measurebase will either delete all Customer Data (including existing copies) or make it available for export by the Controller within a reasonable period, unless Union or Member State law requires continued storage.

10.2. The Controller can export its own request logs as CSV at any time before deletion via the Service's own export tools, for whatever retention window its plan still covers.

10.3. Residual copies of deleted Customer Data may persist briefly in encrypted backups: the nightly backup rotation overwrites them within seven days, and the single off-site copy is replaced on each release cycle. Measurebase does not restore or otherwise process such residual copies except to recover from a system failure.

11. Audits and Information

11.1. Measurebase will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

11.2. Given the operational and security sensitivity of allowing physical or system-level audits across Measurebase's shared infrastructure, Measurebase may satisfy this obligation, in the first instance, by providing: (a) a written summary of the technical and organizational measures in Annex 3; (b) any relevant third-party certification, audit report, or penetration test summary then available; and (c) written responses to the Controller's reasonable security questionnaire. On-site or system-level audits, where the above is insufficient, will be scheduled with reasonable advance notice, no more than once every 12 months absent a Security Incident or a Supervisory Authority requirement, at the Controller's own expense, and subject to confidentiality obligations protecting other customers' data and Measurebase's security posture.

12. Personal Data Breach Notification

12.1. Measurebase will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Data.

12.2. That notification will describe, to the extent then known: the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and Customer Data records concerned; the likely consequences; and the measures taken or proposed to address it, including to mitigate its possible adverse effects. Where full information is not available within the initial notification, Measurebase will provide it in phases without further undue delay as it becomes available.

12.3. Measurebase will cooperate with the Controller and take reasonable commercial steps as directed by the Controller to assist in the investigation, mitigation, and remediation of a Security Incident.

13. Security Measures

13.1. Measurebase implements the technical and organizational measures described in Annex 3, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of natural persons.

14. International Transfers

14.1. All Service infrastructure that Processes Customer Data is located in a single EU region: Amsterdam, the Netherlands. Customer Data does not leave the European Union in the ordinary course of providing the Service.

14.2. Where a Sub-processor listed in Annex 2 Processes Customer Data outside the European Economic Area, Measurebase ensures that transfer is subject to an appropriate safeguard under Chapter V GDPR (e.g. the European Commission's Standard Contractual Clauses, or an adequacy decision), details of which are available on request.

15. Liability

15.1. Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.

16. Term and Termination

16.1. This DPA takes effect and terminates automatically alongside the Principal Agreement, and survives termination to the extent needed to give effect to Sections 8, 10, 11, and 12.

17. Miscellaneous

17.1. This DPA is governed by the laws of the Netherlands, without regard to conflict-of-law principles, consistent with the Principal Agreement.

17.2. In the event of a conflict between this DPA and the Principal Agreement regarding the Processing of Personal Data, this DPA prevails.

17.3. If any provision of this DPA is found unenforceable, the remaining provisions remain in full force, and the unenforceable provision is replaced with one that most closely reflects the Parties' original intent.

Annex 1 — Details of Processing

Subject matterProvision of the Measurebase server-side Google Tag Manager hosting service
DurationFor the term of the Principal Agreement, per Section 2.2
Nature and purposeReceiving, routing, optionally enriching/masking/filtering (per the Controller's own configuration), and logging tracking requests from the Controller's website/app to the destinations the Controller's own tag configuration specifies
Categories of Data SubjectsVisitors to and users of the Controller's website(s)/app(s)
Categories of Personal DataIP addresses (stored only in anonymized form; masked before reaching the Controller's container where IP Anonymization is enabled), device/browser/OS identifiers, approximate geolocation, first-party cookie and click identifiers, and any other data the Controller's own tag configuration transmits
Special categories of dataNone intentionally processed; the Controller must not configure tags to transmit special category data through the Service
Frequency of processingContinuous, for the duration of the Service

Annex 2 — Sub-processors

Sub-processorPurposeLocationData processed
TransIP B.V. Infrastructure hosting for the tagging server and database The Netherlands (Amsterdam region) All Customer Data described in Annex 1
Stripe Payments Europe, Limited Payment processing for the Controller's own subscription billing Ireland (certain processing by Stripe affiliates in the United States, subject to Chapter V safeguards) Billing contact and payment details only — not Customer Data
AC PM, LLC (Postmark) Delivery of account and alert emails United States (transfer safeguarded by Standard Contractual Clauses incorporated in Postmark's own Data Processing Addendum) Account contact email address; alert content does not include Customer Data

This list reflects sub-processors as of 28 July 2026 and is kept up to date per Section 7.3's notice mechanism.

Annex 3 — Technical and Organizational Security Measures