GDPR compliance

Last updated: August 15, 2026

1. The short version

Kometrics is built so that both sides of the GDPR relationship work: we comply with it for the data we control, and the product is designed so you can stay compliant while using it for the data you control. As a Brazilian company we follow the LGPD too, which mirrors the GDPR on everything this page covers.

2. Our roles

For your account data (name, email, workspace settings) we are the controller. For the billing data you import, you are the controller and we are your processor: we act only on your instructions, as set out in the Data Processing Agreement, which is part of the Terms of Service. No separate signature is needed; it applies to every workspace automatically.

3. Lawful bases

We process data to perform the contract (computing the metrics you signed up for), on legitimate interest (keeping the service secure, knowing which channels bring signups), and on consent where the law requires it. We do not sell personal data and we do not run advertising trackers; analytics on this site is cookieless.

4. Data minimization by design

Access to your billing providers is read-only and we import only what the metrics need. Privacy mode goes further: customer names are replaced by irreversible pseudonyms and emails are dropped at ingest, keyed by a per-workspace secret, so your metrics work with no personal data at rest. Deleting that secret makes the pseudonyms permanently unlinkable, which is deletion in its strongest form.

5. Data subject rights

Access, correction, export, deletion and objection, within the legal deadlines. For your account data, write to privacy@kometrics.com. For the billing data you imported, requests from your customers go to you as the controller, and we assist: deleting a customer, a source or the whole workspace propagates within 30 days.

6. Subprocessors and transfers

Every provider that can touch personal data is listed in the Data Processing Agreement, with what each one receives. Most processing happens in the United States, relying on the safeguards in each provider's data processing terms, including standard contractual clauses where they apply. We update the list before a new subprocessor starts handling personal data.

7. If something goes wrong

If a breach affects personal data we process for you, we notify you without undue delay with what we know, so you can meet your own notification duties.

8. Questions

The details live in the Privacy Policy and the Data Processing Agreement. Anything else: privacy@kometrics.com.